ISO/IEC 27001
Information Security Management System (ISMS). Azure’s certification underpins secure operations, controls, and continuous improvement.
AzureOur platform is built on Microsoft Azure and aligns with AAMVA guidance for DL/ID style credentials.
Below is a concise overview of the frameworks and standards we rely on.
All ID PaaS services run on Azure. Azure maintains third party attestations and certifications across numerous global and sector standards. Here are key highlights our customers care about most.
Information Security Management System (ISMS). Azure’s certification underpins secure operations, controls, and continuous improvement.
AzureIndependent audit of security, availability, confidentiality, and related controls across Azure services.
AzurePrivacy Information Management extension to ISO 27001, supports robust governance of personal data.
AzurePublic cloud controls for protecting personally identifiable information (PII) in cloud environments.
AzureAzure offerings include FedRAMP authorizations used by U.S. public sector workloads (program and boundary dependent).
AzureAzure supports law enforcement workloads via CJIS aligned controls and agreements (jurisdiction dependent).
AzureAzure enters into BAAs and provides guidance for handling ePHI on the platform when configured appropriately.
AzureAzure provides PCI DSS validated services used to build cardholder data environments when required.
AzureAzure provides tools, DPAs, and features to help controllers/processors meet privacy obligations.
AzureImportant: These certifications/attestations are held by Microsoft for Azure services. Your program’s compliance depends on configuration and shared responsibility controls across Azure, ID PaaS, and your organization. Formal evidence can be provided upon request.
For jurisdictions and programs that model U.S. driver license/ID credentials, we implement features aligned to AAMVA guidance.
Layout and data element guidance (portrait placement, mandatory/optional fields) for interoperable, verifiable cards.
AAMVABest practice physical security features (e.g., OVDs, microtext, UV) and supplier guidance to deter fraud and tampering.
AAMVANote: AAMVA does not “certify” products. We implement card designs and data structures consistent with published AAMVA guidance and specific program requirements.
Azure provides certified infrastructure; ID PaaS secures the platform and production workflow; your agency defines issuance policies and approvals.