Black Shard

We design, build, and run production software.

Engineering for the systems a business runs on: web, native mobile, portals, and the platform underneath.

We build and operate our own products, and we build to the same standard for clients: threat modelling from the first design session, disciplined delivery, and a ship cadence that keeps going after launch.

Product & platform engineering

Full builds from brand to production: web apps, native iOS and Android, client portals, and internal operations platforms.

What you get

  • Discovery and design through to a shipped, operating product
  • Design system and brand identity where the build needs one
  • A standing cadence: the product keeps shipping after launch

Web development

Marketing sites, web applications, and client portals engineered for speed, accessibility, and a security posture you can verify.

What you get

  • Modern-stack builds with performance and accessibility held to account
  • Hosting, CDN, and deployment set up and run, not handed back
  • Security headers and hardening as standard, never an add-on

Mobile app development

Native iOS and Android apps taken from concept through the App Store and Google Play, by a team that ships its own.

What you get

  • iOS and Android from a shared codebase where it fits, native where it matters
  • App Store and Play submission, review, and release management
  • Offline, push, and device integration engineered for production

UI/UX design

Interface and product design that earns trust: UX flows, design systems, and brand identity for software people rely on.

What you get

  • UX and interface design grounded in the jobs the product actually does
  • A design system the codebase enforces, not a style guide that drifts
  • Brand identity where the product needs one

Cloud engineering on Azure

The Azure architecture we run in production ourselves: Container Apps, PostgreSQL, Key Vault, and CI/CD with workload identity.

What you get

  • Architecture and deployment design in Australian regions
  • Multi-tenant data layers with row-level security
  • Delivery pipelines with secrets kept out of code

AI & automation engineering

Speech, document, and workflow automation wired into real operations, not bolted on.

What you get

  • Speech and OCR pipelines built for production use
  • Workflow automation across intake, outreach, and reporting
  • Guardrails and audit trails around every automated action

Secure-by-design development

Security in the SDLC from the first commit, the way we build our own products in regulated industries.

What you get

  • Threat modelling before a line is written
  • Least-privilege architecture and disciplined secrets handling
  • Security review gates through delivery

How it is shaped

An embedded build engagement with a weekly ship cadence, or a fixed-scope build with a defined brief and delivery date.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Scope agreed first

    Fixed-scope builds are quoted before work starts; embedded engagements run to an agreed cadence and budget.

  • We run what we ship

    Launch is a milestone, not an exit; we operate what we deliver.

  • Written down and handed over

    Architecture and deployment design delivered as part of the build.

  • Security in the SDLC

    Threat modelling before a line is written, review gates through delivery.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

Questions, answered

Who does the engineering work?
The team that builds and runs Black Shard's own products. We operate clinical software through Aurii, and the same engineers build for clients: GRM LAW, a Brisbane law firm, engaged us to build and operate the compliance and operations portal it runs on, and Stone Leaf Capital, an Australian capital-markets firm, engaged us to build its technology, brand, and operating systems. Every build is held to the same standard: threat modelling from the first design session, disciplined delivery, and a ship cadence that keeps going after launch. One team is accountable for both the build and its security, so nothing gets lost between a design decision and the code that implements it.
How do you handle our data and access during an engagement?
Access is scoped to the work: people and systems get only what the engagement requires, and no more. Administrative privilege is granted deliberately, not by default, and access is reviewed as roles change. Data is encrypted in transit and at rest, the services that host client data sit in Australian regions, and we keep the set of third parties that touch data deliberately small. In delivery, secrets stay out of code: our pipelines are built that way for our own products, and yours are no different. Our trust page sets out the full posture, including the one certification we hold, SMB1001:2026 Gold, verifiable on the public CyberCert registry. If you are running procurement, ask for our capability statement; we answer security questionnaires as part of the job.
What do we get at the end of a build?
A shipped, operating product, not a prototype. Discovery and design run through to production: the web app, native iOS and Android where the product needs them, the client portal or internal platform underneath, and a design system and brand identity where the build calls for one. The architecture and deployment design is written down and delivered as part of the build. Delivery pipelines are stood up with secrets kept out of code, multi-tenant data layers carry row-level security where the product needs them, and the system is running on Azure in an Australian region when we call it done.
What happens after launch?
Whatever suits the product. Some clients take a fixed-scope build with a defined brief and delivery date. Others keep us embedded: a standing build team that designs, ships, and operates under an ongoing engagement, at a weekly ship cadence. That second shape is how our own ventures run, and how GRM LAW and Stone Leaf Capital run today: the firm operates from the system, and the build evolves with the workflow. We run what we ship, so launch is a milestone, not an exit.
Is security part of the build or a separate line item?
Part of the build. Threat modelling happens before a line is written, the architecture is least-privilege by design, secrets handling is disciplined from the first commit, and security review gates run through delivery. This is how we build our own products, so it is not an optional extra on client work. If you want a standalone check on an existing codebase, our secure development service does line-level code review with a concrete fix for every finding and a re-review of the fixes once they land.
Do you only work with Brisbane businesses?
No. We are a national firm, with the head office in Brisbane and the work delivered Australia-wide. Every build runs on Microsoft Azure in Australian regions, so data residency holds wherever the client sits. Distance changes nothing about the engagement: the same discovery, the same ship cadence, the same accountability.
How is the cost of a build set?
By the shape of the engagement, and there are two: a fixed-scope build with a defined brief and delivery date, or an embedded build engagement with a weekly ship cadence. Scope is what drives it, and scope is concrete: which surfaces need building, whether that is web, native mobile, a client portal, or an internal operations platform, whether the data layer is multi-tenant, and what the platform underneath must carry. We do not publish prices because a real number depends on that scope, and a scoping conversation gets you one quickly.
How do we start, and how fast will you hear back?
Send a brief to info@blackshard.com.au or open one through the contact page. Someone will contact you as soon as possible. From there we run discovery the way our approach page describes it: how your software and your team work, the data that matters, the obligations you carry. Then we agree the shape of the engagement, fixed-scope with a defined brief and delivery date or embedded with a weekly ship cadence, and the build starts.

Ship software you can defend.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au