Software in secure and public-sector environments has to satisfy more than functional requirements. It must account for sensitive information, specialized hardware, controlled workflows, accessibility, auditability, and operational continuity. The best outcome is a system that strengthens these controls while making the work easier for the people responsible for using it.
The approach was to modernize carefully, separating user workflows from hardware and legacy dependencies while preserving the controls required by the environment. Testing practices were strengthened, acceptance criteria were made explicit, and hardware, firmware, and software teams were aligned around a shared operating model. Accessibility and secure data movement were treated as architectural requirements rather than late-stage additions.