Skip to content

Custom software development · London

Custom software development in London.

QalbIT builds bespoke software for London businesses from Ahmedabad, India: regulated firms in the City and Canary Wharf, law and accountancy partnerships, media and production companies in Soho and Fitzrovia, retailers and e-commerce brands, proptech and healthtech founders around Shoreditch and King’s Cross, and the mid-sized firms across the boroughs whose operation still depends on a workbook and the one person who understands it. There is no QalbIT office in London and no UK entity, and this page sets out exactly what that changes.

London is the market where a remote partner loses least to the clock. Your 09:00 is our early afternoon, so six hours of every working day are live, and the rest of this page is about the contract, UK GDPR, the sector rules and the rows where a firm in Farringdon is the better hire.

  • 2018

    Building bespoke software since

  • 120+

    Projects delivered

  • 6 hours

    Live on UK time, every working day

  • 4.9

    Google rating, 18 reviews

Get your free estimate

Three quick questions: scope, approach and a price range back within 48 hours. No sales call required first.

What do you need built?
When do you want to start?
Where should we send the estimate?

Answer all three questions above, then send.

NDA-friendly · IP yours from day one

Definition


What custom software development in London means when the developers are not in London

Custom software development in London means designing, building and running software shaped to one firm’s way of working: a client onboarding system for a Canary Wharf asset manager, a matter management tool for a City law firm, a subscription platform for a Soho publisher. QalbIT does that work as a remote engineering partner from Ahmedabad, India, live for six hours of every UK working day, under a contract governed by English law, with no office in London.

The engineering is the same wherever the developers sit. The clock, the contract and the data rules are what differ, and in London two of the three work in a remote partner’s favour.

A studio in Farringdon or a consultancy in Canary Wharf is inside your jurisdiction. Someone can be at your office on Tuesday, the invoice carries UK VAT, and procurement recognises the supplier. A partner outside the country earns the same confidence on paper. That is what bespoke software development from us includes before a line of code: a written scope with the exclusions named, an architecture your CTO or technical adviser can challenge, a data protection position your DPO has read, and a working window that covers most of your day.

None of that is unusual, and all of it is easier to settle before a contract than after a supplier due-diligence review.

We are the remote option. We would rather make the case here than have it surface in month four.

At a glance

  • What we build

    Client onboarding and case management systems, client and member portals, SaaS products, mobile apps, integrations

  • Engagement shapes

    A first release · a rebuild of a tool you have outgrown · modules over a practice or CRM system · a standing engineering pod

  • Hours

    Remote from Ahmedabad, live 09:00 to 15:00 UK time Monday to Friday, written handover after that

  • Presence in the UK

    None. No office, no staff, no UK entity. Your MSA under English law, invoiced in pounds sterling

  • Who owns what

    Code, cloud accounts and IP in your company’s name, assigned as each piece is written

Definition


London agency, contractor or staffing firm, remote engineering partner

Three purchases that get compared on day rate when they are not the same purchase.

  • London agency

    A limited company registered at Companies House, on UK time all day, able to put people in your office. You are buying proximity, a domestic invoice and eligibility for frameworks that require a UK-established supplier. The right answer when the work is stakeholder-heavy, needs people on site, or runs through a procurement process that expects a local vendor.

  • Contractor or staffing firm

    Individual engineers billed by the day into a process you already run, with the status questions that come with engaging individuals. You are buying capacity; architecture, review, testing and release stay with your own lead. The right answer when you already have an engineering manager with room to direct more people.

  • Remote engineering partner

    A small senior company team that owns a defined build, works your day from outside the country and hands over the repository at the end. There is no UK entity, so contract, VAT treatment and the due-diligence questionnaire are dealt with at the start. The right answer when you know what the system must do and want it built properly the first time.

We are the third of those. If one of the first two is the better fit for your firm, we say so on the first call, not after a deposit has been paid.

Fit


When a London firm should use a remote partner for custom software development, and when it should not

Both lists, in the open. A page arguing only one side is not helping you decide.

