11.05.2026
Vaultwarden 1.36.0 & NIS2: Self-Hosted Password Management for SMBs
On 3 May 2026 the Vaultwarden maintainer team released version 1.36.0 — closing six security advisories, one of which is a server-side request forgery that...
Auth, permissions, and audit as integral platform parts - not bolt-on add-ons. We build platforms where tenant isolation, compliance, and support workflows work from day one.
Companies worldwide trust WZ-IT
The first 80 percent of any member or tenant platform are built in two weeks. The last 20 percent - impersonation for support, audit-grade logs, soft delete without data loss, safe permission inheritance, MFA onboarding without lockouts - eat three months if not planned from the start.
We bring architecture patterns from production platforms. You skip the tuition phase and start with a model that survives audit number five.
Login, single sign-on against your existing identity provider, OIDC or SAML integration - vendor-independent, self-hosted on request. Accounts can be deactivated without losing audit history.
Global roles, tenant level, project or site level, optionally down to individual devices or records. Inheritance and exceptions cleanly modeled - and anchored deep in the data model, not just in the UI.
Every write action is logged - who changed what when, from where. When an admin acts on behalf of an end customer (support case), the admin identity stays in the log - accountability is preserved.
Multi-tier throttling against brute-force attacks, detection of unusual login patterns, generic error messages without data leakage. Optional multi-factor layer for sensitive areas.
API keys, stored credentials, and sensitive configurations are encrypted at rest. Per-install key, key rotation without downtime - even when compliance requirements demand it.
Tenant isolation is enforced at the database level - not just in the application. So separation holds even when an endpoint forgets a check. Defense-in-depth instead of blind trust in the frontend.
A SaaS product distributed by reseller partners to their end customers. Reseller admin sees all their own end customers, end customers see only themselves, platform operator sees everything and can intervene - all in one code base.
Associations, federations, cooperatives - with roles (board, member, guest), membership fee workflows, elections, and resolutions. Including privacy-focused data handling and right to forget.
Tools for your staff to manage customers, tickets, devices, or licenses. Single sign-on against your existing IdP, audit trail per action, export for compliance reports.
Per-tenant features, limits, UI branding. Self-service configuration by the tenant admin, centrally controlled by the platform operator. Feature toggles as first-class citizens.
Member and tenant platforms usually live in the context of other platform jobs. We combine them seamlessly with remote site management, custom dashboards, or classical business apps.
Scoping Sprint
Requirements, target architecture and effort are clarified. The result is a fixed-price offer for implementation.
Enquiry
Name target groups, roles, operational processes, and existing data sources.
Answers to the most important questions
Depends on the goal. For fast time-to-market and SaaS: Supabase. For enterprise compliance with SAML/OIDC and existing IdP landscape: Keycloak. For modern lightweight self-hosting: Authentik. We decide jointly in the workshop and advise vendor-neutrally.
Yes. We encapsulate auth behind a service layer in the API, so a switch from Supabase to Keycloak (or the other way around) is possible without losing permissions or audit data. It is an architectural effort, not a data-loss risk.
You pay a fixed price that we determine in a scoping sprint with a defined scope - scoped individually to your feature set, from a lean MVP with auth, tenant model, audit, and one permission level to a full platform with multi-level permissions, impersonation, MFA, and self-service tenant config. Instead of unpredictable per-user or per-seat license costs, you get predictable one-time project costs with no surprises as you grow.
MVP: 6-10 weeks. Full build: 4-8 months. We ship in iterative releases - usually something usable is in production by week 4.
Not necessarily. We host in European data centers (Hetzner, IONOS, OVHcloud, STACKIT) - privacy-focused, with dedicated VPC on request. Alternatively the platform runs on your Proxmox infrastructure or in a hyperscaler of your choice.
Default: all data in the EU, backups in the EU, no transfer to third countries. On request we document this in a data protection concept document you can attach to processor agreements.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Proof for modernization, API extension, architecture, deployment and ongoing operations.
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

11.05.2026
On 3 May 2026 the Vaultwarden maintainer team released version 1.36.0 — closing six security advisories, one of which is a server-side request forgery that...
01.04.2026
If you're looking for an Okta or Auth0 alternative, two open-source projects quickly rise to the top: Authentik and Zitadel. Both solve the same problem...
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.