Isometric illustration of a customer portal with centralised login, multi-factor authentication, audit log, tenant separation, and document exchange
Included in every delivery

Customer Portal & Logins — Included in Every krafteq Delivery

The krafteq Customer Portal and our centralised login stack on Keycloak are part of every krafteq delivery — not sold separately, no extra charge. You receive centralised logins, multi-factor authentication (MFA), a complete audit trail, and a portal for requests, documents, and status the moment your software is running. One clarification up front: the portal is the layer between your business and krafteq — it is not a portal for your business's own customers. krafteq Handwerk is standard software for trade businesses — not a project built for you from scratch. We are currently rolling it out with the first businesses: you test it free of charge, receive an individual offer afterwards, and we set up your business together with you.

Keycloak Centralised logins, MFA, single sign-on on request
Traceable GDPR-compliant handling of accounts and data
Customer Portal Requests, documents, and status in one place
Try it free

Portal and IAM are included in every krafteq engagement — not sold separately, no extra charge.

What the Portal and the Login Stack Handle for You

The Portal and the login stack are the two finished building blocks that come standard with every piece of krafteq software. These eight points are included as standard — no add-on tier, no separate licence, no configuration marathon.

Centralised Login with Email and Password

Standard login built on Keycloak — hardened, with a sensible password policy and self-service password reset via confirmed email delivery. No custom-built login per application.

Single Sign-On against Microsoft 365 or Google Workspace

SSO via OIDC against Microsoft Entra ID or Google Workspace, available on request. If your business already uses one of these platforms, your staff sign in with their familiar account.

Multi-Factor Authentication (MFA) — Optional

MFA activatable per user or per tenant — recommended for owner accounts, optional for all others. Standard methods such as TOTP or email, with no external licence model.

Roles, Permissions, and Tenant Separation

Standard roles (Owner, Staff, Read-Only) plus custom roles per application. Strict logical tenant separation — one client can never access another client's data.

Audit Log with a Minimum of 90 Days' Retention

Who did what and when — exportable, with a minimum of 90 days' retention; longer retention available on request. Satisfies GDPR requirements for the traceability of data access.

Account Lifecycle and Right to Erasure

Onboarding, suspension, and GDPR-compliant deletion of accounts and personal data. The right to erasure (Art. 17 GDPR) is implemented as standard, not retrofitted.

Customer Portal — Status, Documents, Change Requests

A single interface for your relationship with krafteq: see where set-up, fine-tuning and go-live stand, exchange contracts, Data Processing Agreements (DPAs) and documents, submit change requests and questions, and track their progress. No more scattered email threads.

Changes, Invoices, and Backup Status in the Portal

The Portal shows you what changed in the latest update, your open and settled invoices, and the status of your software's most recent backup. A self-service data export for your application data is available optionally.

Four Reasons Why Both Should Be Standard

Solo-developer agencies build a new, basic login for every project — usually without MFA, without an audit log, without a proper password policy. Subscription software provides its own logins but no portal for the relationship between you and your vendor. We build both once, properly, and use them for every client — which is why a ten-person business gets a security standard it could otherwise never afford.

Security From The Start, Not a Home-Built Login

Home-built logins suffer from well-known vulnerabilities — missing rate limits, insecure password storage, no MFA path. krafteq IAM is built on Keycloak, an open-source standard with over ten years of production use. You inherit hardened security defaults without anyone having to start from scratch.

GDPR-Compliant Without Workarounds

Audit log with a minimum of 90 days' retention, account lifecycle including the right to erasure, tenant separation per client — all included as standard. This allows you to satisfy GDPR's evidencing and deletion requirements without last-minute compliance theatre. A Data Processing Agreement (DPA) is included in every krafteq contract.

Grows With You — From 5 to 50 Employees

As your business grows from 5 to 25 or 50 employees, the login stack scales with you. Role granularity, per-tenant MFA policies, and audit log retention are equally reliable regardless of your headcount. And because krafteq does not bill per head, the software does not get more expensive when you hire.

