Organizations across the private and public sectors are under pressure to deliver better digital experiences and new services while enabling secure, convenient access for employees, contractors, partners, B2B customers, and consumers. Meeting these needs requires flexible authentication methods and assurance levels, risk-adaptive “step-up” authentication and authorization, policy-based access control, comprehensive identity/attribute management for workforces, consumer self-service identity capabilities, and identity federation for partners and B2B relationships. Provisioning and de-provisioning must be timely to reduce data-loss risk at employment end, while attribute assignment is central to enforcing policies. In regulated consumer industries such as banking, retail, and insurance, online registration, profile editing, and consent management are essential.
Some organizations prefer fully customizable IAM/CIAM, open-source approaches, or component-based builds; others only need limited identity “wrapping” around a single application. Dev-centric C/IAM solutions address these needs by enabling modular deployment around existing infrastructure, often on-premises or in IaaS, commonly with Docker/Kubernetes support, but they require skilled developers.
Curity AB, a privately held IT security firm in Stockholm, offers the Curity Identity Server (launched in 2015) with an API-first focus on authentication, token services, and user management. The product runs on Linux, supports container platforms, and provides Basic, Standard (single company), and Enterprise (covers affiliates/subsidiaries) licensing. It supports a broad set of authentication methods (including social login, GSMA Mobile Connect, select European national eIDs, and Swedish BankID), plus OAuth, OpenID Connect, and SAML for federation/SSO. A built-in risk engine evaluates factors like IP, time, device type, and user history, with extensibility via SDK for advanced risk and intelligence feeds. Its token service supports extensive OAuth/OIDC-related standards and exposes standard-compliant APIs, while user management integrates with LDAP, RDBMS, SCIM, and existing portals and data stores (SQL/no-SQL). Strengths include standards support and modularity; challenges include limited native mobile capabilities, lack of FIDO, and a relatively basic risk factor set.
See All Locations
See All Locations