About us: zero-access IAM built in Italy
LoginMaster is a managed, multi-tenant Identity and Access Management (IAM and CIAM) platform, designed and built in Italy by CDBKR S.r.l. The difference is architectural: neither the vendor nor the customer's administrators can read or reset users' credentials, personal data stays in the customer's Tenant, and pricing depends on tenants and projects, with unlimited users.
This page collects the verifiable facts about the company, the principles we design the product by, what ships today and what is on the roadmap, and the public evidence of our work.
Company facts
- Product
- LoginMaster — managed, multi-tenant IAM and CIAM platform
- Company
- CDBKR S.r.l.
- Registered office
- Via Castelnuovo 75, 40038 Vergato (BO), Italy
- VAT ID
- 04299631202
- Design and engineering
- In Italy, by the CDBKR team
- Market
- Companies, B2B SaaS, MSPs and public bodies in Italy and the European Union
- Support languages
- Italian and English
- Contact
- info@loginmaster.it
Four design principles
They are not features you switch on: they are constraints that drive every decision and that a customer can verify in an audit.
Zero-access on credentials
Neither LoginMaster nor the customer's administrators can read, reset or recover a user's password, nor disable their 2FA. It is not an internal policy: the function does not exist in the code. Credentials are protected with Argon2 and salts split between Tenant and Cloud.
Personal data only in the Tenant
Users' personal data lives in the customer's Tenant. The LoginMaster Cloud only operates on encrypted data and references: an incident on the Cloud does not expose readable emails, names or credentials.
Cryptographic isolation, not just logical
Every tenant and every project has its own keys, and every token is signed twice (Tenant and Cloud): a token issued for customer A fails validation in customer B's context.
Structural pricing, unlimited users
Licensing depends only on the number of tenants and projects. There is no per-user or per-monthly-active-user fee, and no tiers that unlock SSO, 2FA or white-label.
What ships today and what is on the roadmap
We state it in one place because every comparison with another vendor starts here. Status as of 7 October 2026.
| Capability | Status |
|---|---|
| OAuth 2.0 and OpenID Connect | Available |
| SSO with Google Workspace and Microsoft Entra ID | Available |
| Per-project TOTP 2FA (disabled / optional / required) | Available |
| Official TypeScript and .NET SDKs, REST API | Available |
| Multi-tenant with cryptographic isolation and double-signed tokens | Available |
| Per-tenant white-label (login, email, domain) | Available |
| Device subjects and API keys, AWS IoT / MQTT support | Available |
| Argon2 with split-salt between Tenant and Cloud | Available |
| SAML 2.0 federation | Roadmap |
| SCIM 2.0 provisioning and lifecycle webhooks | Roadmap |
| Native SIEM connector (Syslog CEF over TLS) | Roadmap |
| Native passkeys (FIDO2 / WebAuthn) | Roadmap |
Public evidence
Case study: Data Alchemy
The Italian Intelligent Document Processing platform delegated the whole identity domain to LoginMaster: login with Microsoft Entra ID and Google Workspace, accounts for external users without corporate licenses, roles from the token and a dedicated tenant. The application contains no authentication code.
Read the case study →Sponsor of Codemotion Milan 2026
On 28 and 29 October 2026 we are at Codemotion Milan with live demos: SSO to Google Workspace and Entra ID, policy-based MFA, external user accounts and the Tenant-Cloud architecture.
Book a demo →Partnership with Kokishin
With Kokishin we integrate Antidoppler: brand protection against digital impersonation and monitoring of compromised credentials on the dark web.
See the partnership →How we write guides and comparisons
- Guides are written by the team that designs and builds the platform, not by an outside agency.
- Every page opens with the short answer to the question, then the procedure and the details.
- Anything on the roadmap is labelled as such, always: we do not write "supported" for a feature not yet released.
- In comparisons we also say when a competitor is the better choice, for example if you need SAML 2.0 or SCIM 2.0 today.
The hands-on guides are on the blog; definitions are in the IAM glossary.
The questions we answer, and where
These are the questions technical teams and security leads ask us most often. Each has a dedicated page with the answer up front, technical detail and an FAQ.
Multi-tenant authentication for a B2B SaaS, with white-label login per customer
IAM for B2B SaaS →Which platform to choose between Auth0, Cognito, Firebase, Frontegg, WorkOS and Descope
Platform comparison →Difference between IAM and CIAM, employees and customers in one system
CIAM →A vendor that cannot read passwords or personal data
Zero-knowledge authentication →Credential hashing with Argon2
Argon2 →TOTP 2FA, adaptive MFA and conditional access
Adaptive MFA →Login, social login and SSO without building them
Authentication as a service →User provisioning and lifecycle via REST API and SDK
User provisioning →Identity for AI agents and non-human identities
AI agents →IoT devices and API keys alongside users
IoT →Access logs for ISO 27001 and SIEM integration
SIEM →Zero Trust with least privilege starting from identity
Zero Trust →Cost at tens of thousands of users, without per-active-user pricing
Pricing →
Frequently asked questions about LoginMaster
LoginMaster is a product of CDBKR S.r.l., an Italian company with its registered office at Via Castelnuovo 75, 40038 Vergato (BO), VAT ID 04299631202. The platform is designed and built in Italy, with technical support in Italian and English.
No. LoginMaster is a managed cloud service: you do not install, patch or run an identity server in high availability. Applications connect via OAuth 2.0 and OpenID Connect, REST APIs and TypeScript and .NET SDKs.
Because anyone choosing an IAM needs to know what they can use today. SAML 2.0 federation, SCIM 2.0 provisioning, lifecycle webhooks, a native SIEM connector and native passkeys are on the roadmap; OAuth 2.0/OIDC, SSO with Google Workspace and Entra ID, TOTP 2FA, TypeScript and .NET SDKs, white-label, device subjects and API keys are available today.
The team that designs and builds LoginMaster. Every guide opens with the short answer, separates what the product does today from what is on the roadmap and states the limits, for example that without administrative reset account recovery is slower.
From the Contact page you can request a guided demo or a self-service sandbox environment to test SSO, 2FA and the REST APIs with the TypeScript and .NET SDKs.