Industry guide · Internal Tools

International Student SEVIS Compliance Software: Why a Rejected Batch Record Sits Unnoticed Until the Site Visit

International Student Compliance software visual showing stamp, calendar clock, and cloud upload.
The short answer

Expect $70,000 to $150,000 for a first release in 12 to 18 weeks covering SEVIS batch submission with a genuine result reconciliation loop, term registration driven by live enrolment from your student information system, and document issuance, and $180,000 to $400,000 phased over 6 to 12 months for a full platform adding advising case types and student e forms, CPT and OPT recommendation workflows with post completion tracking, J exchange visitor management and audit reporting. Those are Digital Heroes delivery bands. Be aware this is a category where we tell most institutions to buy: Sunapsis and Terra Dotta ISSS are built specifically for this and the compliance risk of a home grown mistake is your ability to enrol international students at all. Build when you run several SEVIS school codes across campuses, when a medical centre or research office manages exchange visitors separately, or when your enrolment rules are too local for a packaged registration engine.

Why the risk here is different from every other campus system

Most administrative software fails in ways that cost money or time. This one fails in a way that costs an institution its Student and Exchange Visitor Program certification, and with it the ability to enrol F and J students. That is a revenue line most universities cannot replace, and it is why the international student and scholar services office behaves differently from every other office on campus.

The failure mode is not dramatic. A batch of records goes to SEVIS overnight. Eleven come back with errors, in a result file that nobody opens because the process was set up years ago by someone who has since left, and the person running it now believes that no news is good news. Six months later, a site visit asks why forty two students were never registered for the term. Nobody was negligent. The loop was never closed.

In our experience with institutions in this space, the underlying problem is almost always the same. SEVIS work is submission plus reconciliation, and most implementations treat it as submission. The government's system is the record of truth, your system holds what you believe, and any difference between them is a compliance gap that grows silently. Everything else, the advising, the e forms, the document generation, is comfort. The reconciliation is the job.

Problem 1: batch reporting without a result loop is a liability

The SEVIS batch interface accepts an XML submission and returns a result identifying which records were accepted and which were rejected, with error codes. That is a well designed contract and it works. What institutions build around it varies enormously.

A serious implementation treats every submitted event as an outstanding obligation until SEVIS confirms it. Each event carries a state: queued, submitted, accepted, rejected with a code, corrected and resubmitted. Rejections are triaged automatically where the cause is mechanical and routed to a named adviser where judgement is required, with an ageing clock, because an unresolved rejection is a reportable event that did not happen. There is a daily reconciliation that compares your record set to what SEVIS holds and surfaces divergence rather than assuming agreement. And there is an alarm when a batch does not run at all, which is the single most common failure we find when we inherit these systems, since a silent scheduler is indistinguishable from a clean night.

The schema also changes on the government's timetable, not yours. Any build must treat schema version as configuration with a validation layer that fails loudly against the current version before submission, rather than discovering an incompatibility from a rejection file after the deadline has passed.

Problem 2: enrolment truth lives in the student information system, and it moves daily

Term registration reporting requires knowing who is actually enrolled, at what load, with which exceptions authorised. Full course of study rules, the limits on online study, authorised reduced course loads for medical or academic reasons, programme extensions and level changes all determine what should be reported and when. That data lives in Banner, PeopleSoft, Workday or Colleague, and it changes throughout add and drop.

The pattern that fails is an export at a point in time. A student drops below full time on the last day of the add and drop period, after the export, and the record reported to SEVIS says something that is no longer true. The pattern that works is a continuous read with rules evaluated as data changes, so a student falling below the threshold generates an adviser task the same day and a reportable event only after the adviser has determined whether an authorisation applies.

This integration is where most of the real engineering sits. It is also where local rules concentrate: how your institution defines full time for a thesis student, how a graduate assistantship counts, how your medical school's block scheduling maps to credits, how a consortium or cross registration arrangement is treated. Packaged products handle the common cases well and are configured against a model. Institutions whose academic structures do not fit that model end up maintaining a spreadsheet of exceptions, which is the signal that a build might be warranted.

