Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

DEVELOPER

mTLS

Use mutual TLS where the integration profile requires workload-level authentication in addition to OAuth authorization.

01 / CONCEPT

Integration contract

01

Identity

Client certificate represents an approved workload/integration, not an individual user.

02

Trust

Validate chain, hostname and policy; do not disable certificate verification.

03

Key protection

Private keys stay in protected keystore/HSM-equivalent boundary according to deployment policy.

04

Rotation

Support overlap and staged rotation before expiry to avoid integration outage.

02 / WORKFLOW

From sandbox to evidence

  1. 01Provision certificate identity
  2. 02Configure trust anchors
  3. 03Bind certificate to client/integration
  4. 04Test handshake/failure modes
  5. 05Monitor expiry
  6. 06Rotate with overlap
  7. 07Revoke compromised identity
03 / SECURITY & PRODUCTION

Production is an evidence decision

mTLS authenticates the approved workload identity; key protection, certificate trust, rotation and revocation must be operated for the deployed environment.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access