Isometric illustration of a customer portal with centralised login, multi-factor authentication, audit log, tenant separation, and document exchange

Customer Portal & IAM — Security From Day One, Included in Every Krafteq Engagement

The Krafteq Customer Portal and our Identity and Access Management (IAM) stack on Keycloak are core components of every Krafteq engagement — not sold separately, no extra charge. You receive centralised logins, multi-factor authentication (MFA), an audit log, and a web portal for tickets, documents, and status updates the moment your software goes live. Solo-developer agencies cannot operate this stack reliably; we build it once, correctly, and leverage it across many clients.

  • Centralised logins via Keycloak — MFA and SSO optional
  • Audit log and GDPR-compliant account lifecycle
  • Customer Portal for tickets, documents, and status

What the Portal and IAM Handle for You

The Portal and IAM are the two productised components that come standard with every piece of Krafteq software. These eight building blocks are included as standard — no add-on tier, no separate licence, no configuration marathon.

Centralised Login with Email and Password

Standard login built on Keycloak — hardened, with a sensible password policy and self-service password reset via confirmed email delivery. No custom-built login per application.

Single Sign-On against Microsoft 365 or Google Workspace

SSO via OIDC against Microsoft Entra ID or Google Workspace, available on request. If your business already uses one of these platforms, your staff sign in with their familiar account.

Multi-Factor Authentication (MFA) — Optional

MFA activatable per user or per tenant — recommended for owner accounts, optional for all others. Standard methods such as TOTP or email, with no external licence model.

Roles, Permissions, and Tenant Separation

Standard roles (Owner, Staff, Read-Only) plus custom roles per application. Strict logical tenant separation — one client can never access another client's data.

Audit Log with a Minimum of 90 Days' Retention

Who did what and when — exportable, with a minimum of 30 days' retention; longer retention available on request. Satisfies GDPR requirements for the traceability of data access.

Account Lifecycle and Right to Erasure

Onboarding, suspension, and GDPR-compliant deletion of accounts and personal data. The right to erasure (Art. 17 GDPR) is implemented as standard, not retrofitted.

Customer Portal — Project Status, Documents, Tickets

A single web interface for your relationship with krafteq: view the status of active sprints, exchange contracts, Data Processing Agreements (DPAs), and specifications, submit tickets, and track resolution progress. No more scattered email threads.

Releases, Invoices, and Backup Status in the Portal

The Portal shows you the changelog for every update, your open and settled invoices, and the status of your software's most recent backup. A self-service data-export button for your application data is available optionally.

Four Reasons Why Portal and IAM Should Be Standard

Solo-developer agencies build a new, basic login for every project — usually without MFA, without an audit log, without a proper password policy. SaaS tools provide their own logins but no integrated portal for the relationship between you and your vendor. Krafteq invests once in a productised stack — and delivers enterprise-grade security at a small-business price.

Security From Day One, Not a Home-Built Login

Home-built logins suffer from well-known vulnerabilities — missing rate limits, insecure password storage, no MFA path. Krafteq IAM is built on Keycloak, an open-source standard with over ten years of production use. You inherit hardened security defaults without anyone having to start from scratch.

GDPR-Compliant Without Workarounds

Audit log with a minimum of 30 days' retention, account lifecycle including the right to erasure, tenant separation per client — all included as standard. This allows you to satisfy GDPR's evidencing and deletion requirements without last-minute compliance theatre. A Data Processing Agreement (DPA) is included in every Krafteq contract.

Scalable from 1 to 50 Employees

As your business grows from 5 to 25 or 50 employees, the IAM scales with you. Role granularity, per-tenant MFA policies, and audit log retention are equally reliable regardless of your headcount. You do not swap login architectures as you grow — you simply grow into the one you already have.

Integration with Microsoft 365 or Google Workspace

If your business already uses Microsoft 365 or Google Workspace, SSO via OIDC can be configured at short notice. Your staff sign in with their familiar account; on- and offboarding runs centrally through your existing directory management. The standard email-and-password login remains available in parallel if required.

Krafteq Portal & IAM vs. Home-Built Login vs. No Portal

Three realistic options when running bespoke software for your business — with an honest assessment of each dimension. The point is not that home-built solutions never work. The point is that they must be rebuilt from scratch for every project — and only a vendor with a productised stack can make that economically viable.

Krafteq Portal & IAMHome-Built Login (Solo Developer)No Portal — Email Threads
Security (MFA, password policy) MFA optional, hardened defaults via KeycloakMFA rare, password policy often weakNot applicable — no centralised login
Audit Log Standard, minimum 30 days' retention, exportableRarely present, often only application logsNot present
GDPR Compliance By design, right to erasure included as standardIncomplete, right to erasure usually retrofittedRisky — no traceability of data access
SSO Integration (Microsoft 365, Google Workspace) Via OIDC, configurable at short noticeRarely supported, separate effort per projectNot possible
Tenant Separation Strictly logical, dedicated tenant per clientVariable, often redesigned per projectNot applicable — no centralised system
Scalability from 1 to 50 Employees Seamless, identical architectureFrequently rebuilt from 10–20 users onwardsBreaks down at 5 employees at the latest
Maintenance and Patches Included in Krafteq Cloud, managed centrallyEach application is your own responsibility, often neglectedNot applicable
Onboarding Effort for New Employees Self-service or via existing Microsoft 365 / Google WorkspaceManual account creation per applicationManually maintained email distribution lists
Client Document Exchange In the Portal, with version history and statusEmail attachments, no central version controlEmail attachments, no central version control

With the Diligence of a German Engineering Partner

The Portal and IAM are operated by krafteq GmbH, Leverkusen. The same engineering standards with which we serve enterprise clients in industry and manufacturing flow into the small-business stack — at a different scale.

krafteq GmbH, Leverkusen

A German limited company headquartered in Leverkusen, NRW. A dedicated point of contact rather than a call centre. On-site meetings are possible; fully remote engagements equally so.

ISO 27001 Certification in Progress

ISO 27001 certification in progress — currently in the gap analysis phase, target Q1 2027. Already in place today: code review on every change, secrets management with HashiCorp Vault, SBOM generation, and vulnerability scanning on every container.

Keycloak Open Source, EU-Hosted

Krafteq IAM is built on Keycloak — an established open-source standard. Self-hosted in Krafteq Cloud (servers in Germany), no third-party IAM licence, no vendor lock-in, no US CLOUD Act exposure.

Built by Senior Engineers

Every specialist brings at least 10 years of professional experience. Access to production systems is granted only via MFA and bastion hosts.

“A custom-built login per project is the most common vulnerability we find in software inherited from solo vendors. We invest once in a productised IAM stack on Keycloak and in a shared Customer Portal — and deliver enterprise-grade security at a small-business price. Solo competitors cannot do this without the same economies of scale. That is precisely why Portal and IAM are standard at Krafteq, not an add-on.”

Ivan Bianko, Geschäftsführer krafteq

Frequently Asked Questions about the Customer Portal and IAM

Not a small business? Krafteq also serves mid-market and enterprise clients.

SRE/DevOps, QA Engineering, cloud cost optimisation, legacy-to-cloud migration, managed squads, DevSecOps, and CRA compliance — with senior engineers who have delivered in enterprise projects. Production-first, ownership over ticket-pushing.

View All Services

Would You Rather Speak First?

Book a 30- to 60-minute free consultation. You describe your situation; we give you an honest assessment — even if the answer is: a simpler login is sufficient in your case. No sales pitch, no obligation.

  • Free
  • No obligation
  • 30–60 minutes

Book an appointment

Loading booking calendar…

Or contact us directly: contact@krafteq.de