Industry guide · Internal Tools

Domestic Violence Shelter Software: Meeting Funder Reporting Without Keeping Two Sets of Client Records

Domestic Violence Shelter software visual showing house heart, clipboard pen, and eye off.
The short answer

Expect $60,000 to $130,000 for a first release in 12 to 16 weeks covering confidential client records with strict access control, bed and unit availability, service and hotline logging, and de identified aggregate reporting for your funders. A full system adding safety planning, protective order support, multi programme confidentiality walls, outcome measurement and secure document handling runs $150,000 to $320,000 over 7 to 12 months. For a single agency running one shelter, build is usually the wrong answer and Osnium or Apricot by Bonterra will serve you at a fraction of the cost. The build case belongs to multi programme agencies, state coalitions funding a shared system across members, and agencies whose funder reporting requirements have outgrown what a configured product can produce.

Two sets of records, kept for a good reason

Your funders want detail. VOCA and FVPSA reporting asks for service counts, demographics, outcomes and unmet requests, and your state administering agency has its own template on top. Your legal obligations point the other way. The confidentiality provisions attached to VAWA and VOCA funding prohibit sharing personally identifying information about a survivor without informed, written, reasonably time limited consent, and they specifically prohibit entering that information into shared databases such as a community homeless management information system. That is why domestic violence providers use comparable databases rather than the shared system every other homelessness funded agency in the county uses.

The practical result inside most agencies is two records of the same work. One identified record so advocates can actually serve the person in front of them, and one de identified extract assembled at report time. They are built by different people at different times from the same underlying reality, and they never quite agree. Reconciling them is a week of somebody's quarter, and the discrepancies are impossible to explain because there is no lineage from the aggregate number back to the work that produced it.

The second constraint shapes the technology itself. Shelter location confidentiality is a physical safety matter, not a preference. That affects what the system may store, what it may display, what appears in a URL, what shows in an email notification, what a printed report contains, and what an audit log needs to capture. Most software products treat address as a field. Here it is a risk.

What Osnium and Apricot actually cover

Osnium is built specifically for this sector and understands the domain, including the shape of victim services reporting. Apricot by Bonterra is a broader nonprofit case management platform with wide adoption and real configurability. If you run a single agency with a shelter and an advocacy programme, one of these is very likely the right answer and you should exhaust that path before considering a build.

Where they run short is at the edges that matter most. The first is reporting specificity. Every state administering agency has its own template, its own definitions of a service unit, and its own quirks about how a person served in two programmes should be counted. Configurable products get you close, and the last mile becomes a spreadsheet that somebody rebuilds every quarter.

The second is confidentiality architecture. What most products offer is role based permissions. What this work needs is programme level walls, meaning an advocate in the legal programme cannot see the shelter record for the same person unless a release exists, plus a record of every access, plus a design where the answer to who is in shelter right now is not visible to anyone whose role does not require it. That is a data model decision, not a permissions setting, and it is hard to retrofit.

The third is the hotline. Crisis line contacts are mostly anonymous, frequently do not become clients, and still have to be counted, categorised and reported. Products that assume a client record exists before a service can be logged force advocates to create phantom records, which is both bad data and a confidentiality problem.

Problem one: report from the record, not alongside it

The design goal is that the aggregate report is derived from the same records advocates create in the course of their work, with de identification applied at the reporting boundary rather than by keeping a parallel file. Every service entry carries the programme, the funding source, the service type mapped to your funder's definitions, and the unit measure. The quarterly report then computes from those entries, and every figure can be traced back to its constituent records by someone with the right access.

That traceability is the whole point. When a funder queries a number, you should be able to see what it is made of without reconstructing the quarter. And when the same person receives shelter and legal advocacy, the deduplication rule for reporting should be a defined rule in the system rather than a judgement someone makes differently each time.

