Industry guide · Custom Software

Safety Data Sheet Authoring Software: When the Recipe Changes and the Label Does Not

Sds Authoring Chemical Compliance software visual showing barrel, file pen, and triangle alert.
The short answer

If you manufacture formulated chemical products and a recipe change in your enterprise system does not automatically trigger a safety data sheet revision, you are shipping documents that do not match what is in the drum, and a custom build is worth costing. A focused first release covering a live recipe feed from your enterprise system, a classification engine for your home jurisdiction and authoring with a managed phrase library runs $80,000 to $170,000 and ships in 12 to 18 weeks in Digital Heroes delivery experience. A full platform adding multiple jurisdictions and languages, label generation, transport classification and distribution tracking runs $220,000 to $500,000 phased over 9 to 18 months. If you make under roughly 200 formulations that ship to two or three jurisdictions, buy Chemwatch or an authoring service from Verisk 3E and spend the money on your laboratory.

Why the sheet and the drum stop matching

A production chemist substitutes a surfactant because the original supplier is on allocation. The change goes through as a bill of materials revision in the enterprise system, is approved by technical, and runs the following Monday. The safety data sheet for that product was authored fourteen months ago from the previous formulation and lives as a PDF on a shared drive and in a distributor's document portal. Nobody told the regulatory affairs manager, because in the enterprise system a bill of materials revision is a routine event that happens dozens of times a month.

Six weeks later a customer's health and safety team notices the sheet does not mention a hazard class the new component carries. Or worse, a shipment is held at a border because the transport classification on the paperwork does not match the declared composition. Now you are recalling documents and explaining to a customer why your own record of your own product was wrong.

This is the defining failure of chemical compliance software, and it is a plumbing failure rather than a knowledge failure. Your regulatory team knows how to classify. What they do not have is a connection between the system where formulations actually change and the system where documents are produced. In most manufacturers those two systems are joined by a person hearing about a change.

What the incumbents do well and where the gap sits

Sphera, Verisk 3E, Chemwatch, SAP Environment Health and Safety Management and Cority are the established names, and they are not weak products. Sphera and 3E carry deep regulatory content and phrase libraries that would take years to build. Chemwatch is strong on substance data. The SAP module has the advantage of living inside the enterprise system where recipes already are.

The gap appears in two places. First, the classification content is excellent and the workflow around it is generic, so the specific way your business decides things, which technical authority approves a hazard determination, how a customer specific variant is handled, what happens when a raw material supplier changes their own sheet, ends up as email around the product. Second, the connection to a live recipe is usually a periodic extract rather than an event. A weekly file of formulations is not the same as knowing that formulation 4471 changed at 14:20 on Tuesday and its sheet is now stale.

The honest positioning is that you should not build your own substance database. The build that pays is the workflow and integration layer around licensed content.

Problem one: classification has to be recomputed, not remembered

Under the globally harmonised system that most jurisdictions have adopted in some form, classification of a mixture is calculated from its components, their concentrations and their own classifications, using defined rules and cut off values. That is a computation, and computations should be run rather than recalled.

What actually happens in most manufacturers is that classification is a decision made once by a competent person, recorded in a document, and revisited when someone remembers. Every input to that decision can change underneath it. A supplier revises their own safety data sheet and adds a hazard. A jurisdiction adopts a newer revision of the globally harmonised system, as the United States did when the hazard communication standard was updated to align with a later revision. A harmonised classification changes in Europe. Your own formulation changes.

A build worth paying for treats classification as a derived value that is recomputed whenever any input changes, with the result versioned and the derivation stored. That gives you two things you cannot otherwise have. A stale list, meaning every product whose sheet no longer reflects its current classification, available on demand rather than discovered by a customer. And an answer to the audit question of why a product was classified as it was in March, which requires storing the inputs as they were in March.

