Research lab and core facility tools
Instrument booking, sample and request tracking, usage reports and recharge billing.
Booking and tracking tools, portals, workflows and integrations for Boston-area research labs, universities, healthcare operations, financial firms and startups.
Boston, MA, United States, served remotely from Pune, India
Quavento Technologies develops custom software for organizations in Boston, Massachusetts. We build web applications, internal tools, client and member portals, dashboards and the integrations that connect them to systems you already use. We work remotely from Pune, India, hold calls between 9 am and 1 pm Eastern Time and price in US dollars.
Greater Boston runs on specialized knowledge, and the organizations that produce it, such as laboratories, clinics, investment teams and engineering firms, have specialized ways of working. A core facility schedules a dozen instruments among two hundred researchers. A fund's operations team tracks documents through several approvals. A robotics company supports machines installed in forty warehouses.
General-purpose software fits these only loosely. This page describes what we build for the region's main kinds of organization, the rules that apply to their data and, plainly, the categories of work we do not take.
Last updated:
Instrument booking, sample and request tracking, usage reports and recharge billing.
Applications, advising, events and reporting built with student privacy rules in mind.
Referrals, scheduling and reporting around the health record, with HIPAA safeguards.
Document collection, approvals, client portals and record keeping for advisers and funds.
Customer, partner and service portals for robotics, hardware and software firms.
Encryption, access controls and logging that support Massachusetts data security rules.
When the way you work is the point, and no product models it. Standard functions should use standard software: accounting, payroll, email, and in a hospital the certified health record. Institutions here also have central systems that departments are expected to use.
Custom work pays in the space between those systems. A lab's request process does not fit the institution's ticketing tool. A program office tracks applicants in a spreadsheet because the admissions system cannot hold what reviewers need. An operations team reconciles two reports by hand every week.
We build the missing piece and connect it to the core systems through their interfaces, so nothing is entered twice. A first project should be small, finished in a couple of months and clearly useful. Our guide to planning an MVP explains how to choose it.
Scheduling, tracking and a fair way to charge for use. Shared facilities, such as microscopy, sequencing, mass spectrometry and animal care cores, serve many research groups and usually recover their costs by billing those groups' grants.
We build booking systems that know each instrument's rules: who is trained to use it, how long a session may be, how far ahead it can be reserved and what happens to a no-show. Service requests are submitted with the details the facility needs, tracked through each stage and returned with results. Usage is recorded automatically and turned into charges against the right account, with reports for the facility director and the finance office.
There is a boundary. Systems that hold regulated records, such as data supporting a submission to the drug regulator or clinical trial data, must be developed and validated under formal quality procedures, and we do not take that on. Our work is with operational tools for research and service, and your quality group should confirm which side of the line a system falls on.
The tools that sit around the central student system. Program offices, institutes and student services run processes of their own: applications to a fellowship, advising notes, placement of students in internships, event registration, alumni mentoring.
Student records are protected by federal education privacy law, which limits who may see them and how they may be shared. We design with that in mind: access by role, records of who viewed what, data kept to what the purpose needs and sign-in through the institution's own identity system. Companies selling to schools are usually asked to sign a data agreement and may face additional state requirements.
For education technology companies, we build product features and integrations with the learning platforms institutions use, through the standard interfaces. Products used by children under thirteen come under stricter federal rules on consent, and we raise that at the start. Accessibility is required by institutional policy and law, and we build and test to WCAG 2.2 level AA.
By handling what the health record does not. Boston's hospitals and physician groups are heavily invested in their record systems, and those remain the source of truth. Around them, a great deal of coordination is done by phone, fax and spreadsheet: referral intake, scheduling of scarce specialists, patient transport, interpreter booking, research coordination and operational reporting.
Software that handles protected health information falls under the Health Insurance Portability and Accountability Act. We sign a business associate agreement, host with a provider that does the same, encrypt data, restrict access by role, log who viewed what and collect only what each feature needs.
Integration uses the record system's supported interfaces, including the standard for exchanging health data. Hospital information security teams review vendors closely, and we complete their questionnaires as part of the proposal. Software that diagnoses or guides treatment may be regulated as a medical device, which is a separate undertaking we would refer to a specialist firm.
Order in their paperwork. Boston's fund managers, private equity firms and wealth advisers process a constant flow of documents and approvals: client onboarding, subscription documents, due diligence questionnaires, marketing reviews, regulatory filings and board materials.
We build workflow tools that give each item a status, an owner and a history, collect what is missing, route approvals in the right order and keep a complete record. Client and investor portals let people upload documents and see reports without email attachments. Marketing review tools record who approved each piece and when, which regulators expect firms to be able to show.
We do not build trading, pricing or portfolio systems, and we do not hold client money. Firms are required to retain their communications and records for set periods in a way that prevents alteration, so our systems are designed to work with the archiving service your compliance team has chosen. Our page on financial services describes how we work with regulated firms.
Portals and internal tools their own engineers have no time for. The technology corridor around Boston and the Seaport is home to companies building robots, medical instruments, energy systems and enterprise software. Their engineers are fully occupied with the product.
