Service · Web development

Custom software that fits the way you work.

Custom software development for organisations that have outgrown off-the-shelf packages. We build web applications, mobile apps, backend platforms and integration layers — vendor-independent, with code ownership for you and a senior team based in Amsterdam.

Vendor-independentCode ownershipSenior teamEU data residency

Software is not a product, but the way your organisation works.

Companies rarely commission software out of preference. More often it is out of necessity: an off-the-shelf package that has reached its limits, a process that cannot be squeezed into a SaaS template, or a commercial opportunity that depends on a digital product that does not yet exist. Choosing bespoke development is then a rational decision, not an ambitious one.

We build software for mid-market businesses, scale-ups and specialist organisations in sectors where standard packages fall short: healthcare, finance, logistics, manufacturing and the public sector. Our position is deliberately mid-market: more pragmatic than a Big Four consultancy, more senior than a freelance collective, and without the lock-in of a low-code platform. You keep the code, and we make sure it works, and keeps working.

The definition of "commissioning software" stretches far on this page. It might be an internal web application for your operations team, a client portal that forms part of your service, a mobile app for your field staff, or a platform on which your entire proposition runs. It could be a new product that lives alongside existing systems, or a migration in which you gradually replace a legacy system. What all these projects share is that they do not fit into a standard template, and you want to stay in control of what gets built.

On this page you can read which kinds of software we build, with which tech stack, what our process looks like, and what sets us apart from the alternatives. For a conversation about your specific situation, you can get in touch directly; for a broader overview of what we do, our services page is a good starting point, and for enterprise-scale projects we refer you to our page on enterprise software development.

What falls under commissioned software.

Three main directions in which most projects take place. A project often combines elements from several — a web application with a mobile companion, or a platform with a separate integration layer.

Web & mobile applications

Applications that work the way your people work

Custom web applications and mobile apps for processes that can't be forced into an off-the-shelf package. From customer portals and vendor portals to field service apps, scheduling software and internal operations tools. We build them as single-page web apps, native mobile, or a combination of both with a shared backend.

React / Vue / AstroReact Native / FlutterNative iOS / AndroidPWA
Backend platforms & APIs

The system everything runs on

The backend layer where your data, business logic and integrations live. Multi-tenant SaaS platforms, enterprise software serving multiple applications, customer portals, and the API layer that connects front-ends and external systems to the same source. Architecture that scales with your organisation: modular, observable, and free of vendor lock-in.

Node.js / Spring BootPython / Django / FastAPILaravel / .NET / GoPostgreSQL / MongoDB
Integration, data & AI

The layers that hold your IT landscape together

An integration layer connecting to ERP, CRM, accounting software and industry-specific systems. Data platforms for analysis, reporting or regulatory returns. AI integration where it adds real business value, not as a gimmick but as part of a workflow. And migrations: legacy systems you retire step by step without bringing your operations to a standstill. We often combine these layers with our software development projects into one coherent whole.

REST & GraphQLEvent-drivenAnthropic / OpenAILegacy migration

What you receive at the end of a project.

No black box that only Appfront can see into, and no loose code without context. You get a working product plus everything you need to understand it, manage it and, should that ever be needed, have another party continue its development.

Code ownership is not a marketing line for us, it is contractual. You own what we build for you, receive the repository under your own control, and we do not impose a compulsory maintenance contract that puts you in a corner.

  • Production-ready softwareA working application with production and staging environments. Runs in your cloud (AWS, Azure, GCP) or hosted with us: your choice, no lock-in.
  • Complete codebase + documentationSource code in your own Git repository, with architecture overview, build instructions and API documentation. No keys held by Appfront.
  • Test suite + CI/CD pipelineAutomated tests covering the key flows and a deployment pipeline so your IT team can release without us.
  • Admin & end-user guidesPractical runbooks for your administrators and short tutorials for end users, written for people rather than for compliance tick-boxes.
  • Security & compliance auditA penetration test in the final sprint, a DPIA where GDPR requires one, and compliance documentation for NEN 7510, ISO 27001 or DORA/NIS2 where relevant.
  • Maintenance & further development (optional)Monitoring, security patches and functional extensions under a transparent monthly fee, or you take it over with your own team.

