- 01 Collect new launches
- 02 Crawl sites, extract contacts
- 03 Verify addresses
- 04 Score & deduplicate
- 05 Manager approval
- 06 Rate-limited personal sending
- 07 Reply tracking & CRM hand-off
Build
Custom software development, built around how you work
Sensaria is a Swiss custom software development company in Lugano. We build web applications, internal business systems, customer portals, dashboards and API-driven services for companies whose processes have outgrown spreadsheets and off-the-shelf tools. You get software running in production, tested and documented code that you own, and a team that can keep developing it.
When does custom software make sense?
Custom software pays off when the way you work is part of what makes you competitive, or when standard tools force workarounds that cost more every year than building would. It is usually the wrong call when an off-the-shelf product covers most of the process and the rest can be handled by configuration or a small integration. We check this honestly at the start, because the cheapest software is the software you don’t have to build.
Signals we look for: a process that runs through spreadsheets and email because no tool fits it; staff re-typing the same data into several systems; per-user licenses paid for people who only need one screen; data that has to stay under your control. The trade-offs are laid out in custom vs off-the-shelf software.
How we build custom software
Discovery with the people who do the work. We map the process as it runs today, exceptions included, and write business rules as testable statements (“an order above the credit limit needs a manager’s approval”) rather than descriptions of screens. The output is a data model, an architecture note and a first release that is useful on its own.
Plain, proven architecture. Most business systems we build are one application with a PostgreSQL database, a typed REST API documented with OpenAPI, and a React or server-rendered interface. We split out separate services only where load, isolation or an independent release cycle justifies it. Backends are Python (FastAPI, SQLAlchemy, Alembic migrations) or Node.js with TypeScript, chosen to fit your team and existing systems.
Tests from the first week. Unit and integration tests run in CI on every change, with Playwright end-to-end tests on the critical flows, and deployments are gated on a passing suite. The first instance of the outreach platform we built for a SaaS client shipped with about 160 automated tests.
Security as the default. Roles are enforced in the backend, passwords are hashed and logins lock after repeated failures, and secrets stay out of the code. Admin dashboards refuse to start on a public address until authentication is configured. Where the server fetches external URLs, it only connects to public addresses and re-checks them after every redirect, which closes the usual SSRF holes.
Operations planned before launch. Docker images, a staging environment, a reverse proxy with TLS, structured logs, backups and a runbook that someone other than the original developer can follow.
What goes wrong in custom software projects
- Rules discovered during user testing. When scope is described as screens, edge cases surface late. Writing rules as tests and as settings (thresholds, time windows, priorities) keeps them visible and changeable without a release.
- Integrations underestimated. External APIs have rate limits, missing fields and undocumented behavior. We connect to every external system in the first sprint, and integrations stay read-only unless writing is required. In one system we built, the integration can only call an allow-list of read operations, and a test proves that a full import makes no write calls.
- Jobs that run twice. A retried job sends the same email or creates the same order a second time. Unique keys, atomic claims and idempotent handlers make re-runs safe.
- No owner after launch. Software nobody understands decays quickly. You get documentation, a runbook and the option of ongoing development with Sensaria.
What drives cost and timeline
| Driver | Effect on effort |
|---|---|
| Workflows and user roles | Each role and approval path adds screens, rules and tests. |
| Integrations | The quality and limits of external APIs often decide the schedule. |
| Data migration | Cleaning and moving existing data is routinely underestimated. |
| Audit and compliance | Logs, retention rules and access controls add design and testing work. |
| Interface complexity | Bulk editing, complex tables or offline use cost more than simple forms. |
| Availability | Round-the-clock operation needs monitoring, redundancy and on-call cover. |
We quote a fixed price for a clearly defined first release, or work in phases when discovery shows that parts of the scope depend on how people use the first version. Either way you see the plan and its assumptions before work starts.
Data protection and hosting
Business systems usually hold personal data, so data protection law shapes the design: the revised Swiss Federal Act on Data Protection (FADP), in force since 1 September 2023, for data processed in Switzerland, and the GDPR for people in the EU. Under the FADP, Article 7 requires data protection by design and by default. Article 16 allows disclosure abroad only to countries with adequate protection or under additional safeguards. Article 24 requires reporting to the FDPIC any breach likely to result in a high risk for the people concerned. In practice we build roles, retention rules and audit logs into the first release, document which processors see which data, and host in Switzerland or in an EU region depending on your contracts and sector.
How it connects to the rest of your systems
Custom software rarely stands alone. It reads from and writes to your CRM, accounting or e-commerce platform through API integrations, sometimes grows into a custom CRM or ERP, and occasionally becomes a product for other companies through SaaS development. Typical scenarios are described under internal business systems.
Why Sensaria
Sensaria AG is a Swiss company based in Lugano. For a SaaS client we built a startup discovery and outreach platform: a daily pipeline with approval queues, a role-based dashboard and hand-off to the client’s CRM. We also built an affiliate reactivation system that analyzes a third-party platform strictly read-only, and an affiliate recruitment engine with SSRF-safe crawling and an audit trail for every merged identity. We work in English, Italian, German and French.
