Sector · Security & Legal-tech

App development for security and legal tech. Two disciplines where confidentiality is the product.

We build custom apps for cybersecurity vendors and legal service providers: SOC portals, CISO dashboards, contract management, case management and e-discovery. Professional secrecy and NIS2 are not a plugin but an architectural choice, built in from the first sprint rather than bolted on during an audit week.

SecuritySOC & SIEM tooling
SecurityVulnerability management
Legal-techContract management
Legal-techCase & e-discovery

The Dutch security and legal-tech market in figures.

~17.000
Lawyers registered with the NOvA
~2.700
Law firms in the Netherlands
~450
Cybersecurity vendors and MSSPs active in the NL
NIS2
Mandatory for thousands of essential and important entities

Source: NOvA annual report, CBS, NCSC NIS2 implementation report.

Two sectors, one shared requirement.

At first glance, a SOC analyst and a corporate lawyer have little in common. One hunts for indicators of compromise in a SIEM, the other drafts a deed of transfer. But in both sectors you are essentially selling the same thing: confidentiality that must be demonstrable. An outsider must not get near the data, a regulator must be able to see who did what, and the client, here either the company or the individual seeking justice, must be able to produce evidence when something goes wrong.

That makes these two sectors look far more alike in software architecture than an average B2B SaaS product. A good legal-tech application and a good security tool share the same foundations: end-to-end encryption with keys you control, a record-level audit trail, a role-based permissions model that takes the principle of least privilege seriously, and data residency choices you can defend to a regulator. The rest is content: in legal-tech it revolves around case files, in security around alerts.

Our broader approach to custom apps is set out on the app development overview page. On this page we show how we translate that approach specifically for cybersecurity vendors, law firms, corporate legal departments and compliance functions, and which compliance layer we supply as standard, because in these sectors building it in afterwards is not an option.

Apps that suit every sub-discipline.

Security and legal-tech are each divided into a handful of specialisms, each with its own workflow, its own integrations and its own compliance requirements. For each discipline we show what we typically build, and which modules we include as standard.

SOC & vulnerability management

The workhorse for cybersecurity vendors, MSSPs and in-house SOC teams. This is where we build client portals in which an end organisation sees its own alert feed, vulnerability status and incident timeline, plus the operator side in which your own analysts perform triage, run playbooks and report to the client. Penetration test reports are generated from the same data, so a client never receives three different documents with mismatched figures.

Our SOC module set includes a SIEM add-on for the most widely used platforms (Microsoft Sentinel, Splunk, Elastic), a ticketing layer that feeds directly into the end client's ServiceNow or Jira, and a reporting engine for both operational weekly reports and executive quarterly overviews. Everything runs on keys that you or your client manage, not us.

  • Multi-tenant client portalsEach end client in its own tenant with its own data, roles and retention.
  • SIEM integrationsBidirectional integration with Sentinel, Splunk, Elastic, Wazuh and IBM QRadar.
  • Vulnerability management dashboardsAsset inventory, CVSS scoring, remediation status and asset ownership.
  • Penetration test report generatorFindings drawn from the same dataset, readable for both client and developer.

Built to the strictest standards of security and the legal profession.

In both sectors, compliance requirements are non-negotiable. From sprint one we work within the frameworks of GDPR, NIS2, ISO 27001 and the specific professional rules of the legal and notarial professions. The supervisory authority will not catch us out with questions we cannot answer.

GDPR Art. 32 + 35

Security and DPIA

Privacy by design as the starting point. For every project we deliver a DPIA document. Data flows, retention and data subject rights are documented for your DPO. In a legal context, this also means explicit legal bases for special category personal data within case files.

NIS2 Directive

Incident reporting obligations and risk management

For essential and important entities (and their suppliers), we build the incident management flow in line with NIS2 timelines: early warning to the CSIRT, incident notification and final report. Integrated with your own escalation process, not separate from it.

ISO 27001 + 27017/27018

Information security management

We work to an ISO 27001-compliant development process, with traceable risk assessment, secure SDLC and a tested deployment flow. For cloud implementations, additional controls from 27017 and 27018 where relevant.

EU AI Act

Responsible use of AI in legal tech

For AI features such as automatic classification of incoming post, case law search and contract clause extraction, we map the risk classification and document the governance, the provenance of training data and the points of human intervention. For law firms, this is the difference between an impressive demo and something you can confidently use.

eIDAS Regulation

Qualified electronic signature (QES)

eIDAS-compliant signing for clients and lawyers, with an audit log per signature and a qualified timestamp. We integrate with DocuSign, Adobe Sign, ValidSign, KENA, Signhost and specific notarial providers where needed.

NOvA regulation + Wna

Professional secrecy as a system property

For law firms and notaries, we build professional secrecy into the architecture: BYOK encryption, administrators can see that a case file exists but not its contents, and audit logs are themselves bound to the case file. No third party, including us, can access the data.

