// About us

A small senior team for data, security and compliance

We build and test the systems where compliance evidence is created. Based in Wrocław, working across Poland and the EU.

// Our story

From software to controls you can see

We started out building software and data systems for clients in the European Union. Project by project, our clients' questions moved to where the risk is: who owns the data, who can access it, how to prove it to an auditor and what to do about the AI their teams already use.

That is why we now work in four areas: data, security, compliance and AI. We don't keep them in separate silos, because most problems start in the gaps between them. We are based in Wrocław, Poland, and work with companies in Poland, the DACH region and the rest of the EU.

A policy you can't show in the system is not a control. It is a document about a control.

FutureCode in numbers, September 2026

  • 10+EU clients in data and software projects
  • 5+years of experience per person, at minimum
  • 4areas in one team

How we work

  1. A partner runs the project personally

    From the first day to the handover. After signing, we don't pass the project to a delivery team, and there is no account manager between you and the person doing the work.

  2. A senior matched to the area

    For each discipline we bring in someone with experience in it. If we don't have the right person for your problem, we say so instead of learning on your system.

  3. At least 5 years of hands-on experience

    This applies to everyone on the project, including large engagements where it would be easiest to fill the team with someone cheaper.

  4. A team you can check before signing

    On request, we share the profiles of the people assigned to your project: experience, certifications and scope of work. We can name the team in the contract.

  5. Fixed scope, date and retest

    We agree scope and date in writing before we start. We retest fixes after a penetration test at no extra cost.

  6. Independence

    We don't perform formal KSC audits under Article 15. We prepare you for them and tell you who can audit you and who cannot.

// Principles

What we do, and what we don't

Every "no" on this list costs us some business. That is why we put them in writing.

We do

  • A fixed-scope first step of 4 to 6 weeks
  • Controls implemented in your systems, with evidence
  • Penetration tests with a retest of your fixes
  • Readiness assessments and pre-audit reviews

We don't

  • Keep a bench of people who need to be placed somewhere
  • Let a senior sell the work and a junior deliver it
  • Pad the team to raise the contract value
  • Resell tool licenses
  • Issue NIS2 or KSC compliance certificates, because no such certificate exists

If all you need is a document for the inspection file, we'll be upfront about that on the first call.

// Credentials

Expertise on board

We don't publish names next to certifications. Our team includes certified auditors as well as data and security engineers. We present the certifications and references of the people assigned to your project when we agree the scope, in a form you can verify.

Certifications held by our team

  • CISA (Certified Information Systems Auditor)ISACA
  • IODO (Polish data protection officer certificate)
  • CompTIA Security+CompTIA
  • ITILAXELOS / PeopleCert
  • REQBRequirements Engineering Qualifications Board
  • SAFeScaled Agile
  • ISTQBInternational Software Testing Qualifications Board

Technologies and skills

  • Snowflake
  • Databricks
  • Azure
  • AWS
  • SQL Server
  • Hadoop
  • dbt
  • Airflow
  • Prefect
  • RAG on your infrastructure
  • Document access control

Let's talk about your situation

We reply within one business day

Tell us which system, data or regulation you are dealing with. We'll come back with questions about scope and a proposed first step of 4 to 6 weeks. No sales pitch.