Nehos Groupe

The short version

Nehos builds SaaS products for software vendors and scale-ups in Brussels: tenancy and isolation design, subscription billing, in-product AI and the documentation your buyers' risk reviews ask for. Multi-tenant MVP from €13,952 excl. VAT in six to eight weeks; full platform from €50,000 excl. VAT.

Brussels buyers are institutional and supervised, so the architecture has to produce evidence — access logs, sub-processor lists, data residency answers and a tested export path — not reassuring adjectives.

Billing is a compliance surface here: structured B2B e-invoicing has been mandatory between Belgian taxable persons since 1 January 2026, with Peppol BIS as the default route, on top of intra-EU VAT handling.

AI features are qualified under Regulation (EU) 2024/1689 during scoping, not after launch — the regime depends on what the feature does, and re-qualifying a live product means rebuilding documentation, governance and logging at once.

We also take over SaaS platforms built by other teams, and we give the honest verdict — including the one where a rebuild does not pay for itself.

SaaS development in Brussels — from multi-tenant MVP to enterprise platform

Products built to clear the security, legal and procurement review that Brussels buyers run before they sign. Multi-tenant MVP from €13,952 excl. VAT in six to eight weeks, quote within 24 hours.

Nos clients types

Scale-up
PME
ETI
Grand Groupe
Questions & Réponses

Frequently asked questions — SaaS development in Brussels

A multi-tenant SaaS MVP — authentication, organisations and roles, subscription billing and usage analytics — starts at €13,952 excl. VAT and ships in six to eight weeks. A full platform, with fine-grained permissions, enterprise SSO, third-party integrations and hardened traceability, starts at €50,000 excl. VAT. Those are published entry points: the firm quote depends on the number of screens, the tenancy model chosen and the integrations required, and it reaches you within 24 working hours of a free scoping workshop. We work on a fixed price per deliverable rather than a running meter.

Usually not, and deciding otherwise as a precaution is one of the more expensive mistakes we see. A shared database with row-level security, logged access and a documented authorisation policy clears most vendor risk reviews. Schema-level or database-level isolation earns its cost in three cases: an explicit contractual requirement for a dedicated instance, a data residency constraint specific to one customer, or a data volume that makes sharing counterproductive. Our usual recommendation is hybrid — a shared core for most tenants, hardened isolation offered as an enterprise option and priced at its real operating cost.

If you are established in Belgium and you invoice Belgian taxable customers, structured electronic invoicing between businesses has been mandatory since 1 January 2026, with the Peppol network and the BIS format as the default route. We therefore treat Peppol output as a first-class part of the billing module rather than an export added afterwards. Some situations are exceptions, and VAT treatment depends on each customer's status and country, so have your configuration validated by your accountant before go-live — a half-day check that prevents months of correcting entries.

It depends entirely on what the feature does, not on the technology behind it. Under Regulation (EU) 2024/1689, the obligations attached to the Annex III high-risk systems have been fully applicable since 2 August 2026, as have the transparency duties for systems that interact with people or generate synthetic content. An internal drafting assistant, a semantic search over your own catalogue, a CV screening tool and a creditworthiness engine are in different regimes. We qualify the feature during scoping with your legal counsel, because re-qualifying after market placement means rebuilding the technical documentation, the data governance and the logging at once.

If you sell to a supervised financial entity, you become an ICT third-party service provider under the regulation, applicable since 17 January 2025. Expect four demands: precise contractual clauses covering data location, audit rights, service levels and termination; entry in the register of information your customer maintains on its providers, with your own subcontractors identified; a documented and genuinely testable exit strategy including a complete data export; and a defined place in the incident notification chain with response times you can honour. None of it is exotic engineering, and all of it is expensive to retrofit.

