SECURITY & COMPLIANCE · FASTPASS IVM V4.5
Built for regulated environments and security-conscious organisations
FastPass IVM is deployed in government, defence, healthcare, financial services, and critical infrastructure — industries where identity verification failures carry regulatory and operational consequences.
01 · REGULATORY COMPLIANCE
How FastPass IVM maps to your compliance obligations
FastPass IVM enforces a structured, auditable workforce identity verification workflow at the help desk, aligned with Zero Trust principles where identity must be continuously verified before privileged actions are executed
NIS2 & DORA Compliance
NIS2(opens in new tab) requires organisations in critical sectors to implement appropriate technical and organisational measures to manage cybersecurity risk, including controlling access to sensitive systems and demonstrating that identity is verified before privileged operations are performed. FastPass IVM(opens in new tab) directly supports NIS2 by enforcing a structured, policy-driven verification workflow, producing a full tamper-evident audit trail for every interaction, and removing human discretion from access decisions.
GDPR & CCPA
FastPass IVM is designed to operate in compliance with GDPR and CCPA requirements. All personal data stored is pseudonymised at both user and organisation level using GUIDs. Data is encrypted at rest using AES-256. FastPass provides functionality to automatically delete user data when accounts are removed, disabled, or removed from authorised groups — ensuring data hygiene aligns with HR off-boarding processes. Our consultants have a proven track record of maintaining high-level security clearances, with many previously vetted to PET and BPSS standards. To ensure ongoing compliance and security, all staff members undergo mandatory annual data protection training.
SOC 2 Audit Support
FastPass IVM produces automatic, detailed audit logs for every verification attempt — including the factor used, the outcome, and the timestamp — written directly into the ITSM ticket. This supports the access control and monitoring requirements in SOC 2 Type II audits. FastPassCloud as a product holds Cyber Essentials Plus, and product-level SOC 2 certification is in progress.
NIST & Healthcare
We align our security practices with the NIST Cybersecurity Framework, which is the gold-standard blueprint for protecting digital infrastructure. To ensure your data remains private and secure, our system is built to meet HIPAA technical safeguard requirements. This means we use a structured verification process to confirm identities and role-based access, ensuring that only the right people have access to specific information. Every action within our system is automatically recorded through mandatory audit logging. This creates a clear 'paper trail' that helps you meet strict legal requirements (such as HIPAA Security Rule §164.312) during an audit.
FedRAMP GCC
FastPass IVM has been successfully deployed in a customer's ServiceNow Government Community Cloud instance carrying a FedRAMP High and DoD IL-4 Provisional-ATO. No code changes were required, and the deployment passed agency security acceptance testing. Contact FastPass sales for further details on US government deployments.
ISO 27001 & PCI
FastPassCorp aligns its security practices, processes, and technology controls with ISO/IEC 27001:2013. The FastPass Cloud environment carries SOC 2, ISO 27001, 27017, and 27018 certification. FastPass IVM has been penetration tested against PCI, OWASP, and SANS standards. (released March 2026) has been penetration tested by a third-party firm. A summary of the findings and remediation status is available to customers upon request. FastPass further complements these efforts with secure development lifecycle practices, continuous vulnerability management, and regular security assessments to ensure resilience against evolving threats..
02 · PRODUCT SECURITY
Security controls built into FastPass IVM
FastPass IVM is used by police forces, the Ministry of Defence, and the nuclear industry. As a result the product is held to a high standard and regularly tested by security-sensitive customer organisations.
ENCRYPTION AT REST
ENCRYPTION IN TRANSIT
ISSENSITIVE CONTROLS
AUDIT LOG INTEGRITY
PENETRATION TESTING
VULNERABILITY SCANNING
A stolen password issued by a well-meaning agent can grant an attacker access to corporate systems, financial data, HR records, or customer information. The Clorox breach in 2023 — costing $380 million — happened because an agent bypassed verification protocols despite clear written procedures. FastPass IVM significantly reduces this risk by enforcing system-controlled verification workflows rather than relying on agent judgement.
Regulators are increasingly treating help desk identity verification as a named control. NIS2 Article 21, SOC 2 CC6, and HIPAA §164.312(a) all require demonstrable, auditable controls over privileged access operations — which is exactly what FastPass IVM enforces.
