Skip to main content
Version 0.1Draft

Security overview for assessors

Who this is for

Security and compliance officers assessing or approving a LuxID integration. This page is the front door of your dossier: every claim links to the page that carries the detail and its evidence. Nothing here replaces the linked pages - it routes you to them.

What LuxID is, in one paragraph

LuxID is a Luxembourgish digital identity service operated by POST Luxembourg for the LuxID E.I.G. It is a shared sovereign identity provider: your application federates to it over standard protocols (OIDC, OAuth 2.0, SAML 2.0); you never hold the user's credentials, and authentication - including MFA - happens entirely on LuxID's hosted surfaces. Trust model and governance: Trust framework.

Responsibility split

LuxID is responsible forYour organisation is responsible for
Operating authentication (Universal Login), credential storage, MFA methods, and the built-in recovery flows (password reset, resend activation, lockout recovery)Validating tokens correctly (signature, iss, aud, exp, nonce) - Protect your Application
Account security monitoring and breached-password detectionProtecting your own sessions and cookies - Session management
Platform hardening, availability and incident response on the IdP sideSecuring your redirect handling and credential storage - Key management
Gatekeeping which claims your application may request (Claim Templates)Data protection of the claims you receive (you are an independent controller) - GDPR and data protection

The facts assessors ask for

QuestionAnswerSource
Protocols and flowsOIDC (Authorization Code + PKCE primary), OAuth 2.0, SAML 2.0Authenticate
Assurance levelseIDAS-aligned Low / Substantial / High; per-application minimum + step-up via acr_valuesAuthentication levels
MFA methodsOTP (SMS/voice), TOTP, passkeys (FIDO2), LuxTrustMulti-factor authentication
User identifiersPseudonymous sub, scoped per Sphere (no global identifier exposed to Partners)Tokens and claims
Authentication log retention6 months rolling (cookies/navigation data: 13-month maximum, separate)GDPR and data protection
Availability commitment99.90%, with maintenance windows and severity-based incident responseSLA and support
Breach notificationUrgent Security Matter regime contractually defined; GDPR Art. 33 applies where personal data is affectedGDPR and data protection
CertificationsLuxID operates under POST's certification scope; LuxID-specific certification status and target dates are tracked on the certification pageCertification and accreditation
Sub-processors and legal basisDocumented in the LuxID Agreement and the GDPR pageLegal agreements, GDPR
Roadmap and change noticeContractual notice windows; quarterly roadmap; feature-status snapshotChange management and roadmap

Known open confirmations

Several assessment-relevant items are still marked "to be confirmed" on their pages (certification target dates, NIS2 classification, ETSI alignment assessment, BCP/DR figures). They are deliberately flagged rather than asserted - check Certification and accreditation for current status, and raise unresolved items with your onboarding contact; written confirmations can be requested through Contact and support channels.

Suggested assessment path

  1. Trust framework - the model and governance.
  2. GDPR and data protection - roles, data flows, retention, breach handling.
  3. Authentication levels + Tokens and claims - what assurance you actually get.
  4. Secure - the duties your own teams must implement.
  5. Certification and accreditation + SLA and support - evidence and commitments.
Updated 2026-07-02