Skip to content

Custom software · Hamburg

The digital sea wall for your data.

Custom software development from Germany. Secure. Modern. GDPR-compliant. Built, run and maintained by people you know by name.

In production
82,000 lines of code
On one platform
16 locations
To third parties
No data
If it goes wrong
€ 250,000 insured

About us

We give companies back control over their data.

NordTrust is a software company based in Hamburg. We build applications that follow a company's actual process — not the process of an off-the-shelf product everyone involved has to bend around.

Behind that is a small, permanent development team, extended by a network of experienced specialists for infrastructure, data protection law and interfaces to legacy systems. Lean structures instead of corporate overhead: you talk to the people writing the code, not to a ticket number.

What we do not sell is data. Yours sits on servers in Germany, it is not passed on, and it does not train anybody else's model.

Trust
We tell you up front what something costs and how long it takes — and we speak up when that changes.
Security
Threat model before the first line of code, not hardening after the first incident.
Transparency
You get the code, the data model and the logs. Even if you continue elsewhere.
Innovation
New methods are tools, not an end in themselves. We use them where they take work off your desk.

Services

Eight fields, one team

We take a project on completely or not at all — analysis, build, security and operations from one source. Pricing on request, always fixed per stage.

Custom software

Applications that follow your process — not that of a standard product.

CRM systems

Customer history, leads and appointments in one place, with rights per role.

Customer portals

Your customers see their own status — no phone call, no spreadsheet attachment.

Employee portals

Rosters, time accounts, leave and payroll documents — on the phone as well.

AI solutions

Language and text models with a filter in front of the interface, run in-house.

Automation

Recurring manual work becomes a traceable nightly run.

Cloud systems

Our own servers in northern Germany instead of rented space on other continents.

Interfaces

Your existing systems stay — we connect them instead of replacing them.

Security

Data protection is not a feature. It is the foundation.

Eight points that come at the beginning of a project here, not at the end as a retrofit. Every one of them is named in the quote and verifiable in operation.

Servers in GermanyOperated exclusively in German data centres in the north. No provider based outside the EU in the data path.
GDPR complianceProcessing agreement under Art. 28, records of processing, deletion concept and data subject rights are part of the delivery.
Privacy by designWe collect what the function needs — not what is technically possible. Personal data is kept separate.
Security by designThreat model before the first line of code. Dependencies are pinned, reviewed and documented.
Encrypted communicationTLS 1.3 outbound, encrypted connections and backups inbound. Access by key only.
Access controlsEvery access is bound to one person and one device. Shared accounts do not exist.
Auditable processesWho changed what and when is on record — in the system, not in a developer's memory.
Roles and permissionsVisibility follows the task. What a role does not need, it does not see — not in reports either.

Insured € 250,000

You are not left alone with the damage.

With this way of building, a data breach is close to impossible: separated security zones, encrypted channels, every access bound to one person and one device.

But “close to” is no foundation for a company to park its risk on. That is why our work is backed by cover from a well-known German insurer — € 250,000 of cover, explicitly including damage that occurs at your customers. Not just claims against us.

What applies in an individual case is set out in the contract and the policy, both of which you see beforehand. That we stand behind our work applies in every case.

Cover
€ 250,000
Insurer
Well-known German insurance company. Confirmation on request.
Included
Third-party damage — damage occurring not at your company but at your customers.
Also
Costs of notifying the supervisory authority, informing data subjects and restoring systems.
Not covered
Systems not developed or operated by us, and credentials shared on your side.
Evidence
Confirmation of cover is attached to every quote — before you sign, not after.

This overview is a summary, not an insurance certificate. The project contract and the policy are binding; you receive both in full before entering into a contract.

From practice

One retail network, one platform.

portal · roster · calendar week 37Sample data
EmployeeLocationMonTueWedThuFriSatTargetActual
A. MeinkeLocation 0409–1809–18off11–2011–2010–1638,539,0
B. KrollLocation 0411–20off09–1809–1809–16off32,031,5
C. SanderLocation 11LeaveLeaveLeaveLeaveLeaveoff38,538,5
D. WiechmannLocation 1109–1809–1811–20off11–2010–1638,540,25
E. TholenField sales08–1708–1708–1708–1708–15off40,039,75

Anonymised illustration with sample data · no real people, locations or amounts

From practice

For a telecommunications retailer we run a company portal that brings together rostering, time tracking, commission accounting and field sales management across 16 locations — grown in daily operation, without a single day of downtime.

Personal data never leaves the system: personnel file documents, photos and settlement lists are locked down at role level and technically prevented from appearing in reports or exports.

We build software we would have to use ourselves every day. That is the hardest quality benchmark I know.Christian Opitz · CTO
16
locations in production, one shared data set
25
mobile applications from one shared toolkit
82k
lines of production code, statically checked at every step
0
data transfers to third parties, since day one

How a project runs

Five stages, no surprises.

Every stage ends with something you can hold: a document, a running version, a test report.

01

Analysis

We look at how your process actually runs — not how it is documented.

02

Design

Data model, roles, permissions and threat model are agreed in writing.

03

Development

A running version to click through every two weeks, not a screenshot.

04

Test & security

Static analysis, load test, permission review and a report your data protection officer can read.

05

Operations

Maintenance, backups and further development — with a named contact instead of a ticket number.

Team

You know who works on your software.

A small, permanent team in Hamburg — extended by a network of experienced specialists when a project calls for it. No rotating subcontractors.

Andreas Asangarani

Managing Director

Responsible for quotes, contracts and commitments. First point of contact for everything that is not technical.

Christian Opitz

CTO

Responsible for architecture, security and operations. Writes code — and reads every line that ships.

Developers & specialists

Standing network

A young development team, plus experienced freelancers for specialist questions: infrastructure, data protection law, interfaces to legacy systems.

Let's build software you can trust.

Write two sentences about what you have in mind. You will get an honest assessment of whether and how we can help — even when the answer is that you do not need us for it.