Talk to us about your extranet.
A no-obligation half-hour introductory call. We listen to your flow, probe into roles and compliance, and give you direction you can act on, whether that's a custom build, a standard platform or a hybrid.
A secured portal behind a login where external stakeholders view documents, track statuses and collaborate. Multi-tenant, with SSO, audit log and per-client branding. Custom-built for when Liferay or SharePoint are too blunt for your workflow.
An intranet serves your own employees. A public website serves anyone who comes across you on Google. An extranet sits in between: a secured online environment for parties who belong to your organisation in some way, but who are not on your payroll. Customers, distribution partners, suppliers, agents, freelancers, referrers, dealers, industry members, alumni: all with their own roles, their own flows and their own sensitivities. The UX has to be self-explanatory (your partners won't receive an onboarding manual), the security has to be tighter than on a public site, and branding matters even more because external parties experience the portal as your brand.
Customer portal, partner portal, vendor portal and industry portal are all manifestations of the same concept. The label depends on who logs in, not on the underlying technology. Under the bonnet they share the same building blocks: authentication, multi-tenant data separation, role management, audit log, document vault, notifications and API access. What differs is the UX, the business flow and which systems you connect to it.
We build extranets for B2B companies with external stakeholders: insurers (policyholder and broker portals), banks and financiers, SaaS vendors, construction companies (client portal for ongoing projects), healthcare institutions (referrer portal), staffing agencies, law firms and notaries (case file portal), educational institutions (alumni environment) and energy companies (large-consumer portal). Always custom: not a standard Liferay template that half fits, but a portal that clicks with your workflow and your brand. For lighter cases we also combine this with headless CMS components via our web development practice; for more complex projects you're better served by enterprise software development as the backbone.
The label varies by organisation and audience (customer portal, partner portal, vendor portal), but underneath there is always the same extranet architecture. We advise which variant suits you in the first conversation.
A secure environment where your customers can download invoices, create support tickets, manage account details, renew contracts and track statuses. Suited to SaaS vendors, insurers, telecom providers and energy companies that want to offer self-service to ease the support load. SSO via the customer's IdP or magic link for occasional users, with a light branding layer so the environment feels like part of your brand. Often also integrated with your CRM and invoicing system so customers see their own status in real time. Related: employee portal if you want to centralise internally rather than externally.
For channel partners, distributors, dealers, agents or resellers who run their own business through your channel. A branded portal where partners configure products, place orders, check stock, retrieve marketing assets and co-branded material, register leads and keep track of their pipeline. Multi-tenant so each partner only sees their own data, with granular permissions within a single tenant (a sales colleague sees different data from a partner admin). Approval workflows for non-standard pricing or large orders. On the procurement side, you can set up a vendor portal in parallel so that your suppliers also work within a secured environment.
A mission-critical extranet that simultaneously connects ERP, CRM, DMS, policy administration and e-signing. Sector-specific flows for healthcare (referrer portal compliant with NEN 7510), finance (DORA-compliant audit), energy (large-consumer portal with real-time meter data) or construction (client portal for ongoing projects with drawings, planning and invoicing in one view). Multi-language and region-specific flows, as your clients work across several countries. This often comes with a CIAM platform for federated identity across dozens of client identity providers, plus granular consent management that demonstrably upholds GDPR rights.
Not every password-protected login page deserves the label extranet. Under the bonnet, there are a number of building blocks that make the difference with an ordinary login page or a lightweight CMS. We build these in virtually every project:
Authentication and identity. Single sign-on via your IdP (Microsoft Entra, Google Workspace, Auth0, Keycloak) or federated SSO so external parties can bring their own IdP. MFA is on by default for admins and optional for users. Magic link for occasional users who don't want a permanent account. For government contact, we integrate eHerkenning or DigiD.
Multi-tenant data architecture. One client only sees their own data. Implemented via row-level security in PostgreSQL or MySQL, a schema per tenant, or a separate database per tenant, depending on your risk profile. For strictly confidential data (medical, financial) we often opt for stronger isolation; for SaaS tenants with many small clients, row-level with rigorous testing is more common.
Granular permissions and audit log. Multiple roles within one tenant are normal: admin, user, viewer, external accountant. Every action (login, view, edit, export, delete) is logged to an audit table with retention spanning several years. For compliance-driven sectors this is a hard requirement; for other sectors it is a reassuring safeguard.
Document vault and communication. A secured place for documents with version management, watermarking on sensitive files and an audit log per file. In-app comments, mentions and notifications (email, push) so that communication no longer runs through separate email threads and the whole organisation can see who needs to act next.
Approval workflows and self-service. Four-eyes principle, escalations and delegation where your business requires it. Self-service for invoice downloads, support tickets, account management and GDPR requests, so your own team does not have to handle every request manually.
Branding, reporting and API. Branding per tenant (white-label) so that trade associations can deliver their extranet under their own brand. Reporting and dashboards per tenant. API access for PunchOut/cXML in procurement, and webhooks for real-time integrations with ERP, CRM and invoicing.
A production-ready extranet plus everything around it so you can manage it yourself: codebase, documentation, training and, optionally, a maintenance contract.
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Not every extranet needs to be custom. For simple document sharing there are perfectly good standard platforms. We come into the picture when one of these patterns applies.
You exchange dozens of documents every week with customers or suppliers. Versions get lost, statuses are unclear, and your data protection officer points to the risk of leaks through business attachments.
Your sector (finance, healthcare, energy) requires demonstrable logging of who has viewed or changed what. A SharePoint-level audit log is too coarse for that; you need per-record granularity with retention spanning several years.
What was manageable by hand with a handful of partners doesn't scale to dozens or hundreds. Self-service onboarding, automated role management and multi-tenant separation become necessities rather than luxuries.
Trade associations, consultancies and SaaS vendors want to deliver their extranet to clients under their own brand. Own domain, own colours, own logo per tenant, which standard platforms only partly support.
The extranet has to pull data from ERP, policy administration, CRM and DMS, sometimes in real time. Standard portal templates would force you into duplicate data storage or fragile integrations; a custom layer prevents that.
One extranet serves policyholders and brokers, dealers and clients, or referrers and patients alike. Each type sees its own view with its own permissions and its own UX, which is not a standard out-of-the-box flow.
A conversation in which we establish which external parties need to work in the extranet, which flows they go through, which systems we need to connect to and which compliance requirements apply. The result is a draft scope with assumptions that we test in the next step.
A workshop with your team plus interviews with a handful of external users: customers, partners or suppliers. At the end you have clear personas, a role matrix, an initial screen flow and a final scope. This is also where we determine how multi-tenant data separation works and which IdP integrations we set up.
A working build in staging every two weeks. Your key users test along the way, as does a select group of external pilot users. The MVP is up and running after a few sprints for the first tier, often the customer or partner side, and it grows from there with a document vault, approval workflows, branding and the heavier integrations with ERP, CRM and invoicing.
Before go-live, a penetration test by an external party, a DPIA review, and a phased rollout to your customer or partner base. We start with a pilot group, monitor the support load, fine-tune where needed and then scale up. Training sessions for key users, video tutorials for everyone else. After that, ongoing management for security patches, dependency updates, monitoring and further development based on what your users feed back.
An extranet is not a project that is finished at go-live. External parties change, identity providers get updated, compliance requirements shift and new integrations come along. We stay involved through a maintenance agreement covering patches, monitoring and smaller features, so we still know the codebase when you want a larger expansion. No lock-in: the code lives in your own Git repository, and you can switch or take it over in-house at any time.
What clients usually want to know before we start.
A no-obligation half-hour introductory call. We listen to your flow, probe into roles and compliance, and give you direction you can act on, whether that's a custom build, a standard platform or a hybrid.
Appfront uses cookies and similar technologies to keep the website working properly, for analytics and for marketing. You choose what you allow. Read more in our privacy policy.