Identity and access platform · CIAM + IAM

One identity
for customers, partners, and
employees across all your applications_

Veloce One Id takes over login, MFA, roles, and identity data from every application in your organization — for customers (CIAM) as well as employees and partners (IAM). You connect your portal, mobile app, store, CRM, and internal systems; the user logs in once, and you manage access from a single place.

 
Trusted by_
Logo mBanku
Logo TUI
Logo Medicover
Logo Centrum Medyczne Damiana
Logo Invimed
Logo Ediny
Logo NordPartner
Logo Snickers
Logo Stroeer
Logo IgoriaCard
Logo Ovoria
Logo Orange
Logo Deutsche Bank
Logo Ministerwsa Rolnictwa i Rozwoju Wsi
Logo Lays
Logo Raiffeisen Leasing
Logo Credit Agricole
Logo Born Donor Bank
Logo Oney
Logo mBanku
Logo TUI
Logo Medicover
Logo Centrum Medyczne Damiana
Logo Invimed
Logo Ediny
Logo NordPartner
Logo Snickers
Logo Stroeer
Logo IgoriaCard
Logo Ovoria
Logo Orange
Logo Deutsche Bank
Logo Ministerwsa Rolnictwa i Rozwoju Wsi
Logo Lays
Logo Raiffeisen Leasing
Logo Credit Agricole
Logo Born Donor Bank
Logo Oney
01 · Features

Everything that login and access_ need

Instead of building registration, passwords, MFA, roles, and consents separately in every application — one platform for customers, partners, and employees, used by all of them.

One account and one session for all applications

The customer logs in once – on the portal, mobile app, store, or internal system – and stays logged in everywhere.

Shared web + mobile session
Logging out in one place ends the session everywhere
Active session · a.nowak@...
Patient portal logged in
Mobile app (iOS) logged in

Second factor set up once, enforced everywhere

You configure methods, requirements, and exceptions centrally. Applications inherit the policy from Veloce One Id, so a regulatory change means one settings change, not six separate projects.

Methods: SMS, email, authenticator app

Policies per application and per operation (step-up)

Gradual rollout and adoption report

MFA Policy · Patient portal
Require MFA at login
Step-up: access to test results
Step-up: phone number change
Remember device (30 days)
MFA adoption 98.4%
 

The customer manages their own account

A dedicated panel (Vue.js) in your branding: data, password, login methods, devices, consents, history. Every change propagates to all applications and systems — no helpline needed.

Changing contact details and password

MFA methods and trusted devices

GDPR and marketing consents — withdrawal effective everywhere

Login history and active sessions

My account
Email
a.nowak@…
Phone
+48 ··· ··· 412
MFA method
SMS
Marketing consent
iPhone · App
now
Chrome · Windows · Portal
yesterday

Users, applications, policies, and integrations in one place

The administrator manages the entire login ecosystem from a single panel. A helpline consultant sees account status, recent logins, and can send a reset — without seeing the password and with a full activity log.

Application registration (client ID, redirect URI, scopes)

User search, status, blocks, MFA reset after verification

Administrator roles: full, consultant, read-only

Every administrator action is recorded in the event log

User · j.wisniewski@…
Account status
active
Last login
yesterday 19:41 · Store
Failed attempts (24 h)
0
MFA
Email
Send password reset
Reset MFA
Unblock

Who, when, from where, and to what — in a single log

Every login, error, MFA event, data change, and administrator action goes into a central log covering all applications. You can prepare evidence for KSC/NIS2 and DORA audits in minutes, not days.

Events from all applications in one place

Configurable retention

Export / stream to SIEM (Splunk, Sentinel, Elastic)

Ready-made audit reports: MFA adoption, unusual logins, admin actions

Event log
08:12 · login_success · Portal
a.nowak · PL
08:12 · mfa_verified · SMS
a.nowak
07:58 · login_success · App
m.kowalska · PL
07:41 · login_failed ×3 · Store
new country
07:30 · admin_reset_mfa
consultant_12
SIEM export: active · retention 24 months

One identity, many roles

Customer, dealer, agent, consultant — the same systems, completely different permissions. You pass roles to applications in the token, and granting or revoking a partner's access takes a minute and applies everywhere at once.

Roles and attributes in the token (OIDC claims)

Organization contexts: an agent at two insurance companies, a dealer at three showrooms

Delegated administration for partners

Instant deactivation — sessions expire across all applications

User · p.zielinski@dealer.pl
Role
Dealer
Organization
Warsaw-Ursynów Showroom
Dealer portal
access
Customer portal
none
Policy calculator
access

Identity and access for employees and partners

The same platform handles internal accounts: consultants, administrators, facility staff, dealers, and agents. Employees log in with their domain account (federation with Active Directory / Entra ID), and Veloce One Id manages their roles and access to business applications — with MFA and a full audit trail, which is exactly what KSC/NIS2 and DORA require first.