  • Hire a remote partner when

    • Somebody on your side can describe the process and make decisions about it without a partners’ meeting.
    • The work has a defined shape, a first release, a rebuild or a set of modules, rather than an open-ended programme whose sponsor keeps changing.
    • Six live hours a day cover what needs a conversation, and the rest can run on a written handover.
    • You want the source, the pipeline and the documentation in your own company’s accounts when the work is finished.
    • Personal data is in scope in the ordinary way, and your DPO or compliance lead will set the rules and check our evidence against them.
  • Hire in London instead when

    • A framework agreement, a client’s terms or a public-sector procurement rule requires a supplier established in the United Kingdom.
    • People have to be physically present: a trading-floor rollout, a clinic go-live, hardware in a comms room, a warehouse cutover in Park Royal.
    • Your security policy forbids production access from outside the UK and the work cannot be done on masked data.
    • Delivery has to run on UK time until 18:00 because the stakeholders who decide are only free late in the day.
    • What you really want is a contractor under your own architect, in which case a staffing firm costs you less management overhead.

What that looks like for a London buyer

London firms are practised at supplier due diligence. Banks, insurers, asset managers and the Magic Circle have run third-party risk programmes for decades, the FCA expects regulated firms to know what their important suppliers do, and the habit has spread to the agencies, consultancies and start-ups that sell into them. The questionnaire arrives early and it is specific about UK GDPR: where data sits, who can reach it, what is logged, how a subject access request is answered, how deletion is proven. Those are the parts of a remote engagement we settle in writing before the build, and the answers describe what we run rather than what we intend. We decline London projects on the second list. A remote build where a Farringdon studio was the right answer costs far more than the fee, and everyone can see it coming by the third sprint.

Next step


Not sure which list you are on?

Send us what the system has to do, what personal data it will hold and what your procurement rules say. You will get a straight answer, including “hire an agency in London” when that is the honest one.

Comparison


Remote engineering partner vs a London agency vs a contractor or staffing firm

Every row is a real difference, including the ones that go against us. There is no day-rate row because we have no sourced figure for what London agencies charge, and inventing one would be worse than leaving it blank. We will run this table against your real scope, your data and your procurement rules, not the generic case.

Row-by-row comparison of a remote engineering partner, a London agency and a contractor or staffing firm
London agencyContractor or staffing firmQalbIT (remote partner)
Can be in your officeYesOftenNo
Live hours on UK timeAll dayAll day, in most cases09:00 to 15:00, then a written handover
Architecture is owned byThe agencyYour leadUs, reviewed with your technical lead
Testing and release are owned byThe agencyYour leadUs, with your sign-off as the gate
Contract, law and currencyDomestic, English law, GBPDomestic, English law, GBPYour MSA, English law, invoiced in GBP
Nature of the engagementCompany to companyOften individual to companyCompany to company
Source code and IPDepends on the contractYoursYours, assigned as each piece is written
Frameworks requiring a UK-established supplierEligibleUsually eligibleNot eligible
Team continuityShifts with agency workloadTurns over with the contractSmall, senior, named in the proposal, unchanged
  • 01

    Start with the rows we lose.

    A table where one column wins everything is a brochure. Two rows above are reasons to hire somebody else, and it is better to find them here than in month four of a contract you cannot exit cleanly.

  • 02

    Where the data lives and where the developers sit are separate questions.

    Your platform can run in the AWS London region, in your own account, with personal data never leaving the UK at rest, while the engineers writing it work elsewhere under access controls your DPO has approved. Most due-diligence conversations resolve once that distinction is on the table.

  • 03

    A company contract is a different thing from a contractor.

    This is an engagement between two limited companies, with a statement of work, not an individual working through an intermediary. The status questions that attach to engaging individuals are not what is being bought here. Your accountant and counsel confirm the position for your firm.

  • 04

    Staffing adds hands; it does not add a system.

    Contract developers are capacity for a process you already run. If nobody on your side holds architecture, review and release quality, that capacity produces code faster than it produces working software.

