Consumer Identity and Access Management (CIAM) has emerged as a distinct specialty within IAM to address consumer-focused requirements: improving digital experiences, collecting richer consumer data, and using that data to drive sales opportunities and brand loyalty. CIAM platforms provision, authenticate, authorize, and store consumer identities across many domains, including government-to-citizen scenarios. Unlike workforce IAM, consumer data often originates from multiple unauthoritative sources and is reused for diverse purposes such as access decisions, marketing analytics, and compliance initiatives like AML. CIAM must operate at massive scale—millions of identities and potentially billions of daily transactions—making SaaS delivery an increasingly dominant model.
Regulatory and privacy pressures shape CIAM capabilities. Since GDPR (May 2018), explicit, unambiguous consent has become mandatory, pushing CIAM solutions to provide consent capture, user dashboards for data-sharing preferences, policy consistency, change notifications, and acknowledgement collection. Core CIAM feature areas include diverse authentication options (including risk-adaptive and continuous approaches), privacy/consent management, IoT identity association, identity analytics, broad API enablement, robust account recovery (with an explicit recommendation to avoid KBA), and account takeover protection using fraud and compromised-credential intelligence. Many vendors are shifting to “API-first” architectures aligned with micro-services and “Identity Fabrics,” creating opportunities for IT to partner closely with Marketing.
Strivacity (founded 2019, Virginia) offers Strivacity Fusion, a micro-services/serverless CIAM delivered on AWS with a multi-instance (not multi-tenant) approach and separate identity stores per customer to maximize data separation. Fusion supports white-label branding, progressive profiling, multiple registration and provisioning paths, extensive OTP/magic link authentication and recovery, default breached-password protections, botnet and TOR detection, and a risk engine for new-device and impossible-travel detection. Consent tooling supports user access, export (HTML/JSON), and deletion, with planned support for Kantara Consent Receipt. Fusion provides attribute normalization, bi-directional mapping with standards-based schemas, an embedded node.js IDE for customization, federation via OAuth/OIDC/SAML, API governance via OIDC client credentials, analytics dashboards, and connectors for major MarTech/ITSM tools, while noting roadmap gaps such as additional MFA methods, mobile SDK, FIDO2/WebAuthn, IoT identity, and expanded integrations.
See All Locations
See All Locations