Verified account recovery
Email verification, password recovery, verified email changes, and single-use magic links let users recover access without relying on a manual support process.
Security, deployment & compliance
Guardhouse protects sign-in, sessions, tokens, APIs, services, and machine-to-machine access with standards-based controls. Choose Guardhouse Cloud for a managed service, or choose Enterprise operated by your organization or LegioSoft, with hosting, location, responsibilities, and support tailored to your requirements.
Security overview
Guardhouse combines account protection, authorization, session control, and deployment choice. Detailed implementation guidance is linked later on this page.
OAuth 2.0, OpenID Connect, Authorization Code with PKCE, signed JWTs, and published verification metadata.
MFA, recovery codes, trusted devices, passkeys, and temporary lockout after repeated failed sign-ins.
Roles, permissions, scopes, token lifetimes, session revocation, and live token status through introspection.
Guardhouse Cloud in an EU or US region, or tailored Enterprise operated by your organization or LegioSoft.
Identity & account security
Guardhouse covers the account lifecycle around authentication, giving users safe recovery paths and giving administrators control when access must change.
Account recovery and access removal are enforced security controls.
Email verification, password recovery, verified email changes, and single-use magic links let users recover access without relying on a manual support process.
TOTP authenticator apps, recovery codes, trusted devices, and authorized administrator resets protect accounts while providing a controlled path through lockouts.
WebAuthn passkeys work with platform and cross-platform authenticators. Users can name and revoke them, so teams can add phishing-resistant sign-in alongside existing methods.
Repeated failed attempts can temporarily lock an account. Authorized administrators can block access when a direct containment action is needed.
Users can connect and disconnect supported social identities without creating a separate Guardhouse account for each provider.
Authorized administrators can reset MFA, manage account access, and block accounts. Blocking an account invalidates active authorization state.
Tokens, APIs & authorization
Guardhouse issues standards-based tokens for applications, APIs, services, and machine-to-machine clients. Audiences, scopes, roles, and permissions help each client receive only the access it needs.
Token revocation
Local validation
The API validates the signature, issuer, audience, time limits, and required authorization claims without a live status request.
A revoked JWT validated only this way normally remains usable until it expires.
Live status validation
The API asks Guardhouse whether the token is currently active and keeps its introspection credential on the backend.
Use this path when the API must reject revoked access on the next checked request.
For per-request revocation status, use introspection rather than local JWT validation alone.
Sessions & security activity
Users and administrators can understand where an account is active and revoke access without waiting for every session to expire.
Users can review browser and OAuth application sessions with available device, browser, operating-system, IP, approximate location, and last-seen context.
Users can revoke an individual browser session or application authorization, or sign out other devices while keeping the current browser active.
Blocking an account invalidates active authorization state. Authorized administrators can also reset MFA during account recovery.
Security activity covers sign-in, MFA, password, token, social-account, passkey, and session events, with request details when available.
Important: Security activity is operational account history for visibility and investigation. It is not presented as an immutable compliance audit log.
Data location & tenant boundaries
Guardhouse Cloud customers choose the primary region for their managed environment. Each project operates within a logically separated data and application context. Product administration is scoped by tenant and role.
Enterprise can run in infrastructure selected by your team or in a LegioSoft-operated environment, with location tailored to your requirements.
Tenant-scoped controls separate each project's data and application context. Standard Cloud service does not provide physically dedicated infrastructure for every project.
Email, object storage, diagnostics, provider support, and customer-selected integrations may process data outside the selected primary region.
Retention follows the selected plan or agreed Enterprise configuration and the category-specific framework in the Privacy Policy and DPA. Guardhouse also supports account deletion and a basic profile export when the tenant allows those actions.
Deployment options
Guardhouse supports a managed Cloud service. Enterprise can be operated by your organization or by LegioSoft on LegioSoft infrastructure, with a model tailored to your requirements.
For Enterprise, hosting and location, responsibilities, support, service commitments, and account management are agreed with your team.
Managed service
Use Guardhouse without operating the identity service yourself.
LegioSoft operated
Choose an Enterprise deployment operated by LegioSoft on LegioSoft infrastructure.
