entare

Engineering for software that has to survive scrutiny.

We take ideas and prototypes to production-ready products, for industries where the software will be audited, assessed, or trusted with sensitive data.

A product, weighed
grossa product a customer will buy100
tarewhat a demo shows−20
netwhat still has to be built80
The missing 80%, itemised →
17 years·fixed price·Coffs Harbour, Mid North Coast·working Australia-wide
01 The gap

Anyone can produce a prototype now. Almost nobody can produce a product their customer's security review will accept.

The demo takes an afternoon. The rest takes judgement: keeping one customer's data genuinely separate from another's, proving who did what and when, handling documents safely, surviving a questionnaire from an insurer or a government department, and still being maintainable in two years by someone who is not you.

That gap is the whole of our work.

02 What we do
01

Idea or prototype to production

AI tools now produce convincing mockups in an afternoon. They do not produce a product an enterprise, a government department or an insurer will buy. If you have no prototype at all, that is fine: we can build a working clickable version early, and it doubles as the specification for everything that follows, which is far cheaper than discovering the requirements halfway through a build.

The missing 80% is what we build: multi-tenant architecture that keeps customers' data genuinely separate, authentication and access control, audit trails, encryption and key handling, file and document pipelines, deployment, backups and restore, tests that catch regressions, and the operational runbooks that let someone else keep it alive.

Getting to your first paying customer usually takes more than software, so a build can include the launch pieces: a landing page, product copy that says what the thing actually does, onboarding emails, and a demo walkthrough you can send to prospects.

02

Compliance-grade engineering, and documentation that matches it

Two halves of the same problem, usually bought from two different suppliers, which is exactly why they so rarely agree with each other.

The engineering: data residency, tenant isolation with automated proof, immutable audit records, access control that survives review, and evidence an auditor can follow without a scramble. The documentation: system security plans, incident response and continuous monitoring plans, policies, control matrices, and the evidence pack an assessor or an enterprise customer will ask for.

We do both, so the document describes what the system actually does. Whether the standard is ISO 27001, the Essential Eight, privacy obligations, IRAP, or a customer's own security questionnaire, the work underneath is largely the same, and it is the part most teams postpone until a deal depends on it.

This is readiness and remediation. We are not accredited assessors, and we refer assessment itself out, which keeps the independence line clean.

03

AI features that hold up under questioning

Most AI in products is demo-ware: impressive until someone asks how it knows that. We build the defensible version. Answers cite verifiable sources or they do not ship. An evaluation harness catches quality regressions before customers do. Human decisions stay in the record with attribution. Costs are capped and metered. Customer data trains nobody's model, and inference stays in Australia when it needs to.

03 How it runs

Fixed scope, fixed price, milestones.

You know the number before we start, and you pay against delivered milestones rather than hours consumed.

01A callThirty minutes. What you are building, what it has to survive, and whether we are the right people for it.
02Discovery sprintTwo or three days. You get an architecture, a written build plan with phases, a risk list, and a firm quote. If you take that plan and build it elsewhere, that is a legitimate outcome and the plan is yours.
03The buildDelivered in milestones you can see working, not status reports. Handover includes documentation, runbooks, and the knowledge to run it without us.
04After launchA care plan keeps it patched, backed up, monitored and current, or we hand it to your own team and step away.
04 What it costs

Published, because you should not have to sit through a call to find out.

EngagementDurationIndicative
Discovery sprint: architecture, plan, firm quote2 to 3 daysfrom $2,800
Clickable prototype that becomes the build specification1 weekfrom $6,000
Production build, from a prototype or a clear brief6 to 12 weeks$30,000 to $80,000
Compliance readiness: controls, documentation, evidence pack2 to 8 weeks$12,000 to $45,000
Security and architecture review of an existing product1 weekfrom $5,000
Independent test and quality pass before a launch or an audit1 weekfrom $4,500

Prices exclude GST and cloud costs, and durations are elapsed time from the start of work to delivery. The review and the quality pass are standalone: you get written findings and a prioritised list, not a rebuild. If a full build is more than you want to commit to at once, it can be staged: a working core that earns its first customer, then extensions paid from revenue rather than savings.

