Custom Software Security NZ: What to Expect

5 min read
-
-
Updated
Custom Software Security NZ: What to Expect

Custom software security in NZ means the software you commission is built to protect the data inside it: encryption, secure logins, collecting only the data you need and meeting the Privacy Act. Applicable builds these practices into every web app and portal it delivers for Auckland businesses and will answer the questions at the end of this article in plain English.

Why security is front of mind

Breaches of websites and software have been in the news for years now, and it has changed the conversation on projects. Clients ask about security before they ask about features. Their customers expect their information to be looked after. And developers, including the team at Applicable, treat it as part of the job rather than an add-on. As more of a business runs through software, the data in that software matters more.

What security in custom software means

Security in custom software development is the set of measures that protect user data from unauthorised access, breaches and misuse. In practice it comes down to a short list of practices that a good developer applies on every build.

  • Encryption. Data is encrypted in transit, so nothing travels between the browser and the server in the clear, and encrypted at rest where it is stored.
  • Secure authentication. Logins that resist guessing and reuse: sensible password rules, two-factor authentication where the data warrants it, sessions that expire and access limited by role so staff see only what they need.
  • Data minimisation and anonymisation. Collect only the personal information the business needs, keep it only as long as it is needed and anonymise it where the purpose allows.
  • Privacy compliance. Meeting New Zealand's Privacy Act 2020 and overseas rules such as GDPR if you serve customers there. Compliance is a legal requirement and an obligation to the people whose data it is.
  • Maintenance after launch. Keeping the hosting, frameworks and libraries the software depends on patched. Most real-world breaches exploit something that was already fixed upstream.

Why it matters to a small business

The reasons have not changed since we first wrote about this, but they apply to a business with twenty staff as much as to a bank.

  1. Protection of personal information. Users share names, addresses, financial details and sometimes more. Security keeps that out of the wrong hands.
  2. Trust. Breaches elsewhere have made people wary. A business that visibly looks after data earns confidence that a competitor with a leaky system does not.
  3. Legal compliance. Privacy law sets out how personal information must be handled, and in NZ a serious breach must be reported. Ignorance is not a defence.
  4. Avoiding financial loss. A breach means cost: investigation, notification, possible legal action and lost business.
  5. Reputation. A security incident is a story people remember. Prevention is far less expensive than recovery.

What your customers expect

People are more aware of data risk than ever and more selective about who they trust with it. They expect a login to be secure, a form to go somewhere safe and a business to be able to say where their information is kept. They rarely ask. They simply leave if they sense the answer is no.

What a good developer does

Security is built in, not bolted on. It shows up in how the data model is designed, how logins are handled, how the hosting is configured and how the software is tested before launch. Applicable has developed processes around the security of the products we build, the platforms we have built have undergone rigorous testing and our developers keep learning in this area because the threats keep changing.

Questions to ask your developer about security

Ask these at scoping. A good developer will answer all of them without hesitation and in plain English.

  1. Where will our data be hosted, and who can access it? You should be able to name the provider and the region.
  2. Is data encrypted in transit and at rest? The answer should be yes to both.
  3. How are logins handled? Ask about password rules, two-factor authentication and role-based access.
  4. What personal information will we collect, and do we need all of it? Less data is less risk.
  5. What happens if there is a breach? Who finds out, who tells whom and how fast.
  6. How is the software kept patched after launch? Ask what a maintenance plan covers.
  7. Who owns the code and the hosting accounts? With Applicable, you do.
  8. Has it been tested for security, and can we see the results? Testing should be part of the build, not an optional extra.

Where Applicable fits

Applicable builds websites, custom web apps and portals for NZ small and mid-sized businesses on a fixed scope, with security built into the scope rather than sold separately. If you are about to start a digital project, or are partway through one and unsure what has been done, book a scoping call and bring the questions above.

Key takeaways

  • Security in custom software comes down to five practices: encryption, secure authentication, data minimisation, privacy compliance and patching after launch.
  • It matters to a small business for the same reasons it matters to a large one: personal data, trust, the law, cost and reputation.
  • NZ's Privacy Act 2020 requires serious breaches to be reported; a developer should know what that means for your build.
  • Eight questions at scoping will tell you whether a developer takes security seriously; a good one answers all of them in plain English.
  • Applicable builds security into the fixed scope of every web app and portal and the client owns the code and hosting accounts.

Faq

What does security mean in custom software development?

The measures built into the software to protect user data from unauthorised access, breaches and misuse: encryption, secure authentication, collecting only necessary data, meeting privacy law and keeping the software patched after launch.

Is custom software more secure than off-the-shelf software?

It can be, because it collects only the data you need and is built for your access rules, but only if the developer applies the practices above. Off-the-shelf software is patched by the vendor; custom software needs a maintenance plan.

What NZ privacy law applies to my web app?

The Privacy Act 2020 governs how personal information is collected, stored and used in New Zealand and requires notifiable privacy breaches to be reported. If you serve customers overseas, rules such as GDPR may apply too.

How do I know if my developer takes security seriously?

Ask where data is hosted, whether it is encrypted, how logins work, what happens after a breach and how the software is patched after launch. Clear answers in plain English are the sign.

Does Applicable include security in a fixed-scope quote?

Yes. Encryption, secure logins, sensible data collection and testing are part of how Applicable builds, not an optional extra. Ongoing patching is covered by a maintenance retainer.

More articles

6 min read
-
16 Sept 2026

Builder, freelancer, agency or Applicable: the four ways an Auckland SME gets a website built, compared on cost, timeline, ownership and what breaks.

5 min read
-
16 Sept 2026

A generic CRM suits most NZ small businesses. When the real need is a client portal or a workflow tool, a web app built around how you work does better.

5 min read
-
16 Sept 2026

Off-the-shelf inventory software suits most NZ businesses. When multi-site stock, your own process or offline barcode capture breaks it, what to build.