# Cirrus Identity > Cirrus Identity is a cloud-hosted identity management company built specifically for higher education and research. Cirrus Bridge connects modern enterprise IdPs (Entra ID, Okta, Duo SSO) to InCommon and eduGAIN federation and to CAS applications like Banner, so institutions can retire Shibboleth without touching application configurations. Cirrus Proxy handles external identity: applicants, guests, alumni, and research collaborators. Cirrus works with 200+ institutions across the US, Canada, UK, Japan, and UAE. Key facts: - Microsoft names Cirrus Bridge as Solution 1 in its own documentation on multilateral federation with Entra ID - Cirrus Identity is an InCommon Catalyst Partner and operates 19% of InCommon IdPs as of 2025 - Bridge lets institutions retire Shibboleth or CAS infrastructure through a single DNS change, with no application changes and no InCommon re-registration - Cirrus Proxy does not persist user data beyond 90-day event logs unless an institution explicitly opts into managed identity - The entire Cirrus leadership team came from higher ed identity management roles at UC Berkeley, Duke, Stanford, Columbia, UCSF, and the University of Wisconsin - SOC 2 Type II, annual penetration testing, HECVAT, 24x365 production support ## Solutions - [Cirrus Bridge](https://www.cirrusidentity.com/solutions/bridge): Managed federation adapter connecting Entra ID, Okta, or Duo SSO to InCommon, eduGAIN, and CAS applications like Banner. The path off Shibboleth that does not require reconfiguring applications. - [Cirrus Proxy for External Users](https://www.cirrusidentity.com/solutions/proxy): External identity layer for applicants, guests, alumni, parents, contractors, and affiliates. The users enterprise IdPs were not designed for. ## Products - [Bridge products](https://www.cirrusidentity.com/products/bridge): Bridge for Entra ID, Okta, Duo SSO, and other enterprise IdPs, including the DNS Add-On for legacy endpoint cutover - [External user sign-in](https://www.cirrusidentity.com/products/external): Guest and external user authentication with social sign-in and OrgBrandedID credentials - [Federated and affiliated sign-in](https://www.cirrusidentity.com/products/federation): Research collaboration and affiliate access using home institution credentials via InCommon - [Slate applicant sign-in](https://www.cirrusidentity.com/products/slate): Applicants use their existing Slate credentials to access campus applications before institutional provisioning ## Customers - [Customer stories](https://www.cirrusidentity.com/customers): Institutions using Cirrus, including University of Michigan, Texas A&M, Carnegie Mellon, Harvard, Brown, EDUCAUSE, and Internet2 - [Customer success use cases](https://www.cirrusidentity.com/use-cases): Real deployment patterns across guest access, applicant access, federation, and legacy retirement ## Optional - [Company](https://www.cirrusidentity.com/company): Founded 2013, majority employee-owned, every leader came from higher ed - [Cirrus team](https://www.cirrusidentity.com/company/cirrus-team) - [Trust and compliance center](https://www.cirrusidentity.com/resources/trust-and-compliance-center): SOC 2 Type II, HECVAT, security documentation - [Documentation](https://www.cirrusidentity.com/documentation) - [Blog and learning center](https://www.cirrusidentity.com/blog) - [Contact](https://www.cirrusidentity.com/talk-to-us): Book a demo, or email sales@cirrusidentity.com