Skip to main content

Custom software for defense.

Defense industry, aerospace subcontractors, military-component suppliers: required sovereign traceability, ITAR/CMMC compliance, speed-to-field, tamper-proof history by construction. Swoft natively meets these requirements.

01What we solve

Three recurring problems.
The same in most firms.

Before talking software, we talk pain points. If you don't recognize any of these three, we are probably not the right partner for you.

  • 01

    MRO audit trail is rebuilt by hand

    For every maintenance intervention, you must prove to EASA / FAA who did what, when, with which part, from which supplier lot. Today: paper + Excel + multi-day reconstruction for every audit.

    1-3 days to rebuild an MRO audit

  • 02

    US tools aren't sovereign

    American solutions (Maximo, SAP) hosted outside the EU, possible data access via Patriot Act / Cloud Act. Unacceptable for sensitive state contracts.

    Sovereignty risk = ITAR / DGA blocking

  • 03

    CMMC arrives on the US ecosystem

    Cybersecurity Maturity Model Certification: without certification, you lose access to DoD contracts. Levels 2 and 3 demand audit trail and controls most French defense SMEs lack.

    No CMMC L2/L3 = loss of DoD-contract access

02Complex or critical software

The systems that
cannot fail.

When your processes require a replayable audit trail, sagas with compensation, or compliance by construction, we ship an event-driven architecture (DDD + CQRS + Event Sourcing), not a CRUD layered with audit logs.

  • Replayable EASA / FAA aircraft MRO

    Replayable EASA / FAA aircraft MRO

    Every aircraft-maintenance intervention is traced with actor, part, certification reference and supplier lot. Instant reconstruction for EASA or FAA audit, tamper-proof history by construction, sovereign hosting.

    EASAFAAIndustrial ERPs
  • ITAR / CMMC level 2 by construction

    ITAR / CMMC level 2 by construction

    Strict access control by clearance and nationality, full traceability of access to sensitive data, tamper-proof register of technology transfers. Native CMMC level 2 compliance.

    ITARCMMCEnterprise AD
  • Multi-customer supply-chain steering

    Multi-customer supply-chain steering

    Per-program steering (Airbus, Safran, Thales, Dassault, MBDA) with strict compartmentalization: a failure on one program cannot contaminate the others. Clean cross-program rollback, history consultable per customer.

    Airbus EDISafran EDIThales EDI
  • DO-178C / DO-254 signed documentation

    DO-178C / DO-254 signed documentation

    Critical avionics software and hardware documentation: each version is eIDAS-signed, archived per its classification (DO-178C levels A to E), approvals are traced. Compliant with critical aerospace audits.

    DO-178CDO-254Yousign
03Mobile and web applications

The day-to-day apps,
screen by screen.

For everything else (CRM, portals, scheduling, billing), we ship a custom application, on your design system and with your existing integrations.

  • Programs console

    Programs console

    Per-program view (Rafale, A400M, etc.) with contractual milestones, deliveries, quality indicators. For industrial and program management.

    Industrial ERPs
  • DGA / EASA reporting

    DGA / EASA reporting

    Automatic generation of regulatory reports (DGA, EASA, FAA) from history. No reconstruction, no fragile batch. Quality audit passed in hours.

    DGA platforms
  • Secure supplier portal

    Secure supplier portal

    For your subcontractors: secure portal for sending parts (CMR, 3.1), order tracking, certificate transmission. Strong authentication with clearance.

    EDI EDIFACT
  • Industrial-management dashboard

    Industrial-management dashboard

    Program KPIs, OTD (On Time Delivery) indicators, per-customer quality, plant load. Consolidated view for management committee.

    Power BI
04Regulations & integrations

What we handle natively,
no add-ons.

Business compliance and key integrations are not options, they are prerequisites built in from the start.

  • EASA / FAA

    Aerospace, MRO intervention traceability

  • ITAR

    International Traffic in Arms Regulations (US)

  • CMMC

    Cybersecurity Maturity Model Certification (DoD)

  • DO-178C / DO-254

    Critical avionics software and hardware

  • EN 9100 / AS 9100

    Aerospace and defense quality

  • SecNumCloud

    ANSSI-qualified sovereign hosting

05Frequently asked questions

Answers to the questions we get in meetings.

Truly sovereign hosting?
Yes. SecNumCloud (ANSSI-qualified), Outscale (sovereign EU host), or customer on-premise depending on your constraints. No AWS/GCP/Azure, no Patriot Act or Cloud Act applicable.
Does the audit trail hold up against DGA / EASA?
Yes, designed for that. Each event is electronically signed at creation. Tamper-proof by construction, replayable identically five years later. Patented mechanism.
CMMC level 2 or 3 reachable?
L2 reachable natively with the Swoft architecture (audit logs, access control, at-rest and in-transit encryption). L3 requires complementary controls we identify in scoping.
Do you replace Maximo / SAP?
Not the SAP / Maximo core. We complement with the missing modules: sovereign audit trail, avionics document management, compartmentalized supply chain. Synchronization.
How much does it cost?
Subject to functional-scope engagement, no catalogue price. Free 48-hour scoping. Typically €200-500k for a delivered critical defense module, on-premise possible.
06Related industries

Mixed firms (accounting + audit, accounting + advisory, accounting + legal) draw from several industries. Here are those that share the most challenges.

07Articles & veille

L'actualité Defense, décryptée.

Réglementations, virages business, sous-domaines en mutation : ce que notre pôle veille publie sur le secteur Defense.

  • Defense & sovereignty 2026: SecNumCloud becomes mandatory
    Centre de données souverain avec normes de sécurité défense

    Defense & sovereignty 2026: SecNumCloud becomes mandatory

    With the "Cloud at the center" doctrine tightened in 2024 and the LPM 2024-2030, French defense industrials and their subcontractors discover that no non-sovereign cloud is acceptable anymore.

Glossaire connexe

Le cadre réglementaire qui structure Defense.

Les réglementations qui pèsent sur les choix logiciels (appliquées, partielles, ou imminentes), décryptées par notre pôle veille.

  • Network and Information Security 2, Directive (UE) 2022/2555
    In force

    NIS2

    Network and Information Security 2, Directive (UE) 2022/2555

    Directive cybersécurité européenne applicable depuis octobre 2024. Élargit le périmètre aux SaaS, datacenters, transporteurs, alimentaire.

    • B2B SaaS
    • Banking
    • Clinic & Health
    • +3
  • Règlement (UE) 2024/1689 sur l'intelligence artificielle
    Partially in force

    EU AI Act

    Règlement (UE) 2024/1689 sur l'intelligence artificielle

    Premier cadre horizontal mondial de régulation de l'IA. Obligations IA haut risque applicables le 2 août 2026.

    • B2B SaaS
    • Banking
    • Defense
    • +1

A defense or aerospace SME wanting sovereign and auditable?
30 minutes, no sales pitch.

30 minutes with Derick (CTO, ex-Alstom, Novartis) to scope your need and price the sovereign solution.