Securities Reference Data Management Software: Build vs Buy
Buy first. If you take one or two vendor feeds into fewer than four consuming systems, licence a mastering platform or nominate your order management system as the reference and spend the difference on a data steward.
On this page
Buy first. If you take one or two vendor feeds into fewer than four consuming systems, licence a mastering platform or nominate your order management system as the reference and spend the difference on a data steward. Build the golden copy only when vendors disagree on attributes that move money, identifiers get reassigned under you, and six or more systems each keep their own instrument record.
What GoldenSource, NeoXam and Alveo actually do well
Start with the case for buying, because it covers more firms than this category usually admits. If you trade listed equities and vanilla bonds, take one primary feed, and have three systems that need instrument data, a mastering platform is expensive furniture. Consume the vendor model, nominate one system as the reference, and put the money into an operations analyst who owns data quality. That is a better outcome than a build and we say so in the first meeting.
GoldenSource has been mastering securities data longer than most of the alternatives, and its model covers instruments, entities, prices and corporate actions properly rather than as bolt-ons. NeoXam DataHub is genuinely strong on workflow and on the exception queues an operations team actually lives in. Alveo, formerly Asset Control, suits firms that would rather consume a managed data service than run a platform. S and P Global's Markit EDM is widely deployed inside banks and does real work there. SimCorp Dimension and Charles River both carry their own instrument masters, and if one is already your book of record, an extra mastering layer has to justify itself.
On the content side, Bloomberg Data License, LSEG DataScope Select and ICE Data Services deliver clean, documented reference files. Nobody should be rebuilding a vendor feed.
The limitation is not the software. Every one of these products ships an empty framework. The valuable content is your configuration: which source wins for which attribute for which asset class, how your identifiers cross reference, what shape each downstream system needs, and what a data quality exception means to your business. That configuration is the project. Firms consistently find the implementation partner's fee exceeds the licence, and that the resulting logic then sits inside a product they cannot cheaply leave.
Where they stop: the day a ticker gets reassigned
Here is the specific failure that generic products handle badly, and it is not rare.
An instrument is not an identifier, it is a set of them: an ISIN under ISO 6166, a CUSIP, a SEDOL, an exchange ticker qualified by a market identifier code under ISO 10383, a vendor key, and the issuer's legal entity identifier under ISO 17442. Those relationships are not permanent. Tickers are reassigned to different companies after a delisting. CUSIPs can be recycled. A merger collapses two issuers and the surviving legal entity identifier is not necessarily either of the originals. A legal entity identifier that nobody renews lapses, and a lapsed one produces rejections under MiFIR transaction reporting whether or not the entity is trading happily.
Nearly every system downstream of you treats an identifier as a permanent primary key. When a ticker moves, those systems do not raise an error. They quietly attach the new company's history to the old company's record, and you learn about it months later when a performance number cannot be explained and nobody can say which security the return belongs to.
The second thing packaged products model badly is survivorship. The default design ranks vendors: source A beats source B beats source C. Reality is that one vendor is excellent on listed equity terms and mediocre on fixed income analytics, another has the best issuer hierarchy but lags new issues by two days, and your own operations desk is the only reliable source for private placements and internal funds. A single ranking guarantees you are wrong on a large minority of attributes.
Then there is redistribution. Vendor licences restrict which internal consumers may receive which content, and that permission belongs on the attribute by source rather than in a policy memo. Discovering the limits during a vendor audit is an expensive way to learn them.
The arithmetic: cost per consuming system versus a build
Price both paths per consuming system per year, because that is the unit that scales here. Seats are the wrong denominator: a master has a dozen human users and feeds hundreds indirectly.
Work a version of this with your own quotes. A mastering platform licence at $180,000 a year, an implementation partner at roughly the same again in year one and a third of that thereafter, and one and a half data stewards at $120,000 fully loaded, comes to around $300,000 in a steady year. Spread across six consuming systems that is $50,000 a system. Across three it is $100,000 a system, which is the point where buying stops looking obvious.
Now the build. A $400,000 phased platform amortised over five years is $80,000, support at 15 to 20 percent adds $60,000 to $80,000, and you keep the same stewards because software does not adjudicate a disagreement between two vendors. Call it $330,000 a year. That is parity at six consuming systems and better past ten, because each additional consumer costs you a projection and a reconciliation rather than a licence negotiation.
So state the crossover honestly, and it is not instrument count. It sits at roughly six to eight downstream systems each holding their own instrument record, or at three or more vendor sources whose disagreements someone has to adjudicate every week. A firm with 400,000 instruments and four systems should buy. A firm with 40,000 instruments and nine systems frequently should not.
Then cost the recurring damage: the last regulatory report you refiled, the last valuation break you traced to a stale attribute, the last week operations lost re-keying one instrument into three places. We will not invent a probability for the next one. Those costs arrive on a schedule and neither path removes them.
