Ironchip Identity Platform logo
Privacy Security · Security Fraud

Ironchip Identity Platform

Ironchip Identity Platform is a passwordless identity and access management system from Spanish vendor Ironchip Telco. It verifies users through location intelligence, works without a mobile phone, and adds identity threat detection with automatic blocking.

Active GDPR compliant Free plan Freemium API available Verified by Guidaio
Overview

What is Ironchip Identity Platform?

Ironchip Identity Platform is a passwordless identity and access management product built by IRONCHIP TELCO, S.L., a company registered in Barakaldo, in the Spanish Basque Country. Its distinguishing idea is location intelligence: rather than trusting a password or a one-time code, the platform establishes where a user physically is by reading signals from their surroundings, and treats that location as an authentication factor that is hard to spoof. Spain's national cryptologic centre lists the product in its CPSTIC catalogue under the name Location-Based Identity Platform (LBAuth), in the access control category, family authentication servers.

The platform covers the usual ground of an IAM suite and adds several less common options. Authentication can be fully passwordless and is mutual, meaning the server proves its identity to the user as well, which is how the vendor positions it against phishing. It can run without a mobile phone through USB security keys, NFC/RFID cards, desktop authenticators or delegated authentication, and it can run without any agent at all by speaking SAML, OAuth, OpenID Connect and RADIUS to existing applications. Native agents exist for iOS, Android, Windows, macOS and Linux, using device biometrics, push notifications or security keys. Directory integration covers Active Directory, LDAP, SCIM for Entra ID, Google Cloud Identity and plain CSV, with plugins for Microsoft NPS and ADFS and for operating-system logon.

On top of access control sits an identity threat detection and response layer that watches activity continuously, flags suspicious patterns, and can block access, alert the user and notify the security team without waiting for an analyst. The Premium edition adds continuous learning that models each user's usual behaviour and location patterns to surface geographic anomalies, a customisable fraud rule engine, a dedicated forensic tab with evidence export, and SIEM integration over Syslog or API.

Security posture is unusually well evidenced for a company of this size: nominative ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certificates, and an ENS High category certificate under Spanish Royal Decree 311/2022. The vendor also sells a separate Fraud Detection Platform, which is a different product with its own plans.

What it does

  • Remove passwords from employee, contractor and customer access
  • Verify a user's real location from environmental signals, resisting spoofing attempts
  • Detect identity threats in real time and block the attack automatically
  • Authenticate people who have no mobile phone, using USB keys, NFC/RFID cards or desktop agents
  • Apply conditional access policies based on device, role, location and contextual risk
  • Stream access logs and security events into an existing SIEM over Syslog or API
  • Produce the audit and traceability reports required by ENS, PSD2, DORA and NIS2
Audience

When to use Ironchip Identity Platform / When not to

A quick filter to help you decide if Ironchip Identity Platform is the right fit.

When to use Ironchip Identity Platform

  • CISOs and security leaders who must evidence compliance with NIS2, DORA, PSD2 or Spain's ENS framework
  • IT managers phasing out passwords across employee and contractor access without rebuilding existing applications
  • Spanish public-sector bodies and their suppliers, which need a product listed in the CCN-CERT CPSTIC catalogue at ENS High category
  • Banks and fintechs applying location signals against account takeover, a segment where Abanca appears as a named reference
  • Organisations whose staff cannot or will not use a personal phone to authenticate, thanks to USB keys, NFC/RFID cards and desktop authenticators

When not to use Ironchip Identity Platform

  • Teams that need to see a price and buy online: no amount is published anywhere and every plan routes to a sales conversation
  • Buyers who require a contractually binding availability guarantee, since the 99.5% figure is stated as an indicative objective with no credits or penalties
  • Individuals, because the licence is granted to a legal entity through a negotiated Subscription Agreement
  • Teams looking for transactional or banking fraud detection, which belongs to Ironchip's separate Fraud Detection Platform
  • Organisations that need an interface or documentation in a language other than English or Spanish
Get started

How to use Ironchip Identity Platform

A typical end-to-end flow, from setup to results.

