Foundation
The full platform. Every feature your security depends on.
- Authentication
- Passwordless sign-in (FIDO2 & WebAuthn passkeys) Cryptographic sign-in — users authenticate with a device-bound key instead of a password.
- Biometric & device-based verification Touch ID, Face ID, Windows Hello, or a hardware security key — no shared secret leaves the device.
- Authenticator validated against a global registry Every authenticator is checked against the FIDO Alliance registry so only trusted, certified hardware can sign in.
- Unlimited connected apps Connect any number of applications using modern sign-on protocols — no per-app licensing.
- Lifecycle & management
- Trustaige ID Hub — single admin console Manage users, applications, and policies from one unified console.
- Unlimited users No caps on directory size — invite your full workforce, contractors, and partners.
- Groups, dynamic membership, access management Auto-assign users to groups based on attributes and grant app access through group membership.
- Directory sync, inbound & outbound Sync users automatically between Trustaige, your HR system, and downstream apps.
- Bulk user import & app templates Onboard hundreds of users from a CSV and configure popular apps with ready-made integration templates.
- Microsoft Entra ID integration Federate with or migrate from Microsoft Entra without disrupting existing users or apps.
- Security & access control
- Device-bound passkey enforcement Require non-syncable hardware-bound passkeys — the highest-assurance phishing-resistant credential.
- Threat detection — new device, impossible travel Automatically flag sign-ins from unrecognised devices or geographically impossible locations.
- Access policies — geo-fencing, time-based, network Restrict who can sign in by country, IP range, time of day, or device posture.
- Custom roles & fine-grained permissions Define your own admin and user roles so each team only sees and changes what it should.
- Access reviews & entitlement reports Schedule periodic certifications of who has access to what, with audit-ready exports.
- Device trust
- Trustaige Envoy agent (device trust) A lightweight agent that proves device identity at sign-in — only trusted devices reach sensitive resources.
- Audit & integrations
- Analytics dashboard & compliance reporting Visualise sign-in activity, device health, failed attempts, and compliance posture in real time.
- Audit log export (5 industry-standard formats) Export every event in the formats your security and audit tools already read.
- Webhook automation & Admin API Trigger downstream automations on identity events and manage everything programmatically.
- Encrypted vault — per-org isolated storage Each tenant's secrets and credentials live in a dedicated, encrypted store — no cross-tenant blending.
- Support
- Email support — 24-hour first response A real engineer responds within one business day for any question.