- Who does the engineering work?
- The team that builds and runs Black Shard's own products. We operate clinical software through Aurii, and the same engineers build for clients: GRM LAW, a Brisbane law firm, engaged us to build and operate the compliance and operations portal it runs on, and Stone Leaf Capital, an Australian capital-markets firm, engaged us to build its technology, brand, and operating systems. Every build is held to the same standard: threat modelling from the first design session, disciplined delivery, and a ship cadence that keeps going after launch. One team is accountable for both the build and its security, so nothing gets lost between a design decision and the code that implements it.
- How do you handle our data and access during an engagement?
- Access is scoped to the work: people and systems get only what the engagement requires, and no more. Administrative privilege is granted deliberately, not by default, and access is reviewed as roles change. Data is encrypted in transit and at rest, the services that host client data sit in Australian regions, and we keep the set of third parties that touch data deliberately small. In delivery, secrets stay out of code: our pipelines are built that way for our own products, and yours are no different. Our trust page sets out the full posture, including the one certification we hold, SMB1001:2026 Gold, verifiable on the public CyberCert registry. If you are running procurement, ask for our capability statement; we answer security questionnaires as part of the job.
- What do we get at the end of a build?
- A shipped, operating product, not a prototype. Discovery and design run through to production: the web app, native iOS and Android where the product needs them, the client portal or internal platform underneath, and a design system and brand identity where the build calls for one. The architecture and deployment design is written down and delivered as part of the build. Delivery pipelines are stood up with secrets kept out of code, multi-tenant data layers carry row-level security where the product needs them, and the system is running on Azure in an Australian region when we call it done.
- What happens after launch?
- Whatever suits the product. Some clients take a fixed-scope build with a defined brief and delivery date. Others keep us embedded: a standing build team that designs, ships, and operates under an ongoing engagement, at a weekly ship cadence. That second shape is how our own ventures run, and how GRM LAW and Stone Leaf Capital run today: the firm operates from the system, and the build evolves with the workflow. We run what we ship, so launch is a milestone, not an exit.
- Is security part of the build or a separate line item?
- Part of the build. Threat modelling happens before a line is written, the architecture is least-privilege by design, secrets handling is disciplined from the first commit, and security review gates run through delivery. This is how we build our own products, so it is not an optional extra on client work. If you want a standalone check on an existing codebase, our secure development service does line-level code review with a concrete fix for every finding and a re-review of the fixes once they land.
- Do you only work with Brisbane businesses?
- No. We are a national firm, with the head office in Brisbane and the work delivered Australia-wide. Every build runs on Microsoft Azure in Australian regions, so data residency holds wherever the client sits. Distance changes nothing about the engagement: the same discovery, the same ship cadence, the same accountability.
- How is the cost of a build set?
- By the shape of the engagement, and there are two: a fixed-scope build with a defined brief and delivery date, or an embedded build engagement with a weekly ship cadence. Scope is what drives it, and scope is concrete: which surfaces need building, whether that is web, native mobile, a client portal, or an internal operations platform, whether the data layer is multi-tenant, and what the platform underneath must carry. We do not publish prices because a real number depends on that scope, and a scoping conversation gets you one quickly.
- How do we start, and how fast will you hear back?
- Send a brief to info@blackshard.com.au or open one through the contact page. Someone will contact you as soon as possible. From there we run discovery the way our approach page describes it: how your software and your team work, the data that matters, the obligations you carry. Then we agree the shape of the engagement, fixed-scope with a defined brief and delivery date or embedded with a weekly ship cadence, and the build starts.