Software house · Wrocław, Poland

A software house for large companies in regulated industries

Innovix is a software house in Wrocław, Poland, that designs and builds software for large companies and enterprises - and tests its security in-house. We work with finance and insurance companies, healthcare providers, law firms, manufacturers and the public sector - under an NDA, a data processing agreement and an SLA, with data kept in the European Union.

Security by design across the development lifecycle

  1. Requirements analysis

    • OWASP ASVS requirements
    • acceptance criteria
  2. Architecture and threat model

    • threat model
    • data in the EU
  3. Implementation

    • code review
    • SAST and SCA in CI/CD
  4. Pre-release testing

    • penetration test
    • retest
  5. Deployment

    • EU infrastructure
  6. Maintenance

    • vulnerability monitoring
    • SLA

Each new release goes back to analysis - we check security in every iteration, not once at the end of the project.

01Who we are

A software house that tests its own security

A software house is a company that designs, builds and maintains software to order for its clients - from requirements analysis, architecture and coding to deployment and the ongoing development of the system. Innovix combines this with a second capability: a team of penetration testers who test the security of our own systems and of systems built by other vendors.

We work mainly for large companies and enterprises in regulated industries, where software handles customer data, money or confidential information and every supplier has to pass vetting by procurement, security and data protection teams.

For these organisations, it is not enough that the system works. They also need to know:

  • whether the supplier can demonstrate security - with test results, not just assurances,
  • whether it knows the regulations the client is subject to - NIS2/KSC, DORA, GDPR,
  • whether it will sign the contracts the legal team requires - an NDA, a data processing agreement, an SLA,
  • whether the data will stay in the European Union or in the client's own infrastructure.

The way we work, described on this page, is built around these four points.

02Why Innovix

How we differ from a typical software house

Four things that set us apart from a typical software house - each one backed by evidence you can check.

Security

Our own pentesters in the development lifecycle

Penetration testing is part of the release cycle (before every major release), not a separate add-on ordered at the end of the project. The same pentesters also test systems built by other vendors - for companies that do not buy software from us.

  • testing to OWASP WSTG and PTES
  • a report with technical evidence
  • a retest of every fix

Regulation

Regulation built into the architecture, not just the paperwork

We record NIS2/KSC, DORA and GDPR requirements as acceptance criteria from the requirements analysis onwards. Preparing companies for audits is part of our everyday work, so we know what auditors ask about.

  • NIS2/KSC gap analysis
  • assessment of ICT risk frameworks (DORA)
  • data protection by design

Data in the EU

Data and AI models in the European Union

We keep hosting, databases, model training and logs in EU data centres, with no transfers to third countries - or we deploy the system in your own infrastructure.

  • private EU cloud with dedicated GPUs
  • your cloud in an EU region
  • on-premises

Contracts

Accountability written into the contract

We run every project under an NDA, a contract and an SLA with measurable acceptance criteria. We transfer the rights to the code to you, and any personal data entrusted to us in a project is covered by a data processing agreement.

  • an NDA before discussing details
  • acceptance criteria in the contract
  • transfer of the author's economic rights

You will find the evidence on our security service pages: we carry out penetration testing for companies that do not buy software from us, while the NIS2/KSC audit and DORA compliance are areas where we help organisations prepare for regulatory requirements.

03What we build

Software for large companies: systems, applications, integrations and AI

We also build desktop applications and SaaS platforms, and we run every project according to the principles described on our secure by design page.

04Process

How we work with large organisations

A large organisation means many stakeholders: the business, IT, security, data protection, procurement and legal. We shape the process so that each of them gets what they need at the right time.

  1. Call and NDA

    Goals, context and constraints. Before any details are exchanged, we sign an NDA - on your legal team's template if you prefer.

  2. Vendor due diligence

    Security questionnaires, a data processing agreement and a framework agreement - in parallel with the project work, not after it.

  3. Analysis and plan

    An analysis workshop, requirements with acceptance criteria, a release plan and a proposal broken down into stages.

