Security and procurement pack
For security, legal and procurement teams reviewing Dazr Identity. The trust centre explains the same for your end users, in plain words.
At a glance
| Topic | Dazr Identity |
|---|---|
| Provider | Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065 |
| Where data is stored, sub-processors | Listed in the trust centre |
| Standards | OpenID Connect 1.0 with the authorization code flow and PKCE, token revocation (RFC 7009) and introspection (RFC 7662), RP-initiated logout, and OpenID Connect for Identity Assurance for business verification |
| Signatures | ES256 for ID tokens, access tokens and verification reports, with public keys at identity.dazr.eu/oauth/jwks |
| Contract | The Developer Terms, between independent controllers, plus the optional data-sharing addendum below |
| Certifications | None yet. The CSA STAR Level 1 self-assessment is in preparation. |
| Availability | We do our best to keep the service available, but offer no uptime guarantee (SLA) today. |
| Not available yet | SAML, SCIM provisioning and back-channel logout |
Security measures
- Encryption. All traffic uses HTTPS, with HSTS preload for dazr.eu and its subdomains. Accounts and evidence are encrypted at rest with AES-256-GCM at the application layer.
- No passwords. People sign in with a passkey, a one-time email code (valid 10 minutes, 5 attempts) or Google or Microsoft.
- Organisation policy. Owners can require every member of the organisation to sign in with a passkey.
- A different ID per organisation. Each organisation receives its own random ID for a person, so unrelated organisations cannot link their users.
- Tokens. Authorization codes are valid for 60 seconds, once, and bound to the client, the redirect URI and the PKCE challenge. Access and ID tokens last 10 minutes. Refresh tokens rotate, and reusing an old one revokes the whole sign-in.
- Signed webhooks. HMAC-SHA256 with a timestamp, sent only to HTTPS addresses on public networks.
- Signed reports that stay checkable. Verification reports are signed with the published keys. Retired signing keys are kept, so a report signed before a key rotation can still be checked.
- Audit logs. Organisation admins see when members signed in and every download of verification evidence. Each time a reviewer opens the photos of a business verification, it is logged.
- Deletion schedules. ID copies and business verification photos are deleted 30 days after the decision; verification results are kept for 5 years after a verification ends.
- Responsible disclosure. Report vulnerabilities to security@dazr.eu under our vulnerability disclosure policy.
Who is responsible for which data
Dazr is the controller for the Dazr Identity account: the profile, sign-in methods, sessions and verification evidence. When a person signs in to your app, they ask Dazr to give your app the data shown on the consent screen. From then on, your organisation decides what to do with that data, so it is a controller in its own right.
Why no data processing agreement? A processor acts on its customer’s instructions. Dazr does not: it runs the account for the person, under its own privacy notice, and keeps verification evidence for its own legal reasons. Your app does not process data for Dazr either. An Article 28 GDPR agreement would describe a relationship that does not exist, so the Developer Terms set out rules between two controllers instead: purpose limitation, security, breach notification in both directions and deletion requests.
Verification reports work the same way. Dazr keeps the evidence and shares the report with the apps an organisation was shared with, for their audits. Each app then keeps its copy under its own rules.
Optional data-sharing addendum
Some buyers want the cooperation between two controllers in a separate signed document. This text is ready for that. Write to privacy@dazr.eu with your organisation’s legal name, and we send it to you for signature.
- Parties. Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, and the organisation named in the signature block (the Recipient).
- Shared data. The data a person approves on the Dazr Identity consent screen for the Recipient’s apps: a pairwise identifier and, where approved, name, language, email address, address, and organisations with role and verification status. For organisations shared with those apps, also verification reports and evidence files.
- Purpose. Signing people in to the Recipient’s apps, running their accounts, and the purpose shown on the consent screen. For verification reports: the Recipient’s customer due diligence and audits.
- Roles. Each party is an independent controller under Article 4(7) GDPR for the data it holds. Neither party processes personal data on behalf of the other, and the parties are not joint controllers.
- Lawful basis and transparency. Dazr discloses the data at the person’s request (Article 6(1)(b) GDPR) and says so on the consent screen. The Recipient has its own lawful basis and its own privacy notice, linked on the consent screen.
- Security. Each party protects the data with appropriate technical and organisational measures under Article 32 GDPR. The Recipient keeps client secrets on its servers only.
