Service · Software development

Custom defence software development.

Custom software for defence suppliers, defence construction firms and logistics partners of the armed forces. We build non-classified platforms for construction projects on MoD sites, personnel screening workflows, supply chain and facility management, ISO 27001-compliant and in line with the Dutch Baseline Information Security for Government (BIO).

Defence construction softwarePersonnel screeningBIO-compliantISO 27001

We work for the suppliers, not for the armed forces themselves.

Let us be honest about this: Appfront does not hold clearance to work with state secret data or classified information. We are not part of the defence industrial base in the strict sense. What we do, and where we have built experience since 2015, is build software for the companies operating around the defence sector: construction firms with MoD contracts, maritime suppliers, aerospace subcontractors, logistics service providers, screening agencies and cyber security partners.

For these organisations we build platforms that are mission-critical to their business but sit outside the classified perimeter. Tender tracking for defence procurement. Material traceability for military requirements. Personnel screening flows around Wvo procedures and VOG applications. Supply chain and CMMS platforms for barracks, hangars and training grounds. We are clear about where our scope ends, which makes us faster and cheaper than a specialised defence systems house for the work we can take on.

The Dutch defence supply chain is broad. At the top sits a handful of large tier-1 suppliers contracting directly with the Defence Materiel Organisation or NATO, such as Damen, Royal IHC, Fokker Technologies, KLM Engineering, TNO and Marin. Beneath them is a much larger layer of construction firms, logistics providers, facility partners, screening agencies, cyber security suppliers and R&D organisations that take part on a project or framework contract basis. It is this middle layer that has software challenges which are too small for a Big Four or Capgemini engagement, yet too specialised to solve with a standard SaaS package. That is our sweet spot.

One important distinction we make upfront: we do not trade in ITAR- or EAR-controlled US defence technology, and we do not offer NATO STANAG expertise as a core speciality. Where requirements of that kind play a prominent role, we seek collaboration with a party that specialises in them.

Three types of platform we build for defence suppliers.

This depends on where you sit in the defence supply chain and which compliance requirements apply to you. In the first conversation we advise which route fits and which work we would be better off referring to a specialised defence agency.

Defence construction projects · fixed sprint budget

Construction software for defence projects

Tender tracking for defence procurement, project management for MoD construction, material traceability for military requirements, and ATEX/explosion safety compliance at sites where it applies. For construction firms delivering infrastructure at barracks, hangars and training grounds. We connect to your existing construction software stack or replace it selectively where it no longer fits.

In practice this means platforms that carry several processes at once: the procurement process with version history and deadlines, planning and subcontractor coordination on the construction site itself, logistics supply under defence-specific documentation requirements, and handover documentation, which for MoD projects is far heavier than for a commercial client. Audit trails are in place from day one, not as an afterthought but as an architectural choice.

Tender trackingMaterial traceabilityATEX complianceProject management
Screening & personnel management · fixed sprint budget

Personnel screening and compliance flows

Workflow platforms around VOG applications, screening for defence clearance procedures, and Wet veiligheidsonderzoeken (Wvo) procedures. We do not process the classified screening outcomes ourselves, since that is where the AIVD/MIVD boundary lies, but we do build the workflow platform around them: application flow, status tracking, document management, audit trail and intake forms for your HR or screening team.

For screening agencies that deliver this as a service to end clients, we also build multi-tenant variants, in which each client can view its ongoing procedures in its own environment. For defence suppliers that screen in-house, such as a construction firm guiding dozens of engineers a year through a Wvo procedure, we often integrate the platform with your existing HRIS, so that an employee's status is visible alongside the rest of their personnel data.

VOG flowWvo trackingAudit trailDocument management
Logistics & facility management · fixed sprint budget

Supply chain and facility platforms

Just-in-time logistics for deliveries to military barracks, multi-site distribution, and CMMS maintenance systems for military facilities and non-classified equipment. For parties such as Vebego and Sodexo that provide military base services, for maritime maintenance partners, and for facility management on defence property. BIO-compliant, ISO 27001-compatible, with the appropriate audit layer.

