Now with scoped identities for AI agentsRead more

One identity, guarded at the front door.

The sovereign identity layer for healthcare. Authenticate humans, govern organisations, and put every AI agent on a short leash - verified, scoped and fully audited.

Compliance roadmap · SOC 2 · HIPAA · ISO 27001 · IRAP · GDPR-aligned
app.orthid.io
OrthID
Members
Agents
Audit log
Regions
Members
2,400 PEOPLE · AU-SYD-1
Invite
AH
Dr. Amelia Hartford
a.hartford@stmary.health
Verified
NC
Dr. Nathaniel Cole
n.cole@stmary.health
Clinician
Imaging Triage Agent
agt_7K2f91x · on behalf of A. Hartford
TTL 14:58
Passkey verified
FIDO2 · passkey
Action attested
aud_5b2…e0 · sealed
The identity layer for the 3verest family
ForgeBifrostHeimdall3verest
Why now

Humans log in. Companies delegate. Agents act.

Authentication was built for one actor - a person at a keyboard. Now organisations delegate access to each other, and AI agents take real actions in real systems. They are identities too. OrthID governs all three on one trail.

Human

The people inside your products - clinicians and staff - sign in without passwords to phish.

PasskeysMFASSO
Organisation

Tenants that delegate access to one another - with their own admins, roles and boundaries.

OrgsDelegated adminRoles
AI agent

Non-human workloads that take real actions - borrowing access per task, on behalf of a real human.

Scoped credentialsOn-behalf-ofExpiry
Sovereign by design

Dedicated. In your region. Under your keys.

We run OrthID as a managed, dedicated and isolated deployment in the region you choose, on 3verest’s sovereign cloud. Customer-managed keys. A tamper-evident, hash-chained audit. No identity data crosses a boundary you didn’t draw.

Managed sovereign cell
Dedicated, isolated deployment
Data residency by region
BYOK (Vault / KMS / HSM)
Tamper-evident audit
Keys never leave your region
AI agents

Give every agent an identity, a leash, and a receipt.

Agents don’t get standing access. They borrow it - per task, scoped down, on behalf of a real user, and it expires. Every call carries provable provenance. One risk engine. One audit trail. Humans, organisations, and agents.

Per-task, least-privilege scopes
On-behalf-of via OAuth token exchange (RFC 8693)
Expiry & revocation - no standing access
issue-agent.ts · planned API
import { orthid } from "@orthid/sdk";

const agent = await orthid.agents.issue({
  onBehalfOf: "usr_4Qd2",
  scope: ["imaging:read"],
  ttl: 900,            // 15 minutes
  region: "au-syd-1",
});

// → agt_7K2f91x · act-claim sealed to the audit trail

Illustrative of the planned SDK - in preview for design partners.

Drop-in components

Sign-in, profiles, orgs and admin - drop them in.

Prebuilt components for login, user profile, organisation management and the org-scoped Tenant Console. Match your brand with tokens, ship on your own domain.

<SignIn/>
<UserButton/>
<OrgSwitcher/>
Tenant Console
acme.orthid.io/members
Tenant Console
Partners and customers

Built for partners, and the providers they serve.

OrthID serves two kinds of organisation, and isolates every one. Partners - OEMs and healthcare software companies - embed and operate OrthID. Customers - healthcare providers - run on it, sovereign in their own region.

Partner
OEMs & healthcare software companies

Embed OrthID in your product and operate it for the providers you serve. Multi-tenant orgs, delegated admin and agent identities - on your brand, on your domain.

Embed & operateMulti-tenantYour brand
Customer
Healthcare providers

Hospitals, clinics and networks get a sovereign identity layer of their own - a clean, org-scoped Tenant Console, audited in their own jurisdiction.

Org-scopedSovereignTenant Console
The org-scoped Tenant Console
acme.orthid.io/org
Tenant Console
Security & compliance

Trust, proven - not promised.

Concrete controls a CISO can verify, not adjectives. The platform fails closed, isolates every tenant, and seals every change.

Tamper-evident audit

One immutable, hash-chained entry per change - exportable to your SIEM.

RLS tenant isolation

Postgres row-level security and scoped tokens keep tenants provably apart.

Least-privilege agents

Non-human identities get per-task scopes that expire - never standing access.

Compliance roadmap · in progress
SOC 2HIPAAISO 27001IRAP
GDPR-aligned by design. SOC 2, HIPAA, ISO 27001 and IRAP are on our compliance roadmap, with the architecture built to support them.
What we’re building
One identity trail for clinicians, partner organisations and the AI tools on the ward: sovereign, in your region, and audited end to end.
The principle OrthID is built on.

Own your identity layer.

A managed sovereign cell in your region, under your keys. Humans, organisations and agents on one trail.