  4. Iterations

    A working system demonstrated regularly, progress and risk reports, code review and testing in every iteration.

  5. Release

    Acceptance tests against the criteria in the contract, a penetration test and a retest of fixes before production.

  6. Maintenance

    Monitoring, security fixes and further development under an SLA.

Reporting

We report on progress regularly: what has been done, what comes next, what the risks are and which decisions are needed on your side.

Acceptance criteria

The acceptance criteria for each stage also cover security and performance requirements. You know what you will get and when.

Security in every iteration

Code review, static analysis and dependency analysis in the CI/CD pipeline, and a penetration test by our team before every major release.

05Engagement models

A fixed-scope project or a dedicated team

Fixed-scope project

We agree the scope, schedule and acceptance criteria after the requirements analysis. We work in stages, with milestones and sign-off of each stage.

Dedicated team

A permanent Innovix team develops your system at your organisation's pace. We put the team together to suit the project.

We match the billing model to your organisation's cost policy: licence, subscription or hybrid. A fixed-scope project works well when the requirements can be clearly described at the outset; a dedicated team, when the system will evolve over several years and priorities shift with the business. You will find details and a comparison of the models on our engagement models page.

06Procurement readiness

A software house for enterprises: ready for your procurement process

Procurement, security and legal teams vet suppliers against their own checklists. Here is what we can offer from the very first call.

NDA

We sign a non-disclosure agreement before discussing the details of your system, including your own extended version.

Framework agreement

We can work under a framework agreement with successive orders - without renegotiating terms for every project.

Rights to the code

We transfer the author's economic rights to the code written for the client in the fields of exploitation specified in the contract, and hand over the source code after acceptance.

Data processing agreement

When we process personal data on the client's behalf, we sign a data processing agreement in line with Art. 28 GDPR.

Maintenance SLA

We provide maintenance and further development after go-live under an SLA with agreed service levels.

Acceptance criteria

Every stage has measurable acceptance criteria written into the contract - you know what you will get and when.

Security questionnaires

We complete vendor security questionnaires and surveys from procurement and security teams.

Liability insurance

The company holds third-party liability insurance covering its business activities.

07Industries

Industries we build software for

We also work for the public sector. In each of these industries, software is subject to different rules - from professional secrecy and health data to financial supervision requirements - and it is these rules that set the non-functional requirements of each project.

08Case studies and products

What we have built

Projects delivered for clients, and our own products, which are in development. The same expertise goes straight into our clients' projects.

InsurTech · Document AI

Broker-Innovix: data extraction from insurance policies

A production system for a client in the insurance sector. A dedicated language model extracts data from PDF policies, with no transfer to external AI providers.

  • Motor (OC/AC/NNW), property, medical liability, fleet and specialty risk policies
  • Normalisation of data from multi-vehicle and fleet policies
  • Dedicated GPUs in a private cloud in the EU
  • Document AI
  • Language model
  • EU private cloud

Delivered

Consumer AI · Multimodal platform

TutorX AI Assistant: an AI platform for mobile, web and desktop

A commercial AI platform that brings together models from leading providers - native on iOS and Android, in the browser and on Windows, macOS and Linux, localised into 40 languages.

  • Over 120 tools, including video transcription, OCR and PDF and image analysis
  • GPT, Claude and Gemini models in a single dashboard
  • OAuth 2.0 sign-in (Google, Apple), data encryption, CSRF protection
  • iOS
  • Android
  • Web
  • Desktop
  • 40 languages

Delivered

09Technologies

The technologies we work with

Innovix technologies by area
Area Technologies
Web applications TypeScript, React, Next.js, Node.js
Backend and data Node.js, Python, Rust, PostgreSQL, Redis
Mobile applications Swift (iOS), Kotlin (Android), React Native, Flutter, Tauri 2
Desktop applications Tauri 2, Rust, TypeScript, SQLCipher
AI and documents Python, language model fine-tuning, OCR, knowledge graphs
Infrastructure AWS, Azure, GCP (EU regions), private EU cloud with dedicated GPUs, on-premises
Security OAuth 2.0, AES-256-GCM, SQLCipher, CI/CD with security testing

We choose technology to fit the requirements, the team that will develop the system and your organisation's policies - for example, lists of approved programming languages and cloud providers. We justify the choice in the architecture document, so that years from now it is clear why the system was built the way it was.

