Enterprise IAM Platform

All the features of LoginMaster

LoginMaster offers a Tenant-Cloud architecture with dual-signature tokens, configurable 2FA, integrated SSO with Google Workspace and Microsoft Entra ID, tenant-level white-label, and credential protection with Argon2 and split-salt. Every feature is designed to ensure security and control across all identity and access management.

Security and control without compromise

Eight foundational pillars that make LoginMaster an IAM platform designed for security. From the Tenant-Cloud architecture to exclusive user control, every feature ensures real protection of identities and access.

Tenant-Cloud Architecture

The tenant is the customer entity that contains users and credentials. It communicates with the LoginMaster Cloud via dedicated cryptographic keys. Each project has its own key to communicate exclusively with its tenant, ensuring isolation and security at every level of the infrastructure.

Dual-Signature Tokens

The authentication token is signed by both the Tenant and the LoginMaster Cloud, ensuring authenticity on both sides of the communication. The dialog between client and API uses a separate cryptographic certificate, adding an additional layer of verification and protection against token forgery.

Per-Project Configurable 2FA

Two-factor authentication can be disabled, optional, or mandatory on each individual project. The user enables 2FA only if at least one project in their tenant requires it. The system is based on TOTP, compatible with Google Authenticator and similar apps, offering flexibility and tailored security.

SSO with Google Workspace and Microsoft Entra ID

Q2 2026

Single Sign-On authentication with Google Workspace and Microsoft Entra ID coming by end of Q2 2026. Your users will be able to authenticate with their existing corporate credentials, eliminating the need to manage separate passwords and simplifying access to projects linked to the tenant.

Tenant-Level White-Label

Each tenant can customize logo, colors, and company name to deliver a consistent experience aligned with its own visual identity. Linked projects automatically inherit the tenant's branding, so your users interact with a fully customized authentication interface without knowing that LoginMaster is behind it.

Opaque Cloud: Data Only on the Tenant

Users' personal data resides exclusively on the customer's Tenant. The LoginMaster Cloud never contains readable information: it operates only on encrypted data and references. Not even the provider can access your users' data. With the split-salt system, no single component possesses sufficient information to reconstruct credentials.

Exclusive User Control

No administrator can reset passwords, change emails, or disable a user's 2FA. Only the user themselves can perform these operations through secure procedures designed to prevent identity theft. This security model protects users even in the event of administrative account compromise.

Multi-Project Management

IoT Q2 2026

Customer personnel have a single account on the tenant and can access various projects upon confirmation by the project admin or tenant admin. Support for two subject types (user and device) and API keys as a server-to-server communication method. Prepared for AWS IoT integration: manage your IoT device credentials from the same panel without duplicating identity management (available by Q2 2026).

Why choose LoginMaster?

LoginMaster is the IAM platform built on a Tenant-Cloud architecture where every component communicates via dedicated cryptographic keys. Dual-signature tokens, credentials protected with Argon2 and split-salt, and exclusive user control over their own sensitive operations.

Discover the Security Architecture

Dual-signature tokens Tenant + Cloud

Authenticity guaranteed on both sides of the communication

Opaque Cloud: personal data only on the Tenant

The Cloud contains no readable information. Not even the provider can access users' data

SSO with Google Workspace and Microsoft Entra ID (Q2 2026)

Simplified access with existing corporate credentials, coming by Q2 2026

Dedicated LoginMaster technical support

Dedicated team available for assistance and consulting

Frequently Asked Questions About Features

LoginMaster's architecture is based on two fundamental components: the Tenant and the Cloud. The tenant is the customer entity that contains users and credentials. It communicates with the LoginMaster Cloud via dedicated cryptographic keys. Each project has its own key to communicate exclusively with its tenant. This separation ensures that each customer's data is isolated and protected by independent cryptographic keys.

LoginMaster's authentication token is signed by both the Tenant and the Cloud, ensuring authenticity on both sides of the communication. This dual-signature mechanism ensures that the token cannot be forged even if one side is compromised. Additionally, the communication between client and API uses a separate cryptographic certificate, adding an extra layer of protection independent from the token's signature.

No, 2FA on LoginMaster is configurable for each individual project. It can be set as disabled, optional, or mandatory depending on the project's security requirements. The user enables 2FA only if at least one project in their tenant requires it. The system is based on TOTP and is compatible with Google Authenticator and similar applications, offering a balance between security and practicality.

By the end of Q2 2026, LoginMaster will support Single Sign-On authentication with Google Workspace and Microsoft Entra ID. These two providers cover the vast majority of corporate environments and will allow your users to access tenant projects with the corporate credentials they already use daily, without having to manage separate passwords.

No. On LoginMaster, no administrator can reset passwords, change emails, or disable a user's 2FA. Only the user themselves can perform these operations through secure procedures. This principle of exclusive user control prevents identity theft and protects users even if an administrative account is compromised.

Customer personnel have a single account on the tenant and can access various projects upon confirmation by the project admin or tenant admin. Each project supports user and device subject types, with API keys for server-to-server communication. By Q2 2026, AWS IoT integration will be available to manage IoT device credentials from the same panel. The admin controls who can access which project.

Users' personal data resides exclusively on the customer's Tenant. The LoginMaster Cloud never contains readable information: it operates only on encrypted data and references. Not even the provider can access the data. Credentials are protected with advanced hashing and a cryptographic separation mechanism that distributes components across multiple entities, so no single component possesses the information to reconstruct them.

LoginMaster's white-label feature allows each tenant to customize logo, colors, and company name in the authentication interface. Linked projects automatically inherit the tenant's branding, so your users will see a login experience consistent with your organization's visual identity, without knowing that the underlying platform is LoginMaster.

Ready to protect your organization?

Discover how LoginMaster can transform identity management in your company. Request a personalized demo with one of our experts and start protecting your users with LoginMaster's Tenant-Cloud architecture.