Service
Security & Identity (IAM)
Protect your applications and data with modern identity, authentication and authorization.
I help businesses design identity platforms and access control that keep users safe without getting in their way.
- Modern IdentityOAuth2 & OIDC
- Fine-grained AccessRBAC & ABAC
- Zero TrustVerify every request
- Compliance ReadyAudit trails
- 1. IdentifyUsers & services
- 2. AuthenticateSSO & MFA
- 3. AuthorizeRoles & policies
- 4. ProtectAPIs & data
- 5. AuditLogs & reviews
- 6. RespondDetect & recover
What I Provide
Security & IAM services tailored to your business needs.
Identity Architecture
Central identity for users, services and partners.
Authentication & SSO
OAuth2, OIDC, SAML, MFA and passwordless login.
Authorization (RBAC / ABAC)
Fine-grained access control that scales.
IAM Platforms
Keycloak and other IAM systems, set up and customized.
API Security
Protect APIs with tokens, scopes and gateways.
Security Reviews
Find and fix vulnerabilities before attackers do.
How I Work
A structured and transparent process to turn your idea into a production-ready solution.
- 1
Assess
Review current identity and access setup.
- 2
Design
Define identity architecture and access model.
- 3
Implement
Integrate authentication and authorization.
- 4
Test
Security testing and access reviews.
- 5
Roll Out
Migrate users with minimal friction.
- 6
Monitor
Audit, alert and keep improving.
Technologies I Use
Modern, proven technologies to build robust and scalable solutions.
Keycloak
Spring Security
- OAuth2
- OpenID Connect
- SAML
JWT
Spring Boot
NestJS
PostgreSQL
Redis
Docker
Kubernetes
Results & Impact
Delivering measurable value for every client.
100%
SSO Coverage
One login for every app
90%
Fewer Access Tickets
Self-service roles
0
Critical Findings
After security review
95%
Client Satisfaction
Successful project delivery
“Bishal redesigned our identity platform end to end. Our users got single sign-on and our auditors got the controls they needed.”
Frequently Asked Questions
Common questions about Security & IAM projects.
Which IAM platforms do you work with?
Mostly Keycloak and Spring Security, along with standard OAuth2/OIDC and SAML providers.
Can you add SSO to our existing applications?
Yes. I integrate existing apps with a central identity provider, usually without major changes to the apps themselves.
What's the difference between RBAC and ABAC?
RBAC grants access by role (e.g. admin, editor). ABAC uses attributes like department, region or ownership for finer control. Many systems use both.
Can you migrate users without forcing password resets?
Usually, yes — with password-hash import or on-the-fly migration at first login.
Do you do security reviews?
Yes — reviews of authentication flows, access control and API security, with a prioritized list of fixes.
Do you provide ongoing support?
Yes — upgrades, access reviews, new integrations and incident support.
Security & IAM
Ready to secure your platform?
Let's discuss your identity and access needs and design a solution that's secure and simple to use.

