ExcID develops identity and data-centric solutions focused on enhancing security and privacy on the internet. Their solutions aim to integrate security and privacy considerations into the design of internet applications and systems from the beginning.
Funding
Funding not disclosed
Founders
Product
Problem
Modern B2B services require robust security and flexible access management for web-based APIs, but traditional systems often lack fine-grained control and decentralized identity management. Existing solutions may not seamlessly integrate business relationships or provide adequate transparency and traceability in software supply chains, leaving organizations vulnerable to cyber threats and compliance issues.
Solution
ExcID develops identity and data-centric solutions focused on enhancing security and privacy for B2B services. Their offerings include systems for authentication and access control, leveraging decentralized identifiers and relation-based access control with verifiable credentials. ExcID also provides transparency and traceability solutions that integrate into software supply chains, featuring keyless digital signatures and integration with CI/CD services. Furthermore, ExcID participates in the CRACY project, assisting businesses in meeting the requirements of the EU Cyber Resilience Act (CRA) through tools and methods for evaluating product security and managing compliance documentation.
Target Audience
ExcID's primary customers are businesses requiring secure B2B services, particularly those in need of robust API protection, fine-grained access control, and improved software supply chain security, as well as organizations seeking to comply with the EU Cyber Resilience Act.
Features
- Decentralized Identifier (DID) solution that does not require a secure registry and allows private key rotation
- Fine-grained access control based on policies reflecting business relationships and roles
- Integration with OpenFGA, an open-source implementation of Google's Zanzibar authorization system
- Issuance of authorizations in the form of Verifiable Credentials, stored in user wallets
- Software Transparency as a Service (STaaS) platform for signing artifacts with short-lived certificates bound to user identity
- Keyless digital signatures and immutable recording of signature information in a public transparency registry (Rekor)
- Integration with existing CI/CD services like GitLab for software artifact attestation
- Solutions to assist businesses in meeting the requirements of the EU Cyber Resilience Act (CRA)