CSA STAR Level 1
PublishedRead NamoID’s completed CAIQ v4.1 security and privacy answers in the public CSA registry.
Public self-assessment — not an independent audit
Open the public recordProduct
Customer IdentityPublic beta · Hosted customer authenticationMCP AuthorizationDeveloper preview · Scoped AI-client accessAgent AccessDesign partner · External provider accessWorkforce IdentityDesign partner · Employee lifecycle and SSODevelopers
OverviewHosted Auth, OAuth/OIDC, and MCPDocumentationGuides & integrationAPI referenceEndpoints & schemasTrust
DPDP readinessChecklist & readiness reviewSecurityHow we protect your dataPrivacyHow we handle your dataLaunch hosted sign-in for your product. Give each AI client a separate, expiring grant for only the resources and actions a user approves.
$ npx @namoidhq/cli init
Detecting your application and installed agents…
✓ NamoID setup ready
Public beta · Test environment
Trust credentials and supported identity capabilities
Configure sign-in methods and branding, keep Test and Live separate, revoke sessions, manage users, answer privacy requests, and inspect audit events from one console.
A user session proves who is present. An AI client still needs its own boundary: one client, one resource, approved actions, a short lifetime, and an independent revocation path.
Session for your application
Audience-bound grant for exact actions
Authentication methods are the beginning. Recovery, environments, sessions, user lifecycle, privacy requests, notifications, and audit are what keep identity working after launch.
Customer users, workforce users, AI clients, and provider connections can share administration and audit infrastructure without sharing identities, credentials, sessions, or lifecycle state.
Trust record
Open the evidence, check what the product supports, and see which audits and certifications NamoID does not hold yet. No hidden qualifiers.
Available to review
Read NamoID’s completed CAIQ v4.1 security and privacy answers in the public CSA registry.
Public self-assessment — not an independent audit
Open the public recordOperate notice, consent records, privacy requests, audit history, and incident evidence from the identity layer.
Supports your implementation — it does not make your business compliant
See the DPDP controlsPrivacy and security workflows account for data-subject requests and controller–processor responsibilities.
No certification claimed — applicability depends on your processing
Read our privacy approachNot completed
We use the standard as a reference while building NamoID’s information-security management program.
No accredited ISO/IEC 27001 certificate today
Review our security postureThe Security, Availability, and Confidentiality criteria guide our control program.
No SOC 2 Type I or Type II report today
Review our security postureWe run internal checks across code, APIs, OAuth, dependencies, containers, and configuration.
No independent penetration-test report today
Review our security postureIndia ecosystem
Build consent-led DigiLocker document flows through the official partner ecosystem. Each production use case still follows DigiLocker approval and configuration.
Partner status does not mean DigiLocker certifies NamoID’s security
Also recognised: DPIIT and iStart Rajasthan recognise the company as a startup. They do not certify the product or its security.
Read the full security record →Status reviewed 30 Aug 2026 · evidence and availability may change
Security you can inspect
NamoID separates user sessions, AI grants, and provider credentials so each can be limited and revoked on its own path. Review the protocols, assessment, infrastructure region, and current certification status behind the claims.
MCP grant · live lifetime
15:00then the client asks again
01
Signs a human into your application. Ending it does not silently rewrite an agent’s authority.
subject → application
02
Names one client, one resource, and approved actions. It expires and can be revoked on its own.
client × resource × actions
03
Remains sealed inside NamoID. It is used only after policy allows an action and never becomes the agent token.
stored authority ≠ issued grant
Customer Identity is available under public-beta terms. MCP Authorization is a developer preview. Workforce Identity and Agent Access are design-partner product directions, not generally available features.
No. Customer Identity uses OAuth, OpenID Connect, PKCE, WebAuthn, JWT, and JWKS. India is where the product has additional depth: DPDP-focused workflows, local operating context, and India deployment requirements. SAML belongs to the Workforce Identity direction, which is not generally available yet.
No product can make an organization compliant on its own. NamoID provides identity controls and evidence for consent, audit, privacy operations, minimization, and retention. Your organization remains responsible for its notices, purposes, policies, and legal obligations.
Not today. ISO 27001 and SOC 2 inform our control-readiness program, but NamoID does not currently claim ISO 27001 certification or a SOC 2 report. Completed assessments are listed on the Security page.
Usually, but the work is broader than changing an issuer. Callback and token-validation configuration can often move cleanly through OAuth and OpenID Connect; users, password hashes, linked identities, claims, and existing sessions need an explicit migration plan before production cutover.
Hosted Auth through redirect or popup is the supported Customer Identity path during public beta. SDKs handle the OAuth and OpenID Connect mechanics, while NamoID hosts credential collection, passkeys, social sign-in, and MFA. A general native authentication API is not currently offered for production use.
MCP Authorization protects a resource your product exposes to AI clients. Agent Access is the planned inverse: allowing a named agent to use a human-authorized external account through short-lived, policy-bound access without receiving the provider credential.
The first milestone is deliberately small: connect one application, register one exact callback, and complete one Hosted Auth flow in Test. The time depends on your framework and existing authentication setup; the setup assistant and direct engineering support are available if you get stuck.
Public-beta teams can talk directly with the engineers building NamoID. Use the setup assistant for configuration, join the Slack community for implementation questions, or book an engineering call for architecture and migration decisions.
Start in Test
Connect one application, register one exact callback, and complete Hosted Auth. If your product exposes an MCP server, add a separate grant for the resource, actions, audience, consent, and expiry.
No payment card during public beta Customer Identity · public beta MCP Authorization · developer preview