Curity
Pending verificationSwedish identity and API access platform. OAuth and OpenID Connect infrastructure for organisations where security and control are non-negotiable.
Overview
Curity is a Sweden-based European company building authentication and developer tools software. As an EU-headquartered provider, Curity likely operates under GDPR, though EU Alts has not yet independently verified its ownership and hosting facts, so its exposure to the US CLOUD Act isn't confirmed yet — see the Details section below for what's known so far.
Why European teams pick Curity
Teams in Europe consider Curity when they want a authentication provider that bills in EUR and keeps customer data under Sweden law. Its EU headquarters is a good sign compared with Auth0 and Okta, but EU Alts hasn't yet verified Curity's ownership and hosting facts — check back once verification is complete.
See more EU authentication tools or browse other startups from Sweden.
About
Curity AB, founded in Stockholm in 2015, provides access infrastructure for securing APIs and modern systems. Its identity server implements OAuth 2.0 and OpenID Connect at scale, aimed at enterprises and regulated industries that need fine-grained control over authentication and token issuance. A European alternative to US-operated identity providers for organisations subject to GDPR.
Details
- Headquarters
- Sweden
Categories
Other EU startups like Curity
- Idura Denmark — Danish eID authentication and e-signature platform (formerly Criipto) — integrates MitID, Norwegian and Swedish BankID and the Finnish Trust Network.
- Hanko Germany — Open-source passkey and passwordless authentication from Kiel, Germany. Made and hosted in Europe, with self-hosting available.
- cidaas Germany — German cloud identity and access management (CIAM) platform — made and hosted in Germany, with dedicated German server locations for regulated sectors.
- Ploq The Netherlands — Ploq is EU-built webhook infrastructure: retries, event filtering, and health monitoring, GDPR-compliant end to end. SDKs for Node.js and Java, a WordPress plugin, and a forkable Mac/Windows app for sending and receiving events.
- Postscale — European transactional email and email API platform for sending, receiving, and managing email with privacy-first infrastructure and EU data residency.
- DNScale — European managed authoritative DNS platform with anycast, DNSSEC, API automation, Terraform support, and DDoS-protected DNS infrastructure.
Frequently asked questions
What is Curity?
Curity AB, founded in Stockholm in 2015, provides access infrastructure for securing APIs and modern systems. Its identity server implements OAuth 2.0 and OpenID Connect at scale, aimed at enterprises and regulated industries that need fine-grained control over authentication and token issuance. A European alternative to US-operated identity providers for organisations subject to GDPR.
What does Curity do?
Curity is swedish identity and api access platform. oauth and openid connect infrastructure for organisations where security and control are non-negotiable. It is listed under authentication and developer tools on EU Alts because its core functionality serves teams looking for a European authentication tool with EU data residency, typically as a switch away from Auth0 and Okta.
Is Curity a good European authentication alternative?
Curity is a fit for European businesses evaluating authentication options where data residency and GDPR alignment matter — typical buyers include EU-based SaaS teams, public-sector projects, regulated industries (healthcare, finance, legal), and any organisation that needs to demonstrate that customer data does not leave the EU. It also overlaps with developer tools use cases.
Is Curity GDPR compliant?
Curity is headquartered in Sweden and falls under EU jurisdiction, so it likely processes user data under the GDPR by default. Customer data processing is supervised by Sweden's data protection authority, the Integritetsskyddsmyndigheten (IMY). EU Alts has not yet independently verified Curity's ownership structure or hosting location, so we can't yet confirm its exposure to the US CLOUD Act the way we can for verified entries.
How do teams switch from Auth0 to Curity?
Most teams considering a move from Auth0 and Okta to Curity are drawn to its EU headquarters and authentication workflow fit. EU Alts hasn't yet verified Curity's ownership and hosting facts, so treat any CLOUD Act or Schrems II conclusions as provisional until verification is complete. Plan a migration in stages regardless: export your data from the US incumbent, pilot Curity with a small team, then move the rest once integration coverage is confirmed.
Where is Curity based?
Curity is headquartered in Sweden. Its main website is https://curity.io.