Data · Cybersecurity · Compliance · AI

Security that drives growth.

We organize data, secure systems and roll out AI so that you can show every business process and every control in your systems. We work with companies that have to demonstrate compliance with NIS2, DORA or the AI Act. Every engagement starts with a fixed-scope first step of 4 to 6 weeks.

// Areas

Four areas, one accountable team

Data and cybersecurity work falls apart in silos, so we plan every project around the whole company from day one. There is no AI without security, no security without governance and no reliable data without standards. Every project team includes someone with at least 10 years in IT.

  1. 01Data

    Data with an owner, a definition and a change history

    Nobody can tell you within an hour which reports break when one table changes. We sort out owners, definitions and lineage, and the same metadata then serves both AI and the auditor.

    • Data catalog with owners
    • Documented definitions and data lineage
    • Impact analysis in change management
    • One agreed definition per KPI
    • Register of data flows to third parties

    First step, 5 weeks

    One flow, end to end

    • Flow map with owners
    • Control gaps and a 90-day roadmap

    Key deliverable: a working data catalog for one domain

    Data governance and metadata
  2. 02Cybersecurity

    Tests that check real attack paths

    Too often a scanner sets the order of fixes instead of business impact. We validate attack paths by hand, so you fix what an attacker would actually use.

    • Attack surface and dependency map
    • Manual validation of real attack paths
    • Review of permissions and integrations
    • Priorities set by business impact
    • A retest of every fix, not a promise that it is closed

    First step, 4 weeks

    One system and its integrations

    • Attack surface and dependency map
    • Backlog with owners and dates

    Key deliverable: at least one critical path closed

    Penetration testing
  3. 03Compliance and audit

    From gap to evidence, step by step

    A policy that never makes it into your systems does not protect your company. It is just a document. We help you turn the requirements of NIS2, ISO/IEC 27001 and DORA into concrete work: every task has an owner and a deadline, controls run in your systems, and the evidence is ready before the auditor arrives.

    • Gap analysis against one framework
    • Obligations register with owners
    • Controls documented and implemented in your systems
    • Audit-ready evidence
    • Answers to customer security questionnaires

    First step, 5 weeks

    One framework, without rewriting everything

    • Gap analysis with priorities
    • Obligations register and a 90-day roadmap

    Key deliverable: one control implemented in a system, with its evidence

    Compliance and audit
  4. 04AI

    An approved path for AI instead of bans

    A ban does not protect your company, because people will switch to personal accounts anyway. We start with strategy: where AI delivers real value, which risks you are prepared to accept and in what order you scale what works. Then we set up access, data filtering and logging so that the approved tools are simply easier to use than a personal account. We also test the security of applications built on LLMs.

    • AI strategy: use cases with real value and acceptable risk
    • Inventory of AI tools and use cases
    • Risk classification and vendor role
    • Access that mirrors existing permissions
    • Data filtering and event logging
    • Security testing of LLM apps and agents

    First step, 6 weeks

    One approved AI path

    • AI use inventory and vendor assessment
    • Assessment of a private option for one use case

    Key deliverable: an approved path with access control and logging in one department

    AI governance and security

// Deadlines

Dates worth having in your calendar

Each date comes from the legal text and links to its source. On the first call we tell you plainly what needs work now and what can wait.

  1. Machinery

    Machinery Regulation

    Regulation (EU) 2023/1230 applies from this date, including the requirement to protect machinery against corruption (tampering) through connected devices and software (Annex III, 1.1.9).

    EUR-Lex 2023/1230 (opens in a new tab)
  2. KSC

    NIS2 in Poland (KSC): Chapter 3 obligations

    ISMS, risk management, incident handling, business continuity, supply chain, asset management and yearly management training (Article 33(1) of the 2026 amending act).

    Dz.U. 2026 item 252 (opens in a new tab)
  3. AI Act

    High-risk AI systems under Annex III

    The date was moved by Regulation (EU) 2026/1744. Systems under Annex I (EU product legislation) follow on 2 August 2028.

    EUR-Lex 2026/1744 (opens in a new tab)
  4. CRA

    Cyber Resilience Act fully applies

    Requirements for products with digital elements. Reporting of vulnerabilities and incidents has applied since 11 September 2026.

    European Commission, CRA (opens in a new tab)
  5. KSC

    First KSC audit deadline for essential entities

    Applies to entities that were already essential on 3 April 2026 (Article 33(2) of the amending act). From this date the authority can also impose most administrative fines (Article 35 of the amending act).

    gov.pl, KSC deadlines (opens in a new tab)

As of . Sources: Dz.U. 2026 item 252 (Polish KSC Act), gov.pl, KSC deadlines, Regulation (EU) 2026/1744, Regulation (EU) 2023/1230, European Commission, CRA.

// Product: FutureCode Evidence Box

Compliance evidence straight from your systems

FutureCode Evidence Box runs inside your network, with no internet access. It collects evidence read-only from cloud services, identity systems, endpoints, code repositories and configurations, then maps the findings to selected ISO/IEC 27001 and NIS2 requirements.

A human signs off the result: an auditor reviews the exception queue, and the evidence pack is sealed after sign-off. A sample readiness report built on fictional data shows what you get.

// How we work

From the first step to a working control

The same process sits under every engagement. The first stage matters most, because it decides whether the next ones make sense.

  1. Assessment

    4 to 6 weeks with a fixed scope: one data flow, one system, one department or one framework. You get one working result and a 90-day roadmap.

  2. Pilot

    We extend what worked, measured against success criteria agreed up front, not after the fact.

  3. Implementation

    The control goes into the process, not into a binder. The framework and documentation stay with you.

  4. Operate and improve

    Reviews, retests and updated evidence before the next audit. We measure what we agreed at the start.

// Why us

Decisions we stick to

Each of them costs us something, which is why you will find them in the contract, not just on this page.

  1. 01Team

    Senior people only

    We don't put juniors on your systems. Everyone on the project has at least 5 years of hands-on experience in their field, and we can name the team in the contract.

  2. 02Partner

    A partner on the project

    There is no account-management layer. The person who agrees the scope with you runs the project through to the end.

  3. 03Scope

    Fixed scope and date

    Scope, date and price are agreed in writing before we start. The first step takes 4 to 6 weeks, and there are no surprise invoices.

  4. 04Capacity

    One assessment per area

    We never run two assessments in the same area in parallel. If we can't start on your date, we say so right away.

  5. 05Retest

    Retest at no extra cost

    After a penetration test, we retest your fixes without charging for it. A finding is closed by a test result, not by someone saying so.

  6. 06Independence

    Someone else runs the formal audit

    We don't perform formal KSC audits under Article 15. We prepare you for them, implement the controls and support you day to day. The auditor has to be independent of whoever implemented the controls, so we tell you plainly who can audit you and who cannot.

// Credentials

Team credentials

Our team includes certified auditors as well as data and security engineers. We have built data systems and software for more than 10 EU clients (as of September 2026). Below are the certifications our team holds. When we agree the scope, we show you which of them the people on your project have.

Certifications held by our team

  • CISA (Certified Information Systems Auditor)ISACA
  • IODO (Polish data protection officer certificate)
  • CompTIA Security+CompTIA
  • ITILAXELOS / PeopleCert
  • REQBRequirements Engineering Qualifications Board
  • SAFeScaled Agile
  • ISTQBInternational Software Testing Qualifications Board
  • Databricks
  • Snowflake
  • Azure
  • AWS
  • SQL Server
  • Hadoop
  • dbt
  • Airflow
  • Prefect

From the blog

Data, security, compliance and AI

We write the way we work: specific, dated and sourced. Here are the latest posts from our four main topics.

All postsGo to the blog

// FAQ

Questions we hear most often

Where do we start if we don't know whether NIS2 applies to us?

With your sector and the size thresholds. We check both on one call and confirm the result in writing. In Poland, self-registration in the register of essential and important entities is due by 3 October 2026, and the authority can also add a company on its own initiative. In Germany, NIS2 has applied through the new BSIG since 6 December 2025 (as of 24 September 2026).

If it applies, we start with a gap analysis: 5 weeks, fixed scope. Details: NIS2 compliance in Poland (KSC).

Our industry pages show which rules apply in manufacturing, logistics, energy and water, finance and telecom.

How long does the first step take, and what does it cost?

4 to 6 weeks, depending on the area. We quote the price before we start, together with the written scope and date, and there are no surprise invoices. We can give you a range on the first call, once we know which system or framework is involved.

Do you perform formal KSC audits?

No. We prepare you for the KSC audit, implement the controls and provide ongoing support. A formal audit under Article 15 of the Polish KSC Act (NIS2 in Poland) is carried out by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT.

The auditor has to be independent of whoever implemented your controls (Article 15(2a)). We tell you who can audit you and who cannot. As of 24 September 2026.

Does our data leave the company?

It doesn't have to. FutureCode Evidence Box runs inside your network with no internet access and receives updates from physical media. Personal identifiers such as Polish PESEL (national ID) and NIP (tax) numbers are masked before they are stored, and every engagement has its own encryption key.

We don't paste client data into public AI tools. Our rules are on the How we use AI page.

Do you work with companies outside Poland?

Yes. We work with companies in Poland, the DACH region and the rest of the EU. For groups with sites in several countries, we bring the obligations from the Polish KSC Act and the German BSIG into one plan, since both implement the same NIS2 directive.

Tell us what's blocking you.

We reply within one business day with questions about scope and a rough timeline. The call is about your problem, not a sales pitch.

Book a 30-minute call (opens in a new tab)

Prefer to write?

Describe the system or regulation you're dealing with. We'll come back with questions and a proposed first step.

Write to us