Skip to content
§
§ · hiring guide

How to Hire an MDR Platform Development Company

Accept only one answer on tenant isolation: enforced at the data layer, with a test suite whose job is to try to cross the boundary. Application filtering on a tenant column fails a customer penetration test.

Custom Software Development software overview illustration for How to Hire an MDR Platform Development Company.
The short answer

Accept only one answer on tenant isolation: enforced at the data layer, with a test suite whose job is to try to cross the boundary. Application filtering on a tenant column fails a customer penetration test. A first release with multi tenant ingestion, isolation, the analyst queue and tuning overlays runs $110,000 to $220,000 in 16 to 22 weeks.

Most software is only ever audited by the people who paid for it. A managed detection platform is audited by everybody else. Your next prospect's security team will ask how tenant data is separated before they ask what you charge, and they will ask with their own architect in the room. Commissioning this is closer to commissioning a building where every tenant's wall has to survive somebody else's structural survey than to commissioning an internal tool.

What makes the category hard to buy is that the decisions with the longest shadow get made in week one, and none of them are visible in a demo. Tenant isolation cannot be retrofitted without something close to a rewrite. Detection content has to be shared to stay maintainable and tuned to stay usable, and choosing the wrong pattern leaves you with forty divergent copies inside a year. Retention design determines your infrastructure bill for the life of the business. A vendor can show you a clean queue and a customer portal without having got any of that right.

What an MDR platform development company actually does

The visible build is the analyst queue and the customer portal. Underneath, a capable team normalises telemetry from each customer's own endpoint, identity, network and cloud tooling into a shared schema, so nine alerts across three customers can collapse into one case rather than nine investigations. Every query, background job and export carries a tenant context enforced where the data lives, with the analyst view and the customer view built as separate surfaces rather than the same screen with a filter.

Then the part that decides your margin: a detection library held once with a per tenant overlay carrying suppressions, thresholds, asset exclusions and severity adjustments as versioned data rather than forked rules, plus a tuning workflow that sits inside the case so a suppression proposal is one click from the eleventh false positive. Around it sit contracted response actions that enforce what each customer's agreement permits, an SLA model with a live countdown, and onboarding automation, because time from signature to first detection is a number your sales team will quote.

What it really costs in 2026

EngagementCostTimeline
Paid discovery producing a written specification$15,000 to $30,0002 to 4 weeks
Ingestion for two or three telemetry types, isolation, analyst queue, case management, tuning overlays$110,000 to $220,00016 to 22 weeks
Full platform: contracted response actions, SLA modelling, branded portal, reporting, onboarding automation$300,000 to $700,0009 to 18 months
Each additional endpoint or identity sourcePriced per integration2 to 4 weeks each
Telemetry retention and infrastructureRecurring, scales with customer countOngoing

The first line item that goes missing is retention. Holding a year of telemetry for forty customers is an architecture decision with a bill that grows every time you win business, so a quote that prices only the application understates the cost of success. Decide where telemetry lives, and for how long, before anyone writes application code.

The second is connector maintenance. Endpoint and identity vendors change API behaviour and rate limits on their own schedule, and two customers running the same product with different configurations still send you different fields. Integrations are a standing cost, not a delivered item, and the contract should say who absorbs it when a vendor changes something in month seven.

Signals of a strong partner

  • Isolation lives at the data layer. Row level enforcement, tenant scoped credentials for downstream tools, and tests that actively attempt to cross the boundary rather than assert that it exists.
  • They separate the analyst and customer surfaces. A globally prioritised cross tenant queue for your shift, and a customer view that cannot show another estate in a report or an emailed alert.
  • Tuning is an overlay, not a fork. Suppressions and thresholds as versioned data, so you can answer why a detection was suppressed for one customer in March and who approved it.
  • They put tuning inside the case. A suppression proposed at the moment of the false positive, routed for approval, rather than an admin task nobody does at the end of a shift.
  • They ask about rate limits by vendor. Sustained load behaviour shapes ingestion design, and a firm naming specific products has run this in anger.
  • They model contracted permissions. A customer paying for notification only must not be able to have a host isolated by an analyst working quickly at 3am.
  • Ownership is settled before kickoff. Digital Heroes assigns the repository, the cloud accounts and the code from the first commit, and contracts through India, US and UK entities so the assignment holds under your own law.

Red flags

  • Isolation described as filtering on a tenant column. That is the pattern that fails a customer penetration test, and you will find out during a sales cycle.
  • A plan to copy detections per customer. Comfortable at ten tenants, unmaintainable at forty, and you cannot push an improvement to any of them.
  • SLA figures derived from ticket exports. That is a postmortem rather than a control, and it cannot show a shift lead a breach that is about to happen.
  • No opinion on data residency. Some customers will not let telemetry leave their jurisdiction, and that constraint changes the architecture rather than a configuration screen.
  • Response actions treated as simple. They touch somebody else's production estate and need approval modelling, a blast radius check and a recorded authority.

Questions to ask on the first call

  1. Where is tenant isolation enforced, and what does your test suite do to try to break it?
  2. How do you keep detection content shared while allowing per customer tuning, and how is an overlay versioned?
  3. What does a suppression proposal look like from inside an open case, and who approves it?
  4. Which telemetry sources have you ingested in production, by vendor and by type?
  5. What happens to ingestion when a vendor rate limits you during a busy night?
  6. Where does the SLA clock start, what pauses it, and does the analyst see time remaining or time elapsed?
  7. How does the platform stop a notification only customer from having a host isolated?
  8. What does onboarding a new customer look like on day one after launch, step by step?
  9. Model our infrastructure cost at forty customers with twelve months of retention.

