Sector · Defence & security

Custom defence and security app development. Security by design, from the first sprint.

We build native iOS and Android apps for defence suppliers, regional safety authorities, fire services, ambulance services, security companies and operators of critical infrastructure. Not a consumer stack bolted onto a security context, but an architecture that accounts for BIO, GDPR, NIS2 and hardware-key authentication from the first line of code.

Fordefence suppliers
Forregional safety authorities & emergency response
ForEmergency services & control rooms
ForSecurity & surveillance
ForCritical infrastructure (NIS2)

The Dutch defence and security sector in numbers.

25
Safety regions in the Netherlands
~6.500
Companies in the Dutch Defence and Security Industry
~30.000
Private security officers (BOA and POB status)
~150
Organisations in NIS2 essential sectors in the Netherlands

Source: NIDV industry figures 2024, Security Council annual report 2024, BVA publications.

Honest about what we are and are not.

In a sector where trust is quite literally a licensing question, we would rather start the conversation with what we are not. Appfront does not hold ABDO accreditation, and we do not process Stg.-classified or NATO-classified data. We are not an accredited defence supplier in the strict sense of the General Security Requirements for Defence Contracts. If you need a platform for classified information, you should hear that from us in the first conversation, and we will refer you to a specialist defence systems house with the appropriate clearance.

What we are: experienced builders of custom apps for companies and organisations operating in defence and security. Suppliers, civil emergency services, security firms, regional safety authorities, municipalities in a crisis role and operators of critical infrastructure. Security by design is in our DNA, not because it is marketing language, but because most of our clients do not get a second chance if something leaks.

In practice, that means we work vendor-independent, hand code ownership over to the client, treat BIO and ISO 27001 as a framework rather than a tick-box exercise, and have the discipline to decline a project if we are not the right party. What we are not, we will not pretend to be, because the stakes for our clients are too high.

We like to work in a chain model: we build the unclassified platform, for example a training coordination app, a crisis communication tool or an asset tracking system, and a cleared party supplies any classified component on top. For the legal conditions of such a collaboration, read our page custom defence software development.

Off-the-shelf security software rarely fits the way you work.

Many safety regions, fire brigades, security companies and defence suppliers today run on platforms built somewhere between 2010 and 2018 for an average organisation that does not actually exist. The core works (reports, patrols, incident logs), but every extension for the way your particular team operates gets stuck with a supplier who has it "on the roadmap" or will only move it once three other customers ask for the same thing.

Crisis management requires devices that keep working offline during a blackout. Security patrols need NFC checkpoints and evidence for the client. Asset tracking for defence suppliers needs audit trails the procurement office will accept. Workplace first aid and emergency response needs a one-tap flow that still works when your hands are shaking. On a standard package you handle these with workarounds, until the day it really matters.

A custom app solves this in a fundamentally different way: exactly the flow you run every day, with the hardware integrations and compliance requirements your context demands, and code that we do not lock away in a proprietary cloud. For the wider approach, see our app development service.

What we keep seeing with organisations that come to us: they have three or four off-the-shelf tools, each handling part of the work, and the patchwork between those tools is where errors creep in. The first-aider who logs an incident in app A while the control room only looks at app B. The security guard who sends his patrol report as a PDF that nobody stores. The defence supplier whose audit export has to be merged by hand from three different systems. It is rarely the individual tools that fail; it is that they were never designed to work together for your way of working.

A different device per sub-sector, a different threat picture, a different flow.

A crisis communication app for a safety region is a very different animal from an asset-tracking tool for an MoD supplier. For each target group we set out what we typically build, which compliance framework takes precedence, and which hardware stack we choose.

Defence suppliers

Companies across the aerospace, shipbuilding, ammunition, optronics and C4ISR supply chain. No classified platforms, but asset tracking for components tied to an MoD contract, screening status dashboards for staff with POB or VGB requirements, quality and evidence-trail workflows for supplier audits, and project planning where all communication is logged in an auditable way.