Yes, and it is a large share of what we do. We start with a technical audit covering tenancy enforcement, the billing state against what customers actually pay, security, performance, dependency health and test coverage. Three outcomes are possible: maintain as is, modernise incrementally behind a stable interface while the product keeps selling, or rebuild with a migration plan for data and customers. You get the honest verdict, including the case where a rebuild does not pay for itself.

Our Brussels office is in the Securex building, Cours Saint Michel 30A, 1040 Brussels, in Etterbeek and minutes from the European quarter. Scoping workshops, sprint reviews and steering committees happen there or at your offices. The delivery team is based at our Toulouse headquarters and works as one squad on your product, with a named lead for Belgian and EU clients — no subcontracting chain between you and the people writing the code.

#Custom SaaS development in Brussels — building a product that survives the second sale

Every SaaS vendor in Brussels sells twice. The first sale is to the team that has the problem, and it is the one founders rehearse. The second is to procurement, information security and legal — and in a city where a large share of the solvent buyers are supervised financial institutions, EU bodies, international federations and regulatory law firms, that second sale is the long one. It is also the one that kills badly architected products, usually two quarters after the demo went well.

Nehos builds SaaS products designed to pass it. A multi-tenant MVP ships in six to eight weeks from €13,952 excl. VAT; a full platform — fine-grained roles, enterprise SSO, integrations, hardened traceability — starts at €50,000 excl. VAT. Both figures are entry points, published alongside the rest of our price list, and the firm quote follows within 24 working hours of a free scoping workshop.

We keep the word "SaaS" narrow on purpose. A SaaS product is one running system serving several client organisations with an isolation model you can demonstrate, a recurring billing chain that holds up in front of your accountant, and usage telemetry that tells you who activated what. A web application with a payment form bolted on is not that. Our custom SaaS development practice covers the build; the earlier question — buy an off-the-shelf tool or build your own — is worked through in our SaaS software guide.

#What Brussels changes in a product specification

Your buyers get audited, so your architecture has to produce evidence. A vendor questionnaire from an entity supervised by the National Bank of Belgium or the FSMA does not ask whether your data is secure. It asks where the data physically sits, who can reach it, how that access is logged, which sub-processors stand behind you, and what happens to your customer's data if your company disappears. A product built without those questions in view answers them with adjectives, and adjectives do not clear a risk review.

English is the working language; the product is not monolingual. Commercial conversations in the European quarter happen in English, which is exactly why teams underestimate the language work inside the product. Brussels-Capital is officially bilingual French–Dutch, and Belgian administrative Dutch is not interchangeable with the Dutch used in the Netherlands — a Flemish member organisation notices within one sentence. That means language preference stored per user rather than per account, invoice and email templates maintained per language, and a translation workflow that does not require a deployment. Retrofitting that into a data model at Series A costs several sprints; putting it in at sprint one costs almost nothing.

Regulation is both your constraint and your market. Brussels is where the texts that bind your product are drafted — the AI Act, the Data Act, DORA, NIS2 — and it is also the first place where compliance sells. Regtech and legaltech are unusually active here for an obvious reason: the demand is local, well informed and able to pay. A product that automates a European regulatory obligation can find its first reference customers a few metro stops from its own office, which shortens early feedback loops in a way no amount of outbound can replicate.

Invoicing is a compliance surface, not a checkout button. Structured electronic invoicing between Belgian taxable persons has been mandatory since 1 January 2026, with the Peppol network and the BIS format as the default route. Add intra-EU VAT treatment that varies by the customer's country and status, foreign company identifiers, and the fact that most Brussels vendors sell into the Netherlands, France or Germany within the first year, and the billing module stops being a plumbing task.

#Multi-tenant architecture: what to isolate, and what to leave shared

The question we are asked first is almost always the wrong one. Founders arrive convinced that an institutional or banking customer will demand a dedicated database, and they price that assumption into the architecture before anyone has asked for it.

In practice, a shared database with row-level security, logged access and a documented authorisation policy clears most risk reviews. Isolation at schema or database level earns its cost in three situations: an explicit contractual requirement for a dedicated instance, a data residency constraint specific to one customer entity, or a data volume that makes sharing counterproductive. Our standard recommendation is hybrid — a shared core for the majority of tenants, hardened isolation available as an enterprise option and priced at what it genuinely costs to operate, because the operational burden of fifty separate databases lands on you, not on the customer who asked for it.

Three engineering decisions matter more than the isolation debate itself. Tenant scoping must be enforced at a single layer — a policy in the database or a guarded data-access layer — rather than repeated in every query, because "we remembered the tenant filter in 400 places" is not a control anyone can audit. Access logging should be a product feature, not a server log: your customer's auditor will eventually ask who read a specific record and when, and the answer needs to be a screen. And the full data export has to be built and tested early, because for regulated buyers the exit strategy is a contractual clause, not a courtesy.

#Billing that survives an accountant

Subscription billing is where MVPs quietly accumulate debt. Plan changes mid-cycle and their proration, usage metering that has to agree with what the product actually measured, credit notes, dunning and failed payments, a legally continuous invoice numbering sequence, VAT status per buyer country, and revenue recognition that your finance team can reconcile — none of it is difficult individually, and all of it is painful to retrofit once real money is flowing and past invoices cannot be quietly rewritten.

We treat the Peppol output as a first-class component of that module rather than an export added later. One practical instruction we repeat to every founder: have your VAT configuration reviewed by your accountant before go-live. It is a half-day check that prevents months of correcting entries.

#Putting AI inside the product without becoming a high-risk provider

Under Regulation (EU) 2024/1689, the obligations attached to the Annex III high-risk systems have been fully applicable since 2 August 2026, alongside transparency duties for systems that interact with people or produce synthetic content. What determines your regime is what the feature does, not which model you call. An internal drafting assistant, a semantic search over your own catalogue, a tool that screens job applications and an engine that scores creditworthiness sit in four different places. We qualify the feature during scoping, with your legal counsel in the room, because re-qualifying after the product is on the market means rebuilding the technical documentation, the data governance and the logging at the same time.

The engineering consequences are concrete. Log the inputs, the retrieved sources with their identifiers and the model and prompt versions for every generation. Version prompts in the same repository as the code, through the same review, so that "someone changed the prompt" is a traceable event. Build explicit abstention, so a feature that cannot ground an answer says so instead of inventing one — in a product sold to compliance teams, a confident fabrication is a commercial incident. Make human oversight real: an override that a user can actually exercise, not a confirmation dialogue. And route by step — classification and extraction run well on smaller open-weight models that can sit on European infrastructure, while the genuinely hard reasoning steps go to a larger model. Our AI agency practice in Brussels and our AI agents work cover automation inside an organisation; this section is about AI shipped inside a product you sell to others.

#Selling to entities under DORA

If your customers include supervised financial entities, the Digital Operational Resilience Act, applicable since 17 January 2025, makes you an ICT third-party service provider. Expect four things. Contractual clauses covering data location, audit rights, service levels and termination. Entry in the register of information your customer maintains on its providers, with your own subcontractors identified. A documented and genuinely testable exit strategy including a complete data export. And a place in the incident notification chain, with response times you can honour.

None of that is exotic engineering. All of it is expensive to retrofit, and every week it is missing is a week the deal does not close.

#Taking over a SaaS someone else built

A significant share of the SaaS work we are asked to do is not a first build. It is a product that reached its first paying customers and then stopped moving.

The audit findings repeat. Tenant scoping enforced query by query rather than at one layer. A billing state that no longer matches what customers actually pay, discovered when someone reconciles Stripe against the database. No usage telemetry, so nobody can say which features justify their maintenance cost. An upgrade path blocked by one abandoned dependency. Three outcomes follow: maintain as is, modernise incrementally behind a stable interface while the product keeps selling, or rebuild with a migration plan for data and customers. We give the honest verdict, including the one where a rebuild does not pay for itself and you would be better off with a narrower product.

We do not invent local references. The published case closest to this practice is a French B2B SaaS scale-up, anonymised under NDA, where a twelve-month demand programme produced €320k of ARR across seven attributed deals — the go-to-market side of the same problem, detailed in our B2B SaaS and scale-up practice.

#How an engagement runs

Weeks 1–2 — scoping. Workshops with the people who will use the product and the people who will have to defend it in a security review. Deliverables: functional scope, data model, tenancy and billing decisions written down with their consequences, screens for the critical paths, firm quote.

Weeks 3–8 — build. Two-week sprints on a staging environment you can open at any time: authentication, organisations and roles, the core workflow, subscription billing, onboarding, usage analytics. You watch the product take shape instead of discovering it at the end.

Launch. Load and permission testing, a security review pack you can hand to a prospect, documentation, and the export path proven on real data before a customer asks for it.

After. Training for your product team, then optional maintenance and evolution. The code and its documentation are yours: any competent team can pick the project up, and we build no artificial dependency.

#What it costs, without the sales call

Two decisions drive almost all the price variance on a SaaS build: how much you ship before your first paying customer, and how far you push tenant isolation before a buyer actually demands it. We publish both entry points so the conversation starts from a number, not a guess.

A multi-tenant MVP starts at €13,952 excl. VAT — authentication, organisations and roles, subscription billing, guided onboarding, CI/CD and production deployment, plus the usage analytics that tell you what people do with what you shipped. Six to eight weeks, end to end. Once the product outgrows that scope — enterprise SSO, a documented public API, third-party integrations, an admin console built for someone other than you, the traceability an institutional buyer expects — the full platform starts at €50,000 excl. VAT.

Neither figure moves once we have scoped your project against it: the firm number reaches you within 24 working hours of the workshop, priced per deliverable rather than by the hour. After launch, ongoing maintenance and evolution starts at €750 excl. VAT per month — monitoring, security patches, version upgrades and the small changes that keep a product from rotting quietly. Want a rough order of magnitude before talking to anyone? Run it through our free estimator tools first.

#The shortlist question, answered

A Brussels procurement officer or a legal counsel doing vendor diligence will not read this page top to bottom — they scan it for a handful of specific answers. Here they are.

Can you actually deliver, or is this a two-person shop with a well-built site? We have shipped 200+ projects since 2014 and currently run 47 engineers, architects and data specialists across the group, multi-tenant SaaS included.

Does the spend produce a return you can defend internally? Across our engagements the average sits at 340% ROI at twelve months, because every scope starts from a costed outcome rather than a feature wishlist.

What happens when we need to be in the same room? Our Brussels office sits in the Securex building on Cours Saint Michel, in Etterbeek, close enough to the European quarter for a lunchtime workshop — with a named lead for Belgian and EU clients, even though the delivery squad works from our Toulouse headquarters.

What if a regulator later demands a hosting guarantee nobody planned for? If a customer's supervisory status requires it, we move the finished product onto OVHcloud infrastructure, including SecNumCloud-qualified environments — priced when it becomes a real requirement, never billed to everyone as a default.

What happens to the code if the relationship ends? It is yours, documented well enough for another team to pick it up without us in the room.

#The local ecosystem worth using

Founders systematically under-use what sits on their doorstep: the BeCentral digital campus above Brussels-Central station, the incubation programmes of Start it @KBC, the business services of hub.brussels, and Innoviris funding for research and innovation projects run in the Brussels-Capital Region. Belgian tax measures tied to research and innovation deserve an early conversation with a specialist adviser, because they shape how a product team is structured.

We opened by saying every SaaS vendor here sells twice. If you can already name, without opening a folder, the three items on a security questionnaire your product cannot yet answer, you probably do not need a scoping workshop — you need an engineering sprint. If you cannot name them, that uncertainty is the workshop's entire purpose, and it costs nothing to find out.

Réserver un audit