Windows logon, re-engineered

Strong Windows logon. No cloud. No compromise.

On-premises Multi-Factor Authentication (MFA) and passwordless credential provider for Windows.

CodeB hardens Windows logon with NFC cards, TOTP codes, PKI smartcards and USB tokens — used as a second factor on top of the password, or replacing the password entirely. Roughly half of our customers run each pattern; policy decides which fits your environment. Works on local, Active Directory and Entra ID accounts from Windows 8 through Server 2025. Fully on-premises, no cloud or internet connection required. Air-gap deployable.

Why CodeB exists

Four problems your Windows logon has to solve under your own roof.

Most identity vendors assume a greenfield Entra ID environment. Regulated organisations rarely have that luxury. CodeB is built for the parts of your environment that still run Windows logon — be it local accounts or Active Directory — and have to keep running it, securely. We have been doing exactly this for over twenty years; CP V2 is the modern evolution of Aloaha Smartlogin, the credential provider Aloaha has built and supported since the early 2000s.

01 / Legacy systems

Hardening the Windows logon.

Every Windows workstation still authenticates with a username and password — whether it's an office desk, a civil-service terminal, a manufacturing line PC or a clinical workstation on a hospital ward. CodeB layers strong authentication over that existing credential model, in place, without rewriting the desktop and without moving identity to the cloud.

02 / Compliance pressure

Per-user attribution — even for the shared accounts you can’t retire.

NIS2, DORA, the EU AI Act and sector-specific rules demand strong, attributable logon. Most companies cannot simply retire their historically-grown shared accounts. CodeB layers per-user authentication and auditing on top of those accounts, so every action remains attributable to a real person and your auditors get the evidence they recognise.

03 / Operator friction

Clinicians, operators and shop-floor staff need fast sign-in.

A nurse logging into a roving terminal cannot type a 16-character password fifty times a shift. Tap-and-go NFC and TOTP restore sub-second logon without trading away security.

04 / Digital sovereignty

No cloud required. No internet required. Works air-gapped.

CodeB is an EU product (Aloaha Limited, Malta) and runs entirely on your own infrastructure. The product never requires a cloud or internet connection to function. It deploys and runs on fully air-gapped defence networks, clinical OT segments and jurisdictions where data cannot leave the country. No customer data is ever stored or processed outside the EU — and because Aloaha Limited is an EU entity, the product is outside the reach of the US CLOUD Act and similar extraterritorial-disclosure regimes.

Critical infrastructure · NIS2

If you fall under NIS2, strong authentication is no longer optional.

NIS2 (Directive EU 2022/2555) classifies organisations across energy, transport, water, food, healthcare, manufacturing of essential goods, public administration, digital infrastructure and many other sectors as essential or important entities. Article 21 explicitly requires risk-managed authentication for every system that touches the operation. CodeB delivers exactly that — at the Windows logon screen, on-premises, with the audit trail your competent authority expects.

Article 21 Essential entities Important entities DORA IEC 62443 EU CRA
Flagship · Credential Provider V2

One credential provider. NFC, smartcard, TOTP and USB.

The CodeB Credential Provider V2 is a fully managed .NET implementation of Microsoft's ICredentialProviderCredential2 interface. Every supported token — NFC card, TOTP code, PKI smartcard or USB stick — can be deployed as a second factor alongside the existing password, or used to replace the password entirely. Both patterns are equally supported; in practice our customers split roughly 50/50 between them.

  • Local, Active Directory and Entra ID account support on the same workstation.
  • Standalone or domain-joined; works on every Windows edition from Windows 8 through Server.
  • Plugin architecture — you can extend it with your own login token or authorisation workflow.
  • Works with any RFC 6238 TOTP app for the moments where a contactless card isn't available.
  • No cloud required. Installs and runs on-premises. No cloud or internet connection is required for the product to function. Air-gap deployable.
Full product detail
Supported tokens
NFC contactless MIFARE Classic · DESFIRE EV1/EV2/EV3
PKI smartcard X.509 · corporate & sector PKI
USB memory stick For quick evaluation — no hardware to procure
TOTP RFC 6238 · 30 s · SHA-1/SHA-256
Bundled with CP V2

Two companions that ship inside the same licence.

The Credential Provider V2 licence carries two add-ons that solve the next problems most customers run into after they've hardened workstation logon. Each is also available standalone.

Add-on 01

CodeB Web SSO

One login. Every web app. No passwords exposed. A managed browser extension for Edge and Chrome that fills usernames, passwords and the 6-digit TOTP step on the way in — and signs users into legacy Windows and Java apps such as T2med — without ever exposing credentials to page JavaScript.

Read about Web SSO
Add-on 02

CodeB Desktop Switcher

Don't tidy your desktop. Replace it. One hotkey swaps your desktop files, icon layout and per-monitor wallpapers for a clean profile — perfect just before a Zoom or Teams screen share. Tap again to bring everything back exactly as you left it.

Read about Desktop Switcher
Deployment

From pilot workstation to organization-wide rollout in four steps.

CodeB ships as a credential provider DLL and a small set of policy templates. No directory schema changes, no agents on the domain controller, no cloud dependency unless you want one.

01

Install on a pilot workstation.

Sign in once with your existing account. The installer registers the CodeB credential tile alongside the Microsoft password tile. Nothing is locked down yet.

02

Enrol a token per user.

Tap an NFC card, scan a TOTP secret with any compliant authenticator app, present a PKI smartcard, or plug in a USB key for evaluation. Multiple tokens per identity are supported.

03

Roll the policy via Group Policy or the command line.

Push the configuration to your Windows machines via Group Policy or the command line. Hide the Microsoft Password Provider via the built-in CodeB Credential Provider Filter so end users only see the CodeB logon tile.

04

Audit and attribute every logon.

Every logon, lock and unlock event becomes attributable to the token holder and is written to the standard Windows event log — replay-resistant, ready for any audit interview.

Our promise

Humans answer here.

Email read by a person

Every message to info@codeb.io lands in a real inbox watched by engineers. No AI auto-reply. No ticket queue to chase. Same working day in most cases, never later than the next.

Phone picked up by a person

Call our German lines in CET business hours and someone answers. No phone tree, no "press 1 for sales," no hold music. If we're with another customer, we call back the same day.

The reader is the helper

The person who reads your message is the person who can solve the problem, or who knows precisely who to bring in. No deflection into chatbots, no self-service mazes.

Plain answers, including "no"

If CodeB isn't the right tool for your situation, we'll tell you so directly and point you somewhere that fits. Two decades of customers tell us that's why they stay.

Reply target: 1 business day  ·  Phone hours: CET, Mon–Fri  ·  Languages: English, German

Ready to replace the password tile?

Tell us about your environment — Windows mix, account model, token preferences — and we'll propose a pilot deployment within two business days.