Problem 3: practical training is a case type, not a form

Curricular and optional practical training bring workflow that continues long after the recommendation is made. A curricular training authorisation ties to a specific course, employer and date range. Post completion optional practical training brings an unemployment day count that the student must manage and the institution should be watching, employer reporting obligations, and for eligible students a science and technology extension with its own reporting cycle and employer requirements.

Students in this phase have often left campus, which means the interface they use has to work on a phone, send reminders that land, and accept employer details without an adviser retyping them. The office needs a view of who is approaching a threshold, not a list of everyone. Institutions that do this badly discover the problem when a student's status is terminated for something that a reminder would have prevented, and the human cost of that is the reason experienced advisers are so protective of their processes.

A build should treat each of these as a case type with its own required evidence, its own clocks and its own reportable events, all feeding the same batch pipeline. If practical training is modelled as a form that produces a document, the tracking will fall to a spreadsheet within a year.

Problem 4: exchange visitors are a different programme with different obligations

J category exchange visitors are not F students with a different form. The programme has its own categories with their own duration rules, insurance requirements set by the Department of State that the sponsor must verify and monitor, site of activity reporting, and the home residency requirement that affects a visitor's future options and therefore every conversation you have with them.

At many institutions the J population is administered partly outside the international office, particularly research scholars sponsored through a medical centre, a national laboratory relationship or a research administration unit. That split is where records diverge, and it is one of the clearest cases for a custom build, because the requirement is a single compliance picture across units whose processes and staffing are genuinely different rather than accidentally different.

Problem 5: advising volume is the daily reality and the reason staff resist change

An office serving several thousand students runs on e forms and case queues: travel signature requests, programme extensions, change of level, reduced course load petitions, transfer out requests, employment questions, letters for driving licences and social security applications. Hundreds of case types, each with required documents and an approval path.

This is the part packaged systems do well, and it is worth being honest about that. Sunapsis in particular was built inside a large university's international office and it shows in the workflow design. If your advising process is conventional, replicating it from scratch is an expensive way to reach a similar place. The build case is not that you can design better forms. It is that your compliance and enrolment logic is genuinely local, or that your organisational structure spans SEVIS school codes and units in a way the product cannot represent, and that the advising layer has to sit on top of that model rather than beside it.

What this costs and how long it takes

A first release covering batch submission with full result reconciliation and alerting, term registration driven by continuous enrolment reads, document issuance and the core reportable events runs $70,000 to $150,000 and ships in 12 to 18 weeks. A full platform adding advising case types and student e forms, practical training workflows with post completion tracking, exchange visitor management including insurance verification, and audit and site visit reporting runs $180,000 to $400,000 phased over 6 to 12 months.

What drives cost up: the number of SEVIS school codes and campuses, since each carries its own officials and its own reporting. Student information system integration depth, which is the largest single line and is different for Banner, PeopleSoft, Workday and Colleague. Local academic structures that complicate full course of study determination, such as medical and law programmes or block scheduling. A separate exchange visitor administration unit that must be brought into one picture. Single sign on and the security review your information security office will require. And accessibility conformance, which belongs in the build rather than in remediation.

What keeps it down: implementing the reconciliation loop and registration reporting first, keeping your existing e form process for a phase, and migrating advising workflows once compliance is provably solid.

Build versus buy, and when buying is the right call

We say buy more often in this category than in almost any other we write about. If you are a single campus with one SEVIS school code, conventional academic structures and an international office running standard advising, Sunapsis or Terra Dotta ISSS is the right decision. They encode years of compliance detail, they track regulatory change as part of the product, and the downside of a home grown gap is certification risk rather than an inconvenience. Buy also if your office is short staffed, because a build needs your most experienced adviser's attention for weeks and taking that person off the queue has its own compliance cost.

Build when two or more of these are true. You operate several SEVIS school codes across campuses and need one compliance picture with per code separation. Your exchange visitor population is administered by a medical centre or research office outside the international office and the records already diverge. Your academic structures require so many exceptions to the packaged registration logic that staff maintain a parallel spreadsheet. You need workflows and data joined to systems the product does not integrate with, for example a research administration platform or a payroll system for on campus employment. Or you have inherited an existing custom system that works but has no reconciliation loop, which is a rebuild of a specific part rather than a whole platform and is the most common engagement we see here.

