Case study
Socket gave ID.me earlier visibility into active software supply chain threats, helping the team assess exposure faster during major ecosystem incidents.
ID.me expanded vulnerability management beyond tracking and reporting to include earlier fixing, blocking, and prevention with Socket.
Socket Firewall gave ID.me a practical path to address dependency risk across developer workflows, CI/CD, and local development environments.
GitHub-native workflows and flexible Socket controls brought supply chain security closer to how ID.me developers already work.
Timely threat intelligence and close partnership with Socket helped ID.me act quickly when exposure windows mattered most.

ID.me provides identity proofing, authentication, and group verification for government agencies and leading companies across sectors. Its digital identity network allows users to verify their identity once and use that proof of identity across organizations where ID.me is accepted.
As a company operating in a high-trust environment, ID.me’s security team supports critical digital identity infrastructure and a broad engineering organization. The team works across application security, cloud infrastructure, CI/CD, and software supply chain security, with a strong focus on protecting both production systems and the developer workflows that feed into them.
Before partnering with Socket, ID.me already had an application security program in place. But the team wanted to change the center of gravity for vulnerability management.
The existing program supported tracking and compliance reporting, but ID.me wanted to put more emphasis on fixing, prevention, and earlier developer ownership. The team needed a way to reduce dependency risk before vulnerable or malicious packages could reach production, while still fitting into how engineers already worked.
“For us, it was less about getting a new tool and more about changing how we looked at vulnerability management,” Phan said. “The main driver had been compliance reporting. I wanted the main motivator to be fixing and preventing.”
That shift required more than another dashboard. ID.me needed tooling that could support developer adoption, provide better supply chain intelligence, and help the team respond quickly when package ecosystem threats were unfolding in real time.
The rise of AI-assisted development also made local supply chain protection more urgent. Some risks never start in a traditional pipeline. A developer may be socially engineered into cloning a repository or installing a package locally. A coding assistant may pull down dependencies on behalf of a user who does not think of themselves as writing code. Those actions may never pass through standard SDLC controls before creating risk on a developer endpoint.
“Most of the threats that really burn a company do not originate in the pipeline,” Phan said. “The most devastating attacks still begin with social engineering. Someone gets spearphished, gets directed to pull something down from GitHub, and runs it on their laptop. That is not going to be checked into your pipeline, and traditional SDLC workflows are not going to catch it.”
For ID.me, these threats made local and developer-centered supply chain protection a key requirement.
ID.me selected Socket to help move supply chain security earlier in the development lifecycle and give the security team a stronger foundation for prevention.
Socket’s GitHub-native model gave ID.me a practical way to bring dependency security into developer workflows. Instead of relying only on centralized reporting or downstream ticketing, Socket could surface dependency risk where engineers already review and update code.
ID.me was not just looking for visibility. The team wanted security feedback to become part of normal engineering work, with developers able to see and act on issues before they became production risk.
“The foundation for me was scaffolding,” said Arnold Abernathy, Senior Director, Product Security & Security Engineering and Architecture at ID.me. “We needed the ability to orchestrate the developer experience in a way that could drive adoption. Socket gave us the adaptability and flexibility to make it work for our environment.”
Socket Firewall was also a major part of the fit. For ID.me, Firewall addressed an important gap in traditional application security programs: preventing malicious packages and supply chain attacks from reaching developer and build environments in the first place.
“Socket Firewall was a capability we knew we needed,” said Ryan Jacobchick, Principal AppSec Engineer at ID.me. “Supply chain risk posture was one of those things we wanted to address, but there were always other urgent fires. Socket made it much easier to move forward.”
Socket also gave ID.me a clearer path for supply chain threat intelligence. Previously, that capability was more ad hoc. With Socket, ID.me had a more defined way to learn about active incidents, understand potential exposure, and decide what action to take.
The value of Socket became clear during major public supply chain incidents.
In fast-moving dependency attacks, the earlier a security team learns about a compromise, the faster it can determine whether the organization is affected and take action before the situation escalates.
“The threat intelligence has been helping us sleep at night,” Abernathy said.
The early notice was immediately valuable for the team. “That paid on day zero. Socket informed us before anyone else.”
During public supply chain events, including the Axios compromise, Socket’s early communication gave ID.me valuable time to investigate and act. The team could quickly assess whether it was affected, take action where needed, and avoid unnecessary escalation when exposure was limited.
“The fact that Socket was one of the first to identify the issue and then took it upon yourselves to inform customers bought us very valuable time,” Phan said. “Exposure windows are everything in these kinds of events.”
The early warning helped turn a potentially disruptive incident into a much smaller operational event.
“Because we took quick action, it became a nothing burger for us,” Phan said.
Socket has already helped ID.me establish a path toward several important security objectives, including broader participation in supply chain triage.
Instead of requiring application security specialists to manually investigate every supply chain event, ID.me can use Socket as a central place to evaluate dependency risk and support more consistent response workflows.
“We now have a path to the business objectives we care about,” Abernathy said. “For example, enabling security operations to do triage instead of requiring my team to handle everything during an incident. Socket is going to be the control plane for that.”
Socket also supports ID.me’s goal of giving developers more ownership over dependency risk. By integrating security feedback into developer workflows, ID.me can move away from a model where security teams identify issues after the fact and then negotiate for engineering priority.
Instead, Socket helps ID.me build guardrails that support earlier action, clearer ownership, and faster decision-making.
ID.me also valued Socket’s responsiveness and focus on practical security outcomes. The team has worked closely with Socket on rollout questions and feature requests, with Socket responding quickly and taking feedback seriously.
“Nick has been very responsive with all of our Kubernetes questions,” Jacobchick said. “We’ve had a couple of feature requests, and Socket has taken them gracefully.”
For Phan, the broader value was Socket’s focus on the core security problem.

That focus showed up not only in customer communication, but also in product design and roadmap direction.
“You are leaning more heavily into prevention, moving further left, and helping developers fix things,” Phan said. “That is much more valuable to us than a tool that disproportionately invests in charts and reports.”
Socket gave ID.me earlier warning during active supply chain incidents, a stronger foundation for developer-centered protection, and a clearer path for moving vulnerability management closer to prevention.
That combination matters in a threat landscape where dependency risk can begin before code reaches the pipeline. With Socket, ID.me can assess exposure faster, bring dependency security into developer workflows, and build more consistent response processes across security teams.
“Socket was the right fit,” Phan said. “It matched the direction we wanted to go: fixing, preventing, and reducing risk before it reaches our products and infrastructure.”
Interested in Socket for your organization?
Schedule a demo with our team and try Socket.