
Customer Portal & Logins — Included in Every krafteq Delivery
The krafteq Customer Portal and our centralised login stack on Keycloak are part of every krafteq delivery — not sold separately, no extra charge. You receive centralised logins, multi-factor authentication (MFA), a complete audit trail, and a portal for requests, documents, and status the moment your software is running. One clarification up front: the portal is the layer between your business and krafteq — it is not a portal for your business's own customers. krafteq Handwerk is standard software for trade businesses — not a project built for you from scratch. We are currently rolling it out with the first businesses: you test it free of charge, receive an individual offer afterwards, and we set up your business together with you.
Portal and IAM are included in every krafteq engagement — not sold separately, no extra charge.
What You ReceiveWhat the Portal and the Login Stack Handle for You
The Portal and the login stack are the two finished building blocks that come standard with every piece of krafteq software. These eight points are included as standard — no add-on tier, no separate licence, no configuration marathon.
Centralised Login with Email and Password
Standard login built on Keycloak — hardened, with a sensible password policy and self-service password reset via confirmed email delivery. No custom-built login per application.
Single Sign-On against Microsoft 365 or Google Workspace
SSO via OIDC against Microsoft Entra ID or Google Workspace, available on request. If your business already uses one of these platforms, your staff sign in with their familiar account.
Multi-Factor Authentication (MFA) — Optional
MFA activatable per user or per tenant — recommended for owner accounts, optional for all others. Standard methods such as TOTP or email, with no external licence model.
Roles, Permissions, and Tenant Separation
Standard roles (Owner, Staff, Read-Only) plus custom roles per application. Strict logical tenant separation — one client can never access another client's data.
Audit Log with a Minimum of 90 Days' Retention
Who did what and when — exportable, with a minimum of 90 days' retention; longer retention available on request. Satisfies GDPR requirements for the traceability of data access.
Account Lifecycle and Right to Erasure
Onboarding, suspension, and GDPR-compliant deletion of accounts and personal data. The right to erasure (Art. 17 GDPR) is implemented as standard, not retrofitted.
Customer Portal — Status, Documents, Change Requests
A single interface for your relationship with krafteq: see where set-up, fine-tuning and go-live stand, exchange contracts, Data Processing Agreements (DPAs) and documents, submit change requests and questions, and track their progress. No more scattered email threads.
Changes, Invoices, and Backup Status in the Portal
The Portal shows you what changed in the latest update, your open and settled invoices, and the status of your software's most recent backup. A self-service data export for your application data is available optionally.
Competitive AdvantageFour Reasons Why Both Should Be Standard
Solo-developer agencies build a new, basic login for every project — usually without MFA, without an audit log, without a proper password policy. Subscription software provides its own logins but no portal for the relationship between you and your vendor. We build both once, properly, and use them for every client — which is why a ten-person business gets a security standard it could otherwise never afford.
Security From The Start, Not a Home-Built Login
Home-built logins suffer from well-known vulnerabilities — missing rate limits, insecure password storage, no MFA path. krafteq IAM is built on Keycloak, an open-source standard with over ten years of production use. You inherit hardened security defaults without anyone having to start from scratch.
GDPR-Compliant Without Workarounds
Audit log with a minimum of 90 days' retention, account lifecycle including the right to erasure, tenant separation per client — all included as standard. This allows you to satisfy GDPR's evidencing and deletion requirements without last-minute compliance theatre. A Data Processing Agreement (DPA) is included in every krafteq contract.
Grows With You — From 5 to 50 Employees
As your business grows from 5 to 25 or 50 employees, the login stack scales with you. Role granularity, per-tenant MFA policies, and audit log retention are equally reliable regardless of your headcount. And because krafteq does not bill per head, the software does not get more expensive when you hire.
Integration with Microsoft 365 or Google Workspace
If your business already uses Microsoft 365 or Google Workspace, SSO via OIDC can be configured at short notice. Your staff sign in with their familiar account; on- and offboarding runs centrally through your existing directory management. The standard email-and-password login remains available in parallel if required.
Comparisonkrafteq Portal & Logins vs. Home-Built Login vs. No Portal
Three realistic options when running bespoke software for your business — with an honest assessment of each dimension. The point is not that home-built solutions never work. The point is that they must be rebuilt from scratch for every project — and only a vendor with a productised stack can make that economically viable.
| krafteq Portal & IAM | Home-Built Login (Solo Developer) | No Portal — Email Threads | |
|---|---|---|---|
| Security (MFA, password policy) | MFA optional, hardened defaults via Keycloak | MFA rare, password policy often weak | Not applicable — no centralised login |
| Audit Log | Standard, minimum 90 days' retention, exportable | Rarely present, often only application logs | Not present |
| GDPR Compliance | By design, right to erasure included as standard | Incomplete, right to erasure usually retrofitted | Risky — no traceability of data access |
| SSO Integration (Microsoft 365, Google Workspace) | Via OIDC, configurable at short notice | Rarely supported, separate effort per project | Not possible |
| Tenant Separation | Strictly logical, dedicated tenant per client | Variable, often redesigned per project | Not applicable — no centralised system |
| Grows from 5 to 50 Employees | Seamless, identical architecture | Frequently rebuilt from 10–20 users onwards | Breaks down at 5 employees at the latest |
| Maintenance and Patches | Included in krafteq Cloud, managed centrally | Each application is your own responsibility, often neglected | Not applicable |
| Onboarding Effort for New Employees | Self-service or via existing Microsoft 365 / Google Workspace | Manual account creation per application | Manually maintained email distribution lists |
| Client Document Exchange | In the Portal, with version history and status | Email attachments, no central version control | Email attachments, no central version control |
TrustWith the Diligence of a German Engineering Partner
The Portal and the login stack are operated by krafteq GmbH, Leverkusen. The same engineering standards we apply for industrial clients also carry the logins of a ten-person business — simply at a different scale.
krafteq GmbH, Leverkusen
A German limited company headquartered in Leverkusen, NRW. A dedicated point of contact rather than a call centre. On-site meetings are possible; fully remote engagements equally so.
Security built into the process
Code review on every change, secrets management with HashiCorp Vault, SBOM generation, and vulnerability scanning on every container.
Keycloak, Open Source, Operated in the EU
Our login stack is built on Keycloak — an established open-source standard. Self-operated in krafteq Cloud on servers of European providers (Hetzner, OVHcloud or IONOS, depending on requirements) in Germany or the EU. No third-party licence, no vendor lock-in; sub-processors and safeguards are set out in the Art. 28 GDPR DPA and the TOMs.
Built by experienced senior engineers
Every specialist brings 10+ years of hands-on experience. Access to production systems is granted only via MFA and bastion hosts.
“A custom-built login per project is the most common vulnerability we find in software inherited from solo vendors. We build the login stack on Keycloak and the shared Customer Portal once, properly, and use both for every client — which is why even a ten-person business gets a security standard it could otherwise never afford. That is precisely why the Portal and the logins are standard at krafteq, not an add-on.”
FAQFrequently Asked Questions about the Customer Portal and Logins
You decide how your software is operated.
The Portal and the login stack run as part of krafteq operations. If you prefer to operate the software yourself — on your own server, with your IT provider, or entirely without an internet connection — you can; we hand over the container build definition, the documentation and the source code.
See operations and self-operationWould You Rather Speak First?
Book a 30- to 60-minute free consultation. You describe your situation; we give you an honest assessment — even if the answer is: a simpler login is sufficient in your case. No sales pitch, no obligation.
- Free
- No obligation
- 30–60 minutes