How to choose a developer for SEVIS compliance software

Ask them what happens when a batch record is rejected at 2am. The answer must include a state machine per event, automatic triage of mechanical errors, routing of judgement cases to a named adviser with an ageing clock, and an alarm when the batch did not run at all. If they describe submitting a file and logging the response, they will build the exact failure this office fears.

Ask how they will keep enrolment current. A nightly export is not an answer for add and drop week. A continuous read with rules evaluated on change is.

Ask what they have integrated by name, and be specific about your student information system and its version. Ask whether they have worked with a regulated government interface where the schema changes on someone else's timetable, and how they version and validate against it before submission rather than after rejection.

Ask who owns the code and settle it in writing before kickoff. You should hold the repository, the cloud accounts and the right to hire another firm, and given that this system holds immigration records for your students, encryption, role based access and retention should be settled in the same conversation. At Digital Heroes the client owns the code from the first commit. Then ask the developer directly whether they think you should build at all. In this category, a firm willing to tell you to buy Sunapsis is a firm worth hiring for the parts you genuinely need.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  2. Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
  3. The average number of formal learning hours used per employee fell to 13.7 in 2024, down from 17.4 in 2023, a decline the report attributes partly to a shift toward informal and on-the-job learning not captured in the formal-hours metric. Source: Association for Talent Development (ATD) (2025) →
  4. Flexera's 2025 State of the Cloud Report (survey of 750+ technical and executive leaders) found that 84% of respondents believe managing cloud spend is the top cloud challenge for organizations today, with cloud budgets already exceeding limits by 17%. Source: Flexera (2025) →
Mei L. · VP APAC · Sydney

Mei runs the APAC side of Digital Heroes from Sydney, where the work spans custom software, ERP and CRM builds, and commerce platforms. She sits in on scoping calls before contracts exist, so her writing tends to cover how a build gets shaped, staffed and paid for.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

