Identity data deserves identity-grade security.
We hold your organisation's identity data, so we treat security as part of the product, not an add-on. Here is how we protect it, in six pillars.
Your data is kept separate from every other customer’s.
Each organisation’s identity data is held in its own separate store, not mixed in with anyone else’s. Every request is checked against the organisation it belongs to before any data is returned.
- A separate data store for each customer
- Every request checked against your organisation
- Your rules and settings apply to you alone
Your data, credentials and settings are held apart from other customers'.
The credentials we use on your behalf are locked away.
The credentials IDFusion uses to connect to your HR system and your Microsoft tenant are held in a dedicated, encrypted credential store for your organisation. They are retrieved only when a task needs them and are never stored in code or configuration files.
- A dedicated, encrypted credential store for each customer
- Retrieved only when a task needs them
- Never stored in code or configuration files
Held in a dedicated store for your organisation and used only when a task needs them.
Your team signs in with your own Microsoft identity.
People sign in to IDFusion with their existing Entra ID accounts, so your multi-factor authentication and Conditional Access policies apply. There are no separate IDFusion passwords to issue or reset, and every request is authenticated and tied to your organisation.
- Sign in with your organisation’s Entra ID
- Your MFA and Conditional Access policies apply
- No separate passwords to issue or reset
- Portal access controlled by roles you assign
Requests are verified before they reach your data.
Evidence for every access decision.
IDFusion records what changed, what caused it and what happened next — from the HR import through to the account and access in Entra ID. When auditors ask who got access and why, you can show them.
- Change history for every identity
- Provisioning log for every attempt, including failures
- Import log for every HR connection
- An auditor view for compliance reviewers
What changed, what caused it and what happened next.
Encrypted, privately networked and hosted in Australia.
Data is encrypted in transit and at rest. The data stores behind IDFusion are not reachable from the public internet, and the platform is hosted in Australia on Microsoft Azure.
- Encrypted in transit and at rest
- Data stores not reachable from the public internet
- Hosted in Australia
Discipline in how the platform is run.
Production access is restricted, time-bound and logged. The platform is independently penetration tested, with backups and disaster recovery in place. Availability and recovery commitments are set out in your agreement.
- Production access is restricted, time-bound and logged
- Independently penetration tested
- Backups and disaster recovery in place
- Availability and recovery commitments set out in your agreement
- Security questionnaires completed on request
Built for the questions your auditors ask.
Our controls are designed to align with SOC 2 and ISO 27001, and we complete security questionnaires on request.
Our controls
Our controls are designed to align with SOC 2 and ISO 27001.
Our infrastructure
Hosted on Microsoft Azure, which holds certifications including ISO 27001, SOC 2 and IRAP.
Who builds it
Built by Increment, a Microsoft Solutions Partner holding designations across every Microsoft Cloud solution area.
Your privacy
Privacy by design — handled in line with the Australian Privacy Principles and, where it applies, the GDPR.
Read our privacy policy →Put our security posture in front of your team.
Bring your security or compliance lead to the demo — we'll walk through our controls, the audit evidence and how your data is kept separate. Security questionnaires are completed on request.