Who we work for.

We build for organisations that need bespoke software because the market's standard offerings don't cover their problem. Four patterns we encounter often.

Mid-market businesses

Outgrown standard SaaS

Your organisation is hitting the limits of an off-the-shelf package: workflows that don't fit, integrations that don't exist, user numbers that make the pricing unsustainable. A platform of your own is often cheaper and more flexible in the long run. We help you weigh up whether custom development is genuinely the right route in your situation.

Scale-ups

A product that forms part of the proposition

You aren't a software company by origin, but your customers expect a digital experience that either does or doesn't set you apart from the competition. You prefer to build that yourself rather than depend on a third-party SaaS. We think along at product level, not just execution level.

Enterprise

Custom development of specific components

You have a large IT landscape with serious packages such as SAP or Salesforce, but one or two processes need something that doesn't fit. We build that custom layer, often around an existing package rather than replacing it. Alignment with your architecture board and security requirements is standard.

Agencies & cooperatives

White-label or industry-specific development

For agencies that want to deliver their own tool under their brand, or for industry bodies building a shared platform for their members. We deliver under your name, and you keep the client relationship. NDA and non-compete agreed upfront, with no reference to our portfolio without your explicit permission.

Specialist & regulated

Healthcare, finance, public sector, critical infrastructure

Sectors with sector-specific legislation: NEN 7510 in healthcare, DORA and NIS2 in finance, NIS2 for critical infrastructure, and eGovernment standards in the public sector. We build these requirements in from the design stage rather than bolting them on afterwards.

Migration projects

Legacy systems you're phasing out

An outdated system that has been accumulating technical debt for years and that nobody dares to replace. We carry out strangler-fig migrations: a new platform grows alongside the old one, takes over functionality step by step, and the legacy system is eventually switched off. No big bang, no weekend of panic.

The tech stack we master every day.

We are not loyal to a single framework. The stack is chosen based on your situation: the IT landscape you already have, the people who will need to maintain it, and the demands the software itself places on it. Below are the languages, frameworks and platforms in which our team has senior expertise.

Backend & API

Robust server-side foundations

For the backend we work with Node.js (TypeScript) as our all-round workhorse, Spring Boot for Java-oriented organisations, .NET for Microsoft shops, Python (Django, FastAPI) where AI or data processing is central, Go for performance-critical services, and Laravel where PHP expertise is already in place. APIs are REST or GraphQL, event-driven where that fits. The choice is not made on technology preference but on your situation: which languages your team knows, which ecosystem fits your existing integrations, and which skills are available on the Dutch labour market for future maintenance.

Node.js / TypeScriptSpring Boot.NETPython / Django / FastAPIGoLaravel
Frontend & mobile

Interfaces that keep users engaged

React and Vue are our most-used frontend frameworks, with Astro for content-heavy sites and Svelte where bundle size is critical. For mobile apps we work with React Native or Flutter when cross-platform is the right trade-off, and native (Swift for iOS, Kotlin for Android) when platform-specific performance or integrations demand it. Our app developers work in this space every day.

ReactVueAstroReact NativeFlutterSwift / Kotlin
Data, cloud & DevOps

A platform you can manage

Databases: PostgreSQL is our default, MySQL where it fits, MongoDB for document-heavy models, Redis for caching and queuing, ClickHouse for analytics. Cloud: AWS, Azure or GCP, or Hetzner and private cloud where EU data sovereignty is a requirement. DevOps: Docker, Kubernetes where scale demands it, Terraform for infrastructure as code, GitHub Actions for CI/CD. AI integrations via Anthropic, OpenAI or open-source models (Llama, Mistral), depending on privacy requirements and use case. We have no reseller interest in any particular cloud or model provider, so our advice is based on what fits, not on margins.

PostgreSQL / MongoDBAWS / Azure / GCPDocker / KubernetesTerraformAnthropic / OpenAI

How we compare to alternatives.