05 After launch

Software that stops being maintained stops being sellable.

Dependencies age, certificates expire, cloud providers deprecate things, and your customers' security questionnaires get harder every year. Care plans cover that, priced on outcomes rather than counted hours.

What the plan coversManagedCarePartner
Infrastructure managed, patched, monitoredIncludedIncludedIncluded
Backups run and restore-testedIncludedIncludedIncluded
Security updates and dependency currencyIncludedIncludedIncluded
Incident response, business hoursnext daysame daypriority
Fixes and small changes, batched monthlyNot includedIncludedIncluded
Scheduled development time each monthNot includedNot included2 days
Roadmap and architecture inputNot includedNot includedIncluded
From$650/mo$1,200/mo$4,200/mo

You own your cloud account and your data throughout, and we manage it inside your tenancy, so there is no lock-in and no question about who holds what. Larger changes are quoted as fixed-price pieces of work rather than billed hourly. Plans run month to month after an initial three months, and you can leave with everything documented.

06 Who does the work

Senior people, doing the work themselves.

You will not be handed to someone else after the sale.

Arun Jose

Engineering · architecture · security

Seventeen years in software, much of it on systems that are audited before they are trusted, and his own software company since 2021. He owns products end to end: architecture, security, payments, deployment and delivery.

  • Cybersecurity compliance platform, sole engineer. A SaaS platform for IRAP, Essential Eight and NIST CSF assessments, in production across cloud and air-gapped deployments: multi-tenant billing, single sign-on and permission-based access, and offline licensing for disconnected environments.
  • Free public tool for the Australian Government Information Security Manual, built solo. The manual's controls, searchable and browsable, for IRAP assessors and anyone doing Essential Eight work.
  • AI learning and memory retention app, built and shipped. Released in 2023, when large language models were new, and among the early commercial products built on their APIs: notes turned into summaries and revision cues, quizzes generated from them, and an AI tutor to answer questions on the material.
  • Learning platforms for nurses and for schools. Designed and built, with Matrix Health, a learning management platform adopted by the Australian Nursing and Midwifery Federation and the Queensland Nurses and Midwives' Union, and another used in schools.
  • Enterprise and government delivery at national scale. From 2009 to 2021 at Janison, part of the team behind its assessment and learning platforms, including the platform that became the basis of NAPLAN Online. Delivery across 50 or more client organisations including ASIC, Deloitte, ADFA, Corrective Services, Ramsay Health, David Jones, city councils, universities and banks.
Master of Information Technology (Internet Security), Macquarie University
Master of Information Technology (Web Technologies), University of Wollongong
Red Hat Certified Engineer
07 What we do not do

Naming these saves us all time.

  • Staff augmentation. We do not sit inside someone else's team as an extra pair of hands.
  • Pager duty. Care plans respond during Australian business hours, and systems are built so that nights and weekends stay quiet.
  • Open-ended hourly work. Scope is fixed and priced before it starts, or it is quoted as a separate piece.
  • Brochure websites. We build the software behind a business, not its marketing site, and we will happily point you to a good local designer.
  • More than one build at a time. Compliance and quality work can run alongside, but if we are booked we will tell you when we are free rather than take your money and stretch.
08 Next step
A 30-minute call, and an honest answer.

Tell us what you are building and what it has to survive. If we are not the right people for it, we will usually know someone who is.

We reply within one business day. No newsletter, no follow-up sequence, no data going anywhere else. Privacy

Or reach us directly.

We are based in Coffs Harbour and build software and web applications for businesses across the Mid North Coast, from Port Macquarie to Grafton, as well as remotely for clients Australia-wide. If you would rather talk in person first, that is easy to arrange.

Entare Pty Ltd · ABN 13 701 106 658
Coffs Harbour, Mid North Coast NSW · in person locally, remote across Australia
· The name
Tare is the weight of the container, the part you subtract so you know what is actually there. En-tare: weigh what is actually there. It also turns out to be hiding in what we do: ENgineering for sofTwARE.