Should we build custom SEVIS compliance software or buy Sunapsis?
In this category we tell most institutions to buy. Sunapsis and Terra Dotta ISSS encode years of compliance detail and track regulatory change as part of the product, and the downside of a home grown gap is your certification to enrol international students rather than an inconvenience. The build case is narrow: several SEVIS school codes across campuses, exchange visitors administered by a medical centre or research office outside the international office, or academic structures that force staff to maintain a parallel spreadsheet of registration exceptions.
How much does custom international student compliance software cost?
A first release with batch submission and full result reconciliation, term registration driven by continuous enrolment reads and document issuance runs $70,000 to $150,000 and ships in 12 to 18 weeks in Digital Heroes delivery experience. A full platform adding advising case types, practical training tracking, exchange visitor management and audit reporting runs $180,000 to $400,000 phased over 6 to 12 months. Student information system integration is the largest single line and differs meaningfully between Banner, PeopleSoft, Workday and Colleague.
Why do SEVIS batch failures go unnoticed for months?
Because most implementations treat batch as submission rather than submission plus reconciliation. A file goes overnight, a result file comes back with rejected records, and nobody opens it because the process was set up by someone who has since left. The fix is to treat every submitted event as an outstanding obligation with a state until SEVIS confirms it, triage mechanical errors automatically, route judgement cases to a named adviser with an ageing clock, and alarm when the batch did not run at all.
How do you keep SEVIS registration accurate through add and drop week?
Read enrolment continuously from the student information system and evaluate rules as the data changes, rather than exporting at a point in time. A student who drops below full time on the last day of add and drop should generate an adviser task the same day, and a reportable event only after the adviser determines whether an authorised reduced course load or another exception applies. Point in time exports are how institutions end up reporting something that stopped being true hours later.
Can software track OPT unemployment days and STEM extension reporting?
It should, and it should treat practical training as a case type with its own clocks and evidence rather than a form that produces a document. Students in post completion training have usually left campus, so the interface has to work on a phone, send reminders that actually land, and accept employer details without an adviser retyping them. The office needs a view of who is approaching a threshold, not a list of everyone, so that intervention happens before a status problem rather than after.
How should J-1 exchange visitors be handled differently from F-1 students?
As a separate programme rather than a variant. Exchange visitor categories carry their own duration rules, sponsor obligations including verification and monitoring of Department of State insurance requirements, site of activity reporting, and a home residency requirement that shapes every advising conversation. The practical complication at many institutions is that research scholars are administered by a medical centre or research office outside the international office, which is exactly where records diverge and where a single compliance picture is worth building.
What happens when the SEVIS schema changes?
Treat schema version as configuration with a validation layer that fails loudly before submission rather than discovering an incompatibility from a rejection file after a deadline. Government interfaces change on the government's timetable, so the build needs a clear upgrade path, a test harness against the new version, and the ability to run validation without submitting. This is one of the strongest arguments for buying a product, because tracking that change is part of what a vendor is paid to do.
How long does it take to implement, and when should we go live?
Twelve to eighteen weeks for a first release, and you should never cut over mid term. Go live between terms with the reconciliation loop and registration reporting first, running the previous process in parallel for one reporting cycle so any divergence is visible while both exist. Budget your most experienced adviser's time properly, because their knowledge of local exceptions is the specification, and taking them off the advising queue has its own compliance cost.
Who owns the code if an agency builds our ISSS platform?
You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm, agreed in writing before kickoff. Because the system holds immigration records for your students, settle encryption, role based access and retention in the same conversation. At Digital Heroes the client owns the code from the first commit, and in this category we would also expect a developer to tell you honestly which parts you should buy instead of build.
When does a company outgrow Airtable?
The usual breaking points are record limits, permissions, and automation complexity. Airtable's Team plan caps each base at 50,000 records and Business at 125,000, so operations logging thousands of rows a month hit the ceiling within a year or two. The other trigger Digital Heroes sees constantly is permissions: restricting who can view specific fields or records is clumsy below Airtable's Enterprise tier, which becomes a genuine problem once salaries, pricing, or client contracts live in the base.
What questions should I ask a development agency on the first call?
Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.
Should we build our internal tool in Retool instead of hiring developers?
Retool is the right choice if someone on your team is comfortable with SQL and JavaScript and the audience is a handful of technical users, because a basic CRUD dashboard comes together in days. Hire developers when non-technical staff will use the tool daily, when the logic goes beyond forms sitting on a database, or when per-seat pricing stings, since Retool's Business tier lists at $50 per standard user per month. A pattern Digital Heroes sees often: companies arrive after a year on Retool with a tool nobody can maintain because the one person who built it has left.
Will a custom internal tool scale as our company grows?
Yes, provided it sits on a standard stack with a real database: PostgreSQL comfortably handles millions of records, and adding users costs hosting pennies rather than per-seat fees. The real scaling risks are organizational, not technical: new departments want features, processes change, and the tool needs a budget line to evolve. Set aside a small quarterly improvement budget instead of treating launch as the finish line, and the tool stays useful for a decade rather than getting rebuilt every two years.
Can a custom internal tool connect to QuickBooks, Salesforce, and the other software we already use?
Yes, and integrations are usually the strongest argument for going custom instead of chaining tools together with Zapier. QuickBooks, Salesforce, Shopify, Stripe, Slack, and Google Workspace all have mature APIs, and each integration typically adds $1,500 to $5,000 to a Digital Heroes build depending on how much two-way syncing you need. The honest caveat is legacy industry software without an API, which may need file-based imports instead of a live connection, so list every system in the first conversation.
What should I prepare before contacting an agency about an internal tool?
Bring the spreadsheet or document you run the process on today, a list of everyone who touches the workflow and what each person does, and one sentence describing the outcome you want. You do not need wireframes or a technical spec; a 30-minute screen-share of the current process beats a 20-page requirements document. Decide your rough budget band and name a single internal decision-maker, because projects without one take noticeably longer in Digital Heroes experience.
What does it cost to keep an internal tool running after launch, and do we need to hire a developer?
Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?