Made in Germany
GDPR & NIS2 compliant
25 Years of IAM Expertise
Vendor- & Cloud-independent
Reality Check:
When identity data gets out of control
The pressure to move to the cloud creates a dilemma for companies and public authorities: many dominant US IAM providers are subject to laws such as the US CLOUD Act.
This often forces IT decision-makers to store sensitive employee data, access structures and internal system architectures on servers that are not subject to European jurisdiction.
Risk from the US CLOUD Act
US authorities may request access to identity data – even if the servers are physically located in Europe. This creates an unpredictable legal risk for European organizations.
Loss of data sovereignty through vendor lock-in
SaaS monopolies decide where your data is stored and how it is processed. Migration or separation of cloud and on-premises data becomes extremely difficult.
Increased liability under NIS2 & GDPR
Managing directors and IT leaders are personally responsible for complying with European security standards. A lack of data sovereignty can lead to expensive fines and audit findings.
Uncertainty in hybrid infrastructures
Organizations often do not know exactly which identity and attribute data from the local Active Directory is synchronized unfiltered into global cloud directories.

Data Sovereignty with IDM-Portal

Full Data Sovereignty
& Geofencing
You decide where your identity data remains
FirstWare IDM-Portal ensures that your sensitive personnel and access-rights data remains where you define it. Whether on-premises in your own data center, in a sovereign European cloud or in hybrid scenarios: you retain exclusive control over the storage and processing of all attributes at all times.
Protection against third-country access (CLOUD Act security)
Legal certainty for European companies & public authorities
As a German software company, FirstAttribute develops according to the strictest European data protection standards. We provide an architecture free from extraterritorial access rights such as the US CLOUD Act. This reliably protects your core processes against data leakage and industrial espionage.


Granular Data Synchronization &
Filtering
No unintended disclosure of internal structures
You do not have to transfer all internal attributes to the cloud. With IDM-Portal, you precisely control which identity data, such as emergency contacts, internal phone numbers or security attributes, remains locally protected and which data is selectively synchronized with cloud services such as Microsoft Entra ID.
Audit Security &
Compliance at the Click of a Button
Tools for ISO 27001, NIS2 & BSI IT-Grundschutz
Fast, readily available evidence is the key to successful audits. IDM-Portal logs all data changes, role assignments and approvals in a tamper-proof way. You provide compliance evidence to auditors and regulators in minutes instead of after weeks of research.

What is FirstWare IDM-Portal?
Flexible IAM solution for Identity Governance & Administration
FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.
Powered by my-IAM – the underlying technology platform that enables seamless connection of any IT systems and cloud services.

Sovereign Control across Your Entire IT Landscape
Whether cloud-native, hybrid or on-premises, data sovereignty must not end at system boundaries. FirstWare IDM-Portal connects your systems seamlessly and sovereignly:
HR source systems
Personio, SAP SuccessFactors, SD Worx, Loga3
Directory Providers
Active Directory, Microsoft Entra ID, Keycloak, OpenLDAP
Specialist software & APIs
Connection of industry-specific software, SQL databases and specialist systems while strictly preserving your data sovereignty.

Your Benefits
Made in Germany
NIS2, GDPR & ISO 27001 compliance
Free Choice of Storage Location
Granular Control
Reduced Legal and Financial Liability Risks
Future-proof IGA Architecture
Frequently Asked Questions
Frequently asked questions about data sovereignty, transparent data control, secure access processes and self-determined handling of identity data in FirstWare IDM-Portal.
What does data sovereignty mean in IAM?
Data sovereignty means that an organization has complete legal, technical and organizational control over its identity and access data. This includes knowing and determining where data is stored, who can access it and under which laws it is processed.
Why is the US CLOUD Act a risk for European IAM data?
The US CLOUD Act requires American IT providers to give US authorities access to stored data, regardless of whether the server is located in the US or in Europe. For identity data that contains trade secrets and personal data, this creates a major conflict with GDPR.
How does FirstWare IDM-Portal ensure data sovereignty?
As a German company, FirstAttribute AG is subject exclusively to European and German law. The architecture of IDM-Portal and the underlying my-IAM platform allows operation in your own data centers or in European-hosted sovereign clouds such as STACKIT.
How does IDM-Portal support compliance with the NIS2 Directive?
NIS2 requires companies to provide stricter evidence for supply-chain security, access controls and data processing. IDM-Portal provides seamless audit trails, strict role separation and ensures that no critical access data flows abroad unchecked.
Can I use FirstWare IDM-Portal if we already use Microsoft Entra ID?
Yes, absolutely. IDM-Portal integrates seamlessly with Microsoft Entra ID and hybrid environments. It acts as a sovereign governance layer that lets you precisely filter and control which attributes from your local systems are synchronized with the cloud.
Let's Talk
Regain Full Control over Your Identity Data
Let us analyze together how you can set up your Identity Governance in line with GDPR and NIS2 requirements and achieve maximum data sovereignty.
Call us at 0 8196 - 998 4330 or use our contact form.