A simple way to decide

Do not choose from proposals written off a capability list. Buy a paid discovery phase from your leading candidate and insist the deliverable is a written specification you own outright: the isolation model and how it is tested, the ingestion and normalisation design with named sources, the detection overlay pattern, the SLA model with clock and pause definitions, the response action permission model, the retention plan with a costed curve, and acceptance criteria priced individually.

Digital Heroes writes that specification before any code exists and hands it over whether or not you continue. Send it to the security architect at your most demanding prospect and see how it reads to the person who will eventually audit you.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
  2. McKinsey's Developer Velocity research finds best-in-class tools are the top contributor to software business success, yet only about 5% of executives ranked tools among their top-three software enablers, signaling underinvestment in developer tools (this finding originates in McKinsey's Developer Velocity study rather than the linked generative-AI article). Source: McKinsey & Company (2023) →
  3. 73% of surveyed businesses now use a headless architecture (up nearly 40% since 2019), and 98% of those not yet using it are evaluating or planning to evaluate headless within 12 months, with 82% saying it makes delivering consistent content easier. Source: WP Engine (2024) →
  4. Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
FAQ

Frequently asked questions

How much does it cost to build a multi tenant MDR platform?

A first release with multi tenant ingestion for two or three telemetry types, isolation enforced properly, the analyst queue, case management and per tenant tuning overlays runs $110,000 to $220,000 over 16 to 22 weeks in Digital Heroes delivery experience. A full platform adding contracted response actions, SLA modelling, a branded customer portal and onboarding automation runs $300,000 to $700,000 across 9 to 18 months.

What is the one architectural answer I should insist on?

Tenant isolation enforced at the data layer, with tenant scoped credentials for downstream tools and a test suite whose explicit job is to attempt cross tenant access. Application level filtering on a tenant column is the pattern that fails a prospect's penetration test, and retrofitting isolation later is close to a rewrite. Decide it in week one, because a single cross tenant disclosure is an existential event in this business.

Why does retention cost more than the quote suggests?

Because it is a recurring bill that grows with every customer you sign, and most quotes price the application rather than the infrastructure underneath it. Holding twelve months of telemetry for forty customers is an architecture decision made before code, not a line item added later. Ask any bidder to model the cost curve at your target customer count and retention period before you compare proposals.

Should we build or use a partner platform?

Under roughly fifteen customers, use a partner platform. It is faster and cheaper, and your differentiation at that size is relationship and response quality rather than technology. Building becomes right when the shape of your service is being forced into someone else's model, when tuning debt is degrading your analyst queue, or when platform pricing takes a growing share of margin on every contract you win.

Who owns the platform and the detection history at the end?

You should own the repository, the cloud infrastructure accounts, the detection content and the case history, written into the contract before kickoff. When the platform determines how many customers one analyst can carry, owning it is the business rather than a preference. Digital Heroes assigns ownership from the first commit, and any arrangement that leaves your service history inside a vendor tenancy hands them the stronger hand at every renewal.

How long does it take from first call to software my team can actually use?

Plan for four to six months: two to three weeks of discovery, two to four weeks of design, then a 10 to 16 week build with testing. In Digital Heroes delivery experience the schedule killer is not engineering speed but decision lag; a client who takes two weeks to approve wireframes adds two weeks to launch. Book a weekly 30-minute decision slot before kickoff and most of that risk disappears.

Is it cheaper to customize Salesforce than to build a custom CRM from scratch?

If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.

How much should a small business expect to pay for custom software?

Across 2,000+ Digital Heroes projects, a small business system that replaces spreadsheets or one core workflow typically lands between $40,000 and $80,000, with more complex first versions running up to $150,000. The two levers that move the number most are integrations and user roles, not the team's hourly rate. Any quote under $15,000 for a full production system means the vendor has not understood your scope yet.

What is the biggest mistake first-time software buyers make?

Choosing the lowest quote without asking why it is the lowest. A bid 40% under the field usually gets there by skipping tests, documentation, and code review, which are invisible in a demo and brutal to pay for later; every stalled project Digital Heroes has been asked to rescue tells some version of that story. The second mistake is signing without a written scope, which reliably turns the winning cheap quote into 1.5x to 2x the price by launch.

How many people should be working on my software project?

Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.

What is a discovery phase, and is it worth paying for separately?

Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.

Can we migrate years of data out of our current system into new custom software?

Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.

What happens if I stop paying for maintenance after launch?

Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.

What does a $50,000 custom software budget actually buy?

One core workflow done properly: 10 to 15 screens, two or three user roles, a couple of integrations, an admin panel, and automated tests, delivered in roughly 12 to 14 weeks. What it does not buy is that workflow plus a mobile app plus AI features plus five more integrations. The discipline of picking the one workflow that matters is what separates $50,000 projects that ship from $50,000 projects that stall at 70% complete.

We run everything on spreadsheets and Airtable. How do we know it's time for custom software?

The reliable signals are re-typing the same data into multiple tools, one employee acting as human middleware between systems, and errors appearing in handoffs between teams. Hard limits force the issue too: Airtable's Team plan caps at 50,000 records per base, and Business costs $45 per seat per month, so a 20-person team pays about $10,800 a year for a tool it has already outgrown. When workarounds consume more hours than the tools save, the spreadsheet era is over.

Why do agencies charge for a discovery phase instead of quoting for free?

Because an accurate quote requires real work: mapping your workflows, finding the edge cases, and writing a specification, which typically takes 1 to 3 weeks and costs $2,000 to $10,000 at Digital Heroes depending on system complexity. You leave discovery owning a written spec and a fixed price you can take to any vendor, so the money is not locked into one agency. Free estimates are guesses, and the guess usually becomes your budget overrun six months later.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply