Service · Web development

Custom extranet development for customers, partners and suppliers.

A secured portal behind a login where external stakeholders view documents, track statuses and collaborate. Multi-tenant, with SSO, audit log and per-client branding. Custom-built for when Liferay or SharePoint are too blunt for your workflow.

SSO & MFAMulti-tenantAudit logWhite-labelAPI access

An extranet is neither an intranet nor an open website.

An intranet serves your own employees. A public website serves anyone who comes across you on Google. An extranet sits in between: a secured online environment for parties who belong to your organisation in some way, but who are not on your payroll. Customers, distribution partners, suppliers, agents, freelancers, referrers, dealers, industry members, alumni: all with their own roles, their own flows and their own sensitivities. The UX has to be self-explanatory (your partners won't receive an onboarding manual), the security has to be tighter than on a public site, and branding matters even more because external parties experience the portal as your brand.

Customer portal, partner portal, vendor portal and industry portal are all manifestations of the same concept. The label depends on who logs in, not on the underlying technology. Under the bonnet they share the same building blocks: authentication, multi-tenant data separation, role management, audit log, document vault, notifications and API access. What differs is the UX, the business flow and which systems you connect to it.

We build extranets for B2B companies with external stakeholders: insurers (policyholder and broker portals), banks and financiers, SaaS vendors, construction companies (client portal for ongoing projects), healthcare institutions (referrer portal), staffing agencies, law firms and notaries (case file portal), educational institutions (alumni environment) and energy companies (large-consumer portal). Always custom: not a standard Liferay template that half fits, but a portal that clicks with your workflow and your brand. For lighter cases we also combine this with headless CMS components via our web development practice; for more complex projects you're better served by enterprise software development as the backbone.

Three types of extranet we build.

The label varies by organisation and audience (customer portal, partner portal, vendor portal), but underneath there is always the same extranet architecture. We advise which variant suits you in the first conversation.

Compact project · fixed sprint budget

Customer portal or self-service environment

A secure environment where your customers can download invoices, create support tickets, manage account details, renew contracts and track statuses. Suited to SaaS vendors, insurers, telecom providers and energy companies that want to offer self-service to ease the support load. SSO via the customer's IdP or magic link for occasional users, with a light branding layer so the environment feels like part of your brand. Often also integrated with your CRM and invoicing system so customers see their own status in real time. Related: employee portal if you want to centralise internally rather than externally.

SSO + MFARole managementSelf-serviceNotifications
Mid-sized project · fixed sprint budget

Partner or distribution partner portal

For channel partners, distributors, dealers, agents or resellers who run their own business through your channel. A branded portal where partners configure products, place orders, check stock, retrieve marketing assets and co-branded material, register leads and keep track of their pipeline. Multi-tenant so each partner only sees their own data, with granular permissions within a single tenant (a sales colleague sees different data from a partner admin). Approval workflows for non-standard pricing or large orders. On the procurement side, you can set up a vendor portal in parallel so that your suppliers also work within a secured environment.

Multi-tenantWhite-labelPunchOut/cXMLMarketing assets
Larger project · fixed sprint budget

Production extranet with deep integrations

A mission-critical extranet that simultaneously connects ERP, CRM, DMS, policy administration and e-signing. Sector-specific flows for healthcare (referrer portal compliant with NEN 7510), finance (DORA-compliant audit), energy (large-consumer portal with real-time meter data) or construction (client portal for ongoing projects with drawings, planning and invoicing in one view). Multi-language and region-specific flows, as your clients work across several countries. This often comes with a CIAM platform for federated identity across dozens of client identity providers, plus granular consent management that demonstrably upholds GDPR rights.

ERP integrationMulti-languageFederated SSOAudit and DORA

What makes it technically an extranet.

Not every password-protected login page deserves the label extranet. Under the bonnet, there are a number of building blocks that make the difference with an ordinary login page or a lightweight CMS. We build these in virtually every project:

Authentication and identity. Single sign-on via your IdP (Microsoft Entra, Google Workspace, Auth0, Keycloak) or federated SSO so external parties can bring their own IdP. MFA is on by default for admins and optional for users. Magic link for occasional users who don't want a permanent account. For government contact, we integrate eHerkenning or DigiD.

Multi-tenant data architecture. One client only sees their own data. Implemented via row-level security in PostgreSQL or MySQL, a schema per tenant, or a separate database per tenant, depending on your risk profile. For strictly confidential data (medical, financial) we often opt for stronger isolation; for SaaS tenants with many small clients, row-level with rigorous testing is more common.

Granular permissions and audit log. Multiple roles within one tenant are normal: admin, user, viewer, external accountant. Every action (login, view, edit, export, delete) is logged to an audit table with retention spanning several years. For compliance-driven sectors this is a hard requirement; for other sectors it is a reassuring safeguard.