Customer operated
Operate Guardhouse inside infrastructure selected and controlled by your organization.
Enterprise compliance
This section describes customer-operated Guardhouse Enterprise inside infrastructure selected and operated by your organization. It can sit within the system and controls you present for SOC 2, the declared scope of your ISO/IEC 27001 ISMS, or the environment you govern under HIPAA.
A clear Enterprise path
Enterprise self-hosting gives you control over infrastructure, data location, access, configuration, monitoring, and operating procedures. You do not have to step outside your compliance program to use Guardhouse.
Guardhouse does not make an organization compliant on its own. It gives your team a customer-operated deployment that can be governed inside your existing program.
Complete a SOC 2 examination with Guardhouse Enterprise included in your described system.
Include Guardhouse Enterprise within the declared scope of an ISMS certified to ISO/IEC 27001.
Run customer-operated Guardhouse Enterprise as part of a HIPAA-compliant environment.
SOC 2
Yes. Your organization can complete a SOC 2 examination with Guardhouse Enterprise included in its described system. The examination can address vendor assessment, configuration, patching, access, and monitoring as relevant to your controls.
LegioSoft does not currently provide a SOC 2 report covering Guardhouse. Your report remains a report on your organization’s described system and controls; it is not a report on LegioSoft’s controls.
ISO/IEC 27001
Yes. Guardhouse Enterprise can operate within the declared scope of your organization’s ISMS certified to ISO/IEC 27001. Address the deployment through your risk assessment and applicable supplier, change-management, and operational controls, and reflect the applicable controls in your Statement of Applicability.
LegioSoft’s ISMS is not currently certified to ISO/IEC 27001. Your certification applies to your own ISMS and declared scope; it does not certify LegioSoft or make Guardhouse a certified product.
HIPAA
Yes. Customer-operated Guardhouse Enterprise can be deployed as part of a HIPAA-compliant environment. Your organization remains responsible for its risk analysis, safeguards, access controls, logging, backups, incident response, and required Business Associate Agreements with providers that handle PHI.
The runtime keeps tenant-user data, PHI, telemetry, and diagnostics in your environment. It makes licence-validation requests to LegioSoft. The application payload is the licence code; ordinary connection metadata accompanies the request. Under this no-PHI-access software-delivery model, LegioSoft acts as a software vendor, not a Business Associate. LegioSoft does not sign BAAs or offer support that requires PHI access, so support requests, logs, screenshots, and diagnostic material must be sanitized.
This path is for Enterprise self-hosting. Standard Guardhouse Cloud is not currently offered for HIPAA-regulated processing.
Control works when ownership is clear
Map the software, infrastructure, operating, and evidence responsibilities to the teams that control them.
Operational security
Security activity and operational diagnostics support investigation. Guardhouse also maintains incident-response and security-maintenance processes.
Account events and operational diagnostics support investigation and troubleshooting.
Guardhouse reviews security updates and reported vulnerabilities, then prioritizes remediation by severity and exploitability.
Guardhouse maintains an incident-response process covering triage, containment, investigation, remediation, and documentation.
Where Guardhouse acts as a processor, affected customers are notified without undue delay after awareness of a Personal Data Breach.
Enterprise service levels and support-response commitments are tailored to the agreed operating model.
Transparency & documentation
Start with the public product documentation, then confirm any additional Enterprise review requirement in writing before you rely on it.
Production guidance for administrators, OAuth clients, APIs, and self-hosted operators.
A detailed ownership comparison and self-hosted operating guidance.
Login methods, signup, MFA, passkeys, recovery, and rollout checks.
Client types, audiences, scopes, credentials, and token-validation choices.
Enterprise security-review support is tailored to the deployment and customer requirements.
Questionnaire responses, additional review material, release planning, security-fix coordination, service levels, and other assistance can be agreed with your team.
Public documentation is available immediately; any tailored additions are confirmed in writing.
Security FAQ
Answers about compliance, deployment, assurance, responsibilities, and current security operations.
Guardhouse Cloud offers a primary EU region in Madrid and a primary US region in Chicago. The Security & Deployment page, Privacy Policy, and DPA explain the supporting-service locations and transfer controls.
