GatewayPro
One platform for every identity across your operation
GatewayPro is IDGateway’s identity and access management platform for complex and controlled environments. It brings people, vehicles and assets into one clear, auditable process, managing each identity from application and verification through to approval, issuance, renewal and retirement.

Who is GatewayPro For?
Built for security and compliance teams in aviation, rail, ports, energy, construction, nuclear, major events and beyond. GatewayPro can be configured for any industry, bringing identity applications, permissions and approvals into one clear, auditable system.
Identity at the centre
Everything that needs access exists as a single identity record captured correctly the first time, with documents, checks and history attached for its working life. People, vehicles and equipment share one model, not three bolt-ons.
Identity as the centre
A person-centric (or asset-centric) data model in which the identity record is the primary reference credentials, authorisations and events all attach to it.
​
Identity capture & document handling
Structured capture of identity data and documents at the point of application, so the record is right before it enters the workflow.
​
People, vehicles, or objects
Polymorphic by design a contractor, their van and a piece of test equipment each carry an identity, an owner, an authorisation and an audit trail.

Configured, not coded

Application journeys and credential formats are configuration, not code. When your process changes or your regulator does — the platform changes with it. Compliant by configuration, not a development project.
Configurable application journeys
Your process, configured - not someone else's, hard-coded. Stages, approvals and requirements defined by the Security Pass Office, changed without a release cycle.
​
Credentials, configured not coded
Cards, formats and identifiers your way - credential types defined in configuration and issued from the same identity record.
Trust & accountability
Vetting outcomes, training records and competency evidence live on the identity, not in spreadsheets. And every identity has an authorised signatory someone is always answerable for it.
Sponsorship and accountability
Every identity carries an authorised signatory and a responsible party. Accountability is a field on the record, not an assumption.
Vetting, training, and competency
Checks, certificates and competencies attach to the identity — when a training certificate expires, the credential reflects it automatically and immediately.

Audit-ready by default

Every action, decision and change is recorded as it happens, attributed to a person, with a timestamp. When the audit lands, the answer is a report - not a six-week reconstruction from inboxes and spreadsheets.
Audit and traceability by default
A complete, attributable audit trail generated as a by-product of doing the work - who did what, when, and on whose authority - available on demand.
Enterprise fit
One platform serving many organisations, sites and regions, properly separated. Everyone who touches the process works in the same system. It fits inside your existing stack, and it clears security review first time.
Multi-tenant, multi-site, multi-region
One platform, many worlds, properly separated - tenancy boundaries by design, not by discipline.
​
Multi-party collaboration
Applicants, authorised signatories, the Security Pass Office and vetting providers each operate in a workspace matched to their accountability scope.
​
Integration-first, not rip-and-replace
API-first architecture (REST/JSON, SAML 2.0, OIDC, Entra ID) that adds the credential layer your stack is missing without rebuilding what you already have.
​
Procurement-grade operations
ISO 27001, GDPR, EU data residency, defined RPO/RTO, encryption in transit and at rest — through procurement on the first pass, not the third.

Live operational control

The whole lifecycle in one place — application, issue, renewal, suspension, retirement and the live state of any credential checkable on any phone, with every scan logged against the identity.
Operational lifecycle - application to retirement
Cradle to grave for every identity: one continuous record from first application to final retirement, with the live state visible throughout.
​
Field verification, on any phone
Mobile credential verification with real-time status lookup, hot-list and revocation handling, and per-scan event logging tied to the identity record.
Frequently Asked Questions
See GatewayPro built around your process
Tell us what you need, and we will show you how GatewayPro would work for you.


