Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

TRUST

Security

Layered identity, least privilege, encryption, segmented integration, logging and operational controls protect the platform within the published service boundary.

Owner
Security & Platform Operations
Scope
Platform, integrations and privileged operations
Status
Published control statement
01 / CONTROL

Control model

01

Identity & access

Strong authentication/federation, scoped authorization and step-up for sensitive actions where configured.

02

Data protection

Transport protection, protected secret/key handling and controlled data access.

03

Integration boundary

mTLS/OAuth, allowlisted endpoints and dependency isolation according to deployment.

04

Detection & response

Security-relevant logs, service observability, incident triage and controlled remediation.

02 / BOUNDARY

Responsibility boundary

Customer identity configuration, endpoints, user lifecycle and external systems remain shared/customer responsibilities as agreed per deployment.

03 / ESCALATION

Evidence and escalation

Report suspected vulnerabilities through Security Reporting; operational incidents follow the contracted operations channel, with the minimum sensitive detail needed for triage.

Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access