Problem two: one product is many documents

People outside regulatory affairs think of a safety data sheet as a document. It is a matrix. The sheet for one product varies by jurisdiction, because classification rules and required content differ, and by language, because the sheet must be supplied in the language of the destination. A product sold into a dozen countries can carry dozens of valid current versions, plus the superseded ones you must retain.

Labels are related but not identical: content derives from the same classification but is constrained by physical size, which forces decisions about which precautionary statements to carry. Transport classification is a separate determination under the applicable road, air and sea rules and can differ from the supply classification.

The engineering consequence is that documents must be generated rather than authored and stored. The authoritative object is the product and its versioned classification. The sheet in a given language and jurisdiction is a rendering of that object, produced on demand and archived when issued. Manufacturers who instead maintain a folder of documents per product end up with the drift that started this article, multiplied by the number of countries they sell into.

Problem three: phrase libraries are the quiet maintenance burden

The standardised hazard and precautionary statements are published, and their official translations exist. The rest of a safety data sheet is not standardised. First aid measures, firefighting measures, handling and storage advice and disposal considerations are written text that has to be consistent across your range, appropriate to the hazard, and translated accurately.

This is where in house systems age badly. A phrase library grows organically, translations are done once and never reviewed, and eventually the same hazard produces three different first aid paragraphs because three people wrote them in three different years. Then a large customer reads two of your sheets side by side.

What a system should enforce is that free text lives in a managed library keyed to hazard classes and product families, with a translation state per language, an owner, and a review cycle. Authors select from the library rather than typing, and a request for a new phrase is a governed action. This is unglamorous and it is what makes a document set defensible.

Problem four: distribution is part of compliance, not an afterthought

Issuing a corrected sheet is not compliance. Getting it to everyone who received the previous one is compliance. That means you must know who has which version: which customers, which distributors, which portals, which of your own sites, and in some cases which regulatory notification body.

Most manufacturers cannot answer that. Sheets go out attached to order confirmations, uploaded to portals by sales staff and emailed on request, with no register, so a revision becomes a broadcast to a mailing list that has decayed for years.

A build should treat distribution as a tracked event. Every issue of a sheet to a party is recorded with the version and the date, so a revision produces a precise list of who needs notifying and evidence that they were notified. Where a jurisdiction requires notification of mixture information to a poison centre body, including the unique formula identifier now required in the European scheme, that submission should be generated from the same classification data rather than assembled separately by hand.

What a custom chemical compliance build has to include

  • An event driven feed from the enterprise system so a bill of materials or recipe change immediately marks affected documents as stale, rather than a periodic extract.
  • Classification as a recomputed derived value with versioning, stored derivation and effective dates, covering mixtures calculated from component data.
  • Raw material inbound handling, so a supplier's revised sheet updates component classification and cascades to every finished product that uses it.
  • A managed phrase library keyed to hazard class and product family, with translation state, ownership and review cycles.
  • Document generation on demand per jurisdiction and language, with issued versions archived immutably and superseded versions retained.
  • Label output constrained by physical label size, with explicit rules for which precautionary statements are carried when space runs out.
  • Transport classification handled as a distinct determination for the relevant modal rules, capable of differing from the supply classification.
  • A distribution register recording who received which version when, driving targeted revision notices and providing evidence of notification.

What this costs and how long it takes

A focused first release, meaning the live recipe feed, classification for your home jurisdiction, the phrase library and authoring with generation of the sheet in one or two languages, runs $80,000 to $170,000 and ships in 12 to 18 weeks. A full platform adding further jurisdictions and languages, label generation, transport classification, poison centre notification output and the distribution register runs $220,000 to $500,000 phased over 9 to 18 months.

What drives the number up in this category: the number of jurisdictions, since each has its own required content and its own adoption of a particular revision of the globally harmonised system; the number of languages, because translation governance is ongoing operational cost as well as build effort; label printing integration, which is fiddly and legally sensitive because the label is the artefact a worker actually reads; the state of your enterprise system data, since formulations recorded as text rather than structured components are a data project first; and whether you license regulatory content or maintain rules yourself.