We assume the purchasing party at the customer, often a large OEM or the DMO itself, holds audit rights, and we build exportable logs in from day one. For the wider ISO context, you may find our ISO 27001-compliant software development page useful.

  • Component and serial trackingA record of owner, location and usage history for each item.
  • VGB/POB screening status dashboardA status overview without storing the content of the VGB decision itself.
  • Audit trail export for purchaserA read-only export package per audit request, with a hash for integrity.
  • Single sign-on with hardware keyYubiKey or smartcard integration, with fallback used only for admin recovery.

Typical use cases we build for this sector.

Eight concrete building blocks that regularly recur in our defence and security projects. We often combine two or three of them into a single app, depending on the operational reality of your organisation.

Exercise and deployment coordination

Multi-team coordination during exercises or real deployments, with roles, geographic task allocation and a real-time status board on a shared timeline.

Situational awareness tool

A shared map view with units, hazards and incident pinpoints. What each user sees depends on their role and clearance within the system.

Asset and equipment tracking

Weapons, vehicles, protective equipment or communication devices. Each asset has an owner, location and usage history.

First aid and emergency app

One-tap alarm, evacuation coordination, first aid checklist, first-aider locations and a direct line to the control room or emergency dispatch centre.

NFC-based security patrols

A predefined route with NFC checkpoints, photo evidence for anomalies and geo-tagged reporting to the client.

Gate, barrier and access control

Visitor registration with ID scanning, automatic logging of every access event, and integration with the PSIM or access control system on site.

Alarm centre companion

An operator app for control room staff with incident prioritisation, dispatch assignment and a geo-overlay of units in the field.

Crisis communication tool

Encrypted messaging (Signal protocol), a shared situation room, lockdown mode and guaranteed delivery to role-based groups.

Compliance and standards we build into the architecture from the first sprint.

Security and defence work stands or falls on demonstrable protection. We do not build first and bolt a DPIA on afterwards; we start with the standard.

BIO — Baseline Information Security Government

BIO-compliant from the design stage

Safety regions, municipalities and implementing organisations are bound by the BIO (Dutch Baseline Information Security for Government). Our reference architecture covers the basic measures for access, logging, segmentation and incident detection. For clients, we draw up a BIO checklist setting out our approach to each measure.

GDPR — special category personal data

Operational staff data is special category data

When a platform processes location data of emergency responders, firefighters or security personnel, this is typically special category personal data (Article 9 GDPR). We deliver a DPIA, map the legal basis, and build retention and access controls in line with the data minimisation requirement.

NIS2 — critical infrastructure

For essential and important entities

Since the Dutch implementation of NIS2, operators of drinking water, energy, transport and digital infrastructure fall under strict reporting and risk management obligations. Our apps for these sectors come with incident detection, a 24-hour reporting flow and logging that meets the burden of proof towards the supervisory authority.

ABDO — General Security Requirements for Defence Contracts

For suppliers within MoD tenders

We do not process classified data ourselves and do not hold ABDO authorisation. We do, however, understand the structure from Departmentally Confidential up to Secret, and can build the unclassified prerequisites so that a cleared partner can add a classified layer on top. For the full context, see our defence software page.

EU data residency

EU-only hosting with a no-cloud option

For sensitive contracts, we host within EU borders by default — preferably in a Dutch data centre location. For classified-adjacent contracts, we deliver an on-premises deployment option so the platform runs within the client's own network domain, without any dependency on external cloud.

ISO 27001 & ISO 27017

Aligned with the client's ISMS

Many clients in this sector hold their own ISO 27001 certification and expect their suppliers to be at least compatible with it. We work to an ISMS-compatible approach and provide the control mapping their audit requires. You can read our position in our information security policy.

We integrate with the systems your sector already uses.

An app that sits alongside your existing infrastructure rather than over it. Our integrations complement what you have and don't force a migration.

