SECURITY & COMPLIANCE · FASTPASS IVM V4.5

Built for regulated environments and security-conscious organisations

FastPass IVM is deployed in government, defence, healthcare, financial services, and critical infrastructure — industries where identity verification failures carry regulatory and operational consequences.

FIPS 140-2 NIS2 ISO 27001 (AWS INFRA) SOC 2 · SOC 3 (AWS INFRA) GDPR · CCPA DEPLOYED IN FEDRAMP-AUTHORISED ENVIRONMENTS CYBER ESSENTIALS PLUS G-CLOUD
Infrastructure: ISO 27001 · 27017 · 27018 SOC 2 · SOC 3 G-Cloud FastPassCloud product: Cyber Essentials Plus SOC 2 — in progress FIPS 140-2 Deployed in FedRAMP-authorised environments

01 · REGULATORY COMPLIANCE

How FastPass IVM maps to your compliance obligations

FastPass IVM enforces a structured, auditable workforce identity verification workflow at the help desk, aligned with Zero Trust principles where identity must be continuously verified before privileged actions are executed

» EU · NIS2 DIRECTIVE

NIS2 & DORA Compliance

NIS2(opens in new tab) requires organisations in critical sectors to implement appropriate technical and organisational measures to manage cybersecurity risk, including controlling access to sensitive systems and demonstrating that identity is verified before privileged operations are performed. FastPass IVM(opens in new tab) directly supports NIS2 by enforcing a structured, policy-driven verification workflow, producing a full tamper-evident audit trail for every interaction, and removing human discretion from access decisions.

NIS2 AND DORA COMPLIANCE(opens in new tab)

» EU GDPR · US CCPA

GDPR & CCPA

FastPass IVM is designed to operate in compliance with GDPR and CCPA requirements. All personal data stored is pseudonymised at both user and organisation level using GUIDs. Data is encrypted at rest using AES-256. FastPass provides functionality to automatically delete user data when accounts are removed, disabled, or removed from authorised groups — ensuring data hygiene aligns with HR off-boarding processes. Our consultants have a proven track record of maintaining high-level security clearances, with many previously vetted to PET and BPSS standards. To ensure ongoing compliance and security, all staff members undergo mandatory annual data protection training.

» AICPA · SOC 2 TYPE II

SOC 2 Audit Support

FastPass IVM produces automatic, detailed audit logs for every verification attempt — including the factor used, the outcome, and the timestamp — written directly into the ITSM ticket. This supports the access control and monitoring requirements in SOC 2 Type II audits. FastPassCloud as a product holds Cyber Essentials Plus, and product-level SOC 2 certification is in progress.

» NIST CSF · HIPAA

NIST & Healthcare

We align our security practices with the NIST Cybersecurity Framework, which is the gold-standard blueprint for protecting digital infrastructure. To ensure your data remains private and secure, our system is built to meet HIPAA technical safeguard requirements. This means we use a structured verification process to confirm identities and role-based access, ensuring that only the right people have access to specific information. Every action within our system is automatically recorded through mandatory audit logging. This creates a clear 'paper trail' that helps you meet strict legal requirements (such as HIPAA Security Rule §164.312) during an audit.

» US DOD · FEDRAMP

FedRAMP GCC

FastPass IVM has been successfully deployed in a customer's ServiceNow Government Community Cloud instance carrying a FedRAMP High and DoD IL-4 Provisional-ATO. No code changes were required, and the deployment passed agency security acceptance testing. Contact FastPass sales for further details on US government deployments.

» ISO/IEC · PCI DSS

ISO 27001 & PCI

FastPassCorp aligns its security practices, processes, and technology controls with ISO/IEC 27001:2013. The FastPass Cloud environment carries SOC 2, ISO 27001, 27017, and 27018 certification. FastPass IVM has been penetration tested against PCI, OWASP, and SANS standards. (released March 2026) has been penetration tested by a third-party firm. A summary of the findings and remediation status is available to customers upon request. FastPass further complements these efforts with secure development lifecycle practices, continuous vulnerability management, and regular security assessments to ensure resilience against evolving threats..

02 · PRODUCT SECURITY

Security controls built into FastPass IVM

FastPass IVM is used by police forces, the Ministry of Defence, and the nuclear industry. As a result the product is held to a high standard and regularly tested by security-sensitive customer organisations.

FIPS 140-2
Uses FIPS 140-2 compliant cryptographic algorithms. AES-256 encryption and PBKDF hashing. Compliance covers the Windows Client, Password Interceptor and Filter, the server, and domain controller components.