Federation with AD / Entra ID via SAML or OpenID Connect

Onboarding with a role in a minute; offboarding invalidates sessions everywhere (automated with HR/CRM via API)

MFA mandatory for administrators and remote access; policies per role

One event log for customers and employees; export to SIEM

Employees and partners
k.mazur@twojafirma.pl Entra ID
Consultant
a.wrobel@twojafirma.pl Entra ID
Administrator · MFA
p.zielinski@dealer.pl
Dealer · Ursynów
m.lis@agencja.pl
Agent · 2 insurers
j.kot@twojafirma.pl
deactivated · today 16:02

No re-registration, done in waves, one application at a time

The biggest fear around SSO: "will 900,000 people have to create a new account from scratch?" No. We import accounts from your existing systems, merge duplicates using verified attributes, and the customer confirms the merge at first login.

Import of accounts from source systems, passwords as hashes or set anew at first login

Merging duplicates by verified email / phone

Confirmation via code at first login

One event log for customers and employees; export to SIEM

Migration in waves — one application at a time, no big bang

Migration · wave 2 of 4
Patient portal
migrated · 100%
Store (Magento)
in progress
Merged accounts (duplicates)
41,208
Requiring confirmation
3,114
Mobile app, Teleconsultations
wave 3–4

Standards for new applications, an API for older ones

The team registers the application in the panel, adds the OpenID Connect library, and has login, MFA, a panel, and consents from day one. Systems without OIDC are connected via REST API. Ready-made integrations: Magento, SMS, email, corporate systems.

OpenID Connect / OAuth 2.0 for web and mobile

REST API: accounts, roles, events, consents

Ready-made integrations: Magento, SMS gateways, email, CRM/ERP/HIS

Test environment and integration documentation

// Application connected to Veloce One Id
authority: "https://sso.twojafirma.pl",
client_id: "portal-pacjenta",
scope: "openid profile email roles",
response_type: "code",
code_challenge_method: "S256",
OIDC
REST
Magento
SMS
Email
CRM
HIS
SIEM

Your data, a fixed cost, no per-user fees

Veloce One Id is not a Veloce cloud service. We install the platform on-premise or in a private cloud in Poland/the EU. Customer data never leaves your environment, and a million accounts cost the same as a hundred thousand.

On-premise (Windows Server / .NET) or private cloud in PL/EU

No connections to Veloce in production traffic

High availability and scaling — 900,000+ users in a single installation

Updates delivered as part of the SLA

Installation · prod
Environment
Your DC · Warsaw
Application nodes
3 OK
Database (replication)
2 OK
Accounts
912,448
Per-user fee
0 PLN
Last security update: SLA package, no login downtime.
 
02 · MFA and policies

Turn on MFA once. It applies everywhere_

You configure methods, requirements, and exceptions in a single panel. Applications don't have their own mechanisms — they inherit the policy from Veloce One Id. A regulatory change means one settings change, not six separate projects.

Methods: SMS, email, authenticator app

Policies per application and per operation (step-up for results, payments, data changes)

Gradual rollout: a transition period and an MFA adoption report

Password policies, lockouts after failed attempts, new-login notifications

MFA Policy · Patient portal
Require MFA at login
Step-up: access to test results
Step-up: phone number change
Remember device (30 days)
Allowed methods
SMS
Email
App
Passkeys · coming soon
03 · User panel

The customer manages their own account_

My account
Email
a.nowak@…
Phone
+48 ··· ··· 412
MFA method
SMS
Marketing consent
Logged-in devices
iPhone · App
now
Chrome · Windows · Portal
yesterday

A dedicated panel (Vue.js) in your branding: data, password, login methods, devices, consents, history. Every change propagates to all applications and systems.

Changing contact details and password without a helpline

Managing MFA methods and trusted devices

GDPR and marketing consents in one place — withdrawal effective everywhere

Login history and active sessions

04 · IAM · employees and partners

One identity system for
customers and for your team_

Role · Helpline consultant
View customer account
Send password reset
Reset MFA (after verification)
Change customer data
MFA required for this role
yes
Identity sources
Entra ID / AD
Partner accounts
Customer accounts
Or sign in with an external provider

A helpline consultant, an administrator, a facility employee, a dealer, an agent — each has a role, MFA, and access only to what they need. Employees log in with their domain account, partners with their own; Veloce One Id decides who sees what, and records every action.

