Security overview for assessors
Security and compliance officers assessing or approving a LuxID integration. This page is the front door of your dossier: every claim links to the page that carries the detail and its evidence. Nothing here replaces the linked pages - it routes you to them.
What LuxID is, in one paragraph
LuxID is a Luxembourgish digital identity service operated by POST Luxembourg for the LuxID E.I.G. It is a shared sovereign identity provider: your application federates to it over standard protocols (OIDC, OAuth 2.0, SAML 2.0); you never hold the user's credentials, and authentication - including MFA - happens entirely on LuxID's hosted surfaces. Trust model and governance: Trust framework.
Responsibility split
| LuxID is responsible for | Your organisation is responsible for |
|---|---|
| Operating authentication (Universal Login), credential storage, MFA methods, and the built-in recovery flows (password reset, resend activation, lockout recovery) | Validating tokens correctly (signature, iss, aud, exp, nonce) - Protect your Application |
| Account security monitoring and breached-password detection | Protecting your own sessions and cookies - Session management |
| Platform hardening, availability and incident response on the IdP side | Securing your redirect handling and credential storage - Key management |
| Gatekeeping which claims your application may request (Claim Templates) | Data protection of the claims you receive (you are an independent controller) - GDPR and data protection |
The facts assessors ask for
| Question | Answer | Source |
|---|---|---|
| Protocols and flows | OIDC (Authorization Code + PKCE primary), OAuth 2.0, SAML 2.0 | Authenticate |
| Assurance levels | eIDAS-aligned Low / Substantial / High; per-application minimum + step-up via acr_values | Authentication levels |
| MFA methods | OTP (SMS/voice), TOTP, passkeys (FIDO2), LuxTrust | Multi-factor authentication |
| User identifiers | Pseudonymous sub, scoped per Sphere (no global identifier exposed to Partners) | Tokens and claims |
| Authentication log retention | 6 months rolling (cookies/navigation data: 13-month maximum, separate) | GDPR and data protection |
| Availability commitment | 99.90%, with maintenance windows and severity-based incident response | SLA and support |
| Breach notification | Urgent Security Matter regime contractually defined; GDPR Art. 33 applies where personal data is affected | GDPR and data protection |
| Certifications | LuxID operates under POST's certification scope; LuxID-specific certification status and target dates are tracked on the certification page | Certification and accreditation |
| Sub-processors and legal basis | Documented in the LuxID Agreement and the GDPR page | Legal agreements, GDPR |
| Roadmap and change notice | Contractual notice windows; quarterly roadmap; feature-status snapshot | Change management and roadmap |
Known open confirmations
Several assessment-relevant items are still marked "to be confirmed" on their pages (certification target dates, NIS2 classification, ETSI alignment assessment, BCP/DR figures). They are deliberately flagged rather than asserted - check Certification and accreditation for current status, and raise unresolved items with your onboarding contact; written confirmations can be requested through Contact and support channels.
Suggested assessment path
- Trust framework - the model and governance.
- GDPR and data protection - roles, data flows, retention, breach handling.
- Authentication levels + Tokens and claims - what assurance you actually get.
- Secure - the duties your own teams must implement.
- Certification and accreditation + SLA and support - evidence and commitments.