  1. Identify which access you want to protect first: workstation logon, VPN, web applications or an identity provider
  2. Contact the vendor through the Talk to Sales form, since there is no self-service sign-up
  3. Agree a Subscription Agreement, which sets the scope, duration and fees, or start on the free tier if ten users or fewer are involved
  4. Choose an integration route: native agents, agentless standard protocols, or plugins such as NPS, ADFS and OS logon
  5. Connect your existing directory through Active Directory, LDAP, SCIM for Entra ID, Google Cloud Identity or a CSV import
  6. Enrol users and devices, then assign roles and permissions individually or by group
  7. Deploy the mobile or desktop authenticator to users, or issue USB keys and NFC/RFID cards to those without a phone
  8. Define trusted zones, corporate perimeters and conditional access policies based on device, role, location and risk
  9. Connect the audit trail to your SIEM over Syslog or the API, and set up administrator alerting
  10. Consult docs.ironchip.com and the CCN-STIC-1633 secure operation guide, and open tickets through the customer portal
Quick read

Pros & Cons

Pros

  • Three nominative, numbered and independently verifiable certificates: ISO/IEC 27001:2022, ISO/IEC 27701:2019 and ENS High category
  • Listed in Spain's CCN-CERT CPSTIC catalogue with a dedicated secure operation guide, which matters for public-sector procurement
  • Works without a mobile phone, a genuine deployment blocker that most competing products do not address
  • Broad protocol compatibility means it slots into existing applications without rewriting them
  • A permanent free tier for up to ten users, not merely a time-limited trial
  • The vendor holds neither plaintext passwords, nor private keys, nor raw biometric data
  • A Data Processing Agreement ships as an annex to the standard terms, and processing is EEA-based by default

Cons

  • No public pricing at all: neither the product page nor the sitemap nor the 22-page licence terms carry a single amount
  • The 99.5% availability figure is explicitly an indicative objective, with no service credits, penalties or early termination if missed
  • No named list of subprocessors is published, only categories of providers
  • Model training on customer data is never addressed, even though the Premium edition is built on continuous learning
  • There is no about or team page, so the vendor discloses little about itself beyond the legal notice
  • Interface, site and documentation are limited to English and Spanish
  • No self-service demo: the free demo request leads to the same commercial form as the sales contact
Pricing

Pricing & Plans

A permanent free plan is available, limited to between one and ten users, and it includes the agentless, desktop and mobile authenticators together with basic user, group and device management. Beyond that tier, no price is published. The Enterprise and Premium editions both carry a Talk to Sales button, and the commercial, economic and particular conditions, including scope, duration and applicable fees, are set in a Subscription Agreement negotiated with each client. Neither a currency nor a billing unit nor a minimum commitment is disclosed publicly, so no entry price can be stated.

Free
  • agentless
  • computer and mobile authenticators
  • user
  • group and device management for one to ten users
  • NPS and Microsoft ADFS plugins
  • access logs
  • basic metrics. Price on request.
Premium
  • everything in Enterprise
  • plus location-based and context-based authentication
  • secure location management
  • corporate perimeter of trust
  • identity threat detection with custom contextual risk rules and automatic blocking
  • real-time reports via API
  • advanced metrics
  • Syslog and API SIEM integration
Special offers — A permanent free plan for one to ten users, which is the only certain free offer · Free services and trial versions such as proofs of concept, pilots, demos, sandboxes and evaluations may be offered, but the licence terms make this discretionary, without SLA or warranty, and withdrawable at any time without notice · A partner and reseller programme is published, with a dedicated partner portal in the documentation site
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Ironchip Identity Platform handles your data.

GDPR overview

Implementation is concrete and documented. The product privacy policy is written against Regulation (EU) 2016/679 and Spain's Organic Law 3/2018, names IRONCHIP TELCO, S.L. as controller at its Barakaldo registered office with tax ID B95880332, and designates a named Data Protection Officer, Maria Llanas Villa, reachable at dpo@ironchip.com. A record of processing activities is maintained under Article 30, and a Data Processing Agreement is supplied as Annex A to the licence terms rather than negotiated separately. Users are granted access, rectification, erasure, objection, restriction, portability and human review of automated decisions. Processing takes place by default within the European Economic Area. The vendor also holds a nominative ISO/IEC 27701:2019 privacy management certificate. Note that a separate, narrower privacy policy covers the marketing website; the product policy prevails for the platform.

Who owns the data?

Ownership is split by role. When the platform authenticates a client organisation's own users, Ironchip acts strictly as a data processor under Article 28 GDPR: the client remains the controller, decides which data enters the system and on what legal basis, and Ironchip may only follow its documented instructions. Ironchip becomes controller only for the technical data it needs to run and secure the service, such as system logs, usage-derived information, unauthorised-access events and support exchanges. The vendor states it never stores plaintext passwords, never accesses users' private keys, and never receives raw biometric data, only a success or failure signal returned by the device.

