Veloce built a system for us that enables rapid processing of policy preparation and sales. This makes us more competitive. And importantly — we can expand this solution if needed.
One identity
for customers, partners, and
employees across all your applications_
Veloce One Id takes over login, MFA, roles, and identity data from every application in your organization — for customers (CIAM) as well as employees and partners (IAM). You connect your portal, mobile app, store, CRM, and internal systems; the user logs in once, and you manage access from a single place.
Everything that login and access_ need
Instead of building registration, passwords, MFA, roles, and consents separately in every application — one platform for customers, partners, and employees, used by all of them.
One account and one session for all applications
The customer logs in once – on the portal, mobile app, store, or internal system – and stays logged in everywhere.
Second factor set up once, enforced everywhere
You configure methods, requirements, and exceptions centrally. Applications inherit the policy from Veloce One Id, so a regulatory change means one settings change, not six separate projects.
Methods: SMS, email, authenticator app
Policies per application and per operation (step-up)
Gradual rollout and adoption report
The customer manages their own account
A dedicated panel (Vue.js) in your branding: data, password, login methods, devices, consents, history. Every change propagates to all applications and systems — no helpline needed.
Changing contact details and password
MFA methods and trusted devices
GDPR and marketing consents — withdrawal effective everywhere
Login history and active sessions
Users, applications, policies, and integrations in one place
The administrator manages the entire login ecosystem from a single panel. A helpline consultant sees account status, recent logins, and can send a reset — without seeing the password and with a full activity log.
Application registration (client ID, redirect URI, scopes)
User search, status, blocks, MFA reset after verification
Administrator roles: full, consultant, read-only
Every administrator action is recorded in the event log
Who, when, from where, and to what — in a single log
Every login, error, MFA event, data change, and administrator action goes into a central log covering all applications. You can prepare evidence for KSC/NIS2 and DORA audits in minutes, not days.
Events from all applications in one place
Configurable retention
Export / stream to SIEM (Splunk, Sentinel, Elastic)
Ready-made audit reports: MFA adoption, unusual logins, admin actions
One identity, many roles
Customer, dealer, agent, consultant — the same systems, completely different permissions. You pass roles to applications in the token, and granting or revoking a partner's access takes a minute and applies everywhere at once.
Roles and attributes in the token (OIDC claims)
Organization contexts: an agent at two insurance companies, a dealer at three showrooms
Delegated administration for partners
Instant deactivation — sessions expire across all applications
Identity and access for employees and partners
The same platform handles internal accounts: consultants, administrators, facility staff, dealers, and agents. Employees log in with their domain account (federation with Active Directory / Entra ID), and Veloce One Id manages their roles and access to business applications — with MFA and a full audit trail, which is exactly what KSC/NIS2 and DORA require first.
Federation with AD / Entra ID via SAML or OpenID Connect
Onboarding with a role in a minute; offboarding invalidates sessions everywhere (automated with HR/CRM via API)
MFA mandatory for administrators and remote access; policies per role
One event log for customers and employees; export to SIEM
No re-registration, done in waves, one application at a time
The biggest fear around SSO: "will 900,000 people have to create a new account from scratch?" No. We import accounts from your existing systems, merge duplicates using verified attributes, and the customer confirms the merge at first login.
Import of accounts from source systems, passwords as hashes or set anew at first login
Merging duplicates by verified email / phone
Confirmation via code at first login
One event log for customers and employees; export to SIEM
Migration in waves — one application at a time, no big bang
Standards for new applications, an API for older ones
The team registers the application in the panel, adds the OpenID Connect library, and has login, MFA, a panel, and consents from day one. Systems without OIDC are connected via REST API. Ready-made integrations: Magento, SMS, email, corporate systems.
OpenID Connect / OAuth 2.0 for web and mobile
REST API: accounts, roles, events, consents
Ready-made integrations: Magento, SMS gateways, email, CRM/ERP/HIS
Test environment and integration documentation
Your data, a fixed cost, no per-user fees
Veloce One Id is not a Veloce cloud service. We install the platform on-premise or in a private cloud in Poland/the EU. Customer data never leaves your environment, and a million accounts cost the same as a hundred thousand.
