Member areas and log-in systems
Member areas give only authorised people access to documents, invoices or training. Signing in stays secure without becoming a chore.
Background
In a member area, customers, partners or staff handle many tasks themselves. This takes load off service teams. Log-in systems are a frequent target, though, as stolen credentials are tried automatically. If signing in is awkward, users fall back on phone and email.
Registration and sign-in
Registration with email confirmation or by invitation
Password rules based on guidance from the German BSI, stored with Argon2 or bcrypt
Two-factor authentication via app or security key
Passkeys for passwordless sign-in
Single sign-on via OpenID Connect or SAML, for example with Microsoft Entra ID
Roles and permissions
A role model defines who sees what and who may do what. We map it in the code via policies, down to individual records where needed. Administrators manage users and roles themselves, and companies can set up sub-accounts for their staff.
Protection against attacks
Log-in attempts are limited and suspicious sign-ins are logged. Sessions expire after inactivity. We check the implementation against the OWASP ASVS. We support external penetration tests and implement the findings.
Data protection
We collect only the data needed and store consents in a verifiable way. Users can view and export their data and delete their account. This supports data subject rights under the GDPR.
Approach
Existing accounts are migrated without a password reset, provided the old method allows it. One example is the PlanetHome customer area, with two-factor authentication in line with BSI guidelines. It has passed several penetration tests. Before launch, we test sign-in with real users.