Reuse rights

The client keeps full access to its own users' data in order to manage accounts, monitor access and run internal security and audit controls, and it may export access logs and security events over Syslog or the API into its own SIEM. No permission from Ironchip is required for that reuse, since the client is the controller for those records. Ironchip's own reuse is contractually narrow. It processes data to authenticate users and manage access (contract performance), to protect the client's environment and detect anomalies (legitimate interest), to maintain performance and stability, to handle support requests, and to answer lawful requests from authorities. It commits not to use the information for marketing, commercial profiling or anything unrelated to providing the service, not to sell it, and not to disclose it to third parties for unrelated purposes. Optional context features such as location require the client to collect explicit user consent.

Data retention & training

Retention summary
Retention periods are set between Ironchip and the client in the service contract, within legal limits, and no fixed duration is published. As a general rule, account and authentication management data is kept for as long as the user remains active in the system, while technical and security logs are kept for as long as traceability, incident detection and the agreed security obligations require. Periods can be extended for legal reasons, such as an authority request, a sector obligation of the client, or preserving evidence for an internal investigation or legal proceedings. Support data is kept only as long as needed to handle the incident and for the applicable liability periods. Once contractual or legal periods end, data is deleted through blocking, anonymisation or secure erasure. Clients set their own retention criteria for their users.
Trains on customer data
Unclear
DPA available
Yes
GDPR contact

Hosting summary

Processing takes place by default within the European Economic Area, where Ironchip says it keeps its main infrastructure and applies the safeguards required by European law. Transfers outside the EEA are permitted only where genuinely necessary to deliver or maintain the service, and only under adequacy decisions, Standard Contractual Clauses, or additional technical measures such as encryption or pseudonymisation. No individual country is named. The ENS High certificate is more specific about locations in scope, listing the Barakaldo office alongside AWS Europe and Microsoft Azure Europe, both described as external high-level data centres. Third-party providers supplying hosting, messaging for authentication factors, support tooling and log management act as processors under Article 28 contracts, though no named list of them is published. Jurisdiction is Spanish, with the product licence terms pointing disputes to the courts of Bilbao. Note that the marketing website itself runs on a hosted CMS behind a content delivery network, which is a separate matter from where platform data resides.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Ironchip Identity Platform.

  • The domain is second-hand: ironchip.com was registered in 2005 and its earliest archived page advertises an unrelated email autoresponder script, so domain age says nothing about the company, which was incorporated on 15 May 2017
  • The CCN-CERT CPSTIC listing shows approval and qualification windows that both ended on 31 August 2026, so that specific credential should be re-checked before relying on it
  • The website legal notice points to an unsubscribe address on a third-party domain, dpo@leasba.com, which appears to be leftover template text from a legal services provider; the genuine DPO address is dpo@ironchip.com
  • The homepage shows a Banco Santander logo in a logo strip and three named testimonials; these are customer references, not technical integrations or partnerships
  • The vendor sells two separate platforms, and the fraud product has its own plan grid; make sure a quotation covers the identity product you actually intend to buy
  • Governing jurisdiction differs between documents, naming the courts of Barakaldo in the website legal notice and those of Bilbao in the product licence terms
  • Placing an authentication factor on physical location can misfire on legitimate travel or remote work, so trusted zones and risk rules need tuning before enforcement is switched on
Setup

Setup & Integrations

Technical difficulty

Moderate, and gated by a sales process rather than by technical complexity. There is no self-service sign-up, so a contract precedes deployment. Integration is designed to be undemanding, with preconfigured connectors to Active Directory, LDAP, SCIM for Entra ID, Google Cloud Identity or CSV, and three routes to choose from: native agents, agentless standard protocols, or plugins for NPS, ADFS and operating-system logon. The Enterprise edition adds directory provisioning and conditional access policies, familiar IAM work. Premium asks for genuine configuration effort: defining trusted zones, a corporate perimeter and contextual risk rules. Spain's national cryptologic centre publishes a dedicated secure operation guide, CCN-STIC-1633, which signals a deployment that rewards planning.