Problem two: confidentiality has to be structural

Build the walls into the model. A client record exists once. Programme participation records hang off it, and access is granted per programme. Cross programme visibility requires a release of information that is itself a record with a scope, a date range and an expiry, and the system enforces the expiry rather than trusting anyone to remember it. Access to any identified record is logged with the user, the time and the reason where the situation warrants it.

Then handle the details that cause real harm. Notification emails and text messages should never contain identifying content, because a survivor's device may not be private and neither may a staff member's. Printed and exported documents need watermarking and a record of who exported what, since an export is the most common way confidential data leaves a controlled environment. Search behaviour needs thought, because a system that confirms whether a name exists is disclosing information even when it shows no record. And there must be a documented process for what happens when a court order or subpoena arrives, which is a legal question for your counsel and your state coalition, not a technical one, but the system needs to be able to support whatever answer they give.

Problem three: beds, units and the reality of a full shelter

Availability is not a bed count. It is a bed count constrained by room composition, family size, gender of household members, accessibility needs, pets, and whether two households can safely be placed near each other. An advocate taking a hotline call at two in the morning needs to know in seconds whether a family of five with a dog can be accommodated tonight, and if not, which partner agency to call.

A build should model units and their constraints, hold the current occupancy as a live picture, and support the transfer and referral flow to partner agencies without transmitting identifying information unless a release exists. Waitlist and unmet request logging matters too, because unmet requests are both a funder reporting element and the evidence your agency uses when it asks for more capacity.

Problem four: the hotline and the records that are not clients

Crisis line work is the largest volume of service most agencies deliver and the least well captured. The system needs a lightweight contact log that takes seconds to complete, works while the advocate is still on the call, records call type, presenting issues, referrals given and duration, and does not require a client record to exist. Some contacts later become clients, and there should be a way to link them when consent exists, but the default has to be anonymous.

Cost, timeline and what drives it

In Digital Heroes delivery experience a first release covering confidential client records with programme level access control, bed and unit management, service and hotline logging and de identified funder reporting runs $60,000 to $130,000 in 12 to 16 weeks. Adding safety planning, protective order and court accompaniment tracking, outcome measurement, secure document handling and multi site or multi agency deployment takes it to $150,000 to $320,000 over 7 to 12 months.

Price drivers specific to this sector: the number of distinct funder report formats, since each is real work and they change. Multi agency deployment, which is where a coalition build gets its economics, because one system serving fifteen member agencies costs far less per agency than fifteen licences plus fifteen sets of workarounds. Security review depth, which should be higher here than in most projects and should include penetration testing before go live. Offline or low connectivity capture if advocates work in courthouses and hospitals. And accessibility and language support, since your clients and your staff are not uniform and a system that only works in English excludes people who need it.

What keeps it down: starting with one programme, keeping outcomes measurement for phase two, and using an established hosting platform with proper controls rather than anything bespoke at the infrastructure layer.

When to buy, honestly

If you are one agency with one shelter and one advocacy programme, buy. Osnium and Apricot both cost a fraction of a build and both are better than what a small custom project would produce on the budget you are likely to have. Your money is better spent on advocates. We would say the same thing to any agency that asked us.

The build case is real in three situations. A state coalition funding one system across member agencies, where the per agency economics change completely and the reporting consistency across members becomes a genuine asset. A large multi programme agency running shelter, transitional housing, legal advocacy, child services and a hotline, where the confidentiality walls between programmes are a structural requirement rather than a permission setting. And an agency whose funder reporting has genuinely outgrown configuration, where the quarterly spreadsheet rebuild has become an institution. If none of those describe you, buy the product.

How to choose a developer

Ask whether they have read the confidentiality requirements attached to VAWA and VOCA funding, and ask them to explain why victim service providers do not enter client data into a shared homelessness management system. If they have not encountered this, they will design a normal case management system and you will discover the problem after go live.

Ask how they would prevent identifying information appearing in notification emails, exports and URLs. A developer who has thought about this will answer immediately and specifically.

Ask what their security practice actually is: encryption at rest and in transit, access logging, penetration testing before launch, and how they handle their own team's access to production data during development. Insist that no real client data is used in any non production environment.