What we build


Custom software development services we deliver in London

Systems that share one record, so a client, a matter, an order or a patient moves through onboarding, operations, finance and compliance without being retyped at each desk.

  • Onboarding

    Client onboarding, KYC workflow and case management

    The system a regulated firm or a partnership actually runs on: intake, identity checks routed to your chosen provider, approvals, exceptions and reporting, built around your process rather than a vendor template. Usually replacing six inboxes and a tracker spreadsheet.

  • Portals

    Client, member, tenant and patient portals

    A portal over the system you already own, with role-scoped access, document handling and an audit trail that survives a due-diligence review. The fastest way to take volume off a service desk or a partner’s PA.

  • SaaS

    SaaS products and first releases

    Multi-tenant products with billing, roles and usage limits for a founding team in Shoreditch or King’s Cross, or for a firm turning an internal tool into something it sells. This is the shape of the CyberFind vendor decision engine: one system of record, a comparison engine over it, four years in production and no rewrite since launch.

  • Mobile

    Apps that work on the Tube

    One Flutter codebase for iOS and Android, capturing offline and syncing when the signal returns, for couriers, field staff, members and patients who are not always above ground.

  • Integrations

    Practice system, CRM, payments and NHS integration

    Message queues, retries and a reconciliation view sitting between your system of record and everything around it, so that a failed sync is noticed by a person instead of buried in a log file.

  • Cloud

    Cloud environments and release pipelines

    AWS accounts in your company’s name, in the London region where residency matters, defined as code and released in stages with monitoring and the change history a due-diligence questionnaire asks you to show.

Cost


How much does custom software development cost in London?

Custom software for a London firm is priced on the scope of the first release, the number and age of the systems it connects to, and the evidence it has to produce for your DPO, your auditors or your regulator, not on headcount or day rate. At QalbIT, fixed-scope projects start from $6,500 and a scoped first version typically from $5,000, invoiced in pounds sterling at the rate fixed in the contract. A written scope with the exclusions named comes back within 48 hours of the first call, and a first release usually ships 6 to 14 weeks after that scope is signed.

Those are our own floors and the only cost figures on this page. Search the question and you will find day rates and project ranges a factor of ten apart, published with nothing behind them. We are not adding to that.

We do not quote what a London agency charges either, because we have no figure we could attribute to anyone. Send one written scope to three London studios and you will know more than any page can tell you.

Our approach is to scope before we price: one discovery call, a written scope that names the exclusions, then a fixed price for phase one before you commit to anything beyond discovery. The six drivers below are what actually move the figure, so use them to test any quote you receive, including ours.

Try the software development cost calculator

What moves the number

  • What the first release has to do

    The biggest single influence on price, and where most estimates go wrong. A single workflow done thoroughly is worth more than four done thinly, and a first release that does one job well makes the second phase easy to justify.

  • The systems it connects to

    A documented REST API with OAuth is quick. A practice management system with a nightly export, or a CRM that has been customised for a decade, needs a middleware layer and a reconciliation view of its own.

  • Evidence for your DPO, auditors and regulator

    Subject access tooling, retention enforcement, access reviews and an audit trail that cannot be edited are engineering work. Designed in from the first sprint they are modest; retrofitted after an ICO enquiry or an FCA visit they are a project.

  • Roles and approval chains

    Two user types is a data model. Eight, with delegated authority, four-eyes checks on payments and partner sign-off, is a system in itself.

  • Platforms and the offline case

    A web application alone, web plus one mobile platform, or web plus iOS and Android with offline sync: each step up adds build and test effort, and the offline case brings conflict resolution that has to be designed deliberately.

  • How much history moves

    Master records and open matters are routine. Years of transactions or case files, reconciled against the old system and signed off by finance, is a workstream with its own estimate.

How we work with London teams


A custom software development process for London, with six live hours a day

London is four and a half hours behind Ahmedabad in British Summer Time and five and a half in winter, the smallest offset of any market we serve. Your morning and early afternoon are our afternoon and early evening. Here is how we run a project for a London team.

  1. Discovery and written scope

    One call about how the work moves, who touches it, where it breaks and what personal data is involved. Then a written scope with the exclusions named. The document is yours whatever you decide.

    A scope, a first-phase price range and the name of the engineer who would lead it.

    48 hours

  2. Prototype and architecture

    Clickable screens in week one so your head of operations or compliance lead argues with something real. Alongside them: data model, access control, the UK hosting region, retention rules and the rollback path, agreed in writing before an editor is opened.

    Approved screens, an architecture your technical lead has challenged, a data protection position your DPO has seen.

    1 to 2 weeks

  3. Build in two-week slices

    Working software demonstrated every fortnight in your morning, on your real records. Each slice is checked against the scope with you on the call, so progress is watched rather than reported.

    Working modules proven against real scenarios, and a backlog you shaped along the way.

    6 to 14 weeks, by scope

  4. Harden, then release

    Permissions, load behaviour, backups, monitoring and a rehearsed rollback signed off before a London user logs in. Where subject access tooling or an audit trail is required, it is produced here rather than promised.

    A release your security reviewer and your DPO can sign off, evidence included.

    2 to 3 weeks

  5. Run and extend

    Monitoring, a support window across UK office hours, a critical fix within 48 hours, and the next feature chosen from what your people actually use.

    A platform that keeps earning its place, and a team that hands it to yours whenever you ask.

    Monthly, 30 days notice

London runs GMT in winter and BST in summer; our team runs India standard time, which does not change. So 09:00 in London is 14:30 for us from late October to late March and 13:30 for the rest of the year, and 09:00 to 15:00 UK time is inside our working day in every month. Stand-ups, workshops and demos sit in that window, and a written handover goes out before we close, so your late afternoon never waits on us.

Book a scoping call

Where we fit


London projects that work well from a distance

These are the engagements a remote team does well. The ones that need people on site or a UK-established supplier are listed higher up, and we mean that list.

  • First build

    Replacing the spreadsheet that runs the firm

    An onboarding desk, a matter list or an operations team held together by workbooks, email and one person who knows the exceptions, rebuilt as a system with roles, approvals and a history of who did what. Bloomford, a recruitment agency in Belgium, went from four inboxes to one pipeline this way. For operations, compliance and finance teams at growing firms.

  • Rebuild

    Retiring a tool the vendor no longer supports

    An old desktop application or an early web tool rebuilt as a maintainable platform without losing years of records or retraining a firm over a weekend. For firms whose core tool has outlived its maker.

  • Data protection

    Bringing a system up to UK GDPR properly

    Adding subject access tooling, retention enforcement, deletion that reaches backups, consent records and an audit trail that cannot be edited to a platform built before anyone asked. An ICO enquiry, a client audit or a new DPO is usually the trigger. For teams facing a data protection review or a client due-diligence audit.

  • Extension

    Building around the system of record

    Portals, dashboards and custom modules over a practice management system, a CRM or a booking platform, so the core stays put and the retyping around it disappears. Plugin, a tennis club management platform, took bookings, members and payments into one system and cut double-booked courts sharply. For firms extending rather than replacing a core system.

Industries


Sectors we build custom software for in London

Software that runs an operation is shaped by the industry it runs. These are the London sectors where we already understand the process and have answered the compliance questions before.

  1. Financial services and fintech in the City and Canary Wharf

    Client onboarding, KYC workflow, operations tooling and reporting for asset managers, brokers, payment firms and lenders. Four-eyes approvals, segregation of duties and a complete audit trail shape the build, and where the firm is FCA-authorised the operational resilience and third-party expectations decide how we document what we run.

  2. Law, accountancy and professional-services partnerships

    Matter and engagement management, conflict checks, client portals, time and billing integrations and document workflows for firms from the Magic Circle down to a ten-partner practice in Holborn, where confidentiality is the product and the audit trail proves it.

