Skip to content

Member areas and log-in systems

Member areas give only authorised people access to documents, invoices or training. Signing in stays secure without becoming a chore.

Background

In a member area, customers, partners or staff handle many tasks themselves. This takes load off service teams. Log-in systems are a frequent target, though, as stolen credentials are tried automatically. If signing in is awkward, users fall back on phone and email.

Registration and sign-in

  • Registration with email confirmation or by invitation

  • Password rules based on guidance from the German BSI, stored with Argon2 or bcrypt

  • Two-factor authentication via app or security key

  • Passkeys for passwordless sign-in

  • Single sign-on via OpenID Connect or SAML, for example with Microsoft Entra ID

Roles and permissions

A role model defines who sees what and who may do what. We map it in the code via policies, down to individual records where needed. Administrators manage users and roles themselves, and companies can set up sub-accounts for their staff.

Protection against attacks

Log-in attempts are limited and suspicious sign-ins are logged. Sessions expire after inactivity. We check the implementation against the OWASP ASVS. We support external penetration tests and implement the findings.

Data protection

We collect only the data needed and store consents in a verifiable way. Users can view and export their data and delete their account. This supports data subject rights under the GDPR.

Approach

Existing accounts are migrated without a password reset, provided the old method allows it. One example is the PlanetHome customer area, with two-factor authentication in line with BSI guidelines. It has passed several penetration tests. Before launch, we test sign-in with real users.

Project enquiry

Back to top