Ask how they would handle a subpoena for records, and accept an answer that says this is a legal question for your counsel provided they can describe what the system needs to support. Then settle ownership before kickoff: the repository, the cloud accounts and the right to hire anyone else should be yours in writing. At Digital Heroes the client owns the code from the first commit, and for records this sensitive the agency should never be dependent on a supplier for access to its own data.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. ITIF's 2025 report documents that SMEs operate at roughly 60% of large-firm productivity in advanced economies (citing McKinsey), that CRM platforms deliver a 25-40% improvement in customer retention and a 15-30% boost in sales, and that digital advertising returns about $8 in profit per dollar spent on Google Search and Ads. Source: Information Technology and Innovation Foundation (ITIF) (2025) →
  2. Median SaaS spend reached $9,455 per employee, and organizations leave an average of 36% of their SaaS licenses unused. Source: Zylo (2026) →
  3. Deloitte's research found that digitally advanced small businesses experienced revenue growth nearly 4x as high as the prior year, were about 3x as likely to have exported, were nearly 3x as likely to have created new jobs, and were more than 3x as likely to have seen more sales inquiries in the last year. Source: Deloitte (research summarized by Google) (2017) →
  4. Criteo's Global Commerce Review found retail apps convert at 18% versus 4% on mobile web (roughly 4.5x), and travel apps convert at 20% versus 6% on mobile web (about 3.3x). Source: Criteo (2017) →
Ben S. · Senior SEO Strategist · New York

