Trust
Accountability
Version 1.0 · Last updated 2026-06-25
Compliance is not just having the right architecture, it is being able to show that you used it correctly. Accountability is what you bring to a regulator inquiry, a customer dispute, or an internal investigation.
Key concepts
Per-decision audit trail
Every agent answer leaves a record. Inputs, Sources retrieved, model used, output, Procedures triggered. Available for the lifetime of the conversation log.
System audit trail
Every configuration change leaves a record. Who changed what, when, from where. Useful for internal reviews and SOC 2 evidence.
Incident response plan
Documented procedure for detecting, classifying, and disclosing incidents. Customer notification commitments under the DPA.
Regulatory frameworks
Unless is built for GDPR, DORA, and the EU AI Act. Our ISMS is modeled after ISO 27001 and 27002:2022. We monitor ISO/IEC TR 24028 on AI trustworthiness and are preparing for ISO/IEC 42001 certification. Customers in regulated sectors can use Unless under their own supervisory regimes, including entities supervised by BaFin and AFM. The Compliance Center holds the formal documentation behind each framework.
EU AI Act roles
Unless is the Provider of the AI system. We build, configure, and operate the platform: the RAG layer, the Privacy Vault, the agentic framework, and the integrations with foundation models. Foundation models themselves come from upstream providers (AWS Bedrock, Azure OpenAI) hosted in EU regions. Customers act as Deployers within their own context.
OWASP Top 10 LLM safeguards
The platform tracks which mitigations are enabled. Inputs validated, outputs sanitized, supply chain controlled, sensitive information protected. Status visible to your auditor.
What you can do here
- Pull a per-decision audit trail for any conversation
- Pull a system audit trail for any configuration change
- View the configuration status of GDPR, EU AI Act, DORA, and ISO controls
- Export audit data for inspectors
- Access the Compliance Center for DPA, sub-processor list, security addendum, code of conduct, and the rest of the underlying documents
When to use it
- During an audit by a regulator or third party
- When investigating an internal compliance question
- When preparing for an ISO certification renewal
- When a customer disputes something the agent did
How it works
Every meaningful action in the platform writes to the audit log. Conversation decisions, configuration changes, integration changes, access events. Logs are retention-managed under your privacy settings and exportable on demand.