// About us
A small senior team for data, security and compliance
We build and test the systems where compliance evidence is created. Based in Wrocław, working across Poland and the EU.
// Our story
From software to controls you can see
We started out building software and data systems for clients in the European Union. Project by project, our clients' questions moved to where the risk is: who owns the data, who can access it, how to prove it to an auditor and what to do about the AI their teams already use.
That is why we now work in four areas: data, security, compliance and AI. We don't keep them in separate silos, because most problems start in the gaps between them. We are based in Wrocław, Poland, and work with companies in Poland, the DACH region and the rest of the EU.
A policy you can't show in the system is not a control. It is a document about a control.
FutureCode in numbers, September 2026
- 10+EU clients in data and software projects
- 5+years of experience per person, at minimum
- 4areas in one team
How we work
A partner runs the project personally
From the first day to the handover. After signing, we don't pass the project to a delivery team, and there is no account manager between you and the person doing the work.
A senior matched to the area
For each discipline we bring in someone with experience in it. If we don't have the right person for your problem, we say so instead of learning on your system.
At least 5 years of hands-on experience
This applies to everyone on the project, including large engagements where it would be easiest to fill the team with someone cheaper.
A team you can check before signing
On request, we share the profiles of the people assigned to your project: experience, certifications and scope of work. We can name the team in the contract.
Fixed scope, date and retest
We agree scope and date in writing before we start. We retest fixes after a penetration test at no extra cost.
Independence
We don't perform formal KSC audits under Article 15. We prepare you for them and tell you who can audit you and who cannot.
// Principles
What we do, and what we don't
Every "no" on this list costs us some business. That is why we put them in writing.
We do
- A fixed-scope first step of 4 to 6 weeks
- Controls implemented in your systems, with evidence
- Penetration tests with a retest of your fixes
- Readiness assessments and pre-audit reviews
We don't
- Keep a bench of people who need to be placed somewhere
- Let a senior sell the work and a junior deliver it
- Pad the team to raise the contract value
- Resell tool licenses
- Issue NIS2 or KSC compliance certificates, because no such certificate exists
If all you need is a document for the inspection file, we'll be upfront about that on the first call.
// Credentials
Expertise on board
We don't publish names next to certifications. Our team includes certified auditors as well as data and security engineers. We present the certifications and references of the people assigned to your project when we agree the scope, in a form you can verify.
Certifications held by our team
- CISA (Certified Information Systems Auditor)ISACA
- IODO (Polish data protection officer certificate)
- CompTIA Security+CompTIA
- ITILAXELOS / PeopleCert
- REQBRequirements Engineering Qualifications Board
- SAFeScaled Agile
- ISTQBInternational Software Testing Qualifications Board
Technologies and skills
- Snowflake
- Databricks
- Azure
- AWS
- SQL Server
- Hadoop
- dbt
- Airflow
- Prefect
- RAG on your infrastructure
- Document access control
Let's talk about your situation
We reply within one business day
Tell us which system, data or regulation you are dealing with. We'll come back with questions about scope and a proposed first step of 4 to 6 weeks. No sales pitch.