Enterprise
Organization-controlled identity, on the phone.
No passwords, no accounts at a broker, and your own index: a dedicated OpenID Provider for your organization, run by us in our cloud or by you inside your boundary. Available today.
What you get
-
Own it
A dedicated index with its own issuer, signing keys and Postgres, at {tenant}.index.identizen.com in the US or the EU, or inside your boundary. Sites, identities, devices and audit events exist only there, and a token minted by any other issuer is rejected.
In the docs -
Control who signs in
Invite by email and role. Enroll phones by link, QR or MDM and approve them by policy or by hand. Require managed devices, a biometric class, login windows and a session age. Suspend or deprovision a member and every session ends everywhere, with back-channel logout.
In the docs -
Plug into what you have
Register your own applications as OIDC clients, serve SAML 2.0 to the ones that need it, and provision members from Okta or Entra over SCIM 2.0. Intune and Jamf recipes for enrollment; every SDK and guide works unchanged against your issuer.
In the docs -
Prove it
Every login, denial, enrollment, session and revocation is an audit event. Export as CSV or JSON, stream to your SIEM over webhooks signed with the tenant key, set retention per log, and read a status page with quotas, job runs and health.
In the docs
Cloud or on-prem
Same code, two places to run it
Everything documented for Identizen Cloud applies to on-prem unchanged. Choose by where the database has to live and who you want operating it.
Provisioned by us
Identizen Cloud
A tenant index per organization, operated by Identizen on the same code as the public index.
- Issuer, JWKS and challenge key of your own, sealed at provisioning
- Dedicated Postgres in the US or the EU, never moved
- Portal at {tenant}.portal and org app at {tenant}.app, already registered
- Key rotation with overlap, run by Identizen
- Standard or dedicated plan
Installed with us
On-prem
The same edition packaged as signed containers for a pilot with Compose or production with Helm.
- Images signed keyless with Sigstore, with an SPDX SBOM attestation
- A compose bundle for pilots; a Helm chart with a migration Job for production
- One Postgres, two keys you generate, one signed license with seat count and 14-day grace
- Nothing phones home; air-gapped installs pull from your registry
- Backup, restore and upgrade runbooks in the release bundle
Need the index inside your boundary without the enterprise layer? Self-hosting the open index is supported today, free, with no license. See the self-hosting guide and pricing.
How an install goes
White-glove, four steps
There is no self-serve sign-up. We provision, you invite, phones enroll, apps connect.
-
01
We provision
Send us a slug, a display name, an admin contact and a residency. We create the tenant, its keys and its database, and hand your admin contact the registration token and the first owner invitation out of band. On-prem, we install alongside you and the bootstrap prints the invitation once.
-
02
You invite your first owner
The owner enrolls a phone on your index, opens the invitation and accepts. From the portal they invite administrators, helpdesk, auditors and members by email and role, and verify your domains.
-
03
Enroll phones
Each person gets a one-time enrollment link or QR code, issued from the portal, from the org app, or by your MDM. The phone shows the organization, registers on your index and is approved by policy or in the Approvals queue.
-
04
Connect apps
Register your sites and apps as OIDC clients, add SAML apps, turn on SCIM. Point any SDK at your issuer and the quickstart works as written.
Security posture
What the org never gets
The index holds public keys, push tokens, revocation state and audit events, and nothing that could sign for a person; that is true of the public index, of a tenant index and of an on-prem install. Private keys are generated on the phone and never leave it. The organization can enroll, disable and revoke devices, and policy can refuse a login; neither can approve one, and neither the organization nor Identizen can log in as a user. On-prem images are signed with Sigstore and ship with SBOMs, and nothing phones home. The rest of the design, and the risks we still accept, are on the security page.
Want a tenant index?
Tell us the slug, the region and who your first owner is. You are billed monthly per active device, by card through Stripe or by invoice, on a standard or dedicated plan.