Deployment

Web appMobile appDesktop appAPIPluginIOS appAndroid app

Apps stores

Integrations

Active Directory Microsoft Entra ID Google Cloud Identity Microsoft ADFS Microsoft NPS LDAP

Supported languages

EnglishSpanish
Company

Behind Ironchip Identity Platform

Company name
IRONCHIP TELCO, S.L.
Founded
15/05/2017
Country of origin
🇪🇸 Spain
Headquarters
Calle Beurko Viejo, 17 - 48902 Barakaldo, Bizkaia (Spain)
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Fundraising

June 2020: a round led by Inveready and EASO Ventures. Reported amounts differ across sources, at 500,000 EUR in some and 1 million EUR in others. The commercial registry records both investors joining the board on 16 June 2020.
July 2022: 2.1 million EUR, co-led by ABANCA alongside existing investors EASO Ventures and Inveready, with participation from CDTI through its Innvierte programme and from business angel Alex Rocha. New directors were registered on 23 August 2022.
June 2025: 1.5 million EUR led by Sabadell Venture Capital, backed by Inveready, EASO Ventures, ABANCA and CDTI. The operation combined equity and debt, including ENISA facilities.
Share capital has risen from 3,000 EUR at incorporation in 2017 to 91,158 EUR after the increase registered on 12 May 2026.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Does Ironchip Identity Platform require a mobile phone?
No. Mobileless authentication is one of its stated modes: users can authenticate with a USB security key, an NFC or RFID card, or a desktop authenticator instead of a phone.
How does location-based authentication actually work?
The platform reads signals from the user's surroundings to establish their real location, and treats that as an authentication factor. Administrators can define trusted zones and corporate perimeters, and the Premium edition learns each user's usual location patterns to flag geographic anomalies.
Which protocols and directories does it integrate with?
It speaks SAML, OAuth, OpenID Connect, RADIUS and LDAP, and connects to Active Directory, SCIM for Microsoft Entra ID, Google Cloud Identity or a CSV import. Plugins are provided for Microsoft NPS and ADFS, and for Windows, Linux and Mac logon.
Is there a free plan, and how much do the paid editions cost?
There is a permanent free plan for one to ten users. The Enterprise and Premium editions have no published price: their fees are set in a Subscription Agreement negotiated with each client.
Is there an API?
Yes. The privacy policy lists the API among the service's delivery channels, the Premium edition exports access logs and security events over Syslog or API for SIEM ingestion, and real-time reports are available via API. Documentation is published at docs.ironchip.com.
Are there mobile applications?
Yes. Ironchip Authenticator is published on both the Apple App Store and Google Play, and native desktop agents exist for Windows, macOS and Linux.
Which certifications does Ironchip hold?
ISO/IEC 27001:2022 and ISO/IEC 27701:2019, both issued by IVAC-Instituto de Certificacion and valid until June 2028, and an ENS High category certificate issued by SGS under Spanish Royal Decree 311/2022. The product is also listed in Spain's CCN-CERT CPSTIC catalogue.
Where is the data hosted?
Processing takes place by default within the European Economic Area, where the vendor says it keeps its main infrastructure. The ENS certificate names AWS Europe and Microsoft Azure Europe as external data centres in scope. No specific country is named.
Can Ironchip see my passwords or my biometric data?
No. The vendor states it does not store passwords in plaintext, has no access to users' private keys, and never receives raw biometric data; when a user authenticates with biometrics, the device only returns a success or failure signal.
Is a Data Processing Agreement available?
Yes. A DPA is formalised as Annex A to the general terms and conditions of the software licence, and it forms an integral part of the Subscription Agreement.
Conclusion

Should you pick Ironchip Identity Platform?

Ironchip Identity Platform is a focused answer to a narrow question: how to prove that the person authenticating is really where they should be. Building the product on location intelligence rather than on another code-based factor gives it a defensible position, and the option to authenticate without any mobile phone solves a deployment problem that most vendors quietly leave to the customer.

What sets it apart from many tools of comparable size is how much of its security claim is externally verifiable. The ISO/IEC 27001 and 27701 certificates are nominative and numbered, the ENS High certificate names both the auditor and the scope, and the product itself sits in Spain's CCN-CERT CPSTIC catalogue with a dedicated secure operation guide. For a Spanish public body, a bank or any organisation working through an NIS2 or DORA programme, that paperwork is the product as much as the software is.

Two reservations deserve to be stated plainly. The first is commercial opacity: not a single figure is published, the free tier aside, and the 99.5% availability target is explicitly disclaimed as an objective rather than a guarantee, with no credits attached. The second is a gap in disclosure rather than in engineering: the Premium edition is built on continuous learning from user behaviour and location patterns, yet no document anywhere addresses whether or how customer data feeds model training, and no named list of subprocessors is published.

Prospective buyers should therefore treat the certifications as the strong part of the file and put pricing, service levels, subprocessors and the training question on the agenda of the first sales call. The free tier makes an unhurried technical evaluation cheap, which is the sensible way to start.