Security, deployment & compliance

Secure identity infrastructure, deployed on your terms.

Guardhouse protects sign-in, sessions, tokens, APIs, services, and machine-to-machine access with standards-based controls. Choose Guardhouse Cloud for a managed service, or choose Enterprise operated by your organization or LegioSoft, with hosting, location, responsibilities, and support tailored to your requirements.

Security overview

Security from sign-in to API access

Guardhouse combines account protection, authorization, session control, and deployment choice. Detailed implementation guidance is linked later on this page.

  • Standards-based identity

    OAuth 2.0, OpenID Connect, Authorization Code with PKCE, signed JWTs, and published verification metadata.

  • Layered account protection

    MFA, recovery codes, trusted devices, passkeys, and temporary lockout after repeated failed sign-ins.

  • Control over active access

    Roles, permissions, scopes, token lifetimes, session revocation, and live token status through introspection.

  • A choice of operating model

    Guardhouse Cloud in an EU or US region, or tailored Enterprise operated by your organization or LegioSoft.

Identity & account security

Protect the account, not just the sign-in

Guardhouse covers the account lifecycle around authentication, giving users safe recovery paths and giving administrators control when access must change.

Account recovery and access removal are enforced security controls.

Verified account recovery

Email verification, password recovery, verified email changes, and single-use magic links let users recover access without relying on a manual support process.

MFA with recovery paths

TOTP authenticator apps, recovery codes, trusted devices, and authorized administrator resets protect accounts while providing a controlled path through lockouts.

Passkeys with user control

WebAuthn passkeys work with platform and cross-platform authenticators. Users can name and revoke them, so teams can add phishing-resistant sign-in alongside existing methods.

Failed-sign-in protection

Repeated failed attempts can temporarily lock an account. Authorized administrators can block access when a direct containment action is needed.

Social identity controls

Users can connect and disconnect supported social identities without creating a separate Guardhouse account for each provider.

Administrator security actions

Authorized administrators can reset MFA, manage account access, and block accounts. Blocking an account invalidates active authorization state.

Tokens, APIs & authorization

Give every token a defined purpose

Guardhouse issues standards-based tokens for applications, APIs, services, and machine-to-machine clients. Audiences, scopes, roles, and permissions help each client receive only the access it needs.

  • OAuth 2.0 and OpenID Connect
  • Authorization Code with PKCE for browser and native applications
  • Refresh Token and Client Credentials flows
  • Signed JWT access tokens with published verification metadata
  • Custom API audiences and OAuth scopes
  • Roles, fine-grained permissions, and token claims
  • Configurable token lifetimes
  • Client-secret and introspection-secret rotation

Token revocation

Choose validation based on how quickly access must change

Local validation

Signed JWT + JWKS

The API validates the signature, issuer, audience, time limits, and required authorization claims without a live status request.

A revoked JWT validated only this way normally remains usable until it expires.

Live status validation

Token introspection

The API asks Guardhouse whether the token is currently active and keeps its introspection credential on the backend.

Use this path when the API must reject revoked access on the next checked request.

For per-request revocation status, use introspection rather than local JWT validation alone.

Sessions & security activity

See active access and end it

Users and administrators can understand where an account is active and revoke access without waiting for every session to expire.

  1. See where an account is active

    Users can review browser and OAuth application sessions with available device, browser, operating-system, IP, approximate location, and last-seen context.

  2. Revoke a session or application authorization

    Users can revoke an individual browser session or application authorization, or sign out other devices while keeping the current browser active.

  3. Block access or reset MFA

    Blocking an account invalidates active authorization state. Authorized administrators can also reset MFA during account recovery.

  4. Review security activity

    Security activity covers sign-in, MFA, password, token, social-account, passkey, and session events, with request details when available.

Important: Security activity is operational account history for visibility and investigation. It is not presented as an immutable compliance audit log.

Data location & tenant boundaries

Know where data is processed and how tenants are separated

Guardhouse Cloud customers choose the primary region for their managed environment. Each project operates within a logically separated data and application context. Product administration is scoped by tenant and role.

Guardhouse Cloud regions

European Union
Madrid, Spain
United States
Chicago, Illinois

Enterprise can run in infrastructure selected by your team or in a LegioSoft-operated environment, with location tailored to your requirements.

Logical tenant isolation

Tenant-scoped controls separate each project's data and application context. Standard Cloud service does not provide physically dedicated infrastructure for every project.