LCMS
National crisis management system
GMS
Integrated control room system
C2000
Emergency services communication network
Active Directory
Identity & SSO
Microsoft Intune
MDM and device policy
VMware Workspace ONE
Alternative MDM stack
YubiKey / FIDO2
Hardware-key SSO
PSIM platforms
Genetec, Milestone, Verkada

One platform that behaves like the rest of your IT stack.

We standardised the integrations mentioned above in previous projects. Some of them (LCMS, GMS) come with substantive conditions: connecting goes through formal interface procedures at the control room and NCC organisations. We take care of the technology; your organisation submits the connection application itself, and we support you with the inspection documentation.

For sector-specific software (a proprietary PSIM, a local access control controller, a municipality's dispatch system), we build on a case-by-case basis. This takes extra time in the planning phase, but it prevents us from building an unmaintainable shadow integration. If you'd first like to see how we work in a government context, take a look at our page software for municipalities. Much of our safety region work follows the same principles.

One choice we always make with the client upfront: whether the platform gets its own identity provider or integrates with the existing Active Directory or Entra ID tenant. For security regions and larger defence suppliers, the latter is almost always the choice, as otherwise the staff offboarding flow would fall out of sync. For smaller security companies, a standalone identity stack can sometimes be quicker. We weigh this up based on what generates the least manual effort in day-to-day administration.

The technical stack we use to build these apps.

For defence and security contexts, we default to native iOS and Android over hybrid frameworks, owing to OS-level encryption, hardware keychain access and a smaller attack surface. The following layers feature in every engagement.

Stack · 01

Native iOS & Android

No hybrid shells for security-critical apps. Native Swift/Kotlin with direct access to the Keychain (iOS) and Keystore (Android), so encryption keys never leave the secure element. Offline-first design: the app keeps working without a connection and synchronises when it can.

Stack · 02

End-to-end encryption with the Signal Protocol

For messaging and crisis communication components, we use the Signal Protocol, the open standard that also underpins secure messaging apps. Per-message forward secrecy, deniability, and no plaintext on the server. For classified-adjacent projects, we run the protocol implementation on a server managed by the client.

Stack · 03

Hardware key and MDM integration

FIDO2 / WebAuthn for SSO with YubiKey, smartcard or fingerprint plus device binding. Full MDM integration (Intune, Workspace ONE, Jamf) for remote wipe, device compliance checks and certificate distribution. No "trusted" fallback to SMS OTP for high-risk roles.

Stack · 04

On-premises deployment option

For classified-adjacent or NIS2-essential projects, we offer an on-premises deployment path: the entire server stack runs on the client's infrastructure, behind their own firewall, with no external cloud dependencies. We deliver the Helm charts or Ansible playbooks and train the IT team to manage it independently.

Stack · 05

EU data residency by default

Where a cloud deployment is acceptable, everything runs by default in Dutch or EU data centres. No US hyperscaler regions. Database replicas, backups and log aggregation stay within the same residency boundary. For audits, we provide the regional evidence.

Stack · 06

Code ownership stays with the client

All code becomes the property of the client; we hold no retainer lock on the source code. Repositories are handed over on delivery, together with documentation and a runbook. If we step away or are replaced by an internal IT department, your platform carries on regardless.

From scoping conversation to going live in five recognisable phases.

A project for defence or security clients follows its own rhythm. We move through every engagement along the same steps, so that both your security officer and the operational end user know what to expect.

01 · Scope

Classification discussion

Which data flows through the platform, which classification applies to it, and where the line sits between what we build and what a specialised defence firm should handle. An honest demarcation prevents later blockers.

02 · Architecture

Security-by-design blueprint

Threat model, BIO/NIS2 checklist, identity flow, on-premises versus EU cloud, MDM strategy. One document your security officer can sign off before we start building.

