Security & compliance

Security you can prove.

FAPI-grade token binding, sender-constrained tokens, per-realm keys, and a searchable audit trail that streams to your SIEM. Built to open standards, hardened for regulated industries.

Hardened tokens

Sender-constrained tokens (DPoP), mTLS certificate binding, and FAPI client policies stop token replay and theft cold — the controls banks and health systems require.

  • FAPI client policies
  • DPoP (RFC 9449)
  • mTLS certificate-bound tokens
  • Request objects / JARM

Keys you control

Per-realm signing keys with zero-downtime rotation, Argon2id password hashing, and a clean cryptographic story from the ground up.

  • Per-realm KMS/HSM keys
  • Zero-downtime rotation
  • Argon2id password hashing
  • PKCS#11 support

Everything is audited

A persisted, searchable audit log records every authentication and admin action — and streams to your SIEM via signed webhooks and an event-listener SPI.

  • Searchable audit log
  • SIEM streaming (HTTP forwarder)
  • HMAC-signed outbound webhooks
  • Admin impersonation trail

Privacy & governance

GDPR rights tooling, fine-grained admin RBAC, brute-force protection, and required-actions give you provable control over who can do what.

  • GDPR rights tooling
  • Fine-grained admin RBAC
  • Brute-force & lockout policy
  • Password policy + HIBP checks

See HelixIAM on your own stack.

A 30-minute demo: realms, agents, workload identity, and a live migration off Keycloak — mapped to your use case.

No credit card. Self-hostable. Engineered in Europe.