APPLICATION DEVELOPMENT & MODERNIZATION
APPLICATION DEVELOPMENT & MODERNIZATION
Avalon delivers a secure, accessible mobile app your people and your public can actually use in the field, built at small-business speed and priced at a fraction of what a large integrator charges for the same team.
Avalon designs, builds, security-hardens, and fields mobile applications for federal workforces and the public, built to Section 508, NIST security controls, and federal authentication requirements from sprint one, so the app can actually be authorized and fielded, not just demoed.
THE PROBLEM & THE APPROACH
The Challenge
Our Approach
Field personnel, inspectors, responders, caseworkers, clinicians, collect data on paper and re-key it days later, in disconnected environments where laptops don't survive.
Avalon builds offline-first data architecture with conflict-safe sync, designed for the flight line, the clinic, and the disaster zone, not the office.
An existing app fails Section 508 and draws a complaint or OIG finding, or an unvetted app touches agency data outside the security boundary.
Manual assistive-technology testing produces a criterion-level Accessibility Conformance Report, alongside a NIST SP 800-163-aligned app-vetting evidence package built with the build, not after it.
A legacy app breaks with every annual iOS/Android release and the original vendor is gone, while the agency pays large-integrator sustainment rates for what a four-person team could rebuild.
Cross-platform architecture by default for cost control, with source code and pipeline in the agency's own repository from day one, no vendor hostage-taking at the next OS release.
OMB directs agencies to justify a native app against a mobile-responsive web default, and a poorly justified app becomes the visible, low-rated face of the agency's service delivery.
The first deliverable is an honest native-vs-responsive-web decision memo per OMB M-23-22, Avalon says when the website is the right answer, before a line of app code is written.
CORE CAPABILITIES
A documented decision on native versus responsive web, then an architecture built for the field, not the desk.
Evidence your ISSO and 508 office can act on, built alongside the code, not bolted on at the end.
The app fielded and the agency equipped to run it without Avalon.
OUR PROCESS
User research, workflow observation, the native-vs-web decision, and an integration and authentication landscape assessment. (3–5 weeks)
Design system, high-fidelity screens, technical architecture, and ISSO kickoff on security expectations. (3–4 weeks, overlapping discovery)
Two-week sprints with a demo every sprint; integrations built against agency test environments; accessibility and security engineered in throughout. (12–20 weeks)
Manual 508/assistive-technology testing and the ACR; mobile app security testing and vetting-package assembly. (4–6 weeks, partially parallel with build)
App Store / Play submission or MDM packaging, production cutover, and monitoring in place. (2–4 weeks)
Hypercare, defect fixes, knowledge transfer, and runbook walkthrough. (4 weeks)
WHY AVALON
4
Federal Frameworks Addressed
Approvable, Not Just Attractive
Most small app studios can build a pleasant app; few can produce a criterion-level ACR from manual assistive-technology testing, a NIST SP 800-163-aligned vetting package, an SBOM, and SA-11 developer-testing evidence, with an in-house cybersecurity practice behind every one of them.
No leverage pyramid, the four-to-six-person team that scopes the app is the team that builds it, starting in weeks.
A criterion-level ACR, MASVS-aligned vetting package, SBOM, and SA-11 developer-testing evidence, arriving with the build, not chased after it.
Login.gov, agency ICAM, and derived-PIV authentication are engineering Avalon has already done, not a first attempt on your contract.
Avalon tells an agency when responsive web meets the need instead of selling a native app reflexively, and re-scopes accordingly.
FREQUENTLY ASKED
Straight answers about capacity, approval timelines, and what a federal mobile build actually requires.
Talk to Our Team →4
Federal Frameworks Addressed
That's accurate at the corporate level, and Avalon won't pretend otherwise. Our named key personnel carry documented mobile delivery records, the fixed-price milestone structure puts delivery risk on us, and we start with a discovery sprint small enough to judge us on evidence within a month.
Everything lives in your tenancy from day one, code in your repository, designs in transferable files, the pipeline documented. We pair engineers so no component has a single owner, and the transition runbook is a deliverable, not an afterthought.
OMB is often right, and M-23-22 requires the justification, so we make it the first deliverable. If discovery shows responsive web meets the need, we say so and re-scope; you'll have the decision memo either way.
It takes forever when the vendor shows up at the end with a binary and no evidence. We engage your ISSO in Phase 1, build to MASVS, and deliver the vetting package with the release candidate, your reviewers evaluate evidence, they don't excavate it.
The developer accounts are yours, and the app follows platform rules we design to from the start; precedent for agency apps is deep. For workforce apps, managed/MDM distribution avoids public review entirely.
Your team can, code, docs, and pipeline are yours, with no proprietary lock-in. If you'd rather not staff it, sustainment is a priced option, not a hostage situation.
It saves meaningfully, typically 25–40% versus dual native, not 50%, because integration, security, and 508 work don't halve. We default to cross-platform for cost control and go dual-native only where performance or hardware access genuinely requires it.
Talk to Avalon about scoping a fixed-price mobile discovery sprint.