Buy by default. Build where it counts.
Most standard needs should be bought, not built; custom software wins when the process is your differentiator, when generic tools force double-handling, when data and audit obligations reach into the architecture, or when the tool is becoming the business.
Build or buy is the first real technology decision most Australian businesses face, and the industry answers it badly from both directions. Software firms pitch builds because builds are revenue. SaaS vendors pitch subscriptions because subscriptions are revenue. The decision deserves better than either incentive.
We are a software engineering and cybersecurity firm, and most of the time you should buy. Off-the-shelf products are faster to adopt, cheaper for standard needs, and maintained by someone else. Custom software wins in specific, nameable situations: when the process is your differentiator, when generic tools force double-handling, when data control and audit obligations reach into the architecture itself, or when the tool is becoming the business.
We hold that position from both sides of the counter. We build and operate our own products, clinical software at Aurii, buyer's advocacy systems at Bold Property Group, recruitment tooling at Restart Recruitment, and we built client systems for GRM LAW and Stone Leaf Capital, firms that had exactly those nameable reasons. This page sets out the criteria we use, and the cases where a subscription is simply the right call.
Side by side.
| Criteria | Custom software | Off-the-shelf SaaS |
|---|---|---|
| Time to start | Slower by nature. Even a tightly scoped build needs a brief, a design pass, and a first working slice. Fixed-scope work is briefed and dated before it starts, but nothing ships on day one. | Immediate by comparison. Sign up, configure, import your data. For a standard need this speed is decisive, and no build can compete with it. |
| Fit to process | Exact. The system is shaped to how you actually work. GRM LAW's portal holds the firm's own intake, conflicts checks, and matter register, not a vendor's approximation of a law firm. | Approximate. You adopt the vendor's model of the work. For a standard process that model is usually good enough. For a differentiated one, you bend the process to fit the tool and lose the edge. |
| Cost shape over time | Front-loaded. The build is scoped and priced before work starts; after launch, the costs are hosting and maintenance you control. No per-seat pricing, no surprise tier hiding the one feature you need. | Low then compounding. Cheap to adopt, then per-seat and per-module fees that grow with headcount for as long as you use it. For a standard need, years of subscription still usually cost less than a build. |
| Integration depth | As deep as the work demands. A custom system can sit over the tools you keep and close the gaps between them. GRM LAW's portal sits over Smokeball and adds the conflicts checks, AML/CTF readiness, and audit trail the firm needed. | Bounded by the vendor's API. Mainstream pairings work well. Anything off the beaten path becomes CSV exports and re-keying, which is double-handling with a subscription attached. |
| Data control and residency | Designed in. We build on Azure in Australian regions, with tenancy, retention, and access modelled on your obligations. Stone Leaf Capital's data model is built around the firm's AFSL perimeter. | The vendor's call. Many handle Australian residency well; some do not. Confirm where the data sits, who can reach it, and what crosses borders before you sign, not after. |
| Security accountability | Concentrated. The team that built the system secures it: threat modelling from the first design session, least-privilege access, audit trails you can inspect. One party answers for the outcome. | Inherited. You take on the vendor's posture, staffing, and breach history. Their assurance reaches you as documents: independent assessments, audit reports, a sub-processor list. Read them. |
| Evolution | Continuous. Software under an ongoing engagement changes when the workflow does; we ship to the GRM LAW portal weekly, and Stone Leaf Capital's portal evolves the same way. The roadmap is yours. | The vendor's roadmap. Your feature request queues behind every other customer's. Acquisitions, pivots, and product sunsets happen on their schedule, and you migrate on it too. |
When custom software wins
- The process is the differentiator. If the way you run intake, deal flow, or compliance is why clients choose you, a generic tool averages you back to the market. GRM LAW runs on a portal built to its own workflow because that workflow is the firm's.
- Off-the-shelf forces double-handling. When staff re-key the same matter or client into two systems, the subscription is the smaller cost. A custom layer over the tools you keep removes the re-keying instead of adding a third silo.
- Data, residency, or audit obligations outrun configuration. Stone Leaf Capital's portal captures actor, action, and before and after state on every change, structured around an AFSL perimeter. Obligations at that level are architecture, not settings.
- The tool is becoming the business. Aurii is the Black Shard clinical-software venture: we built the entire stack, from the native iOS and Android apps to the multi-tenant data layer, and it runs as clinical voice software for Australian private-hospital specialists. When the software is the asset, ownership is the point.
- No vendor covers the work. Restart Recruitment runs structured scorecard screening per role so the brief gets judged the same way every time, built for a search model that takes on fewer searches at a time and runs each one properly. If your method has no product category, the category will not appear on schedule.
When off-the-shelf is simply right
- The need is standard. Accounting, payroll, email, documents, calendars, video calls: these are solved problems with mature products behind them. Building any of these is spending your budget to arrive last.
- Compliance logic lives in the product. Payroll and tax rules change constantly, and the established products encode the changes as they land. A bespoke rebuild of that logic is a standing liability, not an asset.
- The process is still forming. If you have not run the workflow manually for long enough to know its shape, a subscription you can cancel is the cheapest way to learn. Build after the process proves itself.
- The value is the network. Electronic signatures, payments, conferencing: the worth sits in the counterparties and the compliance regime already on the platform, not in the software itself.
- A mainstream tool fits with light configuration. If a standard CRM covers your pipeline once configured, take the win. A custom build has to clear a high bar over a configured product, not over an empty spreadsheet.
Why does a software firm tell you to buy?
Custom software is our trade, which is exactly why our default answer is buy. A build is not a purchase; it is an asset with a lifetime. Someone has to patch it, monitor it, back it up, and answer for it when it breaks. Every feature is code someone maintains and a surface someone can attack. A firm that quotes a build for a need a configured product would cover is selling you its invoice, not your outcome.
So the decision rule we apply to our own ventures is narrow. Buy for every standard need. Build only where the software touches the thing that makes the business different, and make that build earn its place against a well-configured off-the-shelf alternative, not against nothing.
How do you know the process is the differentiator?
Most businesses overestimate how special their process is. The test is commercial, not sentimental: if a competitor adopted your workflow tomorrow, would clients notice? Standard sales pipelines, standard bookkeeping, and standard support queues fail that test, and they should be bought. The conflicts-and-compliance workflow a law firm runs its matters through every day passes it. GRM LAW engaged us to build that workflow into a portal, over Smokeball rather than instead of it, because the firm's process was worth keeping exactly as the firm runs it.
Regulatory perimeters produce the same answer by a different route. Stone Leaf Capital operates under an AFSL, and its obligations reach into the data model itself: what is retained, who acted, what changed, before and after state on every change. Generic tools let you configure fields. They do not let you make the audit trail machine-enforced, and when the obligation is structural, the software has to be.
The third trigger is quieter: double-handling. When a team keys the same client into the practice system and the spreadsheet beside it, or exports CSVs every Friday to assemble the report no tool produces, the off-the-shelf stack has stopped saving money. The subscription line is visible on the invoice; the labour it fails to remove is not. Counting both is usually what settles the question.
How a Black Shard build runs
If the answer is build, the engagement is legible: the workflows covered, the integrations, the environments, and the tenancy model are all scoped before work starts. Threat modelling happens in the first design session, not as a hardening pass at the end, because security retrofitted is security negotiated down. We build on Azure in Australian regions, and we run what we ship: the same team that designs the system operates it, under least-privilege access, with the audit trail built in. Our approach page describes the method; our trust page shows the posture behind it, including the SMB1001:2026 Gold certification we hold and you can verify on the public CyberCert registry.
Delivery is either a weekly ship cadence under an embedded engagement or a defined brief with a delivery date for fixed scope. GRM LAW and Stone Leaf Capital both operate day-to-day on portals we still ship to under ongoing engagements; the build evolves with the workflow. Delivered Australia-wide from our Brisbane head office.
Questions, answered
- Is custom software more secure than off-the-shelf SaaS?
- Not automatically. A major SaaS vendor employs more security engineers than most Australian businesses ever will. What custom software changes is accountability and inspectability: one team answers for the design, and you can read the audit trail rather than trust a summary. That only holds if the builder takes security seriously. We build secure-by-design, with threat modelling before a line is written and least-privilege architecture throughout, and we hold SMB1001:2026 Gold ourselves, verifiable on the CyberCert registry. Ask any firm quoting you a build to show its own posture first; ours is on our trust page.
- What does custom software cost?
- We will not invent a range here, because scope is everything. The drivers are the workflows covered, the integrations, the number of environments, and the tenancy model; a fixed-scope engagement is agreed with a defined brief and delivery date before work starts. The honest comparison is not build price against subscription price; it is build price against years of per-seat fees plus the cost of the double-handling the subscription leaves in place.
- Can custom software work alongside the SaaS we already use?
- Often that is the right architecture. GRM LAW kept Smokeball; the portal we built over it carries the workflow the practice system does not, through to an append-only audit ledger machine-enforced on every state change. Buy the commodity layer, build the layer that makes you different, and integrate the two properly.
- When should we replace an off-the-shelf tool with a custom build?
- When the workarounds become the job. The signals are consistent: staff maintaining spreadsheets beside the tool, weekly CSV exports to build the report it cannot produce, the same record keyed into two systems, or an audit obligation the tool cannot evidence. If none of those are present, keep the subscription.
- Should a new business ever build custom software?
- Mostly no. Buy nearly everything and spend the build budget on the single system that makes the business different. That is how we run our own ventures. When we set up Bold Property Group, we built what makes it different: the off-market deal-sourcing agent network and the client portal for active acquisitions. The rest of a young company's stack should be bought, configured, and left alone.
Bring us the decision, not a conclusion.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

