When software is a compliance decision, not just a build.
We build custom cloud, web and mobile software for finance, fintech and insurance teams operating under DORA, NIS2, GDPR, PCI DSS and PSD2 — where an audit trail, EU data residency and a team that's still here in three years aren't nice-to-haves. They're the requirement.
In a regulated business, the wrong software partner is a risk on your register.
Most agencies ship and leave. When you answer to a regulator, that's not an option — the decisions your vendor makes become your exposure. Here's what usually goes wrong.
Compliance bolted on last
Audit trails, access control and data residency get retrofitted after the build — expensively, and never quite cleanly. By then the architecture is fighting you.
No one left to answer the auditor
The build team disbands at launch. Six months later a supervisor asks how a decision was logged, and there's no one who can explain the system.
Data leaving the EU quietly
A third-party API here, a US-hosted service there. Under GDPR and DORA, every one of those is a data-transfer and third-party-risk question you now own.
Juniors on regulated work
The people in the sales meeting aren't the people writing the code. In regulated software, that gap between promise and delivery is where the real risk lives.
Compliance-aware from the first architecture diagram.
We've built regulated software since 2015. These are the habits that make our clients' audits, not their incidents, the boring part.
Compliance-aware architecture
Access control, segregation of duties and data classification are design decisions from day one — not a phase we add before go-live.
Audit trails & traceability
Every material action is logged, immutable and exportable. When a regulator or auditor asks "who did what, when", the answer is one query away.
EU data sovereignty
Data, hosting and the team building it all stay inside the EU. No surprise cross-border transfers to explain later.
Security by default
Encryption in transit and at rest, MFA, least-privilege access and dependency scanning — following ISO 27001 and SOC 2 practices as standard.
Senior team, no handoffs
The people who scope your project are the people who build it. No juniors hidden in the back, no account manager between you and the work.
Still here in three years
We stay long after launch — maintenance, incident response and the regulatory changes that keep coming. Partners, not a project team that vanishes.
We speak the frameworks your compliance team lives in.
Our focus is finance, fintech and insurance — and the overlapping EU regimes that govern them. We build software that's ready when the questions come.
Digital Operational Resilience Act
ICT risk management, third-party register of information, and 24-hour incident notification. We built DORApp — a GRC tool used by financial institutions across the EU — so we know it in production, not just on paper.
Network & Information Security Directive
For essential and important entities across 18 critical sectors: governance, risk management and incident reporting baked into the systems you run.
General Data Protection Regulation
Data minimisation, EU residency, consent, and the right to erasure — handled at the data-model level, not with a cookie banner and hope.
Payment Card Industry Data Security
For anything that touches card data: tokenisation, scope reduction and secure integrations with payment providers.
Payment Services Directive 2
Strong customer authentication and secure open-banking integrations, built to the standard supervisors expect.
Anti-Money-Laundering & Know-Your-Customer
Identity verification, screening and audit-ready record-keeping designed into lending, payments and insurance workflows.
Regulated software we've actually shipped.
The strongest signal that we can build under regulation is that we already do — for insurers, financial institutions and payment businesses across the EU.
DORApp
A DORA governance, risk & compliance platform for European financial institutions — register of information, third-party risk, ICT incident management with a 24-hour notification SLA, ISO 27001 practices and XBRL reporting.
Aestimo
A property-valuation platform now powering daily operations at insurers including GRAWE Hrvatska and NAI Significa — end-to-end encrypted, and saving hours on every claim.
Custom financial software
Lending, insurance, payments and regulatory tooling — secure by default and audit-ready, covering AML, KYC, GDPR, PCI DSS and PSD2.
"They understood how significant the regulatory change would be. U-centrix knew how to turn that understanding into technology." Forbes Slovenija — recognition that the software we build for regulated finance stands up to scrutiny.
Have a build that answers to a regulator?
A 30-minute call with our CEO or technical lead. No sales script, no obligation — just a straight conversation about your compliance constraints and what it takes to build for them.
Book a call