
Customer Portal & IAM — Security From Day One, Included in Every Krafteq Engagement
The Krafteq Customer Portal and our Identity and Access Management (IAM) stack on Keycloak are core components of every Krafteq engagement — not sold separately, no extra charge. You receive centralised logins, multi-factor authentication (MFA), an audit log, and a web portal for tickets, documents, and status updates the moment your software goes live. Solo-developer agencies cannot operate this stack reliably; we build it once, correctly, and leverage it across many clients.
- Centralised logins via Keycloak — MFA and SSO optional
- Audit log and GDPR-compliant account lifecycle
- Customer Portal for tickets, documents, and status
What You ReceiveWhat the Portal and IAM Handle for You
The Portal and IAM are the two productised components that come standard with every piece of Krafteq software. These eight building blocks are included as standard — no add-on tier, no separate licence, no configuration marathon.
Centralised Login with Email and Password
Standard login built on Keycloak — hardened, with a sensible password policy and self-service password reset via confirmed email delivery. No custom-built login per application.
Single Sign-On against Microsoft 365 or Google Workspace
SSO via OIDC against Microsoft Entra ID or Google Workspace, available on request. If your business already uses one of these platforms, your staff sign in with their familiar account.
Multi-Factor Authentication (MFA) — Optional
MFA activatable per user or per tenant — recommended for owner accounts, optional for all others. Standard methods such as TOTP or email, with no external licence model.
Roles, Permissions, and Tenant Separation
Standard roles (Owner, Staff, Read-Only) plus custom roles per application. Strict logical tenant separation — one client can never access another client's data.
Audit Log with a Minimum of 90 Days' Retention
Who did what and when — exportable, with a minimum of 30 days' retention; longer retention available on request. Satisfies GDPR requirements for the traceability of data access.
Account Lifecycle and Right to Erasure
Onboarding, suspension, and GDPR-compliant deletion of accounts and personal data. The right to erasure (Art. 17 GDPR) is implemented as standard, not retrofitted.
Customer Portal — Project Status, Documents, Tickets
A single web interface for your relationship with krafteq: view the status of active sprints, exchange contracts, Data Processing Agreements (DPAs), and specifications, submit tickets, and track resolution progress. No more scattered email threads.
Releases, Invoices, and Backup Status in the Portal
The Portal shows you the changelog for every update, your open and settled invoices, and the status of your software's most recent backup. A self-service data-export button for your application data is available optionally.
Competitive AdvantageFour Reasons Why Portal and IAM Should Be Standard
Solo-developer agencies build a new, basic login for every project — usually without MFA, without an audit log, without a proper password policy. SaaS tools provide their own logins but no integrated portal for the relationship between you and your vendor. Krafteq invests once in a productised stack — and delivers enterprise-grade security at a small-business price.
Security From Day One, Not a Home-Built Login
Home-built logins suffer from well-known vulnerabilities — missing rate limits, insecure password storage, no MFA path. Krafteq IAM is built on Keycloak, an open-source standard with over ten years of production use. You inherit hardened security defaults without anyone having to start from scratch.
GDPR-Compliant Without Workarounds
Audit log with a minimum of 30 days' retention, account lifecycle including the right to erasure, tenant separation per client — all included as standard. This allows you to satisfy GDPR's evidencing and deletion requirements without last-minute compliance theatre. A Data Processing Agreement (DPA) is included in every Krafteq contract.
Scalable from 1 to 50 Employees
As your business grows from 5 to 25 or 50 employees, the IAM scales with you. Role granularity, per-tenant MFA policies, and audit log retention are equally reliable regardless of your headcount. You do not swap login architectures as you grow — you simply grow into the one you already have.
Integration with Microsoft 365 or Google Workspace
If your business already uses Microsoft 365 or Google Workspace, SSO via OIDC can be configured at short notice. Your staff sign in with their familiar account; on- and offboarding runs centrally through your existing directory management. The standard email-and-password login remains available in parallel if required.
ComparisonKrafteq Portal & IAM vs. Home-Built Login vs. No Portal
Three realistic options when running bespoke software for your business — with an honest assessment of each dimension. The point is not that home-built solutions never work. The point is that they must be rebuilt from scratch for every project — and only a vendor with a productised stack can make that economically viable.
| Krafteq Portal & IAM | Home-Built Login (Solo Developer) | No Portal — Email Threads | |
|---|---|---|---|
| Security (MFA, password policy) | MFA optional, hardened defaults via Keycloak | MFA rare, password policy often weak | Not applicable — no centralised login |
| Audit Log | Standard, minimum 30 days' retention, exportable | Rarely present, often only application logs | Not present |
| GDPR Compliance | By design, right to erasure included as standard | Incomplete, right to erasure usually retrofitted | Risky — no traceability of data access |
| SSO Integration (Microsoft 365, Google Workspace) | Via OIDC, configurable at short notice | Rarely supported, separate effort per project | Not possible |
| Tenant Separation | Strictly logical, dedicated tenant per client | Variable, often redesigned per project | Not applicable — no centralised system |
| Scalability from 1 to 50 Employees | Seamless, identical architecture | Frequently rebuilt from 10–20 users onwards | Breaks down at 5 employees at the latest |
| Maintenance and Patches | Included in Krafteq Cloud, managed centrally | Each application is your own responsibility, often neglected | Not applicable |
| Onboarding Effort for New Employees | Self-service or via existing Microsoft 365 / Google Workspace | Manual account creation per application | Manually maintained email distribution lists |
| Client Document Exchange | In the Portal, with version history and status | Email attachments, no central version control | Email attachments, no central version control |
TrustWith the Diligence of a German Engineering Partner
The Portal and IAM are operated by krafteq GmbH, Leverkusen. The same engineering standards with which we serve enterprise clients in industry and manufacturing flow into the small-business stack — at a different scale.
krafteq GmbH, Leverkusen
A German limited company headquartered in Leverkusen, NRW. A dedicated point of contact rather than a call centre. On-site meetings are possible; fully remote engagements equally so.
ISO 27001 Certification in Progress
ISO 27001 certification in progress — currently in the gap analysis phase, target Q1 2027. Already in place today: code review on every change, secrets management with HashiCorp Vault, SBOM generation, and vulnerability scanning on every container.
Keycloak Open Source, EU-Hosted
Krafteq IAM is built on Keycloak — an established open-source standard. Self-hosted in Krafteq Cloud (servers in Germany), no third-party IAM licence, no vendor lock-in, no US CLOUD Act exposure.
Built by Senior Engineers
Every specialist brings at least 10 years of professional experience. Access to production systems is granted only via MFA and bastion hosts.
“A custom-built login per project is the most common vulnerability we find in software inherited from solo vendors. We invest once in a productised IAM stack on Keycloak and in a shared Customer Portal — and deliver enterprise-grade security at a small-business price. Solo competitors cannot do this without the same economies of scale. That is precisely why Portal and IAM are standard at Krafteq, not an add-on.”
FAQFrequently Asked Questions about the Customer Portal and IAM
Not a small business? Krafteq also serves mid-market and enterprise clients.
SRE/DevOps, QA Engineering, cloud cost optimisation, legacy-to-cloud migration, managed squads, DevSecOps, and CRA compliance — with senior engineers who have delivered in enterprise projects. Production-first, ownership over ticket-pushing.
View All ServicesWould You Rather Speak First?
Book a 30- to 60-minute free consultation. You describe your situation; we give you an honest assessment — even if the answer is: a simpler login is sufficient in your case. No sales pitch, no obligation.
- Free
- No obligation
- 30–60 minutes