Skip to content
FedTrustFederated Trustfederatedtrust.com

Multi-company trustTrust infrastructure for multi-company software

Build across organizations.Keep authority with the owner.

Federated Trust gives people, organizations, applications, and agents a governed way to establish identity, delegate access, and protect business secrets across company boundaries.

Explore the platform

A neutral trust layer for people, agents, and the organizations they serve.

Start with your responsibility

What the platform means for you.

Five roles, one trust model. Pick your role to see exactly what you own.

PeopleUnderstand identity, password recovery, and delegated authority.
  • Recover access after losing an authenticator
  • Delegate limited access to another person or agent
  • Revoke a delegated grant and see the audit record
Explore People

The platform model

Three boundaries. One governed exchange.

Establish the actor, decide the authority, and protect the business material without collapsing those responsibilities into one system.

How they connect

Each boundary stays independent, then meets at a single governed exchange, so authority is always explicit and revocable.

  1. Identity

    Establish the person or workload independently from any one application, then evaluate authority in the current organization context.

    Identity chapter
  2. Custody

    Keep protected business material in a deployment and key-custody profile chosen for the organization.

    Custody chapter
  3. Collaboration

    Separate software licensing from recorded, reviewable, and revocable access granted to people, apps, and agents.

    Delegation chapter

The result

One governed exchange

The interactive model

Identity travels. Authority stays narrow. Enforcement stays local.

Follow one request across the model. Click a stage to see how each responsibility stays separate, and why the data plane always keeps final deny.

The three-step trust exchange

From presented credential to enforced action.

Three named steps. Each one hands the next a smaller, better-labelled artefact, never a blank cheque.

  1. Recognize

    Authentication answers whether the presented credential belongs to an account. Nothing more.

    • WebAuthn
    • Workload attestation
  2. Delegate

    The person, application, or agent receives a narrowly-attenuated grant. Recorded. Reviewable. Revocable.

    • Attenuated
    • Auditable
  3. Enforce locally

    The resource service applies local policy and retains final deny. No upstream claim can override.

    • Final deny
    • Per profile

Designed deployment profiles

Control the plane where protected business data lives.

Federated Trust is designed for managed, customer-controlled connected, and sovereign/offline data planes. These are not generally available offerings yet; every deployment requires a validated package and explicit key-custody, observability, update, recovery, and support responsibilities.

Profile

Managed profile

The designed provider-operated profile reduces operational burden while retaining tenant boundaries, explicit support access, and export responsibilities.

Provider ownsCustomer owns
75%25%

Required responsibilities

  • Validated deployment package
  • Explicit, audited support access
  • Defined data export path
  • Provider-run observability and updates

Who owns what

Responsibilities by deployment profile.

ConcernManagedCustomer-controlledIsolated
Key custodyFederated TrustCustomerCustomer
ObservabilityProvider baselineShared, customer-scopedCustomer
Support accessExplicit, loggedExplicit, loggedOff by default
Update cadenceProvider-scheduledCustomer-coordinatedCustomer, signed only
Recovery evidenceProvider proofShared drillCustomer-owned drill

Designed means the target architecture is approved, but it is not generally available until its deployment package and operating evidence are validated.

Program snapshot

Control implementation status

Updated Jul 2026
Controls designed

00controls

Ready for pilot handoff

Controls in limited pilot

00controls

Active in production sandbox

Governing references

00docs

Standards mapped to controls

Implementation coalition

Industry Leading Implementers

Cross-disciplinary expertise for cloud delivery, data intelligence, regulated software, physical security, and platform engineering.

Frequently asked

Answers before the meeting.

Six questions that come up in every scoping call. Each answer is written to the same status labels the rest of the site uses.

The design does not require replacing an existing identity provider. Each integration must still document how a person or workload proves identity and how authority is evaluated in the current organization context.

Does Federated Trust replace our IdP?

The design does not require replacing an existing identity provider. Each integration must still document how a person or workload proves identity and how authority is evaluated in the current organization context.

Layered authorization

Design invariant: identity may travel; authority stays narrow; every conforming data plane must retain final deny.

Federated Trust design invariant

Preview access

Tell us where you want the trust boundary.

Submitting opens an email draft in your client. It does not transmit data to this website.