Document vault and communication. A secured place for documents with version management, watermarking on sensitive files and an audit log per file. In-app comments, mentions and notifications (email, push) so that communication no longer runs through separate email threads and the whole organisation can see who needs to act next.

Approval workflows and self-service. Four-eyes principle, escalations and delegation where your business requires it. Self-service for invoice downloads, support tickets, account management and GDPR requests, so your own team does not have to handle every request manually.

Branding, reporting and API. Branding per tenant (white-label) so that trade associations can deliver their extranet under their own brand. Reporting and dashboards per tenant. API access for PunchOut/cXML in procurement, and webhooks for real-time integrations with ERP, CRM and invoicing.

What you get at the end.

A production-ready extranet plus everything around it so you can manage it yourself: codebase, documentation, training and, optionally, a maintenance contract.

  • Extranet production environment + stagingRuns in your cloud (GCP/AWS/Azure/Hetzner) or with us in a managed environment. Multi-tenant separation at row, schema or database level, depending on your security requirements.
  • Authentication layer with SSO and MFASet-up of SAML, OIDC or OAuth towards your IdP. Federated login so that customers and partners can bring their own Microsoft Entra or Google Workspace account. MFA enabled by default for administrators.
  • Codebase + architecture documentFull source code in your own Git repository, build instructions, infrastructure-as-code and a readable architecture overview. No lock-in to a single supplier.
  • Audit log + GDPR control panelWho has viewed, changed or exported which data. Readable per tenant. GDPR rights flow built in (access, rectification, erasure) so you can respond to requests without custom work.
  • Admin guide and end-user trainingTwo sessions for your key users, a short video tutorial for external users and written runbooks for your IT team, covering adding roles, creating tenants and reading the audit log.
  • Maintenance contract (optional)Monitoring, backups, security patches, dependency updates and further development at a fixed monthly price. Four response-time levels depending on how critical the extranet is to you.
Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

When a custom extranet is the right choice.

Not every extranet needs to be custom. For simple document sharing there are perfectly good standard platforms. We come into the picture when one of these patterns applies.

Document flows

Email falls short on compliance

You exchange dozens of documents every week with customers or suppliers. Versions get lost, statuses are unclear, and your data protection officer points to the risk of leaks through business attachments.

Compliance

An audit trail is a hard requirement

Your sector (finance, healthcare, energy) requires demonstrable logging of who has viewed or changed what. A SharePoint-level audit log is too coarse for that; you need per-record granularity with retention spanning several years.

Scalability

The number of external parties is growing

What was manageable by hand with a handful of partners doesn't scale to dozens or hundreds. Self-service onboarding, automated role management and multi-tenant separation become necessities rather than luxuries.

Branding

White-label per client required

Trade associations, consultancies and SaaS vendors want to deliver their extranet to clients under their own brand. Own domain, own colours, own logo per tenant, which standard platforms only partly support.

Integrations

Multiple systems at once

The extranet has to pull data from ERP, policy administration, CRM and DMS, sometimes in real time. Standard portal templates would force you into duplicate data storage or fragile integrations; a custom layer prevents that.

Target audience

Different types of users

One extranet serves policyholders and brokers, dealers and clients, or referrers and patients alike. Each type sees its own view with its own permissions and its own UX, which is not a standard out-of-the-box flow.

How an extranet project runs.

1

Introduction and flow analysis

A conversation in which we establish which external parties need to work in the extranet, which flows they go through, which systems we need to connect to and which compliance requirements apply. The result is a draft scope with assumptions that we test in the next step.

2

User research and scope

A workshop with your team plus interviews with a handful of external users: customers, partners or suppliers. At the end you have clear personas, a role matrix, an initial screen flow and a final scope. This is also where we determine how multi-tenant data separation works and which IdP integrations we set up.

3

Build in sprints with early access

A working build in staging every two weeks. Your key users test along the way, as does a select group of external pilot users. The MVP is up and running after a few sprints for the first tier, often the customer or partner side, and it grows from there with a document vault, approval workflows, branding and the heavier integrations with ERP, CRM and invoicing.

4

Security, penetration testing and rollout

Before go-live, a penetration test by an external party, a DPIA review, and a phased rollout to your customer or partner base. We start with a pilot group, monitor the support load, fine-tune where needed and then scale up. Training sessions for key users, video tutorials for everyone else. After that, ongoing management for security patches, dependency updates, monitoring and further development based on what your users feed back.

5

Operations and ongoing development

An extranet is not a project that is finished at go-live. External parties change, identity providers get updated, compliance requirements shift and new integrations come along. We stay involved through a maintenance agreement covering patches, monitoring and smaller features, so we still know the codebase when you want a larger expansion. No lock-in: the code lives in your own Git repository, and you can switch or take it over in-house at any time.

Frequently asked questions.

