"Finding a software partner you can trust is difficult - especially after being burned before. With Bon.do, there are no surprises: estimates hold, quality is consistently first-class, and I never feel like 'just another customer'. Morten and Kirsten genuinely care about our success - they think proactively about solutions before problems arise. It's so liberating working with experienced software experts who both deliver on their promises and maintain world-class quality standards. I warmly recommend them to any company seeking a partner - not just a supplier."

App and Software Development for Life Science, Built in Denmark
bon.do is a Danish software development company based in Svendborg, Denmark. We specialise in app development and software development for the life science industry: medical device manufacturers, pharmaceutical companies, biotech teams and healthcare organisations that need digital solutions they can trust in regulated environments.
Our quality management system is built around ISO 13485, the international standard for medical device quality. Every project follows documented design controls, risk management and full traceability from the first requirement to the final release. Whether your product is regulated under MDR, IVDR or FDA rules, or must meet GxP requirements, compliance is built into our development process rather than added afterwards.
We deliver the full scope of life science software development: native and cross-platform app development for iOS and Android, web applications, backend systems, IoT platforms and system integration. Our services also include software validation, verification and audit preparation, so your team receives both a compliant, well-documented solution and the documentation that proves it.
We work as an extension of your own team. You own all code, data and intellectual property from day one, with no vendor lock-in and no hidden dependencies. Agile sprints keep progress visible every two weeks, and our developers communicate directly with your stakeholders in both Danish and English.
If you are looking for a software development partner in Denmark who understands both engineering and regulation, we would like to hear about your project. Contact us for a free project assessment and a concrete roadmap for your next app or software solution.
Professional App & Software Development Solutions
We develop complete digital solutions - from modern mobile apps and web applications to robust backend systems and cloud platforms. With specialized expertise in Life Science, med-tech, and regulatory compliance including ISO 13485, MDR, and GxP.
Software Development
Custom software development tailored for Life Science applications, focusing on security, compliance, and scalability.
IoT Solutions
Innovative IoT devices and platforms for monitoring and data collection, including complete ecosystem development from sensors to user interfaces.
Validation and Verification
We ensure your products and processes meet all requirements through validation, testing, and verification, ensuring documented safety and high performance.
System Integration
Seamless integration of systems and APIs, creating cohesive digital solutions that enhance operational efficiency.
Data Security
Protecting patient data is our priority. Our solutions are built with multiple layers of security to safeguard the most sensitive information.
Regulatory Compliance
We provide audit preparation and strategic compliance analysis to ensure your product meets GxP/ISO requirements.
Advanced Software & App Development, Simplified UX
Transforming complex Life Science challenges into elegant, user-friendly software and mobile app solutions.
At bon.do, we transform challenging technical requirements into elegant solutions that create real business value. We combine advanced engineering with deep domain knowledge to build systems that solve complex problems while remaining intuitive for end users.
Value We Deliver:
- Expertise in Life Science software and app development
- Reduced time-to-market through efficient development practices
- Lower maintenance costs with clean, maintainable architecture
- Regulatory compliance built into the development process
- Scalable solutions that grow with your business needs
- Competitive advantage through exceptional user experiences
Example: We helped a healthcare client transform patient care through a smart diaper monitoring system connecting IoT sensors with real-time mobile alerts improving care efficiency while maintaining regulatory compliance.

Powered by Modern Tech
We build on a foundation of industry-leading technologies.
What Our Customers Say
Hear from companies we've helped
Latest Insights
Explore topics on software development, compliance, and digital ownership in Life Science. Essential reading for companies seeking a reliable software partner.
AI in Life Science Software: Validation, Bias & Regulatory Hurdles
Practical guide for validating AI in Life Science Software (SaMD), mitigating bias, and navigating MDR/IVDR & EU AI Act hurdles.
Read ArticleYour Digital Ownership: A Critical Guide When Choosing a Software Partner
Understand the critical importance of owning your code, data, and domain when working with development partners. Avoid vendor lock-in and protect your investment.
Read ArticleFrequently Asked Questions
Get answers to the most common questions about life science software development, validation, and compliance.