  3. Media, publishing and production

    Subscription and paywall platforms, rights and asset management, production scheduling and the integrations between them for the publishers, studios and agencies around Soho, Fitzrovia and King’s Cross.

  4. Retail and e-commerce

    Order management, stock across stores and warehouses, returns, supplier portals and the customer-facing storefront integrations for the brands headquartered in London, with card data kept out of your code by tokenising at the payment provider.

  5. Proptech and property management

    Tenant and landlord portals, lettings and block-management workflows, compliance certificate tracking and maintenance scheduling for the agencies and platforms managing property across the boroughs.

  6. Healthtech and private healthcare

    Booking, triage, patient portals and clinician tooling around an existing clinical system for private clinics, digital health start-ups and the suppliers that sell into the NHS, built with the Data Security and Protection Toolkit standards in mind where NHS data is in scope.

Not on the list? The opening question does not change: what does a day of this work look like, and at which point does it break?

Next step


The off-the-shelf product bends until it breaks. Then it is a bespoke build.

Describe the process the packaged tool cannot follow and we will tell you whether it justifies a build, or whether configuring what you already pay for would do.

UK compliance


Custom software development in London: UK GDPR, FCA expectations, payments and NHS data

The rules below shape how software gets built for a London firm and set the questions a supplier outside the country has to answer before a signature. We are engineers rather than solicitors: this section describes what we build, and your counsel and your DPO decide what applies to you.

  1. UK GDPR and the Data Protection Act 2018

    Any London system holding personal data sits under the UK General Data Protection Regulation and the Data Protection Act 2018, enforced by the Information Commissioner’s Office. The principles that reach the code are lawful basis, purpose limitation, data minimisation, storage limitation, integrity and confidentiality, and accountability, along with the rights of access, rectification, erasure, restriction, portability and objection. The Data (Use and Access) Act 2025 amends parts of this regime, and its provisions commence in stages, so the position is re-verified before each publish. For software that means a data inventory that matches what the system actually stores, retention rules enforced by the system rather than remembered, deletion that reaches backups and exports, subject access answered from the system inside the statutory period, consent records where consent is the basis, and an audit trail that shows who read a record as well as who changed it. Where we process personal data on your behalf we sign your processor terms under Article 28, and where data leaves the UK, the transfer mechanism is agreed with your DPO before any data moves. Lawful basis, whether a data protection impact assessment is needed, and the transfer position for a supplier in India are decisions for your DPO and your counsel. What we build is the machinery that lets you honour the decisions they make. Sources: UK GDPR · Data Protection Act 2018 · Data (Use and Access) Act 2025 · Information Commissioner’s Office.

    Personal data

  2. FCA expectations for regulated firms

    A firm authorised by the Financial Conduct Authority is expected to identify its important business services, set impact tolerances and show it can remain within them through disruption, and to retain oversight and control of the third parties that support those services. For software that means the system has to be documented, monitored, recoverable and auditable in a way the firm can evidence to its regulator, and the supplier has to be someone the firm can actually oversee. We build to that: tested backup and restore, staged releases with rollback, monitoring with alerting your operations team receives, access logs the firm can inspect, and a written description of what we run that fits into your third-party register. Where a firm asks for exit provisions, the code, the infrastructure definitions and the documentation are already in the firm’s name, so exit is a handover rather than a migration. Whether an arrangement is material, and what your firm must notify or record, is for your compliance function. We supply the evidence and the contractual terms your policy requires, and we say plainly where we cannot meet a requirement. Sources: FCA Handbook SYSC 15A (operational resilience) and SYSC 8 (third-party arrangements) · Financial Conduct Authority.

    Financial services

  3. PCI DSS, kept out of your codebase

    The simplest way to handle card data is never to hold it. We tokenise at the payment provider, so the card number is captured by the provider’s hosted field or SDK and your platform stores a token, the last four digits and a scheme. Your application never sees a primary account number, which keeps most of PCI DSS scope out of the code we write. Responsibility under PCI DSS stays with your firm, and the self-assessment questionnaire you complete depends on how payments are taken. We keep the scope as small as the design allows and flag any feature that would grow it. Sources: PCI DSS v4.0.1 · PCI Security Standards Council.