10Location

A software house in Poland: our office in Wrocław

Our office is in Wrocław, Poland (Aleja Śląska 1, 54-118 Wrocław) - meetings at the office by appointment. We deliver projects and security tests for companies across Poland and the European Union, remotely and on site: we run workshops, progress reviews and board presentations wherever your team works.

For clients outside Poland, this means working with a supplier based in the European Union: data stays in EU data centres or in your own infrastructure and is processed in line with the GDPR, and we work in English and Polish. How we work with clients from other countries is described on our software development company in Poland page.

We reply to enquiries within 24 hours on business days - we work Monday to Friday, 08:00-16:00 Polish time (CET/CEST). Tell us what you need: the first call is simply to establish whether and how we can help, and it puts you under no obligation. You will find our contact details on the contact page.

Frequently asked questions

How should a large company choose a software house?

Check five things: whether the supplier understands your industry and its regulations; how it ensures security (and whether it can demonstrate it rather than just claim it); what contract terms it offers - rights to the code, confidentiality, data processing, an SLA; where the data will be processed; and how the work is signed off. Ask for sample acceptance criteria and a description of the release process. A good partner will give you specific answers to these questions before sending a proposal.

Who owns the code you write for us?

We transfer the author's economic rights to the code we write for you in the fields of exploitation listed in the contract, and hand over the source code after acceptance. The exceptions are our own products and open-source libraries, which you use under a licence. Details: code ownership and licences.

How do you ensure team continuity?

Every code change is reviewed by a second person, so knowledge of the system never sits in one developer's head. With a dedicated team, we agree the team composition with you and plan any changes well in advance, with time to bring a new person up to speed on the project.

How do you handle security in your projects?

Security is part of every iteration: OWASP ASVS requirements in the acceptance criteria, a threat model at the architecture stage, code review, static analysis and dependency analysis in the CI/CD pipeline and, before release, a penetration test by our own pentesters with a retest of the fixes. We describe the full lifecycle on our secure by design page.

Can you work on our infrastructure?

Yes. We can deploy the system in your own infrastructure (on-premises), in your AWS, Azure or GCP account in a European Union region, or in a private cloud in the EU. If your company policy requires it, we work in your environments with access granted and controlled by your IT team.

Do you sign a data processing agreement?

Yes. When we process personal data on your behalf in a project - for example when maintaining a system that holds customer data - we sign a data processing agreement in line with Art. 28 GDPR. We also complete the vendor security questionnaires that procurement and security teams ask for.

How do you work out the cost of a project?

We prepare every proposal individually. For a fixed-scope project, we give the cost of each stage after the requirements analysis; for a dedicated team, the cost of the team per billing period. The cost depends on factors such as scope, integrations, security and regulatory requirements, and maintenance. More: how much bespoke software costs.

How long does it take to get a project started?

We reply to enquiries within 24 hours on business days. Next come a call and an NDA, an analysis workshop and a proposal with a schedule - how long these steps take depends mainly on the availability of people on your side and on your procurement procedures. We give the start date in our proposal.

Sources

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR), OJ L 119, 4.5.2016, as corrected by OJ L 127, 23.5.2018 - consolidated text ()
  2. Act of 5 July 2018 on the National Cybersecurity System (KSC Act; Dz.U. 2018 item 1560, as amended) - ISAP, unofficial consolidated text prepared by the Chancellery of the Sejm (in Polish) ()
  3. Regulation (EU) 2022/2554 of the European Parliament and of the Council on digital operational resilience for the financial sector (DORA), OJ L 333, 27.12.2022 ()

Legal status as of Updated

Related services

Let's talk about your project or audit

Tell us briefly what you need - we will come back with proposed next steps. We work in English and Polish.

or call +48 575 621 877