The validation process includes User Requirements Specification (URS), Design Qualification (DQ), Installation Qualification (IQ), Operational Qualification (OQ), Performance Qualification (PQ), and ongoing maintenance. For life science companies, all critical systems must be validated according to ISO 13485, IEC 62304, and relevant GxP guidelines.
1. Data Mapping: Identify all personal data (patient data = special categories under GDPR Article 9)
2. Legal Basis: Establish lawful basis (consent, legitimate interest, legal requirement)
3. Technical Security: Encryption (TLS 1.3, AES-256), pseudonymization, access control (RBAC), audit logging
4. Organizational Measures: DPIA for high-risk processing, data processing agreements, breach response procedures
5. Data Subject Rights: Implement functionality for access, deletion, and data portability
For healthcare software, combine GDPR with ISO 27001 and ISO 13485 requirements.
1. Regulatory Expertise: Experience with MDR/IVDR/FDA requirements
2. Industry Experience: Life science portfolio and domain knowledge
3. Quality System: Working knowledge of ISO 13485 and an established QMS approach
4. Technical Competence: Relevant technology stack and modern architecture patterns
5. Transparent Processes: Agile methodology with comprehensive documentation
6. References: Case studies and client testimonials
7. Post-Launch Support: Maintenance, updates, and regulatory updates
Learn about our expertise or schedule a consultation.
ISO 27001: Information security management, focusing on data security, confidentiality, and cyber threat protection.
Overlap: Both require risk management, comprehensive documentation, and continuous improvement.
For Life Science: Most medical software companies need BOTH certifications - ISO 13485 for regulatory compliance and product quality, ISO 27001 for data security and GDPR compliance. Together they provide a complete framework for developing safe, secure, and compliant healthcare software.
MVP/Prototype: 2-4 months
Validated SaMD (Class I): 6-9 months
SaMD (Class IIa/IIb): 12-18 months
Enterprise GxP System: 18-36+ months
Timeline Factors:
- Regulatory classification and validation scope
- Requirements clarity and stakeholder alignment
- Integration complexity with existing systems
- Team size and resource availability
- Clinical evaluation requirements
Get a project estimate tailored to your specific requirements.
1. Source Code Ownership: Ensure full ownership rights in your contract
2. Open-Source Technologies: Use non-proprietary technologies where possible
3. API-First Architecture: Decouple components for independent replacement
4. Standard Data Formats: Avoid proprietary data formats
5. Documentation & Knowledge Transfer: Comprehensive documentation and team training
At Bon.do, we believe in client ownership. You own all code, data, and intellectual property we develop for you. Read our article on digital ownership.
Classification: Rule 11 classifies most SaMD as Class IIa or IIb based on risk
Key Requirements:
- Clinical evaluation demonstrating safety and performance
- Post-market surveillance system
- Unique Device Identification (UDI)
- Comprehensive technical documentation
- Quality Management System (ISO 13485)
CE Marking Process: Typically takes 12-24 months including notified body review. The process involves risk management, usability engineering, software validation, and clinical evaluation.
1. Determine Classification: Most SaMD falls under Class II
2. Choose Pathway:
- 510(k) Premarket Notification (most common)
- De Novo (novel devices)
- PMA (high-risk Class III devices)
3. Prepare Documentation:
- Design controls per 21 CFR 820.30
- Software validation and verification
- Cybersecurity documentation
- Clinical data (if required)
4. Submit to FDA: Review typically takes 90-180 days
Pro Tip: Consider Pre-Submission (Q-Sub) to get FDA feedback before formal submission. Contact us about FDA strategy for your product.
GMP: Good Manufacturing Practice (pharmaceutical production)
GLP: Good Laboratory Practice (laboratory experiments)
GCP: Good Clinical Practice (clinical trials)
GDP: Good Distribution Practice (medicine distribution)
GAMP: Good Automated Manufacturing Practice (computerized systems)
Software used in GxP-regulated processes must be validated to ensure data integrity (ALCOA+), complete audit trails, access control, and proof of correct function. Non-compliance can result in warning letters, import bans, or product recalls.