Trust

The only AI customer agent built for the EU from day one.

Compliance is not a setting. It is how the platform is built. EU data residency by default. Per-decision audit trail. Real-time guardrails. Transparent by design.

Privacy Vault

Your data goes in. Sensitive identifiers stay home.

  • 01. Zero cookies and built-in consent API
  • 02. User authentication with JWT
  • 03. Formalized transparency
  • 04. User prompt anonymization
  • 05. User profile data minimization
  • 06. Audience-based access control
  • 07. Real-time data management
  • 08. Obfuscation of sensitive data
  • 09. PII filtering for AI sources
  • 10. Source poisoning protection
  • 11. Model shielding with isolation for PII
  • 12. Real-time model switching and failover

Privacy is not a setting. It is how the platform is built. It is also how Living Memory stays trustworthy.

Posture

Three principles. Equal weight.

01

Data sovereignty.

  • EU data residency by default. Your data lives in EU cloud regions you can name.
  • PII is filtered and tokenized at the gateway. Identifiers are swapped for safe placeholders before any call to a third-party generative model.
  • Your auditor will not have to ask. The architecture answers the question before procurement does.

02

EU AI Act ready.

  • Per-decision risk classification. Every AI interaction carries a classification you can read.
  • Per-interaction audit trail. Timestamp, decision path, model used, source citation. Stored. Exportable.
  • Real-time guardrails. The agent stops at the boundary you set. No surprises.
  • Transparency reports your regulator can read. Format and language matter to procurement; the platform produces both.

03

Sector ready.

  • Configurable for GDPR, DORA, ISO 42001. Built into the architecture, not bolted on afterwards.
  • Configurable for entities supervised by BaFin and AFM. Sector-specific guardrails for finance, HR, payroll, healthcare are configured, not custom-built per customer.
  • Independent content silos. One customer's data does not train another customer's agent.

PII = personally identifiable information. Tokenization swaps sensitive values for safe placeholders before they leave your perimeter.

The EU AI Act classifies AI systems by risk and mandates transparency, audit, and human oversight for high-risk systems.

GDPR - EU personal-data law. DORA - EU operational-resilience rules for finance. ISO 42001 - management standard for AI. BaFin / AFM - German and Dutch financial supervisors.

The architecture

Five pillars. One audit trail.

A customer request enters at the left through one of the touchpoints, picks up workspace context, passes through the Privacy Vault, reaches the AI automation layer, and resolves against the EU-resident AI constellation. The data layer underneath shows what each side persists. Compliance is woven through every pillar, not bolted on at the edge.

Customer touchpoints
Co-pilot
Website
In product
API
Workspace context
Identity
User roles
Audiences
Sources
Privacy Vault
  • Detect and classify
  • Filter and mask PII
  • Contextual rules
  • Tokenize identifiers
  • Minimize data
  • Vet sources
AI automation
RAG
Workflows
Agents
APIs
AI constellation
  • Model registry
  • Load balancing
  • Model routing
  • Monitoring
  • Evaluation
  • Error detection
  • Dynamic fail-over
EU resident

Providers

Clouds

  • AWS
  • Microsoft Azure
  • Google Cloud

Models

  • Anthropic
  • Cohere
  • Gemini
  • GPT
  • Mistral
  • Amazon Titan
EU data residency

Source data

Workspace data

User data

Token vault

Logs

The line

What we do not do.

Conservative buyers do not trust complete confidence. Here is where we draw the line.

No autopilot.

UNLESS never takes irreversible action without a human approving the boundary first.

No black box.

Every output points back to its source. If we cannot show our work, we do not ship the answer.

No surveillance.

Living Memory never records what is not necessary to serve the customer. PII is tokenized at the gateway, not after the fact.

Inside the product

Compliance, built in.

The Compliance tab in the Unless dashboard is the workspace your legal, DPO, and security teams already wanted. Audit logs, risk classifications, retention rules, sub-processor inventory, transparency reports - all there, all editable, all exportable.

No engineering tickets to read a log. No calendar invite to update a retention rule. The controls regulators ask about live where the people responsible for them work.

Documents

For procurement, in writing.

  • Standard Data Processing Agreement (DPA) View
  • EU AI Act compliance briefing View
  • Policies for customers View
  • Sub-processor list View
  • Data residency and locations View
  • Security questionnaire pre-filled responses Available on request

The system behind the trust posture

Frequently asked questions

Is your chatbot GDPR compliant?