AI-resistant by design. FastPass IVM verifies identity through deterministic, policy-driven controls that do not depend on how a person sounds or appears. Authentication is based on verifiable factors—such as registered MFA devices and authoritative data sources—rather than human judgement. A push notification sent to an enrolled device cannot be approved by a voice clone, and HR-backed identity checks cannot be bypassed through deepfake interactions. By removing the human decision layer that AI-driven attacks typically exploit, FastPass IVM significantly reduces the attack surface and strengthens overall identity assurance.
FastPass IVM is designed to mitigate the most common identity-based attack vectors targeting IT support operations:
| Threat | Coverage | Control |
|---|---|---|
| Social engineering | Mitigated | Policy-enforced verification workflow removes agent discretion |
| Deepfake / voice impersonation | Mitigated | No reliance on voice or human judgement |
| MFA fatigue | Mitigated | Push approvals tied to controlled verification flows |
| SIM swap | Conditional | Depends on configured authentication factors |
| Insider misuse | Reduced | Full audit trail and enforced process controls |
HR data used for verification — employee IDs, badge numbers, partial dates of birth — is stored encrypted and presented to agents only as a partial value for confirmation. The full value is never exposed to the agent interface. When the ISSENSITIVE flag is set on a keyword field in v4.5, even the verification routine cannot retrieve the raw value through standard channels.
03 · CLOUD ENVIRONMENT SECURITY
FastPassCloud infrastructure controls
The FastPass Cloud hosting environment holds ISO 27001, ISO 27017, ISO 27018, SOC 3, SOC 2. The following controls apply to the managed cloud service.
NETWORK ISOLATION
ACCESS CONTROL
MONITORING
BACKUPS
AVAILABILITY & RESILIENCE
DISK ENCRYPTION
PERSONNEL
Data stored and how it is protected
| Data field | Storage location | Protection method |
|---|---|---|
| Sensitive Userdata | AD LDS (ADAM) | Encrypted at rest, LDAPS in transit |
| Private challenge/response | AD LDS (ADAM) | AES-256 + PBKDF2 hashed/salted |
| Semi-private challenge/response | AD LDS (ADAM) | AES-256 encrypted |
| Password history (if enabled) | AD LDS (ADAM) | AES-256 (+ PBKDF2 per policy) |
| Audit event data | SQL Server | Encrypted disks, AES-256 |
| IVC custom / HR keywords | SQL Server | AES-256; ISSENSITIVE flag available |
| Application logs | Encrypted disk | Encrypted at rest; configurable verbosity |
| AD group memberships | AD LDS (ADAM) | Encrypted disks |
For on-premises deployments, all data remains within your own infrastructure. For FastPassCloud, data resides in the assigned regional instance. No data traverses between cloud instances. On customer off-boarding, data is deleted from live systems immediately and from all rotating backups within 28 days.
FastPass follows a data minimisation approach: only data strictly required for identity verification is stored. Sensitive attributes are pseudonymised, masked, or partially exposed to agents where possible, reducing risk while maintaining verification integrity.
04 · INTEGRATION
Integration with your existing security stack
FastPass IVM is designed to integrate with existing identity, ITSM, and security monitoring platforms.
05 · COMPLIANCE FAQ
Questions from security and compliance teams
These are the questions most frequently asked by procurement, legal, and information security teams during FastPass IVM evaluations.
Yes. The EU's NIS2 Directive requires organisations in critical sectors to implement appropriate technical and organisational measures to manage cybersecurity risk, including controlling access to sensitive systems and demonstrating that identity is verified before privileged operations are performed.
FastPass IVM directly supports NIS2 compliance by enforcing a structured, auditable identity verification workflow at the help desk. Every verification attempt is logged with a full audit trail, verification policies are configurable and consistently enforced, and the system removes human discretion from sensitive access decisions. Contact us for a compliance mapping document.
Need a compliance mapping document?
We can provide detailed documentation of controls for NIS2, SOC 2, HIPAA, ISO 27001, FedRAMP, or any specific framework your organisation requires.