ENCRYPTION AT REST

All sensitive data in the FastPass database is encrypted. Challenge/response answers are AES-256 encrypted and PBKDF2 hashed/salted. Password history data uses AES-256. Supports Bring Your Own Key (BYOK) and Bring Your Own Encryption (BYOE) from v4.5, with per-object cryptographic configuration.

ENCRYPTION IN TRANSIT

All external-facing web servers use modern cipher suites over HTTPS only. All backend communication uses HTTPS TLS 1.2 minimum. Certificate validation for Cloud-to-Gateway connections is enforced at the application layer and cannot be bypassed.

ISSENSITIVE CONTROLS

From v4.5, keyword records in the IVC table can be marked ISSENSITIVE. When set, the decrypted value is exposed only to the verification routine — it is never retrievable through the agent interface or the administration client. Agents see only match/no-match.

AUDIT LOG INTEGRITY

Every action within FastPass IVM is recorded — verification steps, outcomes, timestamps, agent identities, and ITSM ticket references. Logs are stored in a Microsoft SQL Server database on encrypted disks and automatically written back to the ITSM ticket, producing a tamper-evident record. Audit data can be integrated into SIEM platforms via database access or ETL pipelines.

PENETRATION TESTING

FastPass IVM and SSPR are penetration tested by security-sensitive customer organisations including police forces and the Ministry of Defence, as well as by third-party firms. The latest test was conducted by Backbone Security Inc. Results are available on request under NDA.

VULNERABILITY SCANNING

Weekly vulnerability scans across all production systems, applications, and servers, with additional scans following any significant changes to the environment. New vulnerabilities are classified by severity and exploitability, and remediation is prioritised accordingly.
WHY THE IT HELP DESK IS THE HIGHEST-RISK CONTROL POINT

A stolen password issued by a well-meaning agent can grant an attacker access to corporate systems, financial data, HR records, or customer information. The Clorox breach in 2023 — costing $380 million — happened because an agent bypassed verification protocols despite clear written procedures. FastPass IVM significantly reduces this risk by enforcing system-controlled verification workflows rather than relying on agent judgement.

Regulators are increasingly treating help desk identity verification as a named control. NIS2 Article 21, SOC 2 CC6, and HIPAA §164.312(a) all require demonstrable, auditable controls over privileged access operations — which is exactly what FastPass IVM enforces.

AI-resistant by design. FastPass IVM verifies identity through deterministic, policy-driven controls that do not depend on how a person sounds or appears. Authentication is based on verifiable factors—such as registered MFA devices and authoritative data sources—rather than human judgement. A push notification sent to an enrolled device cannot be approved by a voice clone, and HR-backed identity checks cannot be bypassed through deepfake interactions. By removing the human decision layer that AI-driven attacks typically exploit, FastPass IVM significantly reduces the attack surface and strengthens overall identity assurance.

THREAT COVERAGE

FastPass IVM is designed to mitigate the most common identity-based attack vectors targeting IT support operations:

Threat Coverage Control
Social engineeringMitigatedPolicy-enforced verification workflow removes agent discretion
Deepfake / voice impersonationMitigatedNo reliance on voice or human judgement
MFA fatigueMitigatedPush approvals tied to controlled verification flows
SIM swapConditionalDepends on configured authentication factors
Insider misuseReducedFull audit trail and enforced process controls
SENSITIVE KEYWORD HANDLING

HR data used for verification — employee IDs, badge numbers, partial dates of birth — is stored encrypted and presented to agents only as a partial value for confirmation. The full value is never exposed to the agent interface. When the ISSENSITIVE flag is set on a keyword field in v4.5, even the verification routine cannot retrieve the raw value through standard channels.

03 · CLOUD ENVIRONMENT SECURITY

FastPassCloud infrastructure controls

 The FastPass Cloud hosting environment holds ISO 27001, ISO 27017, ISO 27018, SOC 3, SOC 2. The following controls apply to the managed cloud service.

SHARED RESPONSIBILITY MODEL

FastPassCloud operates under a shared responsibility model. FastPassCorp is responsible for securing the cloud infrastructure, platform components, and service availability. Customers remain responsible for identity source integrity (e.g. Active Directory), endpoint security, and access governance policies.

CERTIFICATIONS
The FastPassCloud hosting environment holds ISO 27001, ISO 27017, ISO 27018, SOC 3, SOC 2, and G-Cloud certification. The cloud product itself holds Cyber Essentials Plus certification, SOC 2 certification is currently in progress.