What a custom security master costs to build
From Digital Heroes delivery experience across more than 2,000 projects, a first release covering ingestion from two or three vendor sources, an internal instrument identity with time bounded identifier cross reference, attribute level survivorship with managed overrides, and a distribution service feeding two or three consumers with reconciliation runs $100,000 to $220,000 and ships in 14 to 20 weeks. A full platform adding legal entity and issuer hierarchy with effective dating, pricing, corporate action driven instrument changes, data quality monitoring with an exception workflow, onboarding automation and point in time history runs $280,000 to $750,000 phased across 10 to 18 months.
Data migration runs 10 to 25 percent of the build, and in this category it is loading history rather than copying files. The awkward part is that most firms have overwritten attributes in place for years, so there is no history to load. You begin point in time at cutover and you cannot retrofit what was never kept. Decide that deliberately rather than discovering it in month four.
Year two runs 15 to 20 percent of build cost annually. It pays for new asset classes, vendor file format changes that arrive with little notice, and survivorship rules tuned as your operations desk learns what its exceptions are.
What drives the number up: asset class breadth, because over the counter derivatives, structured products, loans and private assets each need their own attribute model. Consumer count, since every projection and its reconciliation is real work. And issuer hierarchy, which is deeper than it looks once ownership percentages and effective dates enter the picture.
The four situations where building wins
- Regulatory fit. MiFIR transaction reporting under RTS 22, EMIR trade reporting and SFTR each want identifiers and classifications in a shape no vendor file carries natively, including classification of financial instruments codes under ISO 10962 and a legal entity identifier that is current on the reporting date. If you cannot reproduce a report filed two years ago from data as it stood then, point in time history is not a preference, it is the requirement.
- Scale economics. Past roughly six to eight consuming systems each keeping their own instrument record, or three or more vendor sources you adjudicate between, the amortised build matches licence plus services and then pulls ahead with every system you add.
- A workflow that is your competitive advantage. A portfolio manager wants an unusual instrument on Thursday afternoon. If setup takes a day and a half across three systems, the delay never appears as a cost anywhere, and the speed pressure produces the shortcuts that create bad records. Straight through onboarding in minutes, with human input only on missing or conflicting fields, pays for itself in trades you did not miss.
- Integration sprawl across three or more systems. Order management, portfolio accounting, risk, performance measurement, client reporting and the regulatory reporting engine all describe the same bond. Once six systems hold a copy, the analyst reconciling them is your master, and that person leaves eventually.
How to decide in a week, with last quarter's breaks
Monday, pull every data break logged last quarter and sort them into three piles: wrong value, missing value, wrong instrument. The third pile is the identity problem and it is the expensive one. Count how many were fixed by re-keying a field in one system rather than upstream, because those recur.
Tuesday, assemble ten instruments that hurt. A bond with a partial call, an issuer that changed name mid-quarter, a private placement, an internal fund, a company whose ticker was reassigned, a structured note. Hand the same ten to every vendor and developer on your shortlist and ask them to model them. That is the whole product evaluation. If anyone proposes ISIN as the primary key, they will corrupt your history the first time an identifier moves and you will not notice for months.
Wednesday, ask one question of each candidate: what did this instrument look like on 30 June last year. Time the answer.
Thursday, ask what leaves the system. Get the export format, the audit trail and the survivorship configuration in writing, and test the export once a year rather than during a renewal negotiation.
Friday, run the per consuming system arithmetic and decide. If it points to build, start with a paid discovery whose deliverable is a signed product requirements document covering the identity model, the survivorship rule set, the distribution contracts and acceptance criteria. At Digital Heroes no code is written until that is signed, and you keep the document either way.
We are wrong for you if the real problem is that nobody owns data quality, because a platform will not create that role. We are also wrong if you want a vendor to run the data as a managed service, which is a legitimate choice we do not offer. Where we fit: more than fifty specialists, over 2,000 delivered projects, our own products including ShopScore, HeroCheckout and Section Vault, and India LLP, US LLC and UK LTD entities so intellectual property assigns under your own law. You meet the named team before signing. Our record is checkable on Clutch, Trustpilot, Fiverr Vetted Pro and our D-U-N-S listing.
Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
- The right combination of digital transformation actions can unlock as much as US$1.25 trillion in additional market capitalization across Fortune 500 companies, while the wrong combinations put more than US$1.5 trillion at risk; companies with all three core factors (strategy, aligned technology, and change capability) saw a 5% market-value lift relative to peers. Source: Deloitte (2023) →
- In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
- Qualtrics research (Q3 2023 survey of ~28,400 consumers across 26 countries) estimated bad customer experiences put roughly $3.7 trillion in global revenue at risk annually, a 19% jump from the prior year's $3.1 trillion; 64% of customers say they will switch companies over poor service regardless of how much they like the product. Source: Qualtrics XM Institute (via Forbes) (2024) →
Frequently asked questions
How much does it cost to build a security master for a mid-size asset manager
A first release with two or three vendor feeds, an internal instrument identity, attribute level survivorship and distribution to two or three systems runs $100,000 to $220,000 over 14 to 20 weeks in Digital Heroes delivery experience. Adding issuer hierarchy, pricing, corporate action driven changes, quality monitoring and point in time history takes it to $280,000 to $750,000 across 10 to 18 months.
