Trust
Accountability
Version 1.0 · Last updated 2026-05-27
Compliance is not just having the right architecture, it is being able to show that you used it correctly. Accountability is what you bring to a regulator inquiry, a customer dispute, or an internal investigation.
Key concepts
Per-decision audit trail
Every agent answer leaves a record. Inputs, Sources retrieved, model used, output, Procedures triggered. Available for the lifetime of the conversation log.
System audit trail
Every configuration change leaves a record. Who changed what, when, from where. Useful for internal reviews and SOC 2 evidence.
Incident response plan
Documented procedure for detecting, classifying, and disclosing incidents. Customer notification commitments under the DPA.
Regulatory frameworks
Unless is built for GDPR, DORA, and the EU AI Act. Our ISMS is modeled after ISO 27001 and 27002:2022. We monitor ISO/IEC TR 24028 on AI trustworthiness and are preparing for ISO/IEC 42001 certification. Customers in regulated sectors can use Unless under their own supervisory regimes, including entities supervised by BaFin and AFM. The Compliance Center holds the formal documentation behind each framework.
EU AI Act roles
Unless is the Provider of the AI system. We build, configure, and operate the platform: the RAG layer, the Privacy Vault, the agentic framework, and the integrations with foundation models. Foundation models themselves come from upstream providers (AWS Bedrock, Azure OpenAI) hosted in EU regions. Customers act as Deployers within their own context.
OWASP Top 10 LLM safeguards
The platform tracks which mitigations are enabled. Inputs validated, outputs sanitized, supply chain controlled, sensitive information protected. Status visible to your auditor.
What you can do here
- Pull a per-decision audit trail for any conversation
- Pull a system audit trail for any configuration change
- View the configuration status of GDPR, EU AI Act, DORA, and ISO controls
- Export audit data for inspectors
- Access the Compliance Center for DPA, sub-processor list, security addendum, code of conduct, and the rest of the underlying documents
When to use it
- During an audit by a regulator or third party
- When investigating an internal compliance question
- When preparing for an ISO certification renewal
- When a customer disputes something the agent did
How it works
Every meaningful action in the platform writes to the audit log. Conversation decisions, configuration changes, integration changes, access events. Logs are retention-managed under your privacy settings and exportable on demand.
Frequently asked questions
How do I pull an audit trail for a specific conversation?
Open Conversations, find the conversation, and click "Export audit trail". PDF or JSON.
How do I see who changed a setting last week?
Open "Trust > Accountability > System audit trail". Filter by date and section. Each entry shows the actor, the change, and the timestamp.
How do I prove EU AI Act compliance for a specific Moment?
Combine three things. First, the per-decision audit trail from Conversations. Second, the configuration status in Accountability showing which AI Act controls are active. Third, the Provider documentation in the Compliance Center, including risk classification and Provider obligations. Together those cover what an auditor will ask for.
How does incident notification work?
Critical incidents are disclosed to customers within the timeline in your DPA. Status updates are posted at status.unless.com.
Can I assign an external auditor?
Yes. Create an external-auditor role in Team and roles with read access to Trust and Conversations only.
How long are audit logs retained?
Standard retention for security-relevant logs is one year, unless your contract sets a shorter period. Logs are protected against tampering, monitored continuously, and queryable for investigations or audits.
Has Unless had any incidents?
No significant personal data breach in the last three years. No data access requests from non-EU government authorities. The incident response plan, the customer notification commitments, and the liability insurance details are in the Compliance Center and your DPA.
Who is responsible for data protection at Unless?
The CEO is the designated contact for personal data matters. The CTO owns technical operation and security of the platform. Senior management oversees the ISMS and AI governance. Contact details are in the Compliance Center.