Services · Portals and logins

A place to log in,
instead of an inbox.

The moment a business starts sending documents around as email attachments, it has a problem it cannot see: no record of who has what, no way to tell a client where things stand without being asked, and sensitive files sitting in half a dozen mailboxes. A portal fixes all three at once, and it is the point where a website stops being a brochure and starts being a system.

Client portalsInternal dashboards2FA and 2-stepPasskeysRoles and permissionsGDPR readyAudit trails

Two sides of
the same system.

Most businesses need both eventually, and it is usually cheaper to build them together than to bolt the second one on a year later.

01

Client portals

A place your clients log into instead of emailing you for everything. They upload what you asked for, see exactly where things stand, find their own documents without a phone call, and get told the moment something changes. Branded like your business rather than a third-party tool with your logo dropped in the corner, and simple enough that nobody needs showing how.

Secure sign inDocument uploadStatus trackingNotificationsMessagingYour branding
02

Internal portals and dashboards

The same idea pointed inwards. One place your team works from: cases, jobs, bookings, stock, clients, whatever the business actually runs on, with roles that decide who sees what and numbers that keep themselves up to date. It replaces the spreadsheet everybody is frightened to touch and the four tabs nobody can keep in sync.

Roles and permissionsCase and job boardsLive dashboardsExportsActivity history

What a portal
quietly replaces.

None of these feel like a problem on any given day. Added up over a year they are most of a job.

Documents as email attachments

Personal data sitting in inboxes on both sides, forwarded, copied and impossible to withdraw. The thing most likely to become a breach you have to report.

The where are we up to call

Answered by the client looking, at eleven at night, without ringing you. Fewer interruptions and a client who feels better informed for it.

Chasing the same form

The portal shows what is outstanding and reminds them. You stop being the nag and the file still completes.

The spreadsheet nobody dares touch

One source of truth with roles on it, rather than a file with six versions and a formula somebody broke in March.

Shared logins

Individual accounts that can be switched off the day somebody leaves, instead of a password three people know and nobody has changed.

Not knowing who saw what

A record of every sign in, upload and download, which is dull until the day somebody asks you to prove it.

Logins done
properly.

Authentication is the part that is easy to get almost right, and almost right is how accounts get taken over. None of this is an upgrade, it is how we build.

Passwords stored the right way

Hashed with a modern algorithm, never recoverable in readable form by us or by anybody else. If a service can email you your old password, walk away from it.

Two-factor and 2-step

Authenticator app, email or SMS codes, enforced on admin accounts as standard and available to everybody else.

Passkeys where they fit

Face or fingerprint sign in on devices that support it. Faster than a password and it cannot be phished.

Sessions that expire

Automatic sign out, one-click sign out everywhere, and no session that lives forever on a laptop left on a train.

Roles, not all or nothing

An admin, a member of staff, a contractor and a client see four different systems. Access granted deliberately and revoked immediately.

Sensible limits

Rate limiting, lockouts on repeated failures, and alerts on the patterns that look like somebody trying doors.

Built to be trusted
with real data.

The moment a system holds client information it stops being a website and becomes a responsibility. These are handled as standard on anything with a login.

Access control

Roles decide what each person can see and do. Access is granted deliberately and can be revoked immediately, including for staff who leave.

Two-factor and 2-step

Authentication app, email or SMS codes, or passkeys where the devices support them. Enforced for admin accounts as standard.

Encryption

Encrypted in transit and at rest. Passwords hashed, never stored or recoverable in readable form, by us or by anyone.

Lawful basis and consent

What you collect, why, and what the person agreed to, captured at the point it happens and kept as evidence rather than assumed.

Retention and deletion

Data that ages out on the schedule you set, and a real delete when somebody asks for one, including from backups within a stated window.

Audit trail

Who logged in, who changed what, who downloaded which file, and when. Dull until the day you need it, and then the only thing that matters.

Backups and recovery

Automatic backups, tested restores, and a written answer to what happens when something breaks at the worst possible moment.

Where data lives

Hosting chosen so your data sits in the region your obligations require, with the processors named for your privacy policy.

We build to the standard and document what we have done, which is the part most suppliers skip. What we do not do is sign off your policies or act as your data protection officer: those stay with you and, where it matters, your legal advisers. Our job is to make sure the system supports your obligations instead of quietly working against them. If your industry answers to a specific framework, say so at the scoping stage and we build to it.

Portals are usually wired into the tools you already run, and the workflows that feed them are the same ones covered on the AI and automation page.

Start here

Tell us what is
taking the time.

Describe the job in your own words. You will get a straight answer on whether it is worth building, what it would involve, and roughly what size of project it is, usually within one working day.

Message us