STAR Registry Listing for
NamoID
NamoID
NamoID is an India-first OAuth 2.1 / OIDC identity provider (SaaS). It lets developers add secure sign-in, social + India-specific login (WhatsApp OTP, DigiLocker, Aadhaar offline KYC), MFA, and multi-tenant user management to their apps.
Security posture
- OAuth 2.1 / OIDC with PKCE mandatory on every flow (no implicit or password grant).
- RS256-signed tokens via published JWKS; the private signing key never leaves the service.
- Refresh-token rotation with replay-chain revocation.
- AES-256-GCM encryption at rest (provider tokens, TOTP secrets) under rotatable keys; TLS in transit.
- Strict multi-tenant isolation, append-only audit log, Redis-backed rate limiting.
Privacy (India / DPDP Act 2023)
- Data residency in AWS Mumbai (ap-south-1).
- Aadhaar masked at rest (last-4 + name-hash; full number and XML never persisted).
- Data-subject export + deletion; per-connection consent capture.
Security overview, responsible-disclosure policy, and sub-processors: https://namoid.in/security

Listed Since: 06/27/2026
STAR Level 1
Self-Assessment & Partner-Provided

CAIQ Self-assessment v4.1.0
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 3 days ago, on June 27, 2026.