Supporting services may process data elsewhere

Email, object storage, diagnostics, provider support, and customer-selected integrations may process data outside the selected primary region.

Retention and user control

Retention follows the selected plan or agreed Enterprise configuration and the category-specific framework in the Privacy Policy and DPA. Guardhouse also supports account deletion and a basic profile export when the tenant allows those actions.

Deployment options

Choose who operates the identity platform

Guardhouse supports a managed Cloud service. Enterprise can be operated by your organization or by LegioSoft on LegioSoft infrastructure, with a model tailored to your requirements.

For Enterprise, hosting and location, responsibilities, support, service commitments, and account management are agreed with your team.

Managed service

Guardhouse Cloud

Available

Use Guardhouse without operating the identity service yourself.

Best suited for
Teams that want Guardhouse to operate the identity service.
Infrastructure owner
Guardhouse operates the managed service under the selected plan.
Primary location
Customer-selected EU region in Madrid or US region in Chicago.
Version rollout
Managed as part of Guardhouse Cloud.
Service environment
Guardhouse operates the runtime, managed endpoints, and supporting data services.
Customer responsibility
Applications, access policy, administrators, integrations, and API enforcement.
Support access
Guardhouse operational access is restricted by role.

LegioSoft operated

Managed Enterprise

Tailored

Choose an Enterprise deployment operated by LegioSoft on LegioSoft infrastructure.

Best suited for
Organizations that want a negotiated managed Enterprise operating model.
Infrastructure owner
LegioSoft operates the deployment on LegioSoft infrastructure.
Hosting and location
Tailored to your hosting and location requirements.
Version rollout
Rollout responsibilities and commitments are agreed with your team.
Service environment
LegioSoft infrastructure and service components tailored to the deployment.
Customer responsibility
Application, access-policy, integration, and API responsibilities agreed with your team.
Support access
Support, service commitments, and account management tailored to your requirements.

Customer operated

Enterprise self-hosted

Enterprise

Operate Guardhouse inside infrastructure selected and controlled by your organization.

Best suited for
Organizations with the team and requirements to operate identity infrastructure.
Infrastructure owner
Your organization deploys and operates the environment.
Primary location
Your organization selects the infrastructure and processing location.
Version rollout
Scheduled, tested, and rolled back by your operator.
Service environment
A containerized runtime using PostgreSQL, Redis, storage, email, and ingress services selected by your organization.
Customer responsibility
Infrastructure, operations, provider credentials, and application and API enforcement.
Support access
Tenant-user data, PHI, telemetry, and diagnostics stay in your environment. The Enterprise runtime makes licence-validation requests to LegioSoft. The application payload is the licence code; ordinary connection metadata accompanies the request. Support uses sanitized information and does not include PHI access.

Enterprise compliance

Build within the compliance scope your customers expect

This section describes customer-operated Guardhouse Enterprise inside infrastructure selected and operated by your organization. It can sit within the system and controls you present for SOC 2, the declared scope of your ISO/IEC 27001 ISMS, or the environment you govern under HIPAA.

A clear Enterprise path

The short answer is yes.

Enterprise self-hosting gives you control over infrastructure, data location, access, configuration, monitoring, and operating procedures. You do not have to step outside your compliance program to use Guardhouse.

Guardhouse does not make an organization compliant on its own. It gives your team a customer-operated deployment that can be governed inside your existing program.

  • Complete a SOC 2 examination with Guardhouse Enterprise included in your described system.

  • Include Guardhouse Enterprise within the declared scope of an ISMS certified to ISO/IEC 27001.

  • Run customer-operated Guardhouse Enterprise as part of a HIPAA-compliant environment.

SOC 2

Your described system

Yes. Your organization can complete a SOC 2 examination with Guardhouse Enterprise included in its described system. The examination can address vendor assessment, configuration, patching, access, and monitoring as relevant to your controls.

LegioSoft does not currently provide a SOC 2 report covering Guardhouse. Your report remains a report on your organization’s described system and controls; it is not a report on LegioSoft’s controls.

ISO/IEC 27001

Your certified ISMS

Yes. Guardhouse Enterprise can operate within the declared scope of your organization’s ISMS certified to ISO/IEC 27001. Address the deployment through your risk assessment and applicable supplier, change-management, and operational controls, and reflect the applicable controls in your Statement of Applicability.