NEN 7510

Intersections of healthcare and law

For legal tech applications at the intersection with healthcare (medical disciplinary matters, youth care law, personal injury claims), we work in line with NEN 7510: additional information security controls that the healthcare standard imposes on a legal case file.

Seamlessly connected with the ecosystem of security and legal.

We integrate with the tools your security team or firm already uses. No migration of your entire stack: our app complements it and replaces selectively where that is no longer fit for purpose.

Microsoft Sentinel
SIEM / SOAR
Splunk & Elastic
Log platforms
CrowdStrike
EDR / XDR
Tenable / Qualys
Vulnerability scanners
BaseNet / Cleverdesk
Law firm practice management
DocuSign / ValidSign
E-signature & eIDAS
Relativity / Nuix
E-discovery
KvK / CDR / CTR
Legal registers

No one-off integrations on a per-project basis.

The integrations above have been standardised across several security and legal projects. For a new commission we build the integration on the same abstraction layer: fewer bugs, faster delivery, and your IT team can manage it themselves once we step away. For the financial side of your legal practice we integrate with Exact, MoneyMonk, AFAS or e-Boekhouden through the same integration layer we use for contract management software.

For specific office software (in-house middleware, on-premise Java legacy systems, or niche tools such as FilelinX or Knight), we build on a case-by-case basis. This takes extra time in the planning phase, but prevents integration debt that you would otherwise notice years later.

Typical apps we build for these sectors.

Twelve types of apps we use as building blocks: six for security and six for legal tech. In practice, an engagement usually combines two or three of these types.

Security

SOC portals for MSSPs

A client environment where an end organisation tracks its alerts, escalations and SLA status, and an analyst environment where your team performs triage, follows runbooks and documents handovers. A single source of truth instead of a SIEM alongside a mailbox.

Security

Vulnerability management dashboards

Asset inventory, CVSS scoring, remediation tracking and ownership per asset. With automatic correlation between vulnerabilities and ongoing incidents, so a patch team knows which CVE runs on a priority-1 asset and which does not.

Security

CISO reporting and GRC dashboards

Board-level reporting for CISOs: control maturity per ISO domain, open audit findings, a risk acceptance log and NIS2 status. Designed for the quarterly meeting with the board, not for audit week.

Security

Incident response apps

A mobile and desktop app for the IR team: playbooks, evidence collection, chain of custody, a communication log to internal stakeholders and, where needed, the supervisory authority. NIS2 timelines built in, rather than sitting in a PDF somewhere.

Security

Security awareness and phishing simulation

Your own content and branding, with integration into your HR system for cohort segmentation and targeted campaigns per department. Reporting shows where the weak spots are without putting individual employees on the spot.

Security

Penetration test reporting platform

For penetration testing firms: from scope document through execution to readable findings. A client portal where the end organisation tracks the remediation status of each finding, with an automated re-test flow and certificate issuance.

Legal tech

Contract management (CLM)

End-to-end contract management for corporate legal teams and legal service providers: drafting from a clause library, negotiation with version tracking, e-signature, an archive with retention rules and obligation tracking. Builds on our contract management software approach.

Legal tech

Case management for law firms

Client files with statutory deadlines, decision points and time registration that flow directly into invoicing. For legal aid practices, including export for the Legal Aid Board (Raad voor Rechtsbijstand). Built on the same foundations as our case management system.

Legal tech

Legal research with LLMs

Case law search using language models, trained or fine-tuned on public rulings and your own firm's precedents. With source citations for each answer and a confidence score, so a lawyer can verify the outcome. Part of our broader AI development practice.

Legal tech

E-discovery and review platforms

For research and dispute practices: ingestion of large document corpora, deduplication, OCR, predictive coding (TAR), and privilege review with full chain of custody. EU data residency, with keys held under your control, because an investigation leaves no room for doubt about where the data went.

Legal tech

Compliance and regtech apps

GDPR DPIA tooling, AI Act conformity assessment, NIS2 self-assessment, AML onboarding for banks and notaries, sanctions list screening, UBO checks via the KvK. For compliance officers, DPO services and Big Four auditors who deliver this tooling as a service to their own clients.

Legal tech

Secure messaging and client portals

End-to-end encrypted communication between client and lawyer, or between a security team and its client. Case-linked message streams, signed acknowledgements of receipt, and no email attachments ending up on a personal tablet. Optionally with blockchain attestations for indisputable proof of existence.

From intake to go-live in clear steps.

A project for a security vendor or a law firm has a rhythm of its own. Five phases that are identical for every project: the scope within each phase differs, the rhythm does not.

01 · Audit

Workflow mapping

Days on site with your SOC team or with two lawyers. Outcome: current flows mapped, bottlenecks highlighted, compliance requirements inventoried.

02 · Design

Threat model and scope

For each discipline, which flow goes into the app, which integrations take priority, and which flows follow later. Includes an explicit threat model before we start building.

03 · Build

Sprints with security review

Each sprint delivers one working flow. Security review is part of the definition of done; no after-the-fact penetration test that reopens everything.