NETWORK ISOLATION

Strict firewall rules between each component and its neighbours, restricting access to necessary ports only. DMZ platforms are not AD domain joined. Frontend web servers expose only HTTPS/443 externally and can only make outbound connections to HTTPS/443 on backend servers.

ACCESS CONTROL

All environment access is via RD Gateway jump boxes only. MFA is required to access all platforms. Console access is protected by MFA and default accounts are disabled.

MONITORING

Infrastructure and application monitoring is performed using CloudWatch and internal monitoring systems. Endpoint and threat detection capabilities are supported through integrations with security tooling such as Huntress.

BACKUPS

Full backups every 6 hours, encrypted and stored in the same region. Transaction log backups every 5 minutes. Retained for 28 days. On customer off-boarding, live data is deleted immediately and removed from all backups within 28 days as they rotate. Recovery time approximately 1 minute per GB.

AVAILABILITY & RESILIENCE

FastPassCloud is designed for high availability with redundant components and rapid recovery capabilities. Backup and restore processes support a recovery time objective (RTO) of approximately 1 minute per GB. Service availability targets and SLA commitments are available upon request.

DISK ENCRYPTION

All configuration data, customer Gateway credentials, and VPN/domain credentials are stored on encrypted disks. No file shares. All communications over secure protocols.

PERSONNEL

Our consultants have a proven track record of maintaining high-level security clearances, with many previously vetted to PET and BPSS standards. To ensure ongoing compliance and security, all staff members undergo mandatory annual data protection training.

Data stored and how it is protected

Data field Storage location Protection method
Sensitive UserdataAD LDS (ADAM)Encrypted at rest, LDAPS in transit
Private challenge/responseAD LDS (ADAM)AES-256 + PBKDF2 hashed/salted
Semi-private challenge/responseAD LDS (ADAM)AES-256 encrypted
Password history (if enabled)AD LDS (ADAM)AES-256 (+ PBKDF2 per policy)
Audit event dataSQL ServerEncrypted disks, AES-256
IVC custom / HR keywordsSQL ServerAES-256; ISSENSITIVE flag available
Application logsEncrypted diskEncrypted at rest; configurable verbosity
AD group membershipsAD LDS (ADAM)Encrypted disks
DATA RESIDENCY

For on-premises deployments, all data remains within your own infrastructure. For FastPassCloud, data resides in the assigned regional instance. No data traverses between cloud instances. On customer off-boarding, data is deleted from live systems immediately and from all rotating backups within 28 days.

DATA MINIMISATION

FastPass follows a data minimisation approach: only data strictly required for identity verification is stored. Sensitive attributes are pseudonymised, masked, or partially exposed to agents where possible, reducing risk while maintaining verification integrity.

04 · INTEGRATION

Integration with your existing security stack

FastPass IVM is designed to integrate with existing identity, ITSM, and security monitoring platforms.

IDENTITY PROVIDERS                                  Microsoft Entra ID (Azure AD), Active Directory, LDAP directories

ITSM PLATFORMS                                        Deep integration with ServiceNow for workflow enforcement and audit logging

MFA PROVIDERS                                          Supports TOTP, SMS, Email, Okta, Duo, RSA, and other enterprise MFA solutions

SIEM INTEGRATION                                      Audit data is stored in SQL Server and can be integrated with SIEM platforms such as Microsoft Sentinel or Splunk via database access or ETL pipelines

05 · COMPLIANCE FAQ

Questions from security and compliance teams

These are the questions most frequently asked by procurement, legal, and information security teams during FastPass IVM evaluations.

Does FastPass IVM help with NIS2 compliance?

Yes. The EU's NIS2 Directive requires organisations in critical sectors to implement appropriate technical and organisational measures to manage cybersecurity risk, including controlling access to sensitive systems and demonstrating that identity is verified before privileged operations are performed.

FastPass IVM directly supports NIS2 compliance by enforcing a structured, auditable identity verification workflow at the help desk. Every verification attempt is logged with a full audit trail, verification policies are configurable and consistently enforced, and the system removes human discretion from sensitive access decisions. Contact us for a compliance mapping document.

Does FastPass IVM support SOC 2 audit requirements?
Is FastPassCorp ISO/IEC 27001 certified?
Has FastPass IVM been independently security tested?
Does FastPass IVM meet FIPS 140-2 standards?
Is FastPass IVM GDPR and CCPA compliant?
Does FastPass IVM encrypt data in transit and at rest?

Need a compliance mapping document?

We can provide detailed documentation of controls for NIS2, SOC 2, HIPAA, ISO 27001, FedRAMP, or any specific framework your organisation requires.

Scroll to Top