Commissioning bespoke software is not the only route. You are choosing between four or five categories of supplier, each with a different profile. Here is how we position ourselves relative to each.

vs standard SaaS

Salesforce, HubSpot, ServiceNow

We do not replace commodity software. What standardised SaaS does well, such as CRM, marketing automation and helpdesk, we do not rebuild. But the bespoke layer around it, the integrations and the specific workflows that don't fit the off-the-shelf package: that is where our value lies.

vs low-code

OutSystems, Mendix, Power Apps

Low-code is excellent for relatively simple internal tools. We build pro-code where low-code becomes too limiting, such as when you have complex business logic, unusual integrations, or demanding scale or performance requirements. No platform lock-in, and no seat licences that grow with your success.

vs offshore

India, Eastern Europe, Vietnam

Offshore rates are attractive, but the real costs lie in coordination, time zones, language barriers and the absence of EU jurisdiction. We work in the same time zone, speak Dutch with your stakeholders, and fall under the same GDPR and liability framework as you do.

vs Big Four / freelance

Consultancy or contracting

The Big Four deliver process and methodology at enterprise rates; we are more pragmatic and suit mid-market budgets. Freelance teams are flexible but fragile: if one senior person leaves, your knowledge walks out the door. We provide team continuity at senior level.

How an engagement with us works.

We work in seven phases, from first contact through to ongoing management. The phases are not strictly sequential waterfall steps — build and test run in parallel — but this is the order in which an engagement unfolds. You can find a fuller explanation on our process page.

1

Introduction

A no-obligation conversation in which we understand what you want to build, why, and what your situation is. No pitch, no sales funnel: we see whether there is a fit and whether we can add value.

2

Discovery & scoping

Two to four workshops with your team and relevant stakeholders. We map out flows, integrations and risks, prioritise using MoSCoW (must / should / could / won't), and conclude with a concrete scope, a phasing plan and a substantiated estimate.

3

Design: UX and architecture

A parallel track: a UX designer works on the screen flows and interaction, while a tech lead works on the architecture and data models. By the end of this phase the key screens are a clickable prototype and the technical blueprint is fixed.

4

Building in sprints

Two-week sprints, with a working build at the end of each sprint. You test along the way, and end users are involved early. We work iteratively on the actual current priorities, not on a list drawn up a year ago.

5

Testing & pilot

A pilot phase with a limited group of real users, running in parallel with the final build sprints. We measure where people get stuck, fix what needs fixing, and carry out a security penetration test before go-live.

6

Rollout & go-live

A phased rollout (first one team, then one department, then organisation-wide), with monitoring from day one. Training sessions for key users and a runbook for your IT operations team.

7

Maintenance & further development

After go-live: monitoring, security patches and functional extensions. Available on an ongoing contract with us, or you can take it over with your own team, with the handover arranged in advance.

Compliance & security: taken seriously, not a sticker job.

For the sectors we work in (healthcare, finance, the public sector, critical infrastructure), compliance is not a formality. We build the legal and sector-specific requirements into the design from the start, rather than applying them as a final sticker.

For enterprise engagements, we contractually secure audit rights: you can (have) our code, our processes and our infrastructure audited. EU data residency is the default, so your data does not leave the EU unless you choose otherwise.

We shape compliance for each project together with you and your data protection officer, legal adviser or sector regulator. We do not present a standard checklist that is identical for every client, as that would mean not taking the regulations seriously. For healthcare, finance and the public sector, we know the specific points of attention; for less regulated sectors, we limit ourselves to what is genuinely needed rather than what sounds good in marketing material.

  • GDPR / AVGDPIA where necessary, data minimisation, data processing agreement, right to erasure technically implemented.
  • NEN 7510 (healthcare)For healthcare organisations, we build information security controls in from the design stage, with audit trails on patient data.
  • ISO 27001 & SOC 2For enterprise clients with their own ISO/SOC process, we deliver the software chain in compliance, including evidence for your auditor.
  • DORA & NIS2For financial institutions and critical infrastructure organisations: incident reporting, ICT risk management and third-party risk from the design stage.
  • EU AI ActFor AI components: risk classification, transparency requirements, logging and built-in human oversight.
  • EU data residencyData and backups in EU regions, under EU jurisdiction. No American subprocessors without an explicit assessment.