Roles and attributes in the token; organization contexts for partner networks

Delegated administration: a showroom manager creates accounts for their staff

Deactivation from a single place — instantly, across all applications

The consultant handles the customer's account without knowing the password, with an activity log

05 · For product teams

New app in weeks, not quarters_

The team registers the app in the dashboard, adds the OpenID Connect library, and gets login, MFA, dashboard, and consents from day one. Systems without OIDC can be connected via REST API.

OpenID Connect / OAuth 2.0 for web and mobile (PKCE)

REST API for managing accounts, roles, and events

User roles and attributes passed in the token

Testing environment and integration documentation

// App connected to Veloce One ID
authority: "https://sso.yourcompany.com",
client_id: "patient-portal",
scope: "openid profile email roles",
response_type: "code",
code_challenge_method: "S256",
// Login, MFA, dashboard, and consents — without code on your side.
06 · Integrations

Connects with what you already have_

Standards for new applications, ready-made integrations for systems that have been running for years.

OpenID Connect / OAuth 2.0 SAML 2.0 · Active Directory / Entra ID REST API Magento / Adobe Commerce SMS Gateways E-mail (SMTP / API) Enterprise Systems (CRM, ERP, HIS) iOS / Android Mobile Apps Event Export to SIEM HR Systems (onboarding / offboarding)
Need another integration?
We connect it as part of the implementation. Platform technology: Microsoft .NET (C#), Vue.js, REST.
07 · Deployment and hosting

Your infrastructure. Your data.
Fixed cost_

Veloce One Id is not a Veloce cloud service. We install the platform wherever you want, and we do not charge user-based fees — a million accounts cost the same as a hundred thousand.

On-premise
In your data center

Windows Server / .NET, your databases, your monitoring. Zero connections to Veloce in production traffic.

Private cloud
PL / EU Region

Your chosen provider and region. Compliance with medical and financial data residency policies.

Scale
900,000+ users

We handle over 900,000 accounts in a single production installation. High availability and traffic peaks included in the deployment scope.

04
Proven technology

Microsoft .NET + Vue.js/React + cloud-native (Docker, Kubernetes, Kafka). Stack accepted by corporate IT departments, compliance-friendly, ready for KNF or banking audits.

900,000+

users in production

8–12 weeks

to the first application

2–4 weeks

each subsequent application

15+ years

of cooperation with our largest client

08 · Client reviews

What people_ say about working
with us

No buzzwords or marketing clichés. Quotes with real names, job titles, and companies — authentic feedback from our partners.

Following the adaptation of V.CMS to the needs of mForex and mdm.pl, content management has become smooth and intuitive. 900k monthly visits is a test that the system passes every day — without failure, without compromise.
DM
Dominik Murlak Deputy Director for Projects · mBank Brokerage Bureau
The CRM from Veloce integrated our website, the MyTUI app, and the financial-accounting system into one. Around 1,000 users in 136 offices now work within a single ecosystem. Sales automation and reduced booking management costs — in numbers.
PB
Paweł Bieńkowski Sales and Marketing Director
5/5
Average from 47 client reviews · 75% of clients continue cooperation after the first project
Verified on Clutch
09 · Cooperation models

Platform, deployment, maintenance_

One price for everything. No per-user fees, no surprises as your database grows.

01 / Platform

Platform

Veloce One Id license

  • SSO, MFA, user portal, admin panel
  • CIAM + IAM: customers, partners, employees
  • Roles, policies, event log, AD / Entra ID federation
  • OpenID Connect and REST API
  • Installation in your infrastructure
02 / Deployment

Deployment

8–12 weeks to the first application

  • Analysis and architecture (2–3 weeks)
  • Installation, MFA configuration, and panel setup
  • Integrations with your systems
  • Account migration without re-registration
  • Connecting the first application
03 / Maintenance

Maintenance

SLA

  • Monitoring and security updates
  • Connecting subsequent applications (2–4 weeks)
  • Development of features and new login methods
  • Support for your integrating teams
10 · Cooperation models

Per-user SaaS vs Veloce One Id — how
the bill grows_

In the SaaS model, every active user incurs a fee. With Veloce One Id, you pay for the platform, deployment, and maintenance — and the number of accounts doesn't change the bill. Move the slider to see where the curves intersect.

SaaS CIAM (fee per active user)
Veloce One Id (license + SLA, fixed cost)
Active users: 380,000
4,605,600 PLN
SaaS · annual cost
216,000 PLN
Veloce One Id · annual cost
13,816,800 PLN
SaaS · 3 years
898,000 PLN
Veloce One Id · 3 years (with deployment)
With 380,000 users over 3 years, Veloce One Id is cheaper by 12,918,800 PLN. Above approx. 17,822 active users, the annual SaaS cost exceeds the cost of Veloce One Id.