LegioSoft’s ISMS is not currently certified to ISO/IEC 27001. Your certification applies to your own ISMS and declared scope; it does not certify LegioSoft or make Guardhouse a certified product.

HIPAA

Your self-hosted environment

Yes. Customer-operated Guardhouse Enterprise can be deployed as part of a HIPAA-compliant environment. Your organization remains responsible for its risk analysis, safeguards, access controls, logging, backups, incident response, and required Business Associate Agreements with providers that handle PHI.

The runtime keeps tenant-user data, PHI, telemetry, and diagnostics in your environment. It makes licence-validation requests to LegioSoft. The application payload is the licence code; ordinary connection metadata accompanies the request. Under this no-PHI-access software-delivery model, LegioSoft acts as a software vendor, not a Business Associate. LegioSoft does not sign BAAs or offer support that requires PHI access, so support requests, logs, screenshots, and diagnostic material must be sanitized.

This path is for Enterprise self-hosting. Standard Guardhouse Cloud is not currently offered for HIPAA-regulated processing.

Control works when ownership is clear

Map the software, infrastructure, operating, and evidence responsibilities to the teams that control them.

Review shared responsibilities

Operational security

Security maintenance and incident handling

Security activity and operational diagnostics support investigation. Guardhouse also maintains incident-response and security-maintenance processes.

Security and operational activity

Account events and operational diagnostics support investigation and troubleshooting.

Security maintenance

Guardhouse reviews security updates and reported vulnerabilities, then prioritizes remediation by severity and exploitability.

Incident handling

Guardhouse maintains an incident-response process covering triage, containment, investigation, remediation, and documentation.

Breach communication

Where Guardhouse acts as a processor, affected customers are notified without undue delay after awareness of a Personal Data Breach.

Enterprise service levels and support-response commitments are tailored to the agreed operating model.

Customer-operated Enterprise

Your infrastructure, with clear ownership

The customer-operated model gives your team control over infrastructure and data location while keeping the software-vendor boundary explicit. Security reviewers and auditors can map each responsibility to the team that owns the control and the evidence.

This is control you can govern, not responsibility left undefined.

Guardhouse / LegioSoft

Software and support

  • Develop, maintain, and package the Enterprise software.
  • Supply the object-code images and available deployment documentation for your deployment.
  • Receive Enterprise licence-validation requests whose application payload is the licence code. Ordinary connection metadata accompanies the request; tenant-user data, PHI, telemetry, and diagnostics are not sent.
  • Keep standard support within customer-authorized, PHI-free information and sanitized diagnostic material.
  • Tailor support, update, security-review, and service commitments to the selected operating model.

Your organization

Infrastructure and access

  • Infrastructure and network security.
  • TLS and encryption at rest.
  • Secrets and key management.
  • Administrator access and MFA.
  • PostgreSQL, Redis, storage, email, ingress, and related providers.

Your organization

Operations and compliance

  • Monitoring, backups, disaster recovery, and incident response.
  • Testing and deploying Guardhouse updates made available to you.
  • Data retention and deletion.
  • Application controls, API enforcement, and integration credentials.
  • Keeping PHI out of licence verification, support requests, logs, and diagnostic material.
  • Your compliance scope, evidence, auditors, certification body, and BAAs with PHI-handling providers.

Enterprise support, updates, security-review assistance, and service commitments are tailored to the selected operating model. Support never includes PHI access.

Transparency & documentation

Security documentation

Start with the public product documentation, then confirm any additional Enterprise review requirement in writing before you rely on it.

Enterprise review boundary

Enterprise security-review support is tailored to the deployment and customer requirements.

Questionnaire responses, additional review material, release planning, security-fix coordination, service levels, and other assistance can be agreed with your team.

Public documentation is available immediately; any tailored additions are confirmed in writing.

Security FAQ

Common security questions

Answers about compliance, deployment, assurance, responsibilities, and current security operations.

Where is Guardhouse Cloud available?

Guardhouse Cloud offers a primary EU region in Madrid and a primary US region in Chicago. The Security & Deployment page, Privacy Policy, and DPA explain the supporting-service locations and transfer controls.

Can Guardhouse be self-hosted or operated by LegioSoft?

Yes. Enterprise can run in infrastructure selected and operated by your organization, or LegioSoft can operate an Enterprise deployment on LegioSoft infrastructure. The hosting location, responsibility model, support, and account management are tailored to your requirements.

Can our organization complete SOC 2 while using Guardhouse Enterprise?