On-premise (Windows Server / .NET) or private cloud in PL/EU
No connections to Veloce in production traffic
High availability and scaling — 900,000+ users in a single installation
Updates delivered as part of the SLA
Turn on MFA once. It applies everywhere_
You configure methods, requirements, and exceptions in a single panel. Applications don't have their own mechanisms — they inherit the policy from Veloce One Id. A regulatory change means one settings change, not six separate projects.
Methods: SMS, email, authenticator app
Policies per application and per operation (step-up for results, payments, data changes)
Gradual rollout: a transition period and an MFA adoption report
Password policies, lockouts after failed attempts, new-login notifications
The customer manages their own account_
A dedicated panel (Vue.js) in your branding: data, password, login methods, devices, consents, history. Every change propagates to all applications and systems.
Changing contact details and password without a helpline
Managing MFA methods and trusted devices
GDPR and marketing consents in one place — withdrawal effective everywhere
Login history and active sessions
One identity system for
customers and for your team_
A helpline consultant, an administrator, a facility employee, a dealer, an agent — each has a role, MFA, and access only to what they need. Employees log in with their domain account, partners with their own; Veloce One Id decides who sees what, and records every action.
Roles and attributes in the token; organization contexts for partner networks
Delegated administration: a showroom manager creates accounts for their staff
Deactivation from a single place — instantly, across all applications
The consultant handles the customer's account without knowing the password, with an activity log
New app in weeks, not quarters_
The team registers the app in the dashboard, adds the OpenID Connect library, and gets login, MFA, dashboard, and consents from day one. Systems without OIDC can be connected via REST API.
OpenID Connect / OAuth 2.0 for web and mobile (PKCE)
REST API for managing accounts, roles, and events
User roles and attributes passed in the token
Testing environment and integration documentation
Connects with what you already have_
Standards for new applications, ready-made integrations for systems that have been running for years.
We connect it as part of the implementation. Platform technology: Microsoft .NET (C#), Vue.js, REST.
Your infrastructure. Your data.
Fixed cost_
Veloce One Id is not a Veloce cloud service. We install the platform wherever you want, and we do not charge user-based fees — a million accounts cost the same as a hundred thousand.
Windows Server / .NET, your databases, your monitoring. Zero connections to Veloce in production traffic.
Your chosen provider and region. Compliance with medical and financial data residency policies.
We handle over 900,000 accounts in a single production installation. High availability and traffic peaks included in the deployment scope.
Microsoft .NET + Vue.js/React + cloud-native (Docker, Kubernetes, Kafka). Stack accepted by corporate IT departments, compliance-friendly, ready for KNF or banking audits.
users in production
to the first application
each subsequent application
of cooperation with our largest client
What people_ say about working
with us
No buzzwords or marketing clichés. Quotes with real names, job titles, and companies — authentic feedback from our partners.
Following the adaptation of V.CMS to the needs of mForex and mdm.pl, content management has become smooth and intuitive. 900k monthly visits is a test that the system passes every day — without failure, without compromise.
The CRM from Veloce integrated our website, the MyTUI app, and the financial-accounting system into one. Around 1,000 users in 136 offices now work within a single ecosystem. Sales automation and reduced booking management costs — in numbers.
Platform, deployment, maintenance_
One price for everything. No per-user fees, no surprises as your database grows.
Platform
Veloce One Id license
- SSO, MFA, user portal, admin panel
- CIAM + IAM: customers, partners, employees
- Roles, policies, event log, AD / Entra ID federation
- OpenID Connect and REST API
- Installation in your infrastructure
Deployment
8–12 weeks to the first application
- Analysis and architecture (2–3 weeks)
- Installation, MFA configuration, and panel setup
- Integrations with your systems
- Account migration without re-registration
- Connecting the first application
Maintenance
SLA
- Monitoring and security updates
- Connecting subsequent applications (2–4 weeks)
- Development of features and new login methods
- Support for your integrating teams
Per-user SaaS vs Veloce One Id — how
the bill grows_
In the SaaS model, every active user incurs a fee. With Veloce One Id, you pay for the platform, deployment, and maintenance — and the number of accounts doesn't change the bill. Move the slider to see where the curves intersect.
