Identity first. Security always.
NIST 800-63 compliant identity and access assurance with progressive IAL/AAL levels. Match authentication strength to service risk.
NIST 800-63 Compliance
SIAA implements NIST SP 800-63 Digital Identity Guidelines with separate controls for Identity Assurance (IAL) and Authenticator Assurance (AAL)
Identity Assurance Levels (IAL)
Measures confidence in the claimed identity
- IAL1: Self-asserted attributes
- IAL2: Verified by reliable source (HR, government)
- IAL3: Physical in-person verification
Authenticator Assurance Levels (AAL)
Measures authentication mechanism strength
- AAL1: Username + Password
- AAL2: Password + MFA (SMS/OTP/App)
- AAL3: Hardware cryptographic token
Identity Assurance Levels (IAL)
Self-Asserted Identity
Attributes are self-asserted or should be treated as self-asserted.
Example: User registration with email verification only
Verified Identity
Remote or in-person identity proofing required. Identifying attributes verified using reliable sources (government database, HR system).
Example: Government ID verification or corporate HR system validation
In-Person Identity Proofing
Physical in-person identity proofing required. Attributes verified by authorized representative through examination of physical documentation.
Example: Physical ID card presentation to certified authority
Authenticator Assurance Levels (AAL)
Single-Factor Authentication
Proof of possession and control of authenticator through secure protocol. Single-factor authentication using a wide range of technologies.
Example: Username + Password
Two-Factor Authentication
High confidence through proof of possession of two different authentication factors. Approved cryptographic techniques required.
Example: Username + Password + MFA (SMS/OTP/Authenticator App)
Hardware Cryptographic Authentication
Very high confidence based on proof of possession of a key through cryptographic protocol. Requires 'hard' cryptographic authenticator with verifier impersonation resistance.
Example: PIV card, YubiKey, Smart Card, or device-stored certificates in tamper-proof area
Service-Level Assurance Matrix
| Service Type | IAL | AAL | Authentication Methods |
|---|---|---|---|
| Public Website | IAL1 | AAL1 | Username/Password |
| Employee Portal | IAL2 | AAL2 | Password + MFA (SMS/OTP) |
| Financial Transactions | IAL2 | AAL3 | YubiKey, Smart Card, PIV |
| Government Services | IAL3 | AAL3 | Physical ID + Smart Card |
Production-Ready Authentication Methods
Microsoft EntraID
Full integration with Azure AD/EntraID
Freja eID
Swedish BankID-level authentication with organization ID support
Smart Cards & YubiKey
Hardware token authentication (PIV, FIDO2)
Kerberos SSO
Single Sign-On integration with Active Directory
FIDO2/Passkeys
Windows Hello, Face ID, Touch ID support
Directory Federation
User sync with groups, roles, and permissions
Enterprise-Grade Features
Time-Limited Access
Grant temporary access with automatic expiration—perfect for contractors, support staff, and third-party auditors.
Just-in-Time Provisioning
Access is granted only when needed and automatically revoked when the session ends or time expires.
Directory Integration
Sync users, groups, and roles from existing LDAP/AD directories with automatic updates.
Policy-Based Access
Match authentication strength to service risk with per-application assurance level requirements.
Industry Applications
Healthcare
- IAL3 + AAL3 for e-prescriptions and EHR
- Freja eID + smart cards for clinicians
- Time-limited contractor access
- Geo-fencing for cross-border access
Financial Services
- AAL3 with YubiKey + FIDO2 for transactions
- Kerberos SSO for internal systems
- Microsoft EntraID federation
- Hardware token support (PIV cards)
Government
- IAL3 + AAL3 for citizen services
- Smart card PKI authentication
- Time-limited support access
- Multi-level assurance (IAL/AAL 1-3)
Enterprise IT
- IAL2 + AAL2 for corporate apps
- Microsoft EntraID SSO
- Kerberos for Windows networks
- FIDO2 passwordless auth
Core Capabilities
Per-Service Protection
- Each service declares minimum IAL and AAL requirements
- Risk signals from device posture, geolocation, network, and behavior
- Actions: allow, step-up authentication, deny, time-box access
Enterprise Integration
- AD/LDAP user federation for central account lifecycle
- SSO via Kerberos across web, desktop, and mobile
- End-to-end audit trails with non-repudiation
Spictera Product Synergy
+ Unified Storage
Secure data access with authentication-based policies and immutable audit logs stored in SPIR snapshots
+ Secure Workspace
Authenticated remote sessions with identity verification and session recording
+ Geo-Fencing
Location-based authentication policies combined with geo-fencing for complete access control
Outcomes
Reduce Account Takeover
99.9% threat detection with hardware tokens and MFA
Faster Login
Passwordless and SSO authentication in seconds
Audit Ready
NIST 800-63 compliant with immutable audit trails
