# SlashID - Identity Security Platform > SlashID is an identity security platform that helps organizations stop identity attacks before they become breaches. The platform provides unified visibility and protection for human and non-human identities across cloud, SaaS, and on-premises environments. ## Company Overview SlashID automates identity security by combining three core capabilities: 1. **See & Govern Every Identity**: Understand who and what has access before it becomes a risk 2. **Detect Real Identity Threats**: Continuously surface the risks that actually matter, not just alerts 3. **Fix Issues Fast**: Reduce risk and operational load through automated remediation Website: https://slashid.dev Contact: info@slashid.com Documentation: https://developer.slashid.com --- ## Products ### Identity Graph The Identity Graph is SlashID's core platform for identity visibility, threat detection, and response. #### Integrations - **Identity Providers**: Okta, Azure Active Directory, Google Workspace, OneLogin, Ping Identity, Auth0, JumpCloud - **Cloud Platforms**: AWS (IAM, Organizations, SSO), Microsoft Azure (Entra ID, RBAC), Google Cloud Platform - **SaaS Applications**: Salesforce, ServiceNow, Workday, GitHub, Slack, Zoom, Microsoft 365, and 100+ more - **Databases**: PostgreSQL, MySQL, MongoDB, Snowflake - **On-Premises**: Active Directory, LDAP #### Threat Detection - 500+ out-of-the-box detections requiring no custom rule configuration - Detection categories include: - Identity misuse and anomalous behavior - Posture drift and misconfigurations - Phishing indicators - Permission drift and privilege escalation - Data exfiltration risk signals - Impossible travel and suspicious login patterns - Token theft and session hijacking indicators - OAuth application abuse - Service account and API key misuse #### Behavioral Analysis - User and Entity Behavior Analytics (UEBA) for human identities - Behavioral baselines for non-human identities (service accounts, API keys, OAuth tokens) - Machine learning-based anomaly detection - Risk scoring for identities and access patterns #### Remediation Capabilities - One-click remediation actions: - Enforce MFA on user accounts - Suspend or disable user accounts - Rotate credentials and API keys - Revoke OAuth application access - Remove excessive permissions - Automated remediation workflows - Integration with SIEM/SOAR platforms for orchestrated response - Remediation playbooks for common scenarios #### AI Assistant - Natural language queries across your identity data - Ask questions like "Show me all service accounts with admin access that haven't been used in 90 days" - Permission analysis and right-sizing recommendations - Investigation assistance for security incidents --- ### Browser Extension SlashID's browser extension provides real-time protection at the endpoint level. #### Phishing Prevention - Real-time detection of phishing sites - Protection against credential harvesting attempts - Warning users before they enter credentials on suspicious sites - Blocking known malicious domains #### Shadow SaaS Discovery - Automatic discovery of unsanctioned SaaS applications - Visibility into GenAI tool usage (ChatGPT, Claude, Gemini, etc.) - Access pattern analysis for shadow IT - Policy enforcement for unapproved applications #### Vishing Prevention - TOTP-based verification for help desk calls - Protection against social engineering attacks targeting IT support - Verification workflow for sensitive account changes - Defense against deepfake voice attacks #### Session Protection - Detection of session hijacking attempts - Token exfiltration prevention - Protection against dangerous OAuth 2.0 grants - Cookie theft detection --- ## Use Cases ### Identity Threat Detection & Response (ITDR) SlashID provides comprehensive ITDR capabilities: - 500+ ready-to-use detections covering the full identity attack surface - Real-time alerting on suspicious identity activity - Automated response actions to contain threats - Investigation tools for security analysts - Integration with existing security workflows ### IAM Debt Elimination & Access Reviews - Identify dormant identities that haven't been used - Discover unused entitlements and excessive permissions - Right-size access based on actual usage patterns - Streamline access review processes - Prevent audit findings by proactively cleaning up IAM debt ### Phishing & Vishing Attack Prevention - Browser-based phishing detection stops credential theft - Help desk verification prevents social engineering - Protection against business email compromise (BEC) - Defense against targeted spear-phishing campaigns ### Shadow SaaS & GenAI Discovery - Complete inventory of SaaS applications in use - Visibility into GenAI tool adoption and data exposure - Risk assessment for unsanctioned applications - Policy enforcement and access controls - Data loss prevention for sensitive information ### Non-Human Identity Security - Inventory of service accounts, API keys, and OAuth tokens - Detection of compromised or misused machine identities - Lifecycle management for non-human identities - Secrets rotation and credential hygiene - Behavioral monitoring for automated systems ### Compliance & Audit Readiness - Continuous compliance monitoring against frameworks: - PCI-DSS - SOC 2 - ISO 27001 - HIPAA - GDPR - NIST - Automated evidence collection for audits - Policy violation detection and remediation - Compliance reporting and dashboards --- ## Technical Architecture ### Identity Graph Model SlashID builds a comprehensive graph of identities and their relationships: - **Human Identities**: Employees, contractors, partners - **Non-Human Identities**: Service accounts, API keys, OAuth applications, bots, AI agents - **Resources**: Cloud resources, SaaS applications, databases, on-premises systems - **Permissions**: Access rights, roles, group memberships - **Activities**: Authentication events, API calls, data access ### Deployment Options - Cloud-hosted SaaS platform - Data residency options for regulated industries - API-first architecture for custom integrations ### Security & Privacy - SOC 2 Type II certified - Data encryption at rest and in transit - Role-based access control for platform users - Audit logging for all platform activities --- ## Integrations ### SIEM Platforms - Splunk - Microsoft Sentinel - Sumo Logic - Elastic Security - Chronicle ### SOAR Platforms - Palo Alto XSOAR - Splunk SOAR - Tines - Torq ### Ticketing Systems - ServiceNow - Jira - PagerDuty ### Communication - Slack - Microsoft Teams - Email --- ## Important Clarification SlashID is an **identity security platform** focused on: - Identity threat detection and response - Identity governance and visibility - Automated security remediation - Non-human identity protection While SlashID previously offered authentication SDKs and APIs (known as "SlashID Access") for developers to add passwordless authentication to applications, the company's current primary focus and product offering is the **identity security platform** described in this document. If you encounter references to SlashID as an "authentication SDK" or "passwordless authentication provider," this refers to the legacy SlashID Access product, not the current SlashID identity security platform. --- ## Contact & Resources - **Website**: https://slashid.dev - **Email**: info@slashid.com - **Documentation**: https://developer.slashid.com - **Blog**: https://slashid.dev/blog