    Payments

  4. NHS Data Security and Protection Toolkit

    A supplier or system handling NHS patient data is expected to meet the standards of the Data Security and Protection Toolkit, the annual self-assessment against the National Data Guardian’s data security standards. For software that means role-based access with unique identities, an audit trail of access to patient records, encryption in transit and at rest, tested backups, patching discipline and a documented incident process, with the evidence produced by the system rather than assembled for the assessment. The Toolkit submission is your organisation’s, not ours, and whether a given dataset is NHS data in scope is a question for your information governance lead. We build to the standards and hand over the evidence they need. Sources: NHS Data Security and Protection Toolkit · NHS England · National Data Guardian data security standards.

    Health data

  5. Cyber Essentials and supplier due diligence

    Many London buyers, and every public-sector one, ask their suppliers about Cyber Essentials and send a due-diligence questionnaire before signing. The engineers complete ours rather than a sales team, and the answers describe what we operate: least-privilege access, review-gated change management, environment separation, logging and retention, tested restores, staged releases, incident handling and offboarding when an engineer rolls off. If the truthful answer to a question is no, the questionnaire says no and names the compensating control. Suppliers who pad their answers tend to be removed from the shortlist at the final stage, and deservedly. Where your policy requires a specific certification from the supplier itself, raise it on the first call. You will get our current position in plain words, including where we fall short of the bar. Sources: Cyber Essentials scheme · National Cyber Security Centre.

    Vendor risk

We build systems that produce this evidence natively rather than bolting a compliance module onto software that resists it. Where an ICO enquiry, a client audit or a regulatory deadline drives your timeline, that date is where we plan backwards from.

Working with us


Contracting a supplier outside the United Kingdom from London

Legal, finance, your DPO and your security lead each have a short list of questions about a vendor outside the country. Most vendor sites leave the list off. Here is ours with the answers.

  1. The contract

    Your master services agreement and statement of work, governed by English law, with the jurisdiction, liability and termination clauses your counsel asks for. We never ask a London buyer to sign under Indian law, and we never run a project on an exchange of emails in place of a contract. This is a contract between two limited companies, not an engagement of an individual.

    English law

  2. Currency, VAT and invoicing

    Invoices are raised in pounds sterling against the milestones or the monthly rate fixed in the contract, with your purchase order reference on each one. We are a supplier outside the UK, so the VAT treatment of our invoices is a matter for your accountant, and we provide whatever supplier details your finance team needs to record it correctly.

    GBP

  3. Data protection terms

    Where we process personal data on your behalf we sign your processor terms, and the transfer position for a supplier in India is agreed with your DPO before any data moves. Where the work can be done on masked or synthetic data, we say so, because it removes the question entirely.

    Article 28

  4. Intellectual property

    Everything produced for you, code, designs, documentation, infrastructure definitions, is assigned to your company at the moment it is created rather than when the last invoice clears. Repositories, cloud accounts and domains are yours from the first commit, and each engineer on the account has signed the same assignment and confidentiality terms.

    Assignment

  5. Confidentiality

    A mutual non-disclosure agreement, on your firm’s template or ours, is signed before anything confidential is shared. We never name you, your product or your project as a reference without written permission.

    NDA

  6. Insurance, questionnaires and vetting

    Certificates of insurance on request. Due-diligence questionnaires completed by the engineers who would do the work. Background checks on named engineers arranged through your process where your policy requires them, raised at contract stage because they add time before anyone can start.

    Due diligence

  7. What the lack of a UK entity rules out

    There is no QalbIT entity in the United Kingdom, no London office and nobody we can send to Canary Wharf on a Tuesday. If a framework agreement, a client’s terms or a public-sector procurement rule requires a UK-established supplier or on-site delivery, we are simply not eligible, and we say so on the first call instead of discovering it after a proposal.