Ben works on search: site structure, technical crawl issues, content planning and the slow business of earning rankings that hold. Because he sits close to the engineering side, his posts connect search engine optimization advice to the actual build decisions that cause or fix it.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom domestic violence shelter software cost?
A first release covering confidential client records with programme level access control, bed and unit management, service and hotline logging and de identified funder reporting runs $60,000 to $130,000 over 12 to 16 weeks in Digital Heroes delivery experience. A fuller system with safety planning, court advocacy tracking, outcomes and multi agency deployment runs $150,000 to $320,000 across 7 to 12 months. For a single agency the economics rarely justify it, which is why coalition funded builds serving many member agencies are the common shape.
Is Osnium or Apricot by Bonterra enough for our agency?
For a single agency running a shelter and an advocacy programme, usually yes, and we would tell you to spend the difference on advocates. Osnium is built for this sector and Apricot is a widely used configurable case management platform. They run short when your state funder reporting requires a quarterly spreadsheet rebuild anyway, when you need genuine confidentiality walls between programmes rather than role permissions, or when a coalition wants one consistent system across many member agencies.
Why can domestic violence programmes not use the community HMIS?
The confidentiality provisions attached to VAWA and VOCA funding prohibit victim service providers from entering personally identifying information about survivors into shared databases, including a community homeless management information system, which is why providers use a comparable database instead. The requirement also restricts sharing identifying information without informed, written and reasonably time limited consent. Confirm how the rules apply to your specific funding streams with your state coalition and your counsel, since interpretation and state overlays vary.
How do we report to funders without keeping a separate de identified file?
Derive the aggregate report from the same service records advocates create during their work, applying de identification at the reporting boundary rather than maintaining a parallel dataset. Each service entry should carry the programme, funding source, service type mapped to your funder's definitions and unit measure, so every reported figure traces back to constituent records for anyone with the right access. That lineage is what lets you answer a funder query in an hour instead of rebuilding a quarter.
What does confidentiality by design actually mean in this software?
It means the walls live in the data model rather than in permission settings. One client record with programme participation records attached, access granted per programme, cross programme visibility requiring a release of information that carries a scope and an expiry the system enforces, and access logging on identified records. It also means notifications never contain identifying content, exports are logged and watermarked, and search does not confirm whether a person exists to someone without access.
How should shelter bed availability be modelled?
Not as a simple count. Availability depends on unit composition, household size, the gender of household members, accessibility needs, pets and whether two households can safely be placed near one another, and an advocate on a night time hotline call needs the answer in seconds. The system should hold a live occupancy picture with those constraints applied, plus waitlist and unmet request logging, since unmet requests are both a funder reporting element and your evidence when asking for capacity.
How do we log hotline calls that never become client records?
With a lightweight contact log that takes seconds, requires no client record to exist, and captures call type, presenting issues, referrals given and duration while the advocate is still on the call. Systems that force a client record before any service can be logged push staff into creating phantom records, which corrupts your data and creates a confidentiality problem at the same time. Where consent exists later, a contact can be linked to a client record, but anonymous must be the default.
How long does it take to build a victim services case management system?
A first release ships in 12 to 16 weeks. Budget additional calendar time for security review and penetration testing before go live, which should be non negotiable for records this sensitive, and for staff training that covers the confidentiality behaviour of the system rather than just its screens. Agencies that already have documented service definitions and consent forms move faster than those where practice varies by advocate.
Who owns the code and the client data if a coalition funds a shared build?
The coalition or the agencies should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm, agreed in writing before kickoff. With records this sensitive no agency should need a supplier's cooperation to reach its own data or to respond to a legal request. At Digital Heroes the client owns the code from the first commit, and we would also insist that no real client data is ever used in a development or test environment.
What does an internal tool cost for a small business with 20 to 50 employees?
Plan on $5,000 to $15,000 for a focused tool that replaces one painful spreadsheet workflow, such as job scheduling, quoting, or PTO tracking. In Digital Heroes projects at this size, the sweet spot is one core workflow, two or three user roles, and a single integration, usually QuickBooks or Google Workspace. Quotes far below $5,000 usually mean a template with your logo on it rather than software built around your process.
How do I vet a development agency for an internal tools project?
Ask to see two or three internal tools they have shipped and whether those clients still use them daily, because internal tools fail on adoption, not code quality. Good signs: they ask to see your current spreadsheet or process before quoting, they propose a phased build instead of one big launch, and they spell out who handles training and post-launch changes. Walk away from anyone who gives a fixed price before seeing your actual workflow, since internal tools live or die on process details.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
When does a company outgrow Airtable?
The usual breaking points are record limits, permissions, and automation complexity. Airtable's Team plan caps each base at 50,000 records and Business at 125,000, so operations logging thousands of rows a month hit the ceiling within a year or two. The other trigger Digital Heroes sees constantly is permissions: restricting who can view specific fields or records is clumsy below Airtable's Enterprise tier, which becomes a genuine problem once salaries, pricing, or client contracts live in the base.
How do we migrate years of spreadsheet or Airtable data into a new internal tool?
Migration is a standard part of the build, not a separate project: the agency writes import scripts that clean, deduplicate, and map your existing rows into the new database. On typical spreadsheet and Airtable histories, Digital Heroes budgets 3 to 10 extra days, most of it spent resolving inconsistencies like the same customer spelled four different ways. The safe sequence is a trial migration first, a review of flagged conflicts with your team, then final cutover over a weekend so nobody loses a working day.
What does it cost to keep an internal tool running after launch, and do we need to hire a developer?
Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.
Can we start on Airtable or Retool now and move to custom software later?
Yes, and it is often the smartest sequence: run the workflow on Airtable or Retool for 6 to 12 months to learn what you actually need, then go custom once the process stabilizes. The no-code version becomes free requirements documentation, and its data exports cleanly into a custom database. The one risk is waiting too long, because teams stack automations and workarounds until migration becomes a project of its own, so set a concrete trigger in advance, such as hitting Airtable's 50,000-record Team plan cap.
What should I prepare before contacting an agency about an internal tool?
Bring the spreadsheet or document you run the process on today, a list of everyone who touches the workflow and what each person does, and one sentence describing the outcome you want. You do not need wireframes or a technical spec; a 30-minute screen-share of the current process beats a 20-page requirements document. Decide your rough budget band and name a single internal decision-maker, because projects without one take noticeably longer in Digital Heroes experience.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?