- Breaches. Each party tells the other without undue delay, and in any case within 72 hours of becoming aware of it, about a personal data breach that affects shared data, and the parties cooperate on notifying authorities and people where the law requires it.
- Requests from people. Each party answers requests about the data it holds. A party that receives a request about data the other party holds passes it on without undue delay.
- Transfers. A party that transfers shared data outside the European Economic Area does so only under Chapter V GDPR.
- Liability. Each party is liable for its own processing, as set out in the Developer Terms.
- Term. This addendum applies while the Recipient has an app registered with Dazr Identity, and for as long as either party still holds shared data.
- Law. Italian law applies. Disputes are heard in the courts of Italy.
Breach notification
- From Dazr to you. If a personal data breach at Dazr affects people who use your app, data we disclosed to your app, or your app’s credentials, we tell your organisation’s admins without undue delay and in any case within 72 hours of becoming aware of it (Developer Terms, section 9).
- From you to Dazr. If a breach affects data you received through Dazr Identity, or your client secrets or tokens, tell us at security@dazr.eu without undue delay and in any case within 72 hours of becoming aware of it.
Liability
Section 15 of the Developer Terms sets the liability. The service is provided as is. To the maximum extent permitted by law, Dazr is not liable for indirect, incidental, special or consequential damages, or for lost profits. Each party is responsible towards people and authorities for its own processing. Nothing limits liability for fraud, gross negligence, wilful misconduct, or anything that cannot be limited under applicable law. We do not offer service credits today.
For marketplaces
Online marketplaces in the EU must know who their business sellers are before those sellers can offer anything. Article 30 of the Digital Services Act calls this trader traceability. Dazr Identity checks the company and the person behind a seller account when they sign up.
Your payment provider checks the people it pays out to. Dazr Identity covers the step before, when a seller signs up, and the evidence stays with you, not with the payment provider.
Article 30 asks for more than company details, such as contact and payment account details. Dazr covers the company and who acts for it; you collect the rest and decide whether it meets your duties.
How Dazr Identity compares
An honest comparison, so you can choose well. Dazr Identity is young: it does a few things well, and some things not yet.
Compared with Auth0 and Clerk
Auth0 and Clerk are sign-in platforms for developers, with many SDKs, ready-made sign-in components and enterprise features.
- Choose Dazr Identity when you want a European company to run your users’ accounts, when you need to know that the companies behind your users are real, with evidence for each one, or when your users should have one account across apps, with a different ID per company.
- Choose Auth0 or Clerk when your enterprise customers need SAML for their own sign-in or SCIM to create and remove accounts automatically, when you want ready-made sign-in components for many platforms, or when you want your own user database with your branding on every screen.
Compared with Stripe Identity and Sumsub
Stripe Identity and Sumsub are identity verification services: they check ID documents and selfies, and Sumsub also checks companies.
- Choose Dazr Identity when verification should be part of sign-in, done once by a company and reused by every app it chooses, when you want evidence based on official registers and EU qualified signatures in a signed report, or when you want a fixed price per company.
- Choose Stripe Identity or Sumsub when you check individual consumers rather than companies, when you need beneficial owners, which Dazr Identity does not check, when you need more countries or document types than the 32 countries Dazr covers, or when you want a provider that runs regulated checks on your behalf. Dazr provides evidence; the decisions stay with you.
Compared with Microsoft Entra External ID and Okta
Entra External ID and Okta are enterprise identity platforms with broad policy engines and many integrations.
- Choose Dazr Identity when you want a standard OpenID Connect provider without an enterprise contract, with organisation verification against official registers built in, from a European company.
- Choose Entra External ID or Okta when you need SAML, SCIM, conditional access or detailed policies per user group, when your staff already use Microsoft 365 or Okta and you want one platform, or when you need a contractual uptime guarantee.
What Dazr Identity doesn’t have yet
- SAML
- SCIM provisioning
- Back-channel logout
- An uptime guarantee (SLA)
- Certifications such as ISO 27001 or SOC 2
- Checks of beneficial owners
Documents for your review
- Dazr Identity Developer Terms
- Privacy notice and terms of use
- Trust centre, with the sub-processors
- Sample verification reports and the country coverage
- Developer docs
- Vulnerability disclosure policy and security.txt
Contact
- Security questionnaires and audits: security@dazr.eu
- Contracts and the addendum: privacy@dazr.eu
- Everything else: hello@dazr.eu