04 · Cutover

Phased rollout

First one team, then the next. At each rollout: training, documentation, and handover to your own IT or compliance team.

05 · Maintenance

Ongoing compliance

We adapt with every change in legislation and every CVE disclosure. Fixed monthly fee, security patches within an agreed SLA window, and transparent time records for additional work.

The context in which we work.

NCSC NIS2 guidance

"Essential and important entities must take appropriate technical, operational and organisational measures to manage the risks to the security of network and information systems, and must be able to demonstrate that they have done so."

NOvA regulation on the legal profession

"The lawyer must organise their practice in such a way that professional secrecy is safeguarded, including in the digital working environment and where third parties are engaged to manage data."

EU AI Act, Article 6 and Annex III

"AI systems intended to be used by a judicial authority, or on their behalf, to assist a judicial authority in researching and interpreting facts and the law are classified as high-risk AI systems."

Answers for CISOs, partners and heads of legal.

The questions we hear most often from security managers, lawyers and compliance officers.

Do you have experience with security vendors, or only with security departments at end-user organisations?
Both. We build platforms for MSSPs and cybersecurity vendors that deliver their service to end clients (multi-tenant SOC portals, GRC-as-a-service, penetration test reporting), and we build internal tools for security departments at end-user organisations (CISO dashboards, awareness platforms, incident response apps). The architectural approach is the same; the tenant layer differs.
How do you technically safeguard professional secrecy for law firms?
We build professional secrecy as a property of the system, not as a compliance layer on top. Encryption with keys you control (BYOK), administrators can see that a case exists but not its contents, audit logs are themselves case-bound, and backups are encrypted with the same keys. EU-hosted cloud or on-premises, depending on your policy and the NOvA requirements for your type of practice.
Can an app for lawyers or a SOC portal run on-premises?
Yes. For law firms with strict professional-secrecy requirements, for government oversight applications, and for security vendors serving enterprise clients with data sovereignty requirements, we run the entire stack in your own data centre or a Dutch single-tenant private cloud. Encryption keys remain with you in both scenarios.
How do you ensure NIS2 incident reports reach the CSIRT on time?
We build the reporting flow to the NIS2 timelines into the incident-response app: early warning within 24 hours, incident notification within 72 hours, and a final report within one month. The flow is a first-class part of the app, not a PDF alongside the system. Status, content and delivery confirmation are all captured in the audit trail.
Do you work with LLMs for case-law search? And how do you handle hallucinations?
Yes. We work with fine-tuned or retrieval-augmented language models built on public case law (rechtspraak.nl) plus your own precedents. Every answer comes with source citations and confidence scores, and without a citation there is no answer. That is a design decision, not a setting. For advice to clients we always build in a human-in-the-loop step. Under the AI Act this falls into the high-risk category, and we deliver the governance documentation with the solution.
Do you replace BaseNet, Cleverdesk, Splunk or Microsoft Sentinel?
Usually not. BaseNet, Cleverdesk and the major SIEM platforms do their job well. We fill the gaps where your way of working, your client-portal approach or your reporting requirements don't fit a standard package. For a new commission we start by asking whether replacing anything is genuinely better. Often it isn't, and we say so.
Do you work alongside our current IT supplier or in-house IT team?
More often than not, yes. We deliver the codebase, build instructions, infrastructure-as-code, architecture overview and runbook so that an external party can take over. This is a deliberate design choice to avoid vendor lock-in. Knowledge transfer is part of the final sprint. Some clients keep us on under a maintenance contract; others hand over management to their own team after go-live.
What about data residency and sub-processors?
For security and legal work we host in the EU (often in the Netherlands) by default, on infrastructure whose sub-processor list we know and can share. A data processing agreement, including a sub-processor annex, is a standard part of delivery. For clients where US CLOUD Act exposure is an issue, we choose infrastructure without a US parent company.
What determines the cost?
The biggest cost drivers are the number of app types you combine (one SOC portal versus a SOC portal plus vulnerability management plus a CISO dashboard), the depth of integrations, the weight of the compliance layer (NIS2 plus the AI Act plus NOvA is more work than any one of them), and the choice between cloud and on-premises. We work with fixed sprint budgets so you stay in control of spend sprint by sprint and can steer scope as you go.
What if we want to add a new standard or a new type of case file along the way?
That is why we build workflows and compliance controls as data, not code. An extra case-file type, a new control framework or a new NIS2 category can be configured by an administrator. For a new standard with its own risk classification, we run a short follow-on sprint in which we map the rules, build the integrations and supply templates.

Ready to give your security or legal-tech practice its own platform?

A half-hour introductory call. We listen to your cases, ask about your compliance and architecture requirements, and give you direction you can use, including if the outcome is that your existing SIEM, GRC suite or industry package is a better fit than custom development. For the wider context, see our app development overview page.

Fabian van DijkBusiness developer · Appfront · fabian.vandijk@appfront.nl
Share LinkedIn Email

Edit content