    The limit

Nothing above argues against a remote partner. It argues for doing the paperwork properly at the outset, which is why we raise every item on this list before the estimate and not after the signature.

Tech stack


Technology behind the custom software we build for London

A case management system or a client portal stays in service for years after it is written, so we choose tools a new hire can read in an afternoon and a future in-house team can maintain without us.

  • Backend and business rules

    • Laravel on PHP 8 for modular business systems with a complete audit trail.
    • Node.js and NestJS where integrations and event-driven flows dominate.
    • Queues, schedulers and retries for syncs, alerts and end-of-day reports.
  • Interface

    • React and Next.js, rendered on the server where search traffic counts.
    • Keyboard-first data entry for onboarding, case and operations screens.
    • Flutter for a single iOS and Android codebase that works offline first.
  • Data and integration

    • PostgreSQL and MySQL with constraints that protect record integrity.
    • Append-only audit trails and versioned records where evidence is demanded.
    • REST and GraphQL connections to practice systems, CRMs and payment providers.
  • Security and delivery

    • AWS in your name and the London region, defined in Terraform.
    • Logged least-privilege access, with any break-glass use reviewed after the fact.
    • GitHub Actions pipelines with staged, reversible releases.

Already on a practice management system, a CRM or a legacy .NET application nobody wants to replace? We build around it and write down, before the first sprint, which parts stay exactly where they are.

Outcomes


What custom software should change for a London firm

No forecasts here. Each row is an operational change the build is meant to deliver, next to the measure that would show whether it has.

What custom software should change for a London firm: what changes and how you would measure it
What changesHow you would know
One record of the truth across offices, teams and systemsGap between the system and a physical or manual count
Clients, matters and orders move without being rekeyedHand-offs where someone still copies a value by hand
Approvals are enforced by the system rather than rememberedProportion of transactions carrying a complete approval trail
A subject access request is answered from the systemHours to produce a complete access, erasure or audit response
An incident can be scoped to the records actually reachedTime to identify the records reached and the accounts that reached them
Partners and managers see the position without asking anyoneMinutes from question to answer
  • A note on sourcing

    A note on sourcing

    You will not find market statistics here: nothing about London salaries, nothing about agency day rates, none of the project-failure percentages that circulate without a primary source. Every number on the page is either ours or a case-study outcome, and each one says where it came from. If one of them matters to your decision, ask for the source; we will send it or take the claim down.

Why QalbIT


Why London firms keep a custom software development partner they have never visited

  1. The figures we can evidence

    We have delivered 120+ engagements for 50+ clients since 2018, hold a 5.0 on Clutch from 8 reviews and a 4.9 on Google from 18, and carry 100% job success on Upwork. Each of those can be checked on a public profile, which is why they are the only figures we put on a page.

  2. Six live hours, the most of any market we serve

    09:00 to 15:00 UK time is inside our working day all year, which is 13:30 to 19:30 for us in summer and 14:30 to 20:30 in winter. Workshops, demos and decisions happen when you would hold them anyway, and a written handover goes out before we close.

  3. We say what we are not

    No London office, no UK staff, no UK entity, and no implied presence anywhere on this site. The compliance and contract sections above exist because we would rather lose a deal at the scoping call than at the due-diligence review.

  4. The proposal names the people who build it

    We do not subcontract, and we do not move engineers off your project to cover somebody else’s. The developers you interviewed are the developers whose names are on the commits, and the founder answers his own email rather than routing you through an account manager.

  5. Proof from production, not promises

    The CyberFind vendor decision engine has run in production for four years, with 500+ verified CISOs and 2,000+ peer reviews on it and no rewrite since launch. Bloomford, a recruitment agency in Belgium, went from four inboxes to one pipeline. Plugin cut a tennis club’s double-booked courts sharply. The write-ups are on this site, including what we got wrong first.

FAQs · Custom software development in London


Questions London firms ask about custom software development

UK hours, UK GDPR, budgets in pounds, the contract and who owns the code, answered the way we would on a call.

