Identity, hardware and policy are checked in isolation.
A known person, an authentic device and a valid policy are different signals. When they are verified separately, the final trust decision remains difficult to enforce and explain.
Enterprise PKI · Digital Trust Engineering
STRONG IDENTITY & ATTESTATION
SYNRION x.ID connects verified primary identities, controlled secondary identities, authentic hardware and independent policy. Trust is granted only when the required proofs succeed together.
A known person, an authentic device and a valid policy are different signals. When they are verified separately, the final trust decision remains difficult to enforce and explain.
x.ID binds verified identity, authentic hardware and independent policy enforcement. Separation of duties and technical four-eyes control become part of the decision instead of a later manual check.
TECHNICAL CONTROL
x.ID is designed around a clear gate: trust is not assumed from a single attribute but granted when all required proofs are present.
Connect verified primary identity, controlled secondary identities and assigned roles.
Include PIV and FIDO attestation, authentic hardware and the bound cryptographic key.
Apply independent policies, separation of duties and technical four-eyes control to the decision.
FEATURES AT A GLANCE
x.ID evaluates the required trust signals together. The checklist separates identity verification, hardware, platform access and integration into clear groups.
Trust is granted only when identity, role and independent rules are satisfied together.
Keep the accountable person as the starting point for every further identity and authorization decision.
Assign additional identities and roles without losing the connection to the primary identity.
Enforce approval conditions technically instead of relying on the target system or a single signal.
Apply separation of duties and required independent verification as part of the trust decision.
Authentic hardware and bound keys are evaluated together with identity.
Depending on cryptographic algorithms and hardware version, manage up to 23 secondary identities on one hardware security key. This reduces token demand and cost, especially in multi-tier and multi-domain environments.
Include hardware authenticity and the origin of the bound key as trust signals.
Connect phishing-resistant FIDO and passkey use cases with strong device and identity assignment.
Use a portal to assign hardware keys unambiguously to a primary identity before issue and manage their lifecycle under control.
Connect the Thales SafeNet eToken Fusion Series, Nitrokey 3 and Nitrokey HSM 2 to the same identity, attestation and policy model.
Integration of the Swissbit iShield Key 2 Series is planned as the next extension of the supported hardware-token portfolio.
Connect YubiKey, PIV and FIDO attestation, certificate lifecycle and policy evidence in the SYNRION control loop. This helps organizations implement their own cryptographic and identity requirements in line with BSI guidance; conformity assessment remains the organization’s responsibility.
Strong identity remains consistent across operating systems and infrastructure tiers.
Connect certificate-based Windows authentication with verified identity, hardware and policy assignment.
Support certificate-based authentication for Linux use cases with the same trust decision.
Work with a connected local client or without an additional agent according to the target system.
Relate identities and policies across separated tiers and multiple directory structures.
Existing identity sources and external systems remain part of the operating model.
Connect multiple certification authorities to one identity and approval model.
Correlate users, computers and directory information from existing identity sources.
Discover and verify certificate and key assignments in connected directory stores and bring them into the same controlled lifecycle.
Operate outposts with gMSA service accounts and protect their communication with mTLS. Hardware-protected keys are recommended for the gMSA service accounts.
Use OIDC for secure authentication and the correlation of identities and assets.
Connect external systems to SYNRION or integrate x.ID data and decisions into existing processes.
OPERATING CONTEXT
Use x.ID when access or authorization depends on more than a user account and every trust signal must be technically connected.
Relate verified identities and roles without losing the accountable primary identity.
Bring authentic hardware and bound keys into the same decision as identity and policy.
Make approval conditions and separation of duties enforceable rather than implicit.
COMPLEMENTARY TO x.ID
A complementary x.ID offering for selected strong-identity use cases. x.CASEone DUO remains subordinate to x.ID and is considered only where the concrete identity workflow requires it.
THE NEXT CONTROLLED STEP
We map the identity, hardware and policy signals that matter in your environment and turn them into a concrete x.ID use case.