What's included
Custom Software Development
- 01
Custom web applications
Browser-based applications with their own data model and business rules, from a quoting tool to a complete operations system.
- 02
Backend and APIs
Services in Python (FastAPI) or Node.js on PostgreSQL, with a documented REST API and an OpenAPI contract other systems and teams can build against.
- 03
Frontend applications
React and TypeScript interfaces for data-heavy daily work: tables, filters, bulk actions, drafts and approval queues.
- 04
Internal business systems
Tools that replace email chains and shared spreadsheets: approvals, task queues, document handling and a history of every change.
- 05
Customer and partner portals
Logged-in areas where customers check status, download documents or submit requests, reading from internal systems through a controlled API layer.
- 06
Dashboards and reporting
Operational dashboards where each metric is defined once in the data layer, so sales, operations and finance see the same number.
- 07
Workflow and background jobs
Scheduled and event-driven jobs with retries, back-off and a dead-letter queue, so a failed step is visible and recoverable instead of silently lost.
- 08
API-driven applications
Applications that sit between existing systems such as CRM, accounting, e-commerce and email platforms, and move data between them on events.
- 09
Roles, permissions and audit
Role-based access enforced in the backend, login protection and an audit log of who changed what and when.
Typical scenarios
Typical scenarios
-
Replacing a spreadsheet-driven process
Orders, quotes or requests tracked in shared Excel files move into an application with validation, roles and history. The spreadsheet remains available as an export, not as the source of truth.
-
Automating a daily data pipeline
Data collected from several sources is deduplicated, scored and handed to people for approval before anything goes out. Runs are idempotent, so a restart never processes the same item twice.
-
A read-only analytics layer over a third-party platform
Data is synced from a SaaS tool you can't change, the metrics it doesn't offer are computed, and the results drive tasks for your team, with no risk of writing back by accident.
-
A customer portal on top of internal systems
Customers see order status, documents and open requests without calling. The portal reads through an API layer, so internal systems are never exposed to the internet directly.
-
Connecting systems that don't talk to each other
A small service moves data between CRM, accounting and email platforms when something changes, with logs and retries, and ends the re-typing of the same data in three places.
Related projects
- 01 Read-only sync
- 02 Activity metrics & data quality
- 03 Segment & score
- 04 Dry-run shortlist
- 05 Four-step sequence with re-checks
- 06 Replies become manager tasks
- 07 Reactivation tracking
- 01 Discover candidates
- 02 Resolve links, detect affiliate fingerprints
- 03 Merge identities
- 04 Score with explanations
- 05 Enrich & verify contact
- 06 Three-step personal sequence
- 07 Replies & conversion tracking
FAQ
Frequently asked questions
How do I choose a custom software development company?
Ask to see systems the company has built and run, and ask about their architecture, tests and operations rather than screenshots. Check who owns the source code, how changes are tested before release, who operates the software after launch, which languages the team works in and where your data will be hosted. A good partner will also tell you when an off-the-shelf tool is the better answer.
How much does custom software development cost?
Cost depends on the number of workflows and user roles, the quality of the external APIs you need to connect, data migration, audit and compliance needs, and availability requirements. We don't publish prices. After a short discovery we give a fixed price for a clearly defined first release, or a phased plan with an estimate per phase when parts of the scope depend on how users respond to the first version.
How long does a custom software project take?
A first production release of a focused internal tool typically takes two to four months, including discovery. Larger systems are delivered in releases every few weeks rather than in one big launch, so people use the software early and the next phase is based on real feedback. Integrations with slow or poorly documented third-party APIs are the most common source of delay.
Why choose a Swiss software company over a nearshore team?
Nearshore teams can cost less per hour. A Swiss partner makes sense when the project needs close work with your staff in their language, a contract with a company under Swiss law, and a clear answer on where personal data is processed; the EU recognizes Switzerland as adequately protected. Sensaria AG is registered in the commercial register of the Canton of Ticino and works with companies in Switzerland and abroad in English, Italian, German and French.
Do you work with SMEs or only large companies?
Both. We work with small and medium-sized companies and with teams inside larger organizations that need a specific system built quickly. The architecture is sized to the problem: a single application with one PostgreSQL database covers most business systems, which keeps hosting and maintenance costs predictable.
Who owns the source code?
You do. The code lives in your repository or is transferred to it at handover, together with documentation, the database schema and migrations, and the deployment runbook. There is no proprietary framework or license that ties you to Sensaria for further development.
Where is our data hosted, and how do you handle the FADP and the GDPR?
We agree the hosting location with you: a Swiss data center where contracts or sector rules require it, otherwise an EU region, which the Federal Council lists as adequately protected. For data about people in the EU, the GDPR applies as well. Access roles, retention rules and audit logs are part of the first release, and we document which processors can see which data.
Can you take over and extend existing software?
Yes, after a technical review. We read the code, run the tests if there are any, check dependencies and deployment, and give you a written assessment of what can be extended, what needs refactoring first and what carries risk. Taking over a system usually starts with adding tests around the parts that change most.
Technology we use
TechnologyTell us about your project
Web applications, internal systems, customer portals and API-driven services built around how your company actually works, with code and data you own.