Security and compliance

Trust built into every identity action.

MYID Self Verify combines secure identity operations, tenant controls, W7 audit evidence, privacy aware telemetry, and documented deployment testing. Its architecture is informed by leading security frameworks and helps customers advance and demonstrate compliance programs across government, health care, financial services, education, and critical field operations.

MYID Self Verify supports security programs informed by NIST SP 800 53, NIST Cybersecurity Framework 2.0, and Virginia SEC530. Its identity, authentication, awareness, audit, privacy, and response capabilities help customers address applicable requirements under HIPAA, PCI DSS, GLBA, FERPA, CJIS, GDPR, VCDPA, and CCPA and CPRA.
Framework coverage

Standards that shape MYID.

Recognized control catalogs, safeguards, privacy obligations, and application security practices guide architecture, release verification, customer configuration, and evidence review.

NIST

NIST SP 800 53

Security and privacy control reference

CSF

NIST CSF 2.0

Cybersecurity risk program reference

VA

Virginia SEC530

Commonwealth control mapping support

HIPAA

HIPAA Security Rule

Identity and safeguard support

PCI

PCI DSS 4.0.1

Access and authentication scope support

GLBA

GLBA

Financial safeguards support

FERPA

FERPA

Education privacy support

CJIS

CJIS

Criminal justice deployment assessment

CIS

CIS Controls 8

Operational safeguard reference

ASVS

OWASP ASVS

Web and API security verification

MASVS

OWASP MASVS

Mobile application security verification

DATA

Privacy Programs

GDPR, VCDPA, CCPA and CPRA support

Controls in practice

Designed for accountable identity operations.

Identity and access control

Tenant scoped sign in, company controlled capabilities, step up verification, provider authorization, account recovery, directory operations, and MFA management support governed identity services.

Audit and accountability

W7 evidence connects Who, What, When, Where, Why, How, and Outcome with correlation, duration, capture completeness, and protected request and response context.

Security awareness and participation

Training reminders, personal security guidance, incident review, and user responses help make the workforce an active part of the organization’s security program.

Password and recovery safeguards

Password exposure checks, expiration reminders, guided account activation, approved recovery, and manager decisions help reduce insecure credential handling practices.

Privacy and operations

Data minimization, redaction, retention controls, deletion workflows, protected telemetry, testing, and documented customer configuration support accountable operations.

Customer evidence

Audit detail with tenant context.

MYID records identity actions using the W7 methodology and correlates mobile, service, provider, and administrative activity. Protected context, capture quality, outcome, timing, and tenant scope help security and support teams reconstruct what happened and demonstrate that approved procedures were followed.

  • Tenant scoped audit review and approved exports
  • Correlation across app, server, and provider activity
  • Capture completeness, redaction, and integrity context
  • Searchable timing and outcome evidence
Performance assurance

Measure the experience continuously.

Server metrics expose request volume, success, failure, timeout, and latency behavior for critical app journeys. Teams can compare provider timing, investigate regressions, and validate releases against an accepted baseline.

  • API and provider latency distribution
  • Sync freshness and completion evidence
  • Success, failure, and timeout rates
  • Release and tenant comparison
Official references

Review the standards directly.

Evidence ready for review

Bring your requirements. We will bring the evidence.

Every MYID rollout follows company requirements, provider readiness, acceptance testing, audit review, performance measurement, and documented approval. Our team can prepare architecture, data flow, control mapping, release testing, audit, retention, and performance evidence for customer review.

Compliance scope is confirmed for each customer environment based on data classification, enabled capabilities, connected systems, contract terms, and operating controls.