Authentication
- Passwordless email verification and WebAuthn passkeys are implemented.
- Enterprise SAML 2.0 supports signed and encrypted assertions, replay protection, mapped upstream MFA, and step-up policy.
OASIS applies identity, authorization, data-protection, audit, and operational controls across the tenant boundary and the actions teams take inside it.
Important: These controls describe the current OASIS application design and verified implementation. No third-party certification is claimed.