Meanwhile customers want a place to see their fleet or licenses, open support cases, download documentation and order parts. Field service teams need to schedule visits and record what was done. Partners need to register deals. Sales engineers need to track trials. Those are the projects we take.
Each draws on existing systems, such as the CRM, the support desk and the product's own cloud, and presents them under one login. For machines in the field, the portal can show status and history from telemetry the company already collects. We do not handle export-controlled technical data, which some robotics and defense-related work involves.
Foundations and grantmakers need application and review systems: online forms with eligibility checks, reviewer assignments with conflict declarations, scoring, award letters, payment schedules and reporting reminders. When data is captured consistently, the report to the board takes an hour instead of a week.
Nonprofits that provide services need intake, case notes, referrals and outcome tracking, with strict control over who sees what, in the languages their clients speak.
Startups coming out of the universities usually need a first product or a first set of business systems quickly and economically. We reduce the idea to its essential path, test a prototype and build in short cycles on mainstream technology that the engineers they later hire will know. Intellectual property is assigned to the company in writing, which investors check, and founders should confirm what their university's licensing terms require.
A written program and specific safeguards. State regulations apply to anyone who owns or licenses personal information about a Massachusetts resident, defined as a name combined with items such as a financial account number or a government identification number.
The organization must maintain a comprehensive written information security program, name someone responsible for it, assess risks, train staff and oversee its vendors by contract. On the technical side, the regulations call for secure user authentication, access limited to those who need it, encryption of personal information sent across public networks and stored on laptops and portable devices, up-to-date security software and monitoring.
We build to those requirements as a matter of course: single sign-on with a second factor, role-based access, encryption in transit and at rest, audit logs and tested backups. As a vendor, we sign the contractual commitments your program requires. The written program itself is yours, prepared with your counsel.
It starts with a paid discovery of two to three weeks. We interview the people who do the work, review current systems and institutional requirements and produce a specification, wireframes and an estimate that are yours to keep.
Development runs in two-week sprints, each ending with a demonstration on a staging system using test data. We use mainstream technology, typically TypeScript with React and Next.js, Node.js or Python and PostgreSQL, hosted in a United States region in accounts you own. Code is in your repository, and intellectual property is assigned to you on payment.
Calls are between 9 am and 1 pm Eastern, and questions raised in your afternoon usually have answers by morning. We are based in Pune, India, and have no Boston office. Phone apps are covered on our mobile app development in Boston page, contracts on our software development for US companies page, and our other services on the Boston overview.
Weeks 1 to 3
Interviews on Eastern Time mornings, systems and institutional requirements reviewed, with a written specification.
Week 3
Phased plan, data handling, regulatory boundaries and a fixed price for the first phase.
Per phase
Two-week cycles, each ending with a working demonstration on a staging system.
1 to 2 weeks
Security and accessibility review, data migration, user training and a controlled rollout.
Ongoing
A monthly support plan, or a documented handover to your own team.
Discovery is a small fixed-price project. Development is then quoted in US dollars as a fixed price per phase where the scope is clear, or as a monthly team rate where requirements will evolve. The cost depends on the number of user roles and screens, integrations with institutional or product systems, security and privacy requirements and data migration. Cloud hosting and third-party services are paid by you directly. Support after launch is a separate monthly plan. We do not publish prices because projects differ so widely, but discovery gives you a detailed estimate before you commit to building.
Our team works from Pune, India. We do not have a US office, so every project is run remotely with a named project manager, a weekly call and written updates. These are the hours we keep for calls with US clients.
| US time zone | Examples | Call window |
|---|---|---|
| Eastern (ET) | New York, Florida, Georgia, North Carolina | 9 am to 1 pm ET |
| Central (CT) | Texas, Illinois, Tennessee | 8 am to 11 am CT |
| Mountain (MT) | Colorado, Utah, Arizona | 8 am to 10 am MT |
| Pacific (PT) | California, Washington, Oregon | 8 am to 9 am PT, or 5 pm to 7 pm PT |
Yes. Instrument booking with training and time rules, service request tracking, automatic usage records and charges to the right account, with reports for the director and finance.
No. Those need a vendor with formal validation procedures. We build operational tools outside regulated scope, and your quality group should confirm the boundary.
Yes, with the safeguards federal privacy laws require. We sign a business associate agreement for health information and the data agreements institutions ask of vendors.
We build with the authentication, access control, encryption and logging the regulations call for. The written security program is your organization's responsibility.
No. For financial firms we build document workflows, portals and record-keeping tools, and we do not hold client money or build trading systems.
You do. The code is in your repository, cloud accounts are in your name and our agreement assigns intellectual property to you once paid for.
No. Our team is in Pune, India, and works with Boston clients remotely, with calls between 9 am and 1 pm Eastern Time. We do not have a US office.
More services in Boston
Software Development in other locations
Specialised Software Development
Case studies
Guides
Our services
Tell us about your business in Boston and we will reply with a clear plan, timeline and estimate within 24 hours.
Share your requirements and we will send a tailored proposal.