Go to main content Go to main navigation Go to footer

Custom security software manages access, authorization, and accountability within your own business processes: who is allowed to see what, who made what changes, and how you demonstrate this during an audit. Not antivirus or network security, but security that stems from your own processes.

  • Access management with roles and permissions

  • Audit trails that an auditor can read

  • Compliance visible rather than aggregated

Image without description

What is custom security software?

Custom security software manages access, authorization, and accountability within your own business processes: who is allowed to view what, who made which changes, and how you demonstrate that during an audit. It’s about access control, audit trails, and compliance dashboards—not antivirus or network security. The difference from a standard package lies in the questions you ask. A security package protects your infrastructure from the outside world. Custom security software answers questions about your own processes: Is this employee authorized to approve this order? Which supplier has viewed which document? And who adjusted that rate three months ago?

These questions vary by organization because they stem from your own processes, not from a standard. That’s why this type of functionality is usually part of the software you’re already having developed, rather than a separate product on the side.

Design en build

What does Cube build—and what doesn’t it?

Cube builds security directly into digital products. Think of access control, authorizations, audit trails, logging, and compliance dashboards. For example, we build the role structure into your portal, the logging that lets you see what happened afterward, and the reporting that allows you to demonstrate this to an auditor. We do not provide antivirus software, firewalls, network security, or a Security Operations Center, nor do we sell third-party security solutions. We have penetration tests and vulnerability scans performed by specialized partners. This is a deliberate choice: those who build should not be the ones to evaluate their own work.

Want to partner with Cube?

Which security features do we build most often?

Access Control

Access control with roles and permissions.

Role-based access control links permissions to a role rather than to a person. A new employee is assigned a role and, with it, the appropriate access level all at once. When someone leaves, all access is revoked simultaneously. In practice, things go wrong because of exceptions: someone is granted temporary additional permissions and ends up keeping them. A functional setup therefore keeps things simple. One role per user, a permissions matrix that determines what that role can see and do, and roles that belong to a single organization so that data doesn’t leak beyond those boundaries. Plus, a set expiration date for temporary permissions and a periodic review that someone actually carries out. You can see how this works in portals with roles and permissions.

SSO & MFA

Single sign-on and multi-factor authentication.

With single sign-on, a user logs in once and then has access to all linked applications via protocols such as OAuth or SAML. The benefit isn’t just convenience: account creation and revocation are managed through a single central source, so when an employee leaves, they’re removed from everywhere in a single step instead of having to be removed from eight separate applications. We integrate with the provider you’re already using. Microsoft Entra ID is in production, as are SAML integrations via our own Cube packages for Laravel and SilverStripe, and for organizations using AFAS, we use AFAS as the identity source for portal users.

When it comes to multi-factor authentication, the question isn’t “if,” but “which method.” An authenticator app is free and always works, but it doesn’t work for employees who don’t have a phone with them on the job site. A hardware key is phishing-resistant but incurs a cost per user. Approval via email is the weakest form. An external identity provider offers more control and insight, at a monthly cost. We make that assessment on a per-organization basis, not based on standard recommendations.

Traceability

Audit trails and logging.

An audit trail records who changed what and when, in a format that cannot be altered retroactively. This is different from logging for error detection, although the two are often confused. Technical logs may be deleted after thirty days. You must retain an audit trail for as long as your accountability obligation remains in effect, and it must be readable by someone without a technical background.

Such a trail only becomes useful if it also records why something was changed. In one of the platforms we’re building, a user can only modify a critical field after unlocking it, by selecting a required reason from a fixed list and attaching supporting documentation. This takes the user ten seconds and saves an afternoon’s worth of research during an audit.

Compliance

Compliance and audit dashboards.

A compliance dashboard shows whether you’re meeting your own policies: which controls are active, which are overdue, which risks remain open, and who is responsible. The value lies in the moment you consult it. Without a dashboard, an audit begins with weeks of data collection from disparate systems and spreadsheets. With a dashboard, it’s just an export.

Authorization

Authorization in portals.

In a portal where multiple organizations come together, authorization is at the heart of the design. A supplier sees only their own orders and no one else’s. A dealer sees only their own margins. This may seem obvious, but it is the most common source of data breaches in portals: a user accessing another party’s data via a modified URL or a direct API call. Authorization should therefore be handled on the back end and not in what the interface displays.

Privacy

Data minimization, encryption, and pseudonymization.

Data you don’t store cannot be leaked. Data minimization starts with asking which fields your process truly needs—and that is a design decision. Whatever you do store must be encrypted both in transit and at rest. Pseudonymize personal data that you use solely for analysis, so that it can no longer be traced back to an individual. For healthcare applications, the regulatory framework applies; see NEN 7510 for healthcare.

