Why this exists

The problem Atlas Identity solves

Without Atlas Identity

Users have separate accounts for every system. Password reuse is inevitable. When someone leaves, accounts are manually disabled one by one over days. There is no audit trail of who accessed what. A compliance auditor asks for an access control matrix — there is none.

With Atlas Identity

One identity per user. One authentication event covers every system. Leavers are disabled in one place and locked out everywhere in seconds. MFA enforced by policy. Keycloak federates SAML and OIDC so cloud apps join the SSO domain. The entire access control matrix is exportable for any audit.

Architecture

How it works

Atlas Identity — SSO federation flow
Architecture overview — Atlas Identity component relationships

Regulatory compliance

What Atlas Identity satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(i)Multi-factor authentication for all privileged accounts and remote accessKeycloak MFA audit log · failed login alerts
NIS2 Art. 21(2)(j)Role-based access, leavers process, periodic access reviewKeycloak RBAC policy export · user lifecycle report
GDPR Art. 5(1)(f)Only authorised persons access personal dataKeycloak session audit · FreeIPA access policy export
GDPR Art. 32(1)(b)Ongoing confidentiality and integrity of processing systemsFreeIPA sudo rules · Keycloak role mapping export
BSI ORP.4Documented RBAC, leavers deprovisioning, privileged access managementFreeIPA user/group report · Keycloak session log
DORA Art. 9(4)(c)Least privilege, separation of duties, regular access reviewKeycloak user export · privilege review log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

Keycloak SSO — standalone install

Keycloak 24.x on Podman or Docker Compose. Realm config. One OIDC client integrated (OpenCloud, Gitea, or custom app). LDAP/AD federation. Basic RBAC roles defined.

  • Realm + client config
  • LDAP/AD federation
  • 1 OIDC application integrated
  • RBAC role mapping
  • 5-day post-install support

€ 620

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

MFA enforcement — TOTP/WebAuthn

Enable TOTP (Google Authenticator / FreeOTP) or WebAuthn (FIDO2) on existing Keycloak or Active Directory. Enrolment flow. Policy exceptions for break-glass accounts. Zabbix alert on MFA bypass attempt.

  • TOTP or WebAuthn policy
  • Enrolment flow + user comms template
  • Break-glass exception process
  • Zabbix alert hook
  • 5-day post-install support

€ 340

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

OpenSCAP compliance scan

CIS Benchmark Level 2 or DISA STIG scan on up to 10 Linux hosts. Findings mapped to NIS2/BSI controls. Remediation report with severity classification. One re-scan included after remediation.

  • OpenSCAP scan on up to 10 hosts
  • CIS Benchmark L2 or DISA STIG
  • Remediation report (severity-mapped)
  • NIS2/BSI control mapping
  • One re-scan included

€ 480

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. To have it fitted into your existing environment, add the Integration package from the consulting section below.

Ready-made boxes

Foundation · Plus · Enterprise — fixed price, plug & play

Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.

Foundation

5–50 users · 1 site · single server

Pre-configured · quick-start guide included

€ 1,980

Net, excl. VAT · one-off fixed price · hardware not included

  • Keycloak SSO (single node)
  • LDAP/AD federation
  • TOTP MFA enforcement
  • Basic RBAC policy
  • WireGuard VPN for remote users
Order this box
Enterprise

500+ users · multi-site · cluster-ready

Pre-configured · quick-start guide included

€ 3,380

Net, excl. VAT · one-off fixed price · hardware not included

  • FreeIPA multi-master replication
  • Keycloak cluster (3+ nodes)
  • SAML federation with external IdPs
  • SCIM just-in-time provisioning
  • PAM for privileged sessions
Order this box

Consulting services

Need more than the box?

The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.

Installation & handover

We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.

  • Installed and connected on your side
  • Admin walkthrough session
  • Configuration handed over documented

€ 890

Net, excl. VAT · fixed price

Request this package

Integration into your environment

Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.

  • Integration with 2 existing systems
  • Data / config migration
  • Rollback plan and test protocol

€ 1,890

Net, excl. VAT · fixed price

Request this package

Compliance mapping & audit support

We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.

  • Control mapping per regulation
  • Evidence package for the auditor
  • Gap list with remediation steps

€ 1,490

Net, excl. VAT · fixed price

Request this package
Larger scope? Multi-site rollouts, custom engineering and ongoing operations are quoted individually. Tell us what you need and we come back with a fixed price.

An Azure AD / Entra ID alternative: self-hosted SSO

Azure AD (now Microsoft Entra ID) ties your identities to the US cloud and a per-user subscription. Keycloak and FreeIPA provide single sign-on (SSO), MFA and directory services as a self-hosted open-source alternative — your identity data stays under your control, on-premises or in an EU cloud of your choice.

SAML, OAuth2/OIDC and LDAP are supported, so your existing applications stay connected without a Microsoft dependency. We migrate users and groups and hand over the documented configuration.