Integration with Microsoft 365 or Google Workspace

If your business already uses Microsoft 365 or Google Workspace, SSO via OIDC can be configured at short notice. Your staff sign in with their familiar account; on- and offboarding runs centrally through your existing directory management. The standard email-and-password login remains available in parallel if required.

krafteq Portal & Logins vs. Home-Built Login vs. No Portal

Three realistic options when running bespoke software for your business — with an honest assessment of each dimension. The point is not that home-built solutions never work. The point is that they must be rebuilt from scratch for every project — and only a vendor with a productised stack can make that economically viable.

krafteq Portal & IAMHome-Built Login (Solo Developer)No Portal — Email Threads
Security (MFA, password policy) MFA optional, hardened defaults via KeycloakMFA rare, password policy often weakNot applicable — no centralised login
Audit Log Standard, minimum 90 days' retention, exportableRarely present, often only application logsNot present
GDPR Compliance By design, right to erasure included as standardIncomplete, right to erasure usually retrofittedRisky — no traceability of data access
SSO Integration (Microsoft 365, Google Workspace) Via OIDC, configurable at short noticeRarely supported, separate effort per projectNot possible
Tenant Separation Strictly logical, dedicated tenant per clientVariable, often redesigned per projectNot applicable — no centralised system
Grows from 5 to 50 Employees Seamless, identical architectureFrequently rebuilt from 10–20 users onwardsBreaks down at 5 employees at the latest
Maintenance and Patches Included in krafteq Cloud, managed centrallyEach application is your own responsibility, often neglectedNot applicable
Onboarding Effort for New Employees Self-service or via existing Microsoft 365 / Google WorkspaceManual account creation per applicationManually maintained email distribution lists
Client Document Exchange In the Portal, with version history and statusEmail attachments, no central version controlEmail attachments, no central version control

With the Diligence of a German Engineering Partner

The Portal and the login stack are operated by krafteq GmbH, Leverkusen. The same engineering standards we apply for industrial clients also carry the logins of a ten-person business — simply at a different scale.

krafteq GmbH, Leverkusen

A German limited company headquartered in Leverkusen, NRW. A dedicated point of contact rather than a call centre. On-site meetings are possible; fully remote engagements equally so.

Security built into the process

Code review on every change, secrets management with HashiCorp Vault, SBOM generation, and vulnerability scanning on every container.

Keycloak, Open Source, Operated in the EU

Our login stack is built on Keycloak — an established open-source standard. Self-operated in krafteq Cloud on servers of European providers (Hetzner, OVHcloud or IONOS, depending on requirements) in Germany or the EU. No third-party licence, no vendor lock-in; sub-processors and safeguards are set out in the Art. 28 GDPR DPA and the TOMs.

Built by experienced senior engineers

Every specialist brings 10+ years of hands-on experience. Access to production systems is granted only via MFA and bastion hosts.

“A custom-built login per project is the most common vulnerability we find in software inherited from solo vendors. We build the login stack on Keycloak and the shared Customer Portal once, properly, and use both for every client — which is why even a ten-person business gets a security standard it could otherwise never afford. That is precisely why the Portal and the logins are standard at krafteq, not an add-on.”

Ivan Bianko, Geschäftsführer krafteq

Frequently Asked Questions about the Customer Portal and Logins

You decide how your software is operated.

The Portal and the login stack run as part of krafteq operations. If you prefer to operate the software yourself — on your own server, with your IT provider, or entirely without an internet connection — you can; we hand over the container build definition, the documentation and the source code.

See operations and self-operation

Would You Rather Speak First?

Book a 30- to 60-minute free consultation. You describe your situation; we give you an honest assessment — even if the answer is: a simpler login is sufficient in your case. No sales pitch, no obligation.

  • Free
  • No obligation
  • 30–60 minutes

Book an appointment

Loading booking calendar…

Or contact us directly: contact@krafteq.de