Frequently asked questions.

What clients ask before we start an engagement.

What exactly does custom software development cover?
Quite a broad range: custom web applications, mobile apps, backend platforms, customer and vendor portals, multi-tenant SaaS, integration layers between existing systems, data platforms, AI integrations, and migration of legacy software to modern stacks. Often a combination of several, for example a web app with a mobile companion and an API layer towards your existing systems.
Do you replace off-the-shelf SaaS such as Salesforce or HubSpot?
Not for commodity functionality. We don't rebuild a good CRM or marketing automation platform from scratch, as that would waste your money. We do build the custom layer around it: workflows that don't fit the standard product, integrations with your sector-specific systems, and tailored user interfaces for your roles.
How does this differ from low-code platforms such as OutSystems or Mendix?
Low-code is fast and suited to relatively simple internal tools. Pro-code (what we do) is suited to more complex logic, unusual integrations, external users, and anything where performance, scalability or platform freedom matters. Moreover, with low-code you are tied to the platform and its licence costs. With us, you own the code and there are no per-seat licences.
What determines the cost of a custom project?
The main factors are scope (how much functionality), complexity of integrations (one external system or five), compliance requirements (healthcare or finance differ from an internal tool), and the intended scale (internal for 50 users or public for 50,000). In the introductory and discovery phase, we bring these factors together into a reasoned estimate with phasing, rather than an open-ended budget.
How long does such an engagement usually take?
That depends largely on scope. A first working version often arrives after a few sprints; a production-ready platform with integrations and compliance requirements takes several sprints. We work iteratively by design: you receive a working build after every sprint, so there is always something to show, test and decide on priorities for.
How is the team put together?
A typical engagement includes a product owner / business analyst, a tech lead, one or more engineers (depending on scope), a UX designer where relevant, and a QA role. All are senior or mid-level; we don't have juniors learning to code on your project. The team stays together for the duration. We provide team continuity, not staff augmentation.
What does vendor independence mean in practice?
We are not a reseller or partner of Mendix, OutSystems, SAP or any other specific platform, which means our advice isn't driven by licence discounts or partner quotas. We choose the stack based on your situation, not on what suits us commercially. The same applies to cloud providers: AWS, Azure, GCP or an EU provider, whichever fits best.
What if we ever want to work with another party?
That should be straightforward. You have code ownership from the outset, the repository is under your control, and we provide documentation and runbooks so another party can take over. We have no commercial interest in locking you in. If the match stops working, we arrange a clean handover.
Do you only build software, or do you also provide maintenance?
Both, and the choice is yours. Many clients take out a maintenance agreement after go-live covering monitoring, security patches and functional development. Others manage the software themselves with their own team and call us only for larger extensions. We don't make a maintenance contract a condition of the build.
Do you also work with our internal IT or development department?
Almost always. We handle knowledge transfer throughout the engagement, not just at the end, so your team builds alongside us, reviews the work and can ultimately maintain it themselves. For enterprise clients this often means a joint team; for SMEs, a lighter approach with handover sessions and pair programming on critical parts.

Talk to us about your software challenge.

A no-obligation conversation of half an hour. We listen to what you want to build, ask questions where it helps sharpen the picture, and give our view on the way forward. No quote pressure, no sales funnel.

Would you like to look at this challenge from the custom software angle? applatenmaken.com has an overview of custom software development.

Want to start a project?

We'd love to hear from you.

Got a lot to say, or did you send it another way by email? Choose Detailed brief: headings and bullet points, images in the text and files attached.

Mies

Get in touch with Mies

Business Developer

Get in touch with Martijn

Founder of Appfront

Martijn

Your message has been sent

Thank you for your interest! We'll get back to you as soon as possible, usually within 1 working day.

Edit content