Whether you call it a chatbot or the Customer Agent, the GDPR posture is the same: Unless is the processor and you remain the controller. Personal data stays in the EU, is screened for PII the moment it enters the platform, and sensitive identifiers are tokenized before any model call. Your end users exercise access, rectification, and erasure rights through your own dashboard, with a human confirming each request before anything changes.

Does the EU AI Act apply to a chatbot like this?

Yes, whether it's a simple chatbot or a fully agentic one. Under the EU AI Act, Unless is the Provider of the AI system and you are the Deployer. Most agentic deployments like the Customer Agent classify as limited-risk, which requires disclosing that the customer is talking to an AI, keeping a per-decision audit trail, and letting a human review or override any output, all of which the platform gives you by default. Where a specific use case is closer to high-risk, we work with you in advance on the additional obligations that apply.

What are the legal requirements for a customer-facing chatbot in the EU?

Three regimes usually apply at once, whether you're running a basic chatbot or an agentic system like the Customer Agent. GDPR governs the personal data it touches, with you as controller and Unless as processor. The EU AI Act governs the AI system itself: disclosure, audit trail, human oversight. And if you're a financial entity, DORA adds ICT risk management, incident reporting, and third-party oversight on top. Unless is built to carry the technical side of all three, not bolted on per deployment.

What are the risks of using a chatbot for customer support, and how does Unless address them?

The usual risks apply to any chatbot, agentic or not: handling personal data without proper filtering, giving answers with no record of why, or taking an action nobody approved. The Customer Agent addresses each directly: PII is filtered and tokenized before any model call, every answer carries a per-decision audit trail your DPO can read, and it never takes an irreversible action without a human approving the boundary first. The OWASP Top 10 LLM risks, prompt injection, insecure output handling, data poisoning, and the rest, are mitigated at the platform level.

Is a GDPR-compliant AI agent the same thing as a GDPR-compliant chatbot?

Functionally, yes. GDPR doesn't classify by label; what matters is who's the controller, who's the processor, and how personal data moves. The Unless Customer Agent carries the same GDPR posture whether your team calls it an agent, an assistant, or a chatbot: EU data residency, PII filtering and tokenization at the gateway, and data subject rights handled through your dashboard.

Does the EU AI Act classify Unless as high-risk?

Not by default. Most agentic deployments, ours included, across acquisition, retention, expansion, and support, classify as limited-risk, which calls for disclosure, human oversight, and a per-decision audit trail rather than the heavier obligations for high-risk systems. If your specific use case does qualify as high-risk under Annex III, we work with you in advance on the additional measures that apply.

Does any third party see our customers' personal data?

This holds regardless of whether you're running a simple chatbot or the full Customer Agent: the model that phrases the final answer never sees personal data, it receives only tokens and filtered text, never a recoverable name, email, or identifier. The one component that does see personal data in the clear is the PII-detection step itself, which is why it's listed as a sub-processor in your DPA, alongside the EU-hosted cloud providers the platform runs on. We don't claim no component ever touches personal data; we can say exactly which one does, and that it isn't the model.

Is Unless ISO 27001 certified?

Not as its own legal entity. The cloud infrastructure Unless runs on is: AWS holds ISO/IEC 27001, 27017, and 27018 certification, audited independently. Unless's own information security management system is modeled after ISO 27001 and 27002:2022, and we're working toward ISO/IEC 42001 for AI management systems specifically.

Is Unless's infrastructure fully sovereign to the EU?

Not yet at the infrastructure layer, and we don't claim otherwise. Unless runs on AWS EU regions today, and we intend to move to AWS's European Sovereign Cloud once it supports what the platform needs. What we can stand on today is the data flow: raw personal data is tokenized and filtered at the gateway, so it never reaches a model in a form a provider could read, regardless of which cloud region sits underneath.

Does DORA apply if we're a regulated financial institution using Unless?

Yes, and Unless is built to support your obligations rather than add to them. Our ICT risk management aligns with ISO 27001 and ENISA guidance, incidents are disclosed under committed timelines, the platform undergoes annual penetration testing, and subcontractors are disclosed with audit and termination rights you retain.

Bring your DPO. Bring your auditor. Bring your hardest question.

The architecture, the badges, and the documents on this page are the short version. Talking to our team is where the specifics get answered.