What keeps the number down: start with your home jurisdiction, your top product families by revenue, and licensed substance content rather than your own database. Extending to new jurisdictions afterwards is incremental once the model is right.

When you should not build this

Do not build if you make a modest number of formulations shipping to two or three jurisdictions with a stable recipe set. Chemwatch or an authoring service from 3E will produce compliant documents for less than the build costs, and outsourcing authoring entirely is a legitimate answer at that scale. Do not build if you have no regulatory affairs capability in house, because software does not make classification decisions, competent people do.

Build when two or more of these are true. Recipes change frequently enough that document drift is a standing risk rather than an incident. You ship to enough jurisdictions and languages that the document matrix has outgrown a folder structure. Your raw material suppliers revise their own sheets and you have no cascade. You cannot produce a list of who holds which version of which sheet. Your classification decisions cannot be reproduced from stored inputs when an auditor asks. At that point the link between the recipe and the document is the control, and it needs to be code rather than a person hearing about a change.

How to choose a developer for SDS and compliance software

Ask them how they will detect a formulation change. If the answer is a nightly extract, ask what happens to a product that changed and shipped the same day. The right architecture is event driven from the enterprise system, and a developer who has done this will ask which system holds the authoritative recipe and whether it emits change events.

Ask how they version classification. The correct answer stores the inputs, the rule set version and the result, so any historical determination can be reproduced. If only the current classification is stored, you cannot defend a decision made two years ago.

Ask what they will license versus build. A developer proposing to build a substance database from scratch is proposing to spend your money recreating something Sphera and 3E have spent decades on. The sensible build is the workflow, the integration and the generation layer around licensed content.

Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts and the unrestricted right to hire another firm. At Digital Heroes the client owns the code from the first commit. Note the distinction from licensed regulatory content, which remains the licensor's and carries its own subscription. Your workflow, your integrations and your phrase library should be unambiguously yours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey's Developer Velocity research finds best-in-class tools are the top contributor to software business success, yet only about 5% of executives ranked tools among their top-three software enablers, signaling underinvestment in developer tools (this finding originates in McKinsey's Developer Velocity study rather than the linked generative-AI article). Source: McKinsey & Company (2023) →
  2. McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
  3. Sensor Tower's State of Mobile 2026 reports that global users spent 5.3 trillion hours in iOS and Google Play apps in 2025 (+3.8% YoY), roughly 3.6 hours per day per mobile user. (Note: the page does not itself contrast app time vs. mobile-browser time, so the 'overwhelming majority of time in apps vs browsers' framing is not directly supported by this source.). Source: Sensor Tower (2026) →
  4. Per Sensor Tower's State of Mobile 2026, worldwide consumers spent about $85 billion on apps in 2025 (up 21% YoY), and for the first time non-game apps surpassed games in consumer spending; generative-AI in-app purchase revenue more than tripled to top $5 billion. Source: Sensor Tower (via TechCrunch) (2026) →
Arjun S. · Chief Technology Officer · Delhi