AI Policy

AI Governance and AI Security.

As soon as an application contains a large language model or an AI agent, additional questions arise: what data goes to the model, who is authorized to view which responses, and how do you document what the system has decided? The EU AI Act sets requirements for transparency and human oversight, which translate into concrete functionality: logging of prompts and responses, a clear definition of what data the model is allowed to see, and a human review step for decisions with consequences. More on this under AI security and governance.

"We’ve been working closely and enjoyably with our digital partner Cube for years. It all started years ago with a new website and app; today, they assist us with further developments of those products, as well as providing advice and new digital products. A pleasant and productive partnership!"
Leon Molenkamp - Manager Media, Marketing & Communicatie FC Twente
Leon Molenkamp Manager of Media, Marketing, and Communications at FC Twente
"In 2018, we were looking for a partner to help us with our digital transformation. The decision to choose Cube was an easy one. In conclusion, we are extremely satisfied with our long-standing partnership with Cube, and we look forward to the future and to realizing even more successful projects together!"
Mark Analbers - Product Owner bij Pure Energie
Mark Analbers Product Owner at Pure Energie
"Very satisfied with Cube. They’ve now developed two websites for us, and we’re very happy with the results. Great communication, short lines of communication, and a team that thinks along with us. A pleasure to work with!"
Marre brookhuis, marketing manager bij Brookhuis Groep
Marre Oorthuis Marketing Manager at Brookhuis Group
"What a team of digital heroes! Eastern pragmatism combined with worldly wisdom from across the universe. They deliver outstanding work!"
Image without description
Theo Hek CEO at Nou
"I’ve had a fantastic experience with this company; they built a great website and a well-thought-out configurator for us. Their approach is extremely professional, and they always keep us informed about what’s coming next. The applications they build are truly custom-made and therefore super fast, while always looking polished. Perfect!"
Image without description
Wessel Klein Snakenborg Manager at Direct Een Kozijn

When is customization necessary?

Approval

Your approval workflow involves multiple roles and different rules above a certain amount or risk level.

Segregation

Multiple organizations work within the same portal and must not be able to view each other’s data under any circumstances.

Accountability

Your regulator requires evidence at the field level, and that evidence is currently scattered across separate systems.

Management

Permissions are granted and revoked manually, so no one knows exactly who has access to what.

Audits

An audit takes weeks of data collection each time, even though the policy itself is clearly laid out in writing.

AI

Your application uses AI, and you need to be able to demonstrate what data the model processed and who had access to it.

Standard solution

  • For common processes
  • Identity management, endpoint security and network monitoring
  • Functionality that's already available within the package
  • Quick to implement and easy to extend within what the package allows
  • A good fit if your needs match existing functionality

Custom solution

  • For processes that are specific to your organisation
  • Your own approval flows, authorisation logic and data flows
  • Functionality that matches exactly how you work
  • Fully tailored to your processes and flexible to adapt
  • A good fit if you have specific requirements a standard package doesn't support well

Wondering whether the standard package or a custom solution is right for you? Feel free to contact us for a no-obligation consultation.

Jarno Rutjes - Business Director bij Cube - Oldenzaal
Jarno Business Director
Our Approach

How we help you achieve your goals.

From that first cup of coffee to the continued expansion of your digital landscape. Four clear phases that define our collaboration and guide your growth.

Have security software developed by Cube.

Cube is ISO 27001 and NEN 7510 certified. This certification is re-evaluated annually, so it’s not just a one-time piece of paper; the way we handle access, logging, and incidents follows the same framework as the software we build. We see ourselves not just as a supplier, but as a true software development partner. We work with you to make strategic decisions, provide technological advice, and deliver solutions that make a real impact. Our approach is versatile and tailored to your specific needs and goals.

Want to partner with Cube?

We help corporations move like startups, and startups grow into corporations.

Challenge us

Ready to get started with security software? Let’s get to know each other.

No obligations, just insight into how access management, audit trails, and accountability fit into your software. Jarno would love to brainstorm with you.

Jarno Rutjes - Business Director bij Cube - Oldenzaal
Jarno Business Director

With boldness, pragmatism, and a focus on quality.

Our team. Your team.

