Serious protection for your revenue and data
Your licenses are your income and your customers' data is a responsibility. InnoKEYS is built with strong cryptography, real tenant isolation and audit-ready logging from the ground up.
Ed25519 response signing
Every verify answer for a real license is signed with a server-only key, so clients can trust it even offline. The public key is published for pinning and rotation.
Database per administration
Each administration runs in its own dedicated database. A global database holds only cross-tenant identity β no customer data leaks between tenants.
Two-factor authentication
TOTP with backup codes, enforceable per user. Sessions are revoked automatically when a password, role or account status changes.
Scoped API keys
Keys are hashed at rest, restricted to explicit scopes, and can carry expiry dates, per-hour rate limits and IP allow-lists. Access is deny-by-default.
Rate limiting & anti-abuse
Per-IP and per-license limits, an IP blacklist, and automatic blocking of addresses that probe for non-existent license codes.
Signed, integrity-checked downloads
Files are delivered through time-limited, signed URLs with SHA-256 integrity hashes, so nobody can tamper with or hotlink your installers.
Isolation you can actually explain to a customer
Instead of one big shared table with a tenant column, InnoKEYS gives every administration its own database. A tenant registry maps each administration to its database, and a global identity database holds only users, memberships and a fast license-to-tenant lookup.
- Per-tenant databases β a query can't accidentally cross tenants
- Tenant context enforced by middleware on every request
- Atomic administration creation and transactional writes

Audit-ready by default
EU-hosted, with the logging and controls compliance teams expect.
Full audit trails
Creates, updates, deletes and logins are recorded with old and new values, the actor, IP address and user agent β searchable across every field, both per administration and globally.
Responsible disclosure
A machine-readable security.txt (RFC 9116) makes it easy for researchers to report issues. Found something? Email info@innodigi.nl.
Questions about security?
We're happy to walk your team through the architecture and controls.