03 · Build

Sprints with early adopters

One working flow delivered each sprint. End users (firefighters, security guards, paralegals at suppliers) test along the way, so real working processes take precedence over theoretical designs.

04 · Hardening

Penetration test and audit preparation

External penetration test (by a party chosen by the client), code review, BIO/ISO control mapping, DPIA finalisation and logging configuration. We only go live after the report and fixes are complete.

05 · Maintenance

Ongoing and transferable

We adapt with every OS update and change in legislation. We deliver a runbook and training so your IT team can manage it themselves if you prefer. No vendor lock-in.

Frequently asked questions.

What security officers, operations managers and commanders typically ask before we start.

Do you hold an ABDO clearance?
No. Appfront does not hold an ABDO clearance, and we do not process Stg.-classified data or NATO-classified information. For classified platforms, we refer you to a defence systems house with the appropriate clearance. What we do do is build unclassified applications for suppliers, emergency services, security companies and critical infrastructure operators, applying security-by-design discipline and knowledge of BIO, ISO 27001 and NIS2.
Do you work for the Ministry of Defence directly?
Not directly. Our clients are the companies and organisations around the defence and security supply chain: aerospace and shipbuilding suppliers, security firms, safety regions, municipalities in a crisis role, and operators of critical infrastructure. Within a chain model we do collaborate: we build the non-classified part, and a cleared partner delivers any classified layer.
How do you handle BIO and NIS2?
From sprint 1. For BIO-subject clients, we provide a BIO checklist with our implementation of each measure, and build the baseline security (access, logging, segmentation, incident detection) in as standard. For NIS2 essential entities, we implement the 24-hour reporting flow, risk analysis documentation and logging that the supervisory authority requires. We are not your compliance officer, but we are a supplier who helps you avoid doing the same work twice.
Can the platform run without the cloud?
Yes. We offer an on-premises deployment option as standard, where the entire server stack runs on the client's infrastructure, behind their own firewall. We supply Helm charts or Ansible playbooks and train your team to manage it independently. For classified-adjacent or NIS2 essential assignments, this is often the right choice.
Do you work with hardware keys such as YubiKey?
Yes, and we recommend them for high-risk roles. FIDO2 / WebAuthn integration with YubiKey, smartcards or device-bound biometrics is part of our standard blueprint. We do not use SMS OTP for security-critical roles, as there is too much that can go wrong with it in this context.
Who owns the source code?
The client. We hand over the entire codebase, repositories, deployment pipelines and documentation. No retainer lock-in, no proprietary platform cloud you are tied to for life. If we step away or an internal IT department takes over our work, your platform carries on running.
How do you arrange the connection to LCMS, GMS or C2000?
We take care of the technology; your organisation submits the connection application itself to the relevant managing organisations (Instituut Fysieke Veiligheid, Landelijke Meldkamer Samenwerking). We support you with the inspection documentation and the interface process. Connecting goes through formal procedures that you can't skip. We know how they are structured and help you get through them faster.
Do you also build first aid and workplace emergency response apps?
Yes. BHV apps are among the most common safety use cases we build: one-tap alarm, evacuation coordination, BHV warden location, a direct line to the controller or control room, and integration with the access control or fire alarm system on site. For businesses with an ARBO obligation (Dutch workplace health and safety duty) and for public institutions.
What do you do about penetration testing?
For every safety or defence supplier app, we carry out an external penetration test before go-live. We preferably work with a penetration testing firm chosen by the client (Northwave, Fox-IT, Securify or similar). Findings are fixed and retested before we hand over the system, with no "we'll sort it out during maintenance".

Ready to build with a serious partner?

A 30-minute introductory call with our security officer and one operational end user. We listen, ask about your classification boundaries and your BIO or NIS2 requirements, and suggest a first direction. No obligation, and if a cleared defence systems house turns out to be a better fit, we'll tell you so.

Prefer to read first? Our pages on app development, defence software and ISO 27001-compliant software give a deeper picture of our approach.

Edit content