Custom software development in Australia.
Black Shard designs and builds web applications, mobile applications and internal operating systems for organisations across Australia, from its Brisbane head office.
Black Shard designs and builds web applications, mobile applications and internal operating systems for organisations across Australia. Our existing work includes clinical software, legal and compliance platforms, financial-services systems and workflow automation.
Projects can run as a defined build or as an ongoing engineering engagement where the product continues to evolve after launch. Delivery is national, from the Brisbane head office.
What a full build includes
A full build starts before the code. For Bold Property Group, Black Shard designed the brand identity, shipped the editorial marketing site, built the agent network that sourced off-market property, and stood up the client portal that tracked each active acquisition. For Restart Recruitment we built the brand, the site, the candidate intake and scorecard screening flows, and the outreach engine the recruitment team runs on.
Aurii covers the full range. It is clinical voice software for Australian private-hospital specialists, and Black Shard built and operates the entire stack: the native iOS and Android apps, the web app, the marketing site, the speech and OCR pipelines, the multi-tenant data layer, the migrations, and the observability underneath.
- Brand identity and design system where the build needs one
- Web apps, native iOS and Android, client portals, and internal operations platforms
- Speech, document and workflow automation
- Delivery pipelines with secrets kept out of code
- Ongoing engineering after launch where the engagement calls for it
The industries we build for
Legal: GRM LAW, a Brisbane law firm, clears matters through a Black Shard-built intake and conflicts workflow, with role-based access enforced server-side and a hardened content-security policy in the browser. Health: Aurii, clinical software Black Shard built and operates, drafts the clinical note, the letters, and the billing from a spoken consult, inside the framework the practice already uses.
Capital markets: Stone Leaf Capital engaged us to build its brand, its public site, and the staff portal that runs the firm's operations, compliance, and policy framework, with a data model designed around its AFSL perimeter and a fund ledger kept current by the Xero integration services we run on the Accounting API. Property: Bold Property Group ran on the deal-flow systems we built. Recruitment: Restart Recruitment runs on our intake, screening, and outreach stack. The public case studies are on our work page.
How security is handled during a build
The engineers who design the system threat-model it before a line is written, keep the architecture least-privilege, keep secrets out of code, and hold security review gates through delivery.
The firm's cybersecurity practice then tests the finished system against the OWASP and ASD methodologies. Findings are manually verified before they are reported, and each comes back with reproduction steps and a fix.
How we engineer multi-tenancy and audit trails
Regulated software has to answer two questions: whose data is this, and who did what to it. We build multi-tenant data layers with row-level security, so tenancy is enforced in the database as well as the application layer. Aurii isolates tenant health data with PostgreSQL row-level security, on Azure in Australia.
Audit trails are built the same way. GRM LAW's portal writes to an append-only audit ledger, machine-enforced on every state change. Stone Leaf Capital's portal keeps a compliance log that records who changed what, and what it said before, structured around the firm's retention obligations. Aurii carries tamper-evident audit trails and rate limiting throughout. Restart Recruitment's security model is held in place by invariant tests, so authentication behaviour cannot change unnoticed.
Where does the data live?
On Microsoft Azure, in Australian regions. Aurii runs in Australia East: the app server on Container Apps, tenant data in PostgreSQL, speech recognition through Azure AI Speech, secrets in Key Vault, and deploys from GitHub Actions under Workload Identity Federation. Azure's infrastructure is independently IRAP-assessed to PROTECTED and holds ISO 27001 and SOC 2 at the platform level. Those are the platform's assessments, separate from what Black Shard holds.
We build to the Australian Privacy Principles under the Privacy Act 1988, and Aurii's clinical and privacy frame was designed for Australian obligations from the start.
How an engagement runs
An engagement runs as one of two shapes: a defined build with a brief, a delivery date, and a deliverable set agreed before work starts, or an ongoing engineering engagement, where a standing team designs, ships, and operates as the product continues to evolve after launch. Where the brief also carries a compliance target or needs a standing security seat, those run as services in their own right alongside the build: readiness programs toward Essential Eight, SMB1001, ISO 27001, or Privacy Act uplift, and standing advisory or vCISO.
GRM LAW's portal and Stone Leaf Capital's portal both take shipped changes under ongoing engagements. A defined build names the target, timeframe, and deliverable up front.
Questions, answered
- What does a custom build cost?
- There is no published price list; every engagement is scoped to the brief. The drivers are which platforms are in scope, how much integration surface the system carries, whether tenancy is single or multi, and which obligations the data brings with it. Name those in your brief and the reply comes back with the questions needed to scope it.
- Where does the work happen?
- Australia-wide, from the Brisbane head office. The systems we build and run serve national markets: a Brisbane law firm, private-hospital specialists across Australia, a capital-markets firm. Delivery, access, and reporting run the same way in every state.
- Do you keep operating the software after launch?
- Yes, where the engagement calls for it. Aurii continues to ship after launch, and the GRM LAW and Stone Leaf Capital portals both take shipped changes under ongoing engagements. A defined build with a delivery date is scoped that way from the start.
- What technology stack do you build on?
- Microsoft Azure in Australian regions, Container Apps, PostgreSQL with row-level security for multi-tenant data, Key Vault for secrets, and delivery pipelines with workload identity so credentials stay out of code. Native iOS and Android where the product needs it. It is the stack Aurii runs on in production.
- How is security handled during the build?
- Threat modelling in the first design session, least-privilege architecture, disciplined secrets handling, and security review gates through delivery. The finished system is then tested against the OWASP and ASD methodologies by the firm's cybersecurity practice, and findings are manually verified before they are reported.
- Can the build include compliance readiness?
- Yes. We run milestone-driven programs toward Essential Eight, SMB1001, ISO 27001, and Privacy Act readiness, and build the evidence trail an assessor expects as controls land.
- How do I start?
- Email info@blackshard.com.au or open a brief through the contact page. A rough brief is enough to open the scoping conversation.
Related reading
The full practice: Software engineering.
Tell us what you need built.
Brisbane head office. Work delivered across Australia.