Do you work with classified or state-secret data?
No. Appfront does not hold ABDO clearance, and we do not process state-secret (Stg.) data or NATO-classified information. We build platforms that stay outside the classified perimeter: unclassified workflows, supply chain, screening procedures, construction projects and facility management. For classified work we refer clients to a specialised defence systems house with the appropriate clearance, and we prefer a chain model in which we deliver the unclassified platform and another party provides the classified component.
What do you mean by "defence construction software"?
Software for construction firms carrying out infrastructure projects at MoD sites: barracks, hangars, training grounds, naval yards. Think tender tracking for defence procurement, project management that accounts for security requirements on site, material traceability for military specifications, ATEX and explosion-safety compliance, and integrations with your existing construction software stack. We often build the specialist layer on top of your general construction software rather than replacing it entirely.
How do you approach personnel screening platforms?
We build the workflow around the screening process, not the screening itself. Specifically: application forms for VOG certificates, intake flows for Wvo procedures, status tracking, document upload, deadline monitoring, an audit trail, and integration with your HRIS. We do not receive classified screening outcomes, which remain with Justis, the AIVD or the MIVD, but we make the surrounding procedural work manageable from start to finish. For screening bureaus offering this as a service, we also build tenant platforms so that end clients can follow their own cases.
Do you comply with BIO and ISO 27001?
We develop to ISO 27001-compliant standards and build platforms that map onto the controls of the Dutch Baseline Information Security for Government (BIO). On handover, your security officer receives a mapping document showing, for each BIO control, how the platform meets it, along with a penetration test report from an independent party. We are not yet ISO 27001-certified as an organisation ourselves, but we work to those standards, and clients have successfully passed their own audits with these deliverables.
And what about NEN 7510? Isn't that for healthcare?
That's right, NEN 7510 is primarily a healthcare standard. In a defence context it becomes relevant when you provide medical services to personnel at military sites, or carry out maintenance on medical equipment in a defence environment. We have experience building to NEN 7510 through our healthcare projects and can bring those controls into your defence work where they apply.
What types of organisation do you typically build for?
Defence suppliers across the board: construction firms with MoD contracts, maritime players (shipbuilding, maintenance, naval suppliers), aerospace subcontractors, logistics partners (just-in-time delivery to barracks), facilities management for defence property, personnel screening agencies, cyber security suppliers in a defence context, and R&D organisations working on unclassified research. What all of these have in common: they supply to or work for the armed forces, but are not themselves embedded in the classified environment.
Will you replace our existing SAP or Oracle ERP?
Rarely. A standardised cloud ERP such as SAP or Oracle is the right foundation for finance, procurement and HR at large defence suppliers, and we don't touch that. What we do is build specialist modules alongside that ERP, or replace specific workflows where the standard package demonstrably doesn't fit. Think tender tracker, an audit layer for MoD-specific compliance, or a planning module for military deliveries. We integrate with your ERP via API rather than doing a rip-and-replace.
Roughly what does a defence supplier platform cost?
That depends heavily on scope: a screening workflow platform is a fundamentally different project from a multi-site supply chain platform with ERP integrations. In the first conversation we map out the scope and give a transparent direction per phase, including what is fixed-scope work and what is ongoing development. We preferably work with fixed sprint budgets and phased delivery, so you have a usable build after every sprint and can steer along the way.
How long before we can go live?
A first working version of a well-defined workflow, for example a VOG application flow with basic roles and an audit log, can be up and running within a few sprints. For a full-scale defence supplier platform with ERP integrations, BIO compliance and multi-site support, we're looking at a programme of several sprints. We phase deliberately: the core goes live first, then the heavier components are added iteratively, so you realise value sooner and spread the risk.
Do you work together with our existing IT and security department?
Always. We carry out knowledge transfer in the final sprint, deliver an incident runbook, and agree clear responsibilities for management after handover. For security-relevant decisions we work directly with your CISO or security officer, who is involved from the first conversation rather than only at handover.