Veloce One Id, Keycloak, or Auth0_
Three real paths to single sign-on for customers. Each makes sense in a different situation — below is an honest look at where each one wins.
| Criterion | Veloce One Id dedicated solution | Keycloak open source | Auth0 / Okta CIC SaaS |
|---|---|---|---|
| Cost model | License + deployment + SLA fixed cost, independent of the number of users | No license full team and operations cost on your side | Active user fee (MAU) grows along with your customer base |
| Where data resides | ✓ Your infrastructure (PL/EU) | ✓ Your infrastructure | Vendor cloud EU regions available |
| SSO: OpenID Connect | ✓ | ✓ | ✓ |
| MFA | ✓ SMS, e-mail, app policies per application, step-up | ✓ TOTP, WebAuthn SMS via custom extensions | ✓ wide range adaptive MFA in higher plans |
| User portal | ✓ dedicated, in your branding | Basic full portal to be built | ✓ configurable |
| Admin panel and event log | ✓ standard | ✓ admin console reports and retention to be built | ✓ standard log retention depends on plan |
| Legacy system integrations Magento, HIS, CRM, SMS | ✓ ready-made + within deployment scope | To be built | To be built (Actions / API) |
| Existing account migration | ✓ within deployment scope without re-registration | Possible in-house work | Possible lazy / bulk migration |
| Who maintains it | Veloce under SLA | Your team or an external company | Vendor (platform) integrations – you |
| Technology | .NET / C#, Vue.js | Java | SaaS |
| Time to first application | 8–12 weeks with integrations and migration | 2–6 months depending on the team | Weeks simple case, no legacy |
| Identity scope | ✓ customers + partners + employees CIAM and IAM in a single installation | ✓ customers + employees custom configuration and integrations | Customers (CIC) employees – separate Workforce product |
| Best choice when... | 100k–several million customers, partner network or large support team, regulated industry, legacy systems to integrate | you have an IAM/Java team and want full control without license fees | you are launching quickly, have a smaller base, and no data residency requirements |
Frequently asked questions_
Keycloak is an open-source engine that you have to deploy, extend, and maintain on your own. Auth0 is a SaaS service billed per active user, with data stored outside your infrastructure. Veloce One Id is a ready-to-use platform with a user portal, MFA, and integrations, deployed in your infrastructure and maintained by Veloce. You don't pay per user.
The first application is typically up and running on Veloce One Id within 8–12 weeks from the start of analysis; each subsequent one typically takes 2–4 weeks. The schedule depends on the number of systems and the account migration method.
In your organization's infrastructure — on-premise or in a chosen private cloud in Poland or the EU. Veloce does not process your customers' data on its own servers.
Via OpenID Connect / OAuth 2.0 or REST API. Out-of-the-box integrations include Magento, SMS and e-mail gateways, and corporate systems. Existing accounts are migrated without forcing re-registration.
Yes. Veloce One Id implements multi-factor authentication (SMS, e-mail, app) and a central event log for all connected applications, so you deploy and demonstrate MFA and access auditing all at once. Compliance with KSC is an organization-wide program — Veloce One Id covers its customer access portion.
Yes. iOS and Android applications log in via OpenID Connect with PKCE; the session is shared with web applications.
It doesn't have to. Veloce One Id federates with your directory (AD / Entra ID via SAML or OpenID Connect): employees log in with their domain account, while Veloce One Id manages their roles and access in business applications, partner accounts (dealers, agents), and customer accounts — all in one system, with a single event log.
Monitoring, security updates, feature development, and connecting new applications under SLA. We have been cooperating with Medicover continuously for over 15 years.
Let's talk about your project_
Within 24 business hours we will get back to you with a proposal for an initial, no-obligation consultation. We don't sell — we advise. This is the first step to understanding whether Veloce is the right partner for your organization.
- A free 30-minute consultation with a senior developer and business analyst
- An initial assessment of feasibility, technology, and approximate budget
- NDA signed before any discussion of your business details
- No sales pressure — you can simply make use of our expertise