Talk to the team
No. Our only office is in Ahmedabad, India, and we work for London firms as a remote engineering partner on UK hours. There is no UK entity either. If part of your project needs people physically in the City, Canary Wharf or Shoreditch, for workshops, an on-site rollout or hardware, say so on the first call and we will tell you honestly whether that part belongs with a London agency.
Live from 09:00 to 15:00 UK time every working day, which is 13:30 to 19:30 IST in British Summer Time and 14:30 to 20:30 IST in winter. That is six hours, the widest overlap of any market we serve. Stand-ups, workshops and demos sit inside it, a written handover goes out before our day closes, and a critical production fix is handled within 48 hours whatever the hour.
Fixed-scope projects at QalbIT start from $6,500 and a scoped first version typically from $5,000, invoiced in pounds sterling at the rate fixed in the contract. Where yours lands depends on the scope of the first release, how many systems it connects to and the evidence it has to produce for your DPO or regulator. You get a written range with the exclusions named within 48 hours of the first call, free whether or not you hire us. We do not publish London agency day rates because we have no sourced figure.
Two ways. First, the system itself: a data inventory that matches what is stored, retention enforced by the system, deletion that reaches backups, subject access answered from the system and an audit trail of who read what. Second, the engagement: we sign your processor terms, your DPO agrees the transfer position before any personal data moves, and where the work can run on masked or synthetic data we say so. Your DPO and counsel make the decisions; we build the machinery to honour them.
Yes. We provide a written description of what we run for your third-party register, tested backup and restore, staged releases with rollback, monitoring your operations team receives, access logs you can inspect, and exit terms that are simple because the code and infrastructure are already in your name. Whether the arrangement is material, and what you must record or notify, is for your compliance function to decide.
Yes, to the standards of the Data Security and Protection Toolkit: unique identities, role-based access, an audit trail of access to patient records, encryption in transit and at rest, tested backups and a documented incident process, with the evidence produced by the system. The Toolkit submission is your organisation’s, and your information governance lead decides which data is in scope.
You contract with QalbIT Infotech Pvt Ltd, an Indian company, on your master services agreement governed by English law, with the jurisdiction, liability and termination clauses your counsel prefers. It is a contract between two limited companies with a statement of work, not an engagement of an individual through an intermediary, and we leave any status question to your accountant and counsel rather than offer a view ourselves.
Our invoices are raised in pounds sterling. We are not a UK-established business, so how VAT applies to a supply from us is a question for your accountant, and we do not offer a view on it. We provide whatever supplier details your finance team needs to record the invoices correctly, and the purchase order reference goes on every one.
Your company does, from the first commit. Repositories, cloud accounts and domains are opened in your name, intellectual property is assigned as each piece is written rather than on final payment, and a mutual NDA is in place before you share anything. If we part ways you keep everything, including the documentation and the deployment pipeline.
Yes. A scoped first version typically starts from $5,000 and covers one platform and the core journey, with a clickable prototype in week one and a live demo every two weeks after that. Founders around Shoreditch and King’s Cross generally want a release that wins a first paying customer, not a two-year platform, and that is what we scope.
One discovery call, then a written scope with the exclusions named, back within 48 hours. If it fits, a clickable prototype follows in week one and working software is demonstrated every fortnight in your morning. A first release usually lands 6 to 14 weeks after the scope is signed. Dedicated engagements run monthly with 30 days notice on either side.
Probably in shape if not in sector. CyberFind is a vendor decision engine for security leaders that has run in production for four years with 500+ verified CISOs and no rewrite since launch. Bloomford is a recruitment portal for a Belgian agency that replaced four inboxes with one pipeline. Plugin is a club management platform that cut a tennis club’s double-booked courts sharply. The write-ups are on this site, including what we got wrong the first time.

Next step


Let us scope the first release.

Tell us how the work moves through your firm today, where it stalls and which date is fixed. We will map the process, name the system that earns its place first and put an honest range against a phased plan. When a London agency is the better fit, the reply says so. Within 48 hours: a written scope, exclusions named, yours whether or not you proceed.