Looks like overcomplicated authentication with TLS client certificate, for some reason brought on application level.
Websites now store only public data indeed, but confidential data is pushed to client devices, which may be even more vulnerable than the original service (and often are).
On the other hand, if implemented correctly, such approach may be more flexible than web server settings.