Trust and control

EU-First and Compliance

FoxIDs provides architecture, deployment choices and operational controls that can support an organisation's work with GDPR, NIS2 and ISO 27001 requirements.

  • FoxIDs is designed with Europe first. Compliance, data protection, and sovereignty are not add-ons, but core principles built into the platform.
  • FoxIDs can support regulatory work through configurable controls and deployment choices; each organisation remains responsible for its own compliance assessment and operation.
  • Compliance is supported through architecture, not just documentation.

Decision framework

What to verify before approval

Use the same three questions for each area: what FoxIDs provides, where it can be verified and what your organisation must decide or operate.

Identity and access

FoxIDs provides
Configure MFA, authentication methods, application registrations, claims and isolated environments.
Evidence
Product documentation describes supported factors, configuration options and environment boundaries. Review MFA controls
Your responsibility
Define required assurance levels, access policies, administrator roles and review intervals.

Audit and operations

FoxIDs provides
Record security-relevant user activity and administrative changes, stream structured logs and expose health endpoints.
Evidence
Logging documentation describes audit records, diagnostic data, log streams and operational safeguards. Review logging and audit
Your responsibility
Define retention periods, restrict log access, configure alerts and operate the surrounding infrastructure.

Deployment and data

FoxIDs provides
Use FoxIDs Cloud hosted in Europe, self-host in your own environment or combine both in a hybrid deployment.
Evidence
Deployment guidance documents the supported models; current FoxIDs Cloud assurance material is available in the Trust Center. Compare deployment models Open Trust Center
Your responsibility
Select the deployment model, document data flows and assign ownership for customer-controlled infrastructure.

Contracts and assessment

FoxIDs provides
The Data Protection Agreement defines processing roles, safeguards, sub-processors and audit provisions for FoxIDs services.
Evidence
Use the agreement and current Trust Center documents in procurement and security assessments. Read the Data Protection Agreement
Your responsibility
Confirm controller obligations, lawful basis, risk assessment and requirements specific to your organisation.