What is the difference between CIAM and IAM?
IAM (Identity & Access Management) is about employees within your organisation, such as Active Directory, Okta Workforce, Microsoft Entra ID, and single sign-on to internal SaaS tools. CIAM (Customer Identity & Access Management) is about identities outside your organisation: customers, citizens and partners. The volumes are larger, the UX requirements stricter, the brand plays a role, and regulation (GDPR, sector-specific rules) works differently. Tools that excel at IAM (Okta Workforce, Microsoft Entra ID) aren't automatically suited to CIAM, and vice versa.
Do you replace Auth0, Okta or Microsoft Entra External ID?
For standard B2C or B2B flows we often actually recommend those platforms. Auth0, ForgeRock, Microsoft Entra External ID, Amazon Cognito, Ping Identity, FusionAuth and SuperTokens are mature products. We come in once you hit their limits: sector-specific flows (banking, healthcare with BSN), Dutch identities (iDIN, DigiD), the EUDI Wallet, white-label CIAM for partners, or deep integration with core systems that standard CIAM rate limits can't handle.
Do you work with Keycloak?
Yes, often. Keycloak is open source, OpenID Connect-compatible, scalable, and gives you full control over the data layer. We usually build a custom UX layer on top of Keycloak instead of using the bundled theme, which rarely meets modern CIAM requirements. For B2B multi-tenant we configure Keycloak realms strategically; for B2C we often build a dedicated account front end that talks to Keycloak via OIDC. We only build fully from scratch if Keycloak really doesn't fit.
How do you handle the NL Wallet, iDIN and EUDI?
We integrate iDIN via the Currence integration, with the right step-up flow so you don't force a bank login on every sign-in. DigiD and eHerkenning require a Logius connection via a routing provider. We handle the technical part; your organisation must apply for the legal connection itself. For EUDI and the NL Wallet we build on OpenID for Verifiable Presentations (OpenID4VP) and SD-JWT credentials. The ecosystem moves quickly; we build architecture that moves with it.
How about GDPR, consent and data sovereignty?
A CIAM platform carries significant GDPR obligations: you process personal data, receive access, correction and erasure requests, and must maintain a consent administration. We build consent management in as standard, including version control of privacy statements, granular consent per purpose, and APIs for data portability. Data residency within the EU/NL is handled through your choice of cloud provider (GCP europe-west, AWS eu-central, Azure West Europe or a Dutch hosting provider). A DPIA is included in the scoping phase.
What determines the cost?
The biggest cost factors are: the number and type of identity providers (social login is light, iDIN or DigiD requires more work), the number of connected applications (each SDK integration takes time), the regulatory framework (banking and healthcare require audit trails and penetration tests that other sectors do not), migration of an existing user base, and requirements for branding and UX. After the architecture review, we provide a substantiated range rather than a round figure over the phone.
Can you connect to our existing architecture?
Almost always. A CIAM platform communicates through standards: OIDC, OAuth2, SAML, SCIM, webhooks. We have experience connecting to core banking systems, EHRs, ERPs (SAP, Microsoft Dynamics), CDPs (Segment, Tealium, mParticle), e-commerce platforms (Magento, Shopify Plus, commercetools) and customer service tooling. For specific integration questions we often work together with our
smart API integrations page.
What if we want to switch later?
Standards are your safety net. We build on OIDC, OAuth2 and SCIM so that applications connected to your CIAM can move to another platform without being rebuilt. You can export your user data at any time via the admin console. For Keycloak builds, you receive the configuration as infrastructure as code. Avoiding lock-in to our code is an explicit design goal.
How do you handle migrating an existing user base?
We carry over password hashes in their original algorithm (bcrypt, argon2, scrypt, even outdated variants) and upgrade them lazily: at the next successful login, the hash is automatically recalculated using the newer algorithm. This avoids the painful "everyone must reset their password" email, which typically puts 20–40% of your user base into dormant mode. For social identities, we create account-linking records so customers can keep logging in with their existing method.
Do you work only on B2C or also on B2B CIAM?
Both. B2C CIAM (customer accounts, social login, paywalls) and B2B CIAM (organisation tenants, federated identity via SAML, SCIM provisioning) share overlapping foundations but also distinct challenges. We often build platforms that must support both: a retailer with a loyalty brand and a business B2B arm; an insurer with private customers and mandated brokers; a media service with consumer subscribers and licensing clients. We handle the multi-tenant architecture in the foundation.