What is the difference between a security master and a data warehouse
A warehouse stores copies of what other systems already decided. A security master decides. It ingests competing vendor values, applies survivorship rules to produce one authoritative value per attribute, records which source won and when, and publishes that value to consumers under a contract. If your warehouse simply lands vendor files next to each other and lets analysts pick, it is a reporting store rather than a master.
Can we keep our existing vendor feeds if we build our own master
Yes, and you should. Bloomberg Data License, LSEG DataScope Select and ICE Data Services do content collection at a scale nobody sensibly rebuilds. A custom master sits above them, ingesting each feed, resolving disagreements and distributing one answer. Check your redistribution terms before you design the consumer list, because entitlement varies by vendor and by data type and belongs in the model as a property of each attribute.
How long before the first downstream system is fed from the new master
Fourteen to twenty weeks for a first release that genuinely feeds two or three consumers, not a prototype. Run the first consumer in parallel with its existing feed for a full month and reconcile daily, because that comparison is what finds the survivorship rules you got wrong. Sequence the noisiest consumer first rather than the easiest, since the easy one teaches you very little.
What happens if a legal entity identifier lapses before we notice
Legal entity identifiers require periodic renewal, and a lapsed one causes rejections in regulatory reporting even though the issuer is trading normally. The fix is to hold the renewal date as data and alert well before it, treating expiry as an operational exception with an owner rather than a field somebody checks. Firms usually discover the problem from a rejection file, which is the worst place to learn it.
Should prices and instrument terms live in the same system
Model them together and store them separately. Terms change occasionally and prices change daily, so the same platform can own both while the price store is designed for time series volume and the terms store for versioned attributes. Splitting them across two systems recreates the join problem you are trying to remove, because a price is meaningless without knowing which instrument version it belongs to.
Can we add point in time history to data we have already overwritten
Not retroactively. If your systems have updated attributes in place for years, the earlier values are gone and no build recovers them. What you can do is start point in time from cutover, so every future change carries a valid from date, a valid to date, the source and the receipt timestamp. Decide this at design time, because bolting it on later means rewriting the storage model.
Who owns the survivorship rules if an agency builds our platform
You should own the repository, the cloud accounts, the survivorship configuration and the identifier cross reference tables, written into the contract before any code is written. At Digital Heroes the client owns everything from the first commit. Those rules are your accumulated knowledge of which vendor to trust for what, and a firm that keeps them as platform content has taken the most valuable part of the system.
Should a small asset manager build this at all
Usually no. If you trade listed instruments in one or two markets from a single feed and three systems consume the data, buy or configure what you have, appoint one person to own data quality and revisit in two years. A mastering programme at that size is cost without benefit, and we tell firms this regularly even though it means no project for us.
What happens if our data vendor changes its redistribution terms at renewal
Model the exposure before renewal rather than after. Ask which consumers your current entitlement covers, what an external consumer would cost, and what your fee looks like at double your instrument count. If entitlement is enforced in your own platform as a property of each attribute by source, you can answer a vendor audit from the system instead of reconstructing it from contracts and email.
We run everything on Airtable and spreadsheets. When is it time to go custom?
The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.
If an agency builds my software, who actually owns the code?
You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.
Who owns the code when an agency builds my software?
You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.
What is the biggest mistake first-time software buyers make?
Choosing the lowest quote without asking why it is the lowest. A bid 40% under the field usually gets there by skipping tests, documentation, and code review, which are invisible in a demo and brutal to pay for later; every stalled project Digital Heroes has been asked to rescue tells some version of that story. The second mistake is signing without a written scope, which reliably turns the winning cheap quote into 1.5x to 2x the price by launch.
Is custom software more secure than off-the-shelf SaaS?
Neither is secure by default; security tracks the practices of whoever builds and operates the system, not the model. SaaS gives you the vendor's certifications and patching but puts your data in a shared multi-tenant platform on their terms, while custom gives you full control over data residency, access rules, and compliance requirements like HIPAA, with the responsibility sitting with you and your agency. Before hiring anyone for a system holding sensitive data, ask for their security checklist: encryption at rest and in transit, an OWASP Top 10 review, role-based access, and a penetration test before launch.
Our developer disappeared mid-project. Can another team pick up the code?
Yes, this is a routine engagement, provided the code exists somewhere you can access, so your first move is securing the repository, hosting, and domain credentials today. A takeover starts with a one to two week paid code audit that ends in one of three verdicts: continue the build, keep the design but rebuild the weak parts, or start over. Digital Heroes has inherited enough projects to say plainly that sometimes the rebuild is cheaper than the rescue, and an honest agency will tell you which one you have before taking your money.
How many people should be working on my software project?
Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.
We run everything on spreadsheets and Airtable. How do we know it's time for custom software?
The reliable signals are re-typing the same data into multiple tools, one employee acting as human middleware between systems, and errors appearing in handoffs between teams. Hard limits force the issue too: Airtable's Team plan caps at 50,000 records per base, and Business costs $45 per seat per month, so a 20-person team pays about $10,800 a year for a tool it has already outgrown. When workarounds consume more hours than the tools save, the spreadsheet era is over.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .