Software and security audits for regulated sectors

Build with a partner who is accountable for security, not just for code. DORA, NIS2, ISO 27001 and GDPR built into the architecture, not bolted on in the final documentation. Full data sovereignty within the European Union.

Book a consultation

About - Innovix

We deliver custom software and cybersecurity services for regulated sectors - finance, insurance, healthcare and the public sector. We design secure-by-design systems, compliant with DORA, NIS2, GDPR and ISO 27001 from the requirements analysis phase through to production.

We operate on two pillars: we build digital products (SaaS, AI, mobile, desktop and web applications) and we deliver custom projects - from architecture through to deployment and ongoing development. In parallel, we conduct penetration testing and compliance audits in line with OWASP WSTG v4.2, PTES and the CVSS 3.1 classification.

Our team brings together software engineers, architects, pentesters and compliance consultants. We work with Agile, CI/CD and a Zero Trust architecture, while internal research programmes at the intersection of AI and law feed our commercial practice with solutions built to a European standard.

We take responsibility for the full product lifecycle - from architecture through to maintenance. We tailor commercial models (licence, subscription, hybrid) to each client's profile, and we run every project under an NDA, a contract and an SLA with measurable acceptance criteria.

100K+

Documents in the corpora of our AI models

67+

Tests in our audit methodology (OWASP WSTG v4.2)

100%

Of infrastructure in EU data centres

Portfolio - systems built by Innovix

Projects currently in progress

Selected products and systems we are working on this quarter

Cybersecurity · SaaS · Compliance
In progress

Innovix NIS2 Shield

SaaS compliance for NIS2 and UKSC

Guides the organisation through the full compliance lifecycle - from qualification and gap analysis, through a policy and procedure generator, all the way to incident reporting to the CSIRT within the 24 / 72 hour deadlines.

  • Modules: Qualifier, Gap Analysis, Documentation Generator, Vendor Passport
  • LLM model: in-house, fine-tuned on UKSC, NIS2 and CSIRT guidelines
  • Market: 6,000+ Polish companies across 18 regulated sectors
  • Subscription: 499 / 999 / 2 499 PLN (approx. €115 / €230 / €580) across three pricing plans
Manufacturing · logistics · energy · healthcare EU infrastructure
Enterprise DLP · Zero Trust
In progress

Innovix SecureWorkspace

Shadow AI Protection in Zero Trust

Secure access to AI tools across the company - data never leaves the employee's device, and sensitive content is pseudonymised before being sent to public models.

  • Stack: Tauri 2.0 + Rust + TypeScript, AES-256-GCM encryption, SQLCipher
  • Protection: blocks ChatGPT, Gemini and Copilot outside the controlled environment
  • Templates: 12+ policies for finance, healthcare, law, industry and the public sector
  • Compliance: GDPR, ISO 27001, SOC 2 with a full audit trail
Corporations · finance · public institutions Win · macOS · Linux

Recently completed projects

Selected deployments shipped to production - from our wider portfolio

InsurTech · Document AI
Completed

Broker-Innovix

Bank-grade policy extractor

A production system at an insurance-sector client - a custom language model built for a specific business process extracts data from PDF policies, with no transfer to external AI providers.

  • Policy types: motor (TPL/comprehensive/accident), property, medical-facility liability, fleet, special risks
  • Safeguards: bank-grade, 5-layer protection, AES encryption, audit log
  • Infrastructure: dedicated GPUs in an EU private cloud, no external AI models
  • Automation: data normalisation from multi-vehicle and fleet policies
Brokers · multi-agencies · medical-facility liability Production
Consumer AI · Multimodal Platform
Completed

TutorX AI Assistant

AI platform with 120+ tools

A commercial AI platform aggregating the latest models from leading providers - available natively on iOS, Android, in the browser and on Windows, macOS and Linux desktop, with the application fully localised into 40 languages.

  • Models: GPT-5.4, Claude 4.6 and 4.7, Gemini 3.1 in a single panel
  • Tools: YouTube analyser with transcription, OCR, PDFs and images, image generator
  • Platforms: iOS, Android, browser and Windows, macOS, Linux
  • Safeguards: OAuth 2.0 (Google, Apple), data encryption, CSRF
Individuals · freelancers · content creators Production

Security and Compliance Audits

We carry out penetration testing and compliance audits for every client - regardless of whether they use our software. Our methodology is OWASP WSTG v4.2, PTES and CVSS 3.1 with a contextual Risk Rating; we map findings to DORA, NIS2, GDPR, ISO 27001 and the KNF Recommendation D. Non-invasive mode, exclusively under the system owner's written authorisation.

Entry point

External Audit

Black-Box External - the perspective of an external, anonymous attacker from the Internet

  • Reconnaissance and fingerprinting of the technology stack
  • Analysis of HTTP headers and TLS configuration (BEAST, POODLE, Heartbleed)
  • Reflected XSS, endpoint enumeration, directory fuzzing
  • Analysis of session token generation from the client side
  • Public misconfigurations, backup files, path disclosures
6-12 findings · CVSS 3.1 classification
Who it is for: a first assessment of the system, post-deployment verification, a fast external risk assessment
ADD-ON
Extension

Source-Code Review

White-Box - an extension of the Comprehensive Audit with static analysis of the backend code

  • Analysis of authorisation logic, hardcoded secrets, faulty access conditions
  • Vulnerabilities not reachable from the outside: SQLi in internal paths, cryptographic errors
  • Verification of how passwords and secrets are stored (env, config, logs)
  • Analysis of NPM / NuGet / pip / Composer dependencies for known CVEs
  • Assessment of the quality of error handling and logging from a security standpoint
Findings with precise location in the code + a ready patch
Who it is for: software vendors (ISVs), medical and financial systems, due diligence ahead of an acquisition
Compliance

Compliance Assessment

Verification of compliance with a specific standard or regulation - without the full penetration scope

  • DORA 2022/2554 - art. 8-10 ICT risk management, art. 24-27 TLPT
  • NIS2 / UKSC - art. 21 measures, 24/72h notification procedures, supply chain
  • ISO/IEC 27001:2022 - gap analysis of Annex A (93 controls)
  • OWASP ASVS 4.0 - L1 / L2 / L3 verification (286 requirements)
  • GDPR art. 32 - adequacy of technical measures for the supervisory authority (UODO)
List of requirements met / not met + recommendations
Who it is for: KNF, DORA, NIS2 essential and important entities, ISO 27001 certification and recertification

Standards and norms

  • OWASP WSTG v4.2 - the core testing methodology
  • PTES - the audit process framework
  • CVSS 3.1 Base Score + contextual Risk Rating
  • CWE 4.17+ - identification of vulnerability classes
  • OWASP Top 10 2021, API Top 10 2023, ASVS 4.0+

Report format

  • Executive Summary for the board - in business language
  • Section A (Black-Box) and Section B (Grey-Box) presented separately
  • Evidence - the verbatim output of shell commands, no paraphrasing
  • Full remediation proposals for every vulnerability - specific implementation recommendations, ready patches for findings from the code review
  • Remediation SLA schedule per severity
  • PL and EN versions for international boards

Non-invasiveness guarantee

  • Zero modification of data, databases, files and accounts
  • Zero load testing, DoS or DDoS
  • Zero webshells, backdoors or persistent changes
  • Evidence through safe Proof-of-Concept
  • Brute-force limited to 20 attempts - requires written consent

Quote & timeline

We prepare every quote individually after a short scoping conversation - tailored to the specifics of the application, the applicable regulations and the expected remediation timeline. We handle extended NDAs, bilingual reports and board briefings. We respond within 24 business hours.

Request an audit quote

Why Innovix - real advantages

Our own language models

We do not rely on commercial OpenAI or Google APIs. We build custom language models fine-tuned on Polish law, industry regulations and the client's own data corpora. The data stays exclusively within your infrastructure - with no transfer to external AI providers.

Our own technological innovation

We develop our own technologies at the boundary of neuro-symbolic artificial intelligence, knowledge graphs and enterprise cryptography. We invest in our own research teams, and that same expertise feeds directly into our clients' commercial projects.

Reports you can rely on

Every vulnerability is backed by the verbatim output of a shell command - no wording like "probably possible" or "may exist". Contextual Risk Rating over CVSS Base Score, a separate section for positive security aspects, and no duplication of findings across different test levels.

Infrastructure exclusively within the European Union

Hosting, databases, model training and log storage - fully within EU data centres, with no transfers to third countries whatsoever. GDPR compliance designed into the architecture, not merely declared in a privacy policy.

Collaboration Models

Licence

A one-off fee grants a full, perpetual right to use the software. A model for organisations with a CapEx cost policy and stable requirements.

  • One-off fee, recognised as CapEx
  • Full control over the deployed software
  • No subscription fees over a multi-year horizon
  • Option to modify and extend to the client's requirements
  • Technical support under an SLA contract

Subscription

A subscription with continuous access to the latest version, security updates and support. A model for organisations on an OpEx basis with a need to adapt quickly.

  • Regular updates and new features
  • Predictable monthly or annual costs (OpEx)
  • Priority technical support and incident response
  • Flexible plans tailored to the scale of the organisation
  • Scaling up and down in line with demand

Get in Touch

Innovix sp. z o.o.

Software · Security audits · AI

Registered address

ul. Aleja Śląska 1

54-118 Wrocław, Poland

Business enquiries

biuro@innovix.pl

general enquiries, projects, partnerships

Audits and quotes

audyty@innovix.pl

penetration testing, compliance, project quotes

Phone

+48 575 621 877

Mon-Fri 9:00-17:00 · we respond within 24 business hours

KRS 0001151438 NIP 8943252179 REGON 540633767

Send a message

We respond within 24 business hours. The data controller is Innovix sp. z o.o. - we process your data in accordance with our privacy policy.