Yes. Guardhouse Enterprise can be included in the described system your organization presents for a SOC 2 examination. Your controls can address acquired-software and vendor assessment, configuration, patching, access, and monitoring. SOC 2 does not impose a blanket requirement that every software vendor have its own report, although your procurement or vendor-risk policy may set additional requirements.

Can Guardhouse Enterprise be included in our ISO 27001 scope?

Yes. Your organization can govern the self-hosted deployment within the declared scope of its ISMS certified to ISO/IEC 27001. Address it through risk assessment and applicable supplier, change-management, and operational controls. Your certification body evaluates your ISMS and declared scope; your certification does not certify LegioSoft or Guardhouse.

Can Guardhouse Enterprise be used in a HIPAA-compliant environment?

Yes. Customer-operated Guardhouse Enterprise can run as part of a HIPAA-compliant environment when your organization applies the required risk analysis, safeguards, access controls, logging, backups, incident response, and BAAs with providers that handle PHI. Tenant-user data, PHI, telemetry, and diagnostics stay in your environment. The Enterprise runtime makes licence-validation requests to LegioSoft; the application payload is the licence code and ordinary connection metadata accompanies the request. LegioSoft does not sign BAAs or offer PHI-access support. Standard Guardhouse Cloud is not currently offered for HIPAA-regulated processing.

Does Guardhouse automatically make us compliant?

No. Guardhouse provides identity controls and flexible Enterprise deployment models, while your compliance scope also includes your people, policies, configuration, infrastructure, monitoring, evidence, and operating procedures.

Does Guardhouse have its own SOC 2 report or ISO certification?

No. LegioSoft has not completed a SOC 2 examination covering Guardhouse and does not currently provide a SOC 2 report for it. LegioSoft’s ISMS is not currently certified to ISO/IEC 27001. This does not prevent customers from including Enterprise in their own SOC 2 system or ISO/IEC 27001 ISMS scope.

Does LegioSoft sign a BAA?

No. LegioSoft does not sign BAAs, and the Enterprise support model does not permit LegioSoft to create, receive, maintain, transmit, or access PHI. Keep PHI out of support requests and provide sanitized logs, screenshots, and reproductions. If resolving an issue would require PHI access, LegioSoft cannot provide that support under the current model.

Do you provide source code?

No. Guardhouse Enterprise is delivered as object-code container images. Source code and source escrow are not offered. HIPAA, SOC 2, and ISO/IEC 27001 do not inherently require vendor source delivery, although your procurement policy may set a separate requirement.

What security evidence is available?

Available today are this Security & Deployment page and the public product documentation linked below. Additional security-review assistance, questionnaire work, evidence, and service commitments can be scoped for Enterprise around customer requirements.

Review public security resources
How does token revocation work?

Locally validated JWTs normally remain valid until they expire. APIs that require current revocation state can use token introspection, which checks whether the token is still active on each request.

How are hosted tenants separated?

Each Guardhouse Cloud project operates within a logically separated data and application context. The separation is logical; standard Cloud service does not provide physically dedicated infrastructure for every project.

Who manages upgrades?

LegioSoft manages version rollout for Guardhouse Cloud. In customer-operated Enterprise, your operator controls upgrade scheduling, testing, and rollback. For LegioSoft-operated Enterprise, the rollout model and update support are tailored to your requirements.

How is data retention handled?

Retention differs by data category and plan. Customer-operated Enterprise gives your team control of retention inside the deployment; for LegioSoft-operated Enterprise, retention and deletion are tailored to the hosted model. LegioSoft support accepts only PHI-free, sanitized material.

Is security activity a compliance audit log?

No. It is account and security activity intended for visibility and investigation. It is not an immutable or exportable compliance audit log.

How do we report a security concern?

Use the Guardhouse contact page or email info@legiosoft.net with enough information to identify and investigate the issue. Do not include passwords, tokens, client secrets, or unnecessary personal data.

Email Guardhouse
Can standard Guardhouse Cloud process HIPAA-regulated data?

No. Standard Guardhouse Cloud is not currently offered for HIPAA-regulated processing. The affirmative HIPAA path described on this page is customer-operated Enterprise self-hosting with no LegioSoft access to PHI. LegioSoft does not sign BAAs or offer PHI-access support.

Choose the operating model that fits your team

Start a Cloud trial, review the documentation, or define an Enterprise deployment operated by your organization or LegioSoft.