Amber Stuivenberg, projectmanager bij Cube

Amber Projectmanager

Good at padel, social and has a good dose of humor. As project manager at Cube, Amber brings technology and client together and ensures that projects run smoothly. Sporty and curious, always ready for a new challenge and to achieve great results together with the team.
Image without description

Bart Developer

Whether he's on the judo mat or in the office, Bart brings energy and humor wherever he goes. Always in good spirits, quick-witted, and a colleague you can truly count on.
Bernard Diphooren

Bernard Developer

Tukker, lover of squash, PSV, and photography during the golden hour. Bernard has been working with code for years, paying attention not only to functionality but also to readability and testability. Quiet, precise and always focused on beautiful and well-working solutions.
Bob ten Vergert - Security officer bij Cube - Oldenzaal

Bob Test Engineer | Security & Privacy

Of course, someone has to monitor AVG, quality & security. With conviction and punctuality, our Test Engineer and Security & Privacy Officer, Bob safeguards these facets.
Demi Weustink - Office Manager bij Cube - Oldenzaal

Demi Officemanager

With a down-to-earth outlook and organisational talent, Demi is the go-to person who makes sure everything in the office runs smoothly. Her flexibility and people-oriented approach make her indispensable as office manager.
Dennis Hofs, Full-stack developer bij Cube Oldenzaal

Dennis Full Stack Developer

With his vast knowledge and perseverance, he knows how to solve complex issues, while always being committed and pragmatic. We are happy to have someone like Dennis on our team.
Guus Oude Kotte - Back-end Developer bij Cube - Oldenzaal

Guus Full Stack Developer

Genuine Twente down-to-earthness, you're going to find that with Guus. An approachable and open person, a rock for our team.
Jarno Rutjes - Business Director bij Cube - Oldenzaal

Jarno Business Director

As fanatical as Jarno is in the gym and on the tennis court, he is also committed within Cube. His strength? Thinking along with clients' business and getting to the heart of business processes.
Jarno Witjes - Back-end Developer bij Cube - Oldenzaal

Jarno Back-end Developer

A true professional, Jarno keeps every appointment and delivers reliable results.
Jasper Lanting - Projectmanager bij Cube - Oldenzaal

Jasper Developer

With his technical background, he is the perfect link between the developers and our clients. He is a true team player: sociable, structured and therefore a top Project Manager.
Jenne Morsink - Digital Marketeer bij Cube - Oldenzaal

Jenne Marketing Manager

With confidence and a sharp pen, Jenne powerfully conveys any message. She knows exactly how to make an impact.
Jeroen Mager - Back-end Developer bij Cube - Oldenzaal

Jeroen Back-end Developer

Just as in jujutsu, the sport Jeroen practices, the same applies at Cube: Jeroen thinks ahead and acts decisively.
Job Keupink - CEO Cube Oldenzaal

Job CEO | Executive

As founder of the organisation, Job starts his working day full of pride. Proud of the Cube team, of what we have achieved together and full of energy to realise our ambitious goals.
Joost van Dijk

Joost Tech Lead | Team Pentagon

An expert in app development, who loves to share his knowledge! With a keen interest in others and a determined attitude, Joost is an asset to any project.
Jordy ten Elsen - Tech Lead Developer bij Cube - Oldenzaal

Jordy Software Architect

With a good dose of (rubber duck) humour, Jordy oversees every situation perfectly. You don't have to chase anything because he always has everything under control.
Justin Buhrmann - Full-stack Developer bij Cube - Oldenzaal

Justin Tech Lead | Team Hexagon

If there is anyone you can count on within the team, it is definitely Justin! With his sense of responsibility, he radiates calmness to his colleagues.
Kevin Veldscholte- Developer bij Cube - Oldenzaal

Kevin Developer

With his cheerful attitude and fresh outlook, Kevin has become a valuable force. He possesses a lot of expert knowledge and puts it to effective use every day.
Laura Spierings - Digital Designer bij Cube - Oldenzaal

Laura Digital Designer

A creative and curious professional with a passion for design and FC Twente. Cheerful, enthusiastic and always up for a good conversation, she brings both atmosphere and quality to her work.
Maartje Harms - Content marketeer bij Cube - Oldenzaal

Maartje Content Marketeer

Whether it is a catchy image or a compelling video, Maartje combines creativity, openness and honesty to tell stories that connect.
Mans Booijink, operations manager van cube

Mans Operations Manager

With a good dose of enthusiasm, Mans focuses daily on optimising processes and working methods. Cooperation is key, with the aim of achieving great results together.
Image without description

Marcus Projectmanager

Marcus brings a fine energy to the team with his social character and enthusiasm. A real matchwinner, not only within Cube but also on the tennis court!
Marleen Poorthuis, projectmanager bij Cube

Marleen Projectmanager | Team Lead Octagon

With her down-to-earth approach and a wealth of technical knowledge, Marleen makes every project a success. As a driven Project Manager, she continuously helps Team Octagon move forward.
Mart Nijland - Front-end Developer bij Cube - Oldenzaal

Mart Front-end Developer

With genuine interest, Mart builds front-end experiences that stand out. A precise person with whom working together is always a pleasure.
Melanie Meester - Projectmanager Cube