Indicative values for model illustration, not an offer. The SaaS rate is an averaged price from public CIAM platform pricing (volume discounts and minimum thresholds omitted); Veloce One Id costs are sample ranges — a precise quote will be prepared after analysis.
11 · Comparison

Veloce One Id, Keycloak, or Auth0_

Three real paths to single sign-on for customers. Each makes sense in a different situation — below is an honest look at where each one wins.

Criterion Veloce One Id dedicated solution Keycloak open source Auth0 / Okta CIC SaaS
Cost model License + deployment + SLA fixed cost, independent of the number of users No license full team and operations cost on your side Active user fee (MAU) grows along with your customer base
Where data resides ✓ Your infrastructure (PL/EU) ✓ Your infrastructure Vendor cloud EU regions available
SSO: OpenID Connect ✓ ✓ ✓
MFA ✓ SMS, e-mail, app policies per application, step-up ✓ TOTP, WebAuthn SMS via custom extensions ✓ wide range adaptive MFA in higher plans
User portal ✓ dedicated, in your branding Basic full portal to be built ✓ configurable
Admin panel and event log ✓ standard ✓ admin console reports and retention to be built ✓ standard log retention depends on plan
Legacy system integrations Magento, HIS, CRM, SMS ✓ ready-made + within deployment scope To be built To be built (Actions / API)
Existing account migration ✓ within deployment scope without re-registration Possible in-house work Possible lazy / bulk migration
Who maintains it Veloce under SLA Your team or an external company Vendor (platform) integrations – you
Technology .NET / C#, Vue.js Java SaaS
Time to first application 8–12 weeks with integrations and migration 2–6 months depending on the team Weeks simple case, no legacy
Identity scope ✓ customers + partners + employees CIAM and IAM in a single installation ✓ customers + employees custom configuration and integrations Customers (CIC) employees – separate Workforce product
Best choice when... 100k–several million customers, partner network or large support team, regulated industry, legacy systems to integrate you have an IAM/Java team and want full control without license fees you are launching quickly, have a smaller base, and no data residency requirements
Already using Entra ID / Okta Workforce for employees? Veloce One Id doesn't have to replace them — it federates with them and adds what's missing: customer and partner accounts, business application roles, a single event log, on-premise.
12 · FAQ

Frequently asked questions_

Keycloak is an open-source engine that you have to deploy, extend, and maintain on your own. Auth0 is a SaaS service billed per active user, with data stored outside your infrastructure. Veloce One Id is a ready-to-use platform with a user portal, MFA, and integrations, deployed in your infrastructure and maintained by Veloce. You don't pay per user.

The first application is typically up and running on Veloce One Id within 8–12 weeks from the start of analysis; each subsequent one typically takes 2–4 weeks. The schedule depends on the number of systems and the account migration method.

In your organization's infrastructure — on-premise or in a chosen private cloud in Poland or the EU. Veloce does not process your customers' data on its own servers.

Via OpenID Connect / OAuth 2.0 or REST API. Out-of-the-box integrations include Magento, SMS and e-mail gateways, and corporate systems. Existing accounts are migrated without forcing re-registration.

Yes. Veloce One Id implements multi-factor authentication (SMS, e-mail, app) and a central event log for all connected applications, so you deploy and demonstrate MFA and access auditing all at once. Compliance with KSC is an organization-wide program — Veloce One Id covers its customer access portion.

Yes. iOS and Android applications log in via OpenID Connect with PKCE; the session is shared with web applications.

It doesn't have to. Veloce One Id federates with your directory (AD / Entra ID via SAML or OpenID Connect): employees log in with their domain account, while Veloce One Id manages their roles and access in business applications, partner accounts (dealers, agents), and customer accounts — all in one system, with a single event log.

Monitoring, security updates, feature development, and connecting new applications under SLA. We have been cooperating with Medicover continuously for over 15 years.

13 · Let's talk

Let's talk about your project_

Within 24 business hours we will get back to you with a proposal for an initial, no-obligation consultation. We don't sell — we advise. This is the first step to understanding whether Veloce is the right partner for your organization.

  • A free 30-minute consultation with a senior developer and business analyst
  • An initial assessment of feasibility, technology, and approximate budget
  • NDA signed before any discussion of your business details
  • No sales pressure — you can simply make use of our expertise

Get a project estimate_

✓ Thank you! Your message has been sent. We'll respond within 24 business hours.
🔒 Your data is safe · We respond within 24h