Yes. Enterprise can run in infrastructure selected and operated by your organization, or LegioSoft can operate an Enterprise deployment on LegioSoft infrastructure. The hosting location, responsibility model, support, and account management are tailored to your requirements.
Yes. Guardhouse Enterprise can be included in the described system your organization presents for a SOC 2 examination. Your controls can address acquired-software and vendor assessment, configuration, patching, access, and monitoring. SOC 2 does not impose a blanket requirement that every software vendor have its own report, although your procurement or vendor-risk policy may set additional requirements.
Yes. Your organization can govern the self-hosted deployment within the declared scope of its ISMS certified to ISO/IEC 27001. Address it through risk assessment and applicable supplier, change-management, and operational controls. Your certification body evaluates your ISMS and declared scope; your certification does not certify LegioSoft or Guardhouse.
Yes. Customer-operated Guardhouse Enterprise can run as part of a HIPAA-compliant environment when your organization applies the required risk analysis, safeguards, access controls, logging, backups, incident response, and BAAs with providers that handle PHI. Tenant-user data, PHI, telemetry, and diagnostics stay in your environment. The Enterprise runtime makes licence-validation requests to LegioSoft; the application payload is the licence code and ordinary connection metadata accompanies the request. LegioSoft does not sign BAAs or offer PHI-access support. Standard Guardhouse Cloud is not currently offered for HIPAA-regulated processing.
No. Guardhouse provides identity controls and flexible Enterprise deployment models, while your compliance scope also includes your people, policies, configuration, infrastructure, monitoring, evidence, and operating procedures.
No. LegioSoft has not completed a SOC 2 examination covering Guardhouse and does not currently provide a SOC 2 report for it. LegioSoft’s ISMS is not currently certified to ISO/IEC 27001. This does not prevent customers from including Enterprise in their own SOC 2 system or ISO/IEC 27001 ISMS scope.
No. LegioSoft does not sign BAAs, and the Enterprise support model does not permit LegioSoft to create, receive, maintain, transmit, or access PHI. Keep PHI out of support requests and provide sanitized logs, screenshots, and reproductions. If resolving an issue would require PHI access, LegioSoft cannot provide that support under the current model.
No. Guardhouse Enterprise is delivered as object-code container images. Source code and source escrow are not offered. HIPAA, SOC 2, and ISO/IEC 27001 do not inherently require vendor source delivery, although your procurement policy may set a separate requirement.
Available today are this Security & Deployment page and the public product documentation linked below. Additional security-review assistance, questionnaire work, evidence, and service commitments can be scoped for Enterprise around customer requirements.
Review public security resourcesLocally validated JWTs normally remain valid until they expire. APIs that require current revocation state can use token introspection, which checks whether the token is still active on each request.
Each Guardhouse Cloud project operates within a logically separated data and application context. The separation is logical; standard Cloud service does not provide physically dedicated infrastructure for every project.
LegioSoft manages version rollout for Guardhouse Cloud. In customer-operated Enterprise, your operator controls upgrade scheduling, testing, and rollback. For LegioSoft-operated Enterprise, the rollout model and update support are tailored to your requirements.
Retention differs by data category and plan. Customer-operated Enterprise gives your team control of retention inside the deployment; for LegioSoft-operated Enterprise, retention and deletion are tailored to the hosted model. LegioSoft support accepts only PHI-free, sanitized material.
No. It is account and security activity intended for visibility and investigation. It is not an immutable or exportable compliance audit log.
Use the Guardhouse contact page or email info@legiosoft.net with enough information to identify and investigate the issue. Do not include passwords, tokens, client secrets, or unnecessary personal data.
Email GuardhouseNo. Standard Guardhouse Cloud is not currently offered for HIPAA-regulated processing. The affirmative HIPAA path described on this page is customer-operated Enterprise self-hosting with no LegioSoft access to PHI. LegioSoft does not sign BAAs or offer PHI-access support.
Start a Cloud trial, review the documentation, or define an Enterprise deployment operated by your organization or LegioSoft.