Melanie Projectmanager | Team Lead Hexagon

Thanks to Melanie's process-oriented approach, nothing gets left behind and everything comes together within the projects. With her enthusiasm, she takes the team with her in this.
Mick Nijboer, tech lead bij Cube

Mick Tech Lead | Team Nexus

Mick works as a Tech Lead and collaborates closely with colleagues and clients to develop practical and smart solutions. With a strong focus on communication and the use of AI, he contributes to increasingly efficient workflows.
Image without description

Nicky Projectmanager | Team Lead Nexus

Nicky brings people together, keeps an overview and ensures that plans become reality. With her creative vision and down-to-earth approach, she steers projects smoothly to the desired result. Always eager to learn and keen on content.
Onno Scheuten - Business Controller bij Cube - Oldenzaal

Onno Business Controller

With an eye for detail and a talent for numbers, Onno makes sure every comma and decimal is correct. Structured and disciplined - both in the office and on the tennis court, where precision and strategy come together.
Image without description

Remi Software Architect

With a passion for imparting his expertise to colleagues and clients, Remi is known within Cube as the team's mentor - or as many call him: 'the Padre'.
Rogier Lohuis, Business Consultant bij Cube

Rogier Business Consultant

Rogier speaks the language of both our clients and our developers. Understanding processes? He is an expert at that!
Rosan van Oers - Manager People & Organization bij Cube - Oldenzaal

Rosan Manager People & Organization

Rosan is the connecting force within our team. Committed, sincere and punctual - the enquiry point that brings people together and keeps the organisation running smoothly.
Roy Teusink - Javascript Developer bij Cube - Oldenzaal

Roy Full Stack Developer

Roy has made his hobby his profession, with a passion for programming and an eye for detail. A quiet, extremely thorough developer who has his work cut out perfectly.
Ruben Assink - Full-stack Developer bij Cube - Oldenzaal

Ruben Full Stack Developer

Enterprising and structured - Ruben is a developer with vision... and he is always up for a game of darts in the break!
Ruben Vaalt - Digital Designer bij Cube - Oldenzaal

Ruben Digital Designer

A Digital Designer who combines innovation and structure, where his work is not only beautiful, but above all functional and purposeful.
Sander Bekkedam - Developer bij Cube - Oldenzaal

Sander Developer

With an impressive amount of knowledge for his age and an athletic attitude, Sander is a committed and energetic force within any project.
Stijn Lammerink - Javascript Developer bij Cube - Oldenzaal

Stijn Front-end Developer

A social Front-end Developer who loves structure and always keeps an overview. A valuable colleague within our team - not only on the shop floor, but also at Friday afternoon drinks!
Image without description

Tamara Business Consultant

Tamara knows how to turn any issue into new opportunities with her energy and creative thinking.
Thomas Meulenbroek - Back-end Developer bij Cube - Oldenzaal

Thomas Back-end Developer

A skilled Back-end Developer with a social attitude. Whether it is getting to the bottom of an issue, playing ping-pong or a game of football on the square - he always plays at a high level.
Ties Pol - Tech Lead & Developer bij Cube - Oldenzaal

Ties Tech Lead | Team Pentagon

A fine collaboration with Ties? You can count on that! An accurate Tech Lead who stands firmly on his feet and is not afraid to step outside his comfort zone.
Tom Oude Rengerink

Tom Tech Lead | Team Octagon

Think of speed? Then you think of Tom! Whether it's fast cars or racing on the go-kart track - as long as it goes fast. So the innovative technology in this industry suits him perfectly.
Image without description

Wesley Projectmanager

Met zijn IT-ervaring in ERP-software als consultant en projectmanager helpt Wesley klanten graag bij het realiseren van slimme automatisering en digitalisering als waardevolle aanvulling op hun ERP- en CRM-systeem.

Questions about security software? No problem.

Antivirus protects devices from malicious software. Custom security software manages security within your own applications: who is allowed to do what, what has been changed, and how do you demonstrate that. These are different layers that do not replace one another.

Cube builds the functionality you need to meet those requirements, such as access management, logging, and reporting. The certification process itself and the legal review are the responsibility of an auditor or consultant.

An audit trail permanently records who changed what and when. You need it to reconstruct what happened after the fact and to demonstrate during an audit or incident that the process was followed.

Yes. Microsoft Entra ID and AFAS are in production, and we use our own packages for SAML integrations. As long as a system supports a standard protocol such as SAML or OAuth, an integration can be built.

Cube does not conduct them itself. Penetration tests and vulnerability scans are carried out by a specialized partner, ensuring that the party responsible for development does not evaluate its own work. We do, however, incorporate the findings into the software.