Specifically on the logistics side, the difference from a commercial package is that deliveries to military sites come with different documentation, different access rules and different delivery windows than a regular distribution centre flow. We build those rules into the data model, not as a workaround layered on top of a standard system. On the facility and maintenance side, our experience lies mainly with equipment, building installations and periodic inspections within the non-classified scope.

Multi-siteCMMSSLA monitoringBIO-compliant

What you get at the end.

A production-ready platform that fits your defence supplier workflow, with everything around it so you can manage it yourself and demonstrably keep it compliant.

For mission-critical setups we work with a high-availability architecture and build in redundancy at the database and application layers.

  • The defence supplier platform itselfProduction and staging environments, running in your own cloud (GCP/AWS/Azure tenant) or in a Dutch hosting environment that meets BIO requirements for data residency.
  • Codebase plus architecture documentationFull source code, build instructions, infrastructure as code and an architecture overview that explicitly sets out where the data classification boundaries lie.
  • ISO 27001-compliant development processWe work according to ISO 27001-compliant development practices with a traceable risk assessment, secure SDLC and a tested deployment flow.
  • BIO compliance and audit packageDocumentation that allows your security officer to demonstrate that the platform meets the Baseline Information Security Government (BIO) for public-sector suppliers, including a penetration test report and log management.
  • Admin guide for your IT teamWritten for your administrators: how to add roles, how to export data for tender audits, and how to use the audit log for compliance reporting.
  • Management contract (optional)Monitoring, backups, security patches and ongoing minor development. Four response-time levels, a fixed monthly fee and transparent hourly records for additional work.

When custom defence software is the right choice.

Four patterns in which we guide suppliers and defence builders. If you recognise one of them, an introductory conversation is worth your time.

Construction projects

SAP or Oracle does not fit defence requirements

You work with a standardised cloud ERP, but your MoD tender requires material traceability, lot tracking and audit flows that simply are not included. We build specialist modules alongside your ERP: not a replacement, but the missing piece.

Screening

VOG and Wvo processes run on email

You manage dozens of screening processes each month for personnel who will work at defence sites. Status, documents and deadlines are scattered across inboxes. A workflow platform with an audit trail makes this manageable and demonstrably compliant.

Compliance

BIO or NEN 7510 in the tender

Your client requires demonstrable compliance with the Baseline Informatiebeveiliging Overheid (BIO, the Dutch government information security baseline) or NEN 7510 as a condition of the contract. Standard SaaS packages do not provide that documentation, whereas custom software does, because we deliberately build in and document the controls.

Logistics

Multi-site delivery to barracks

You deliver just-in-time to several military facilities with different access rules, delivery windows and documentation requirements. Generic logistics software does not scale without friction; a platform tailored to your flow does.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

How a defence supplier project runs.

1

Scope and classification discussion

A conversation in which we establish exactly which data flows through the platform, which classification levels apply, and where the line falls between what we build and what a specialised defence firm needs to handle. Being honest about this upfront prevents problems later.

2

Architecture, BIO mapping and planning

A workshop with your team, plus interviews with users from the core process. We produce an architecture sketch, map requirements against BIO and ISO 27001 controls, and deliver a concrete scope along with an initial screen flow.

3

Sprint-based build with security by design

A working build at the end of every sprint. We build with secure defaults: encryption in transit and at rest, role-based access, and audit logging from day one. Your team tests along the way, and in later sprints an external penetration tester reviews the deliverable.

4

Rollout, training and tender documentation

A phased rollout to the user organisation, training sessions for key users, and handover of the full documentation package your security officer needs to demonstrate the solution in a tender.

Frequently asked questions.

What defence suppliers and construction firms usually want to know before we start.

