
Quasr is a European customer identity and access management (CIAM) platform that helps developers connect apps, identity providers, and customer data through a fully API-based, standards-obsessed approach. The platform is designed to be privacy-centric, operating without capturing personal data by default, and runs entirely within the EU to ensure data sovereignty. It supports flexible authentication flows, including passwordless and multi-factor options, with granular control over access scores and consent.
Funding
Funding not disclosed
Founders
Product
Problem
Developers and organizations face challenges in managing customer identities and access across multiple applications while ensuring compliance with strict privacy regulations like GDPR. Traditional CIAM solutions often require capturing and storing personal data by default, creating security risks and complicating data sovereignty, especially for European businesses that want to keep data within the EU.
Solution
Quasr provides a European, API-first Customer Identity and Access Management (CIAM) platform that is 100% standards-based and designed to be privacy-centric. The platform does not require or capture any personal data by default, allowing customers to store personal information elsewhere or within Quasr's secure, EU-hosted cloud. It supports a wide range of authentication factors—including passwordless, one-time passwords via email/SMS/authenticator, and private keys—each with configurable security scores that determine access to sensitive resources. Quasr enables developers to connect apps, identity providers, and data through REST APIs, with controls for OAuth scopes, identity claims, and legal consent, all managed via a dashboard.
Target Audience
Primary customers are developers and organizations building customer-facing applications that require secure, privacy-compliant identity management, particularly those operating in or targeting the European market.
Features
- 100% API-based platform with REST Authentication API for authenticating users or machines
- European data sovereignty with cloud hosting within the EU and no personal data captured by default
- Support for multiple authentication factors including passwordless, OTP (email, SMS, authenticator app), private keys, and personal tokens
- Configurable factor scores that accumulate during a session to grant or deny access to sensitive controls
- Attribute management with support for strings, numbers, booleans, and JSON, stored encrypted and injectable into identity/access tokens
- Controls for OAuth scopes, identity claims, and legal text, with extension triggers for custom integration