Modern businesses must enable secure, convenient access across digital properties for partners, B2B customers, consumers, employees, and contractors. This requires multiple authentication methods and assurance levels, risk-adaptive authentication and step-up controls, policy-based authorization, self-service identity management, partner federation, and layered application security. Timely provisioning and de-provisioning is emphasized as both a business enabler and a way to reduce data-loss risk when relationships end, while attribute management underpins effective policy-based access control. Consumer-centric industries also need online registration, profile management, and consent management capabilities. Web applications require multi-layer protection spanning network controls, service-level authentication/authorization, and integration with identity systems. Identity system owners also need visibility through statistics for operations and event detail for security analytics.
AdNovum, a Swiss enterprise founded in 1988 with development operations in Hungary, Portugal, Vietnam, and Singapore, addresses these needs with its Java-based NEVIS Security Suite, delivered as a hardened nevisAppliance or as installable software for platforms such as Linux and IaaS. The suite is modular—nevisAuth (authentication), nevisProxy (reverse proxy/WAF), nevisIDM (identity management), and nevisReports (reporting)—with optional nevisAdmin for deployment and DevOps patterns, including Docker/Kubernetes support and Git-based configuration branching.
nevisAuth supports broad MFA options (including FIDO UAF mobile biometrics, push, tokens, smartcards, and social login) plus federation via OAuth/OIDC/SAML/WS-Fed and a configurable risk engine that evaluates factors like IP, geo-velocity, device signals, and attributes; it can be extended via REST but currently lacks built-in third-party threat or compromised-credential intelligence. nevisProxy integrates tightly with nevisAuth for SSO, step-up authentication, session controls, SSL handling, and WAF protections including validation and adaptive allow/deny lists. nevisIDM is workflow-oriented with delegated admin, provisioning, and self-service, while nevisReports provides dashboards and formatted reports. Strengths center on strong MFA, modularity, and security for sensitive sectors; challenges include geographic concentration, missing external threat-intel inputs, and potential IGA enhancements.
See All Locations
See All Locations