Do you work with classified or state-secret data?
No. Appfront does not hold ABDO clearance, and we do not process state-secret (Stg.) data or NATO-classified information. We build platforms that stay outside the classified perimeter: unclassified workflows, supply chain, screening procedures, construction projects and facility management. For classified work we refer clients to a specialised defence systems house with the appropriate clearance, and we prefer a chain model in which we deliver the unclassified platform and another party provides the classified component.
What do you mean by "defence construction software"?
Software for construction firms carrying out infrastructure projects at MoD sites: barracks, hangars, training grounds, naval yards. Think tender tracking for defence procurement, project management that accounts for security requirements on site, material traceability for military specifications, ATEX and explosion-safety compliance, and integrations with your existing construction software stack. We often build the specialist layer on top of your general construction software rather than replacing it entirely.
How do you approach personnel screening platforms?
We build the workflow around the screening process, not the screening itself. Specifically: application forms for VOG certificates, intake flows for Wvo procedures, status tracking, document upload, deadline monitoring, an audit trail, and integration with your HRIS. We do not receive classified screening outcomes, which remain with Justis, the AIVD or the MIVD, but we make the surrounding procedural work manageable from start to finish. For screening bureaus offering this as a service, we also build tenant platforms so that end clients can follow their own cases.
Do you comply with BIO and ISO 27001?
We develop to ISO 27001-compliant standards and build platforms that map onto the controls of the Dutch Baseline Information Security for Government (BIO). On handover, your security officer receives a mapping document showing, for each BIO control, how the platform meets it, along with a penetration test report from an independent party. We are not yet ISO 27001-certified as an organisation ourselves, but we work to those standards, and clients have successfully passed their own audits with these deliverables.
And what about NEN 7510? Isn't that for healthcare?
That's right, NEN 7510 is primarily a healthcare standard. In a defence context it becomes relevant when you provide medical services to personnel at military sites, or carry out maintenance on medical equipment in a defence environment. We have experience building to NEN 7510 through our healthcare projects and can bring those controls into your defence work where they apply.
What types of organisation do you typically build for?
Defence suppliers across the board: construction firms with MoD contracts, maritime players (shipbuilding, maintenance, naval suppliers), aerospace subcontractors, logistics partners (just-in-time delivery to barracks), facilities management for defence property, personnel screening agencies, cyber security suppliers in a defence context, and R&D organisations working on unclassified research. What all of these have in common: they supply to or work for the armed forces, but are not themselves embedded in the classified environment.
Will you replace our existing SAP or Oracle ERP?
Rarely. A standardised cloud ERP such as SAP or Oracle is the right foundation for finance, procurement and HR at large defence suppliers, and we don't touch that. What we do is build specialist modules alongside that ERP, or replace specific workflows where the standard package demonstrably doesn't fit. Think tender tracker, an audit layer for MoD-specific compliance, or a planning module for military deliveries. We integrate with your ERP via API rather than doing a rip-and-replace.
Roughly what does a defence supplier platform cost?
That depends heavily on scope: a screening workflow platform is a fundamentally different project from a multi-site supply chain platform with ERP integrations. In the first conversation we map out the scope and give a transparent direction per phase, including what is fixed-scope work and what is ongoing development. We preferably work with fixed sprint budgets and phased delivery, so you have a usable build after every sprint and can steer along the way.
How long before we can go live?
A first working version of a well-defined workflow, for example a VOG application flow with basic roles and an audit log, can be up and running within a few sprints. For a full-scale defence supplier platform with ERP integrations, BIO compliance and multi-site support, we're looking at a programme of several sprints. We phase deliberately: the core goes live first, then the heavier components are added iteratively, so you realise value sooner and spread the risk.
Do you work together with our existing IT and security department?
Always. We carry out knowledge transfer in the final sprint, deliver an incident runbook, and agree clear responsibilities for management after handover. For security-relevant decisions we work directly with your CISO or security officer, who is involved from the first conversation rather than only at handover.

Talk to us about your defence software.

A thirty-minute introductory call, no obligation. We listen to your tender or work process, ask questions about classification boundaries and BIO requirements, and give direction on what we can and cannot take on for you. For a deeper view of our approach, you can also look at our pages on maritime software, CMMS maintenance management and enterprise software development.

Edit content