Sign-in without a password
A one-time code by email, or a passkey that uses the face, fingerprint or PIN their phone already asks for.
Customer portals
A private area on your site where each customer signs in and finds their own orders, invoices and documents, so they stop having to phone you for them. We build all of it, including the part that takes the most care: making sure one customer can never see another’s.
Why the wall comes first
OWASP is the nonprofit that publishes the Top 10 list of web application security risks. Its 2025 edition puts Broken Access Control first, the place it also held in 2021. Access control is the rule that a signed-in person can only do what they are allowed to. When it breaks in a portal, one customer opens another customer’s invoice, sometimes just by changing a number in the address.
OWASP’s guidance starts with where the check lives: it only works in code on the server, where the person asking can’t alter it. So that is where we put it, and it runs on every request.
A portal shouldn’t become one more place to type things in. Your customers, their orders and their files already live somewhere: an accounting package, an order system, a shared drive. The portal reads from those, so an invoice marked paid in your books shows as paid to the customer.
Each tool hands over everyone’s records, and the check passes on one customer’s. Where a tool can’t be read by another program, your team gets a screen to add files and updates by hand. Connecting the tools is its own piece of work. How we connect software ›
What you’d get
A one-time code by email, or a passkey that uses the face, fingerprint or PIN their phone already asks for.
What is open, what is owed and what is new, for that customer and nobody else.
The current file is marked as the latest, and earlier ones stay in the list, labeled as replaced.
Sent, opened, paid or overdue, with the PDF one tap away.
A note is attached to the order it is about, so your team reads it with the details in front of them.
Invite a customer, add a file, answer a note, and see who did what, from one screen.
A screen that lists a customer’s orders is the short part. What makes it safe to put real invoices behind that screen is this list, and it is most of the work. See what it takes ›
A free call. You describe the problem in your own words, and we tell you honestly whether software is the answer.
A written scope, timeline and price before any work starts.
We design, code and test in phases. You see working software at the end of each one.
We put it live: app stores, hosting, domains, the lot.
Monthly maintenance if you want it: updates, fixes and regular reviews.
Stopping that is the main job. Every request is checked on the server against who is signed in, and nothing is decided by what a browser sends. OWASP ranks failures of this check as the number one risk in web applications, so we test it directly: we sign in as one test customer, ask for another’s records in every way the portal allows, and confirm the answer is no each time.
Without a password. They type their email and get a one-time code, or they use a passkey, which signs them in with the face, fingerprint or PIN that already unlocks their phone or computer. In a FIDO Alliance survey of 11,000 people in ten countries, run in April 2026, 75% had turned on a passkey for at least one account.
It depends on what is behind the door. A code is as safe as the customer’s mailbox, which is what a “forgot my password” link relies on too. For order status and invoices that is usually a fair trade for never handling passwords. For more sensitive material we would add passkeys: NIST’s 2025 guidelines for U.S. government systems rule out email for sign-in codes, because a mailbox may be reachable with a password alone.
Yes. Then we follow the same NIST guidelines, published in July 2025. A password that is the only thing protecting an account must be at least 15 characters, and each new one is checked against a list of common and leaked passwords. The system must not demand a mix of capitals, digits and symbols, and must not force a change every few months, only when there is evidence the password was exposed.
The price depends on how many kinds of record the portal shows and how many of your tools it reads from. You get a written scope, timeline and price before any work starts. The code and the accounts it runs on are yours. Axel Diaz writes the code and is the person you talk to. We built the operator portal of Said & Done, the product we have been the whole engineering team of since 2023.
Two taps and your email. No call to book, no brief to write.
Prefer email? axel.r.diaz@a2g-tech.com