What clients usually want to know before we start.

What is the difference between an extranet, an intranet and a customer portal?
An intranet is for your own employees: internal knowledge, HR, communication. An extranet is for parties outside your organisation who are still part of your business: customers, partners, suppliers, referrers. A customer portal is a specific form of extranet aimed at a single audience (your customers). A partner portal and a vendor portal work the same way for partners and suppliers. Under the hood they share the same architecture (secure login, role management, audit log), but the UX, content and integrations differ per audience. If you are looking to build internally instead, see our page on an employee portal.
Do you replace Liferay, SharePoint or Salesforce Experience Cloud?
Not by default. For large enterprise portals with hundreds of communities, Liferay DXP and Salesforce Experience Cloud are good choices, with a lot available out of the box. We come into the picture when those platforms aren't flexible enough for your workflow, are too heavy for your scale, or when you want to expose multiple systems at once with your own UX. For truly large, specialised projects with deep system integrations, you may be better served by enterprise software development as a whole.
How is data separated between tenants in a multi-tenant extranet?
There are three models. Row-level means one database and one shared table, with a tenant ID column on every row and row-level security policies in the database (PostgreSQL supports this natively), so queries are automatically restricted to the correct tenant. Schema-level means one database with a separate schema per tenant: shared table definitions, separated data. Database-level means a separate database per tenant, possibly even on separate servers. Which model fits depends on your security requirements, the number of tenants, your cost budget and how much customisation you need per tenant. For strictly confidential data (financial, medical, defence), we more often choose schema or database level, accepting the higher operational complexity. For SaaS providers with hundreds of small tenants, row-level is usually more practical and cheaper to scale, provided the test suite rigorously enforces isolation. We work through the choice together during the architecture phase, based on your risk profile.
How do you handle GDPR and compliance for a B2B extranet?
A few layers at once. Privacy by design in the architecture (data minimisation, encryption at rest and in transit), a DPIA for every major project, GDPR Art. 28 data processing agreements with sub-processors, and a built-in GDPR rights flow per tenant (access, rectification, erasure). For healthcare extranets we add NEN 7510 controls, for financial extranets DORA requirements, and publicly accessible B2C extranets we build to WCAG 2.2 AA in line with the European Accessibility Act. For the full picture, see our page on a CIAM platform.
Are SSO and MFA mandatory for external users?
MFA is strongly recommended and is switched on by default for administrators and users with access to sensitive data. For external users, it depends on your audience. Business partners often have their own identity provider (Microsoft Entra, Google Workspace, Auth0, Keycloak), which we connect via federation using SAML or OIDC, so they sign in with their existing account and you don't have to manage passwords. Occasional users, such as one-off clients, freelancers or patients, often get magic links plus optional TOTP, so they don't have to create an account for a single visit. We use iDIN, eHerkenning or DigiD where your audience expects them, for example in government contact, care portals or financial services where identification is legally required. For the full identity picture, see our page on a CIAM platform.
Do you build a mobile app alongside the web extranet?
We can, but it isn't always necessary. The vast majority of extranets we build are mobile-responsive, so your customers and partners can use them on laptop and phone without installing anything, with a UX that works just as well on a small screen. A separate mobile app makes sense for field services (engineers on site, inspection audit apps), offline scenarios (poor connectivity, remote locations), push notifications as a key conversion driver, or a dedicated camera or scanning flow. We advise case by case and can build either a hybrid (React Native, Capacitor) or native (Swift/Kotlin) app. Often a project starts with a strong responsive web extranet and a lean mobile app is added later for specific flows.
How much does a custom extranet cost?
The honest answer is that it depends on scope, integrations, the number of roles and the level of compliance required. A client portal with SSO and a document vault sits at a very different point on the spectrum from a multi-tenant production extranet with ERP integration, white-labelling and DORA requirements. Three variables have the biggest impact on budget: the number of different roles and flows (each role is effectively a sub-product), the number of external systems the extranet needs to talk to (every API integration requires analysis, build and monitoring), and the level of compliance (audit requirements, penetration testing, DPIA). We work with fixed sprint budgets rather than open-ended spend, and after the scoping phase we provide a justified range that sets out the assumptions with the greatest impact on price. For a broader view of how we work, see our web development page.
Can we use our own brand and domain for each client (white-label)?
Yes, that's one of the reasons to choose custom software. For each tenant we can connect a dedicated subdomain or custom domain, with their own colours, logo, favicon and even email templates. Trade bodies and consultancy firms use this to deliver their extranet to end clients under their own branding. This isn't available out of the box on standard platforms, where you usually trade off consistency.

Talk to us about your extranet.

A no-obligation half-hour introductory call. We listen to your flow, probe into roles and compliance, and give you direction you can act on, whether that's a custom build, a standard platform or a hybrid.

Edit content