Arjun sets the technical direction for Digital Heroes, choosing the stacks and architectures the delivery teams build on across custom software, ERP and commerce work. His posts explain why one approach gets picked over another, which is usually the part buyers never see.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom safety data sheet authoring software cost?
A focused first release with a live recipe feed from your enterprise system, a classification engine for your home jurisdiction, a managed phrase library and document generation in one or two languages runs $80,000 to $170,000 and ships in 12 to 18 weeks in Digital Heroes delivery experience. Adding further jurisdictions and languages, label generation, transport classification and a distribution register takes it to $220,000 to $500,000 phased over 9 to 18 months.
Why do safety data sheets stop matching the actual formulation?
Because the system where recipes change and the system where documents are produced are usually connected by a person hearing about the change. A bill of materials revision is a routine event in an enterprise system, happening dozens of times a month, and nothing about it marks a document as stale. The fix is event driven: a recipe change immediately flags every affected sheet and label for reclassification, which turns drift from an incident into a work queue.
Should we build our own classification engine or license content?
License the substance and regulatory content, and build the workflow and integration around it. Sphera and Verisk 3E have spent decades assembling substance data and jurisdiction rules, and recreating that is a poor use of a software budget. What is genuinely worth building is the connection to your live recipes, your approval workflow, your phrase governance and your document generation, because those are the parts that are specific to how your business operates.
Is Chemwatch or 3E enough for a mid sized chemical manufacturer?
If you make a few hundred formulations shipping into two or three jurisdictions with a stable recipe set, yes, and outsourcing authoring entirely is a legitimate choice at that scale. The case for building appears when formulations change often, when the document matrix across jurisdictions and languages has outgrown a folder structure, or when your business rules for approval and customer specific variants are being handled by email around the product rather than inside it.
How do you handle one product needing dozens of different sheets?
Treat the product and its versioned classification as the authoritative object, and treat each sheet as a rendering produced on demand for a jurisdiction and language, archived immutably when issued. Manufacturers who instead maintain a folder of authored documents per product get drift multiplied by the number of countries they sell into. The same classification also drives labels, which are constrained by physical size, and transport classification, which is a separate determination that can legitimately differ.
What happens when a raw material supplier revises their own SDS?
In most manufacturers, very little, until a customer notices. Properly handled, an inbound supplier sheet updates that component's classification, which recomputes the classification of every finished product containing it, which marks the affected sheets and labels stale and produces a work queue. Without that cascade your finished product classification silently depends on supplier data that was accurate whenever someone last read it.
How do we know who has an outdated version of our safety data sheet?
You need a distribution register that records every issue of every version to every party, whether that is a customer, a distributor, a portal or one of your own sites. Most manufacturers cannot answer this because sheets go out attached to order confirmations and uploaded by sales staff with no central record, so a revision becomes a broadcast to a decayed mailing list. With a register, a revision produces a precise notification list and evidence that notification happened.
How long does it take to implement SDS authoring software?
A first release typically ships in 12 to 18 weeks, and the schedule risk is rarely engineering. It is the state of your formulation data. If recipes are recorded in the enterprise system as structured components with concentrations, integration is straightforward. If some are text descriptions or live in laboratory spreadsheets, that becomes a data project before the software project starts, and it should be scoped honestly rather than discovered in week six.
Can the same system produce labels and transport documentation?
It should, because all three derive from the same classification, but they are not the same output. Label content is constrained by physical size, which forces explicit rules about which precautionary statements survive when space runs out. Transport classification is a separate determination under the applicable road, air and sea rules and can differ from the supply classification for the same product. Building them from one classification object is what keeps them consistent.
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.
Is a solo freelancer enough for my project, or do I really need an agency?
A solo freelancer is a fine choice for a well-defined build under roughly $15,000 to $20,000 with a limited lifespan: an internal calculator, a scripted integration, a prototype. Above $50,000, or for any system your business will depend on for years, you are buying continuity as much as code: enforced code review, cover when someone is ill, and support that outlasts one person's career plans. Price the risk of a single point of failure, not just the hourly rate.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
What is the biggest mistake first-time software buyers make?
Choosing the lowest quote without asking why it is the lowest. A bid 40% under the field usually gets there by skipping tests, documentation, and code review, which are invisible in a demo and brutal to pay for later; every stalled project Digital Heroes has been asked to rescue tells some version of that story. The second mistake is signing without a written scope, which reliably turns the winning cheap quote into 1.5x to 2x the price by launch.
Who owns the code when an agency builds my software?
You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.
How many people should be working on my software project?
A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.
How do I work out whether custom software will pay for itself?
Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
What questions should I ask a development agency on the first call?
Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?