Trust, privacy, and compliance
Security, access control, and transparency reporting
Security, access control, and transparency reporting are foundational elements of the Unless platform, designed to protect customer data, ensure proper governance, and maintain trust throughout the AI-powered customer engagement lifecycle. These elements are deeply integrated into the platform’s architecture and operational practices, aligning with strict compliance standards and industry best practices.
security measures in Unless
Unless employs a comprehensive security framework that safeguards platform systems, integrations, and customer data. This framework includes multiple layers of protection:
Data classification and encryption: Customer data is classified as confidential and protected by encryption both at rest and in transit using AES-256 and TLS with modern cipher suites. Passwords and secrets are securely stored with salting, hashing, and additional encryption.
Multi-factor authentication (MFA): MFA is enforced for all personnel accessing systems that handle customer data, including consoles, dashboards, and administrative tools. Privileged accounts have extra controls.
Role-based access control (RBAC): Access to projects, assistants, and data sets is restricted based on roles and teams. Sensitive areas require higher privileges, and end-user access is managed through secure identification and taxonomy trees.
Backup and recovery: Automated, encrypted backups run regularly with redundancy and restore tests. Continuous backups are retained for 35 days to ensure data availability and integrity.
Network and cloud security: The platform uses firewalls, network segmentation, managed load balancers, intrusion detection, and limited external administrative access. Cloud security frameworks enforce role-based access, encryption, PII filtering, monitoring, and logging across AWS and EU cloud environments.
Secure development and supply chain security: Secure coding practices, peer reviews, automated scanning, dependency monitoring, and patching maintain code security. Subcontractors undergo security posture assessments before onboarding and periodic reviews thereafter.
Incident detection and handling: Logs are collected and monitored with alerting for suspicious activity. Defined processes cover detection, triage, containment, eradication, recovery, and post-incident review, with customer notification when relevant.
Availability and disaster recovery: Redundancy across multiple availability zones, managed replicated services, stateless components, and tested backups ensure platform availability and business continuity.
access control practices
Access control in Unless is strict and comprehensive to prevent unauthorized data access and maintain operational security:
Backend-enforced access control: All access permissions are enforced server-side with fail-secure behavior to prevent unauthorized data exposure.
Centralized access management: The platform enforces least privilege principles, strong authentication, MFA, and detailed logging of access events.
Role and team-based permissions: Customers can restrict access to specific projects, assistants, and data sets according to organizational roles and responsibilities.
Case-by-case personnel access: Unless personnel require explicit customer authorization to access customer accounts, controlled through product account settings.
Password policies and session management: Passwords must be complex, with mixed character types and minimum length. Administrative accounts require MFA, and session tokens are short-lived to reduce risk.
transparency reporting and governance
Transparency is a core pillar of trust and compliance in Unless. The platform ensures clear and open disclosure about how it operates, manages data, and evolves:
Ongoing communication: Unless commits to keeping customers informed about changes to data privacy and security processes, including practices and policies.
Open-source UI components and documentation: Transparency is supported by publicly available user interface components, explicit configuration options, and detailed changelogs.
Dashboard notifications: Customers receive notifications about relevant updates and operational changes through the dashboard interface.
Contractual documentation: Comprehensive agreements, including data processing addenda and security addenda, clarify responsibilities and commitments.
Audit trails and accountability: Every Customer Agent decision leaves an audit trail, supporting accountability and compliance with regulations such as GDPR and the EU AI Act.
Data subject rights support: The platform supports customer operations for data access, correction, and erasure requests, with verification steps and token orphaning to protect privacy.
summary
Unless integrates robust security measures, strict access control, and transparent reporting to build a trustworthy AI platform for customer engagement. These safeguards protect sensitive data, ensure compliance with European regulations, and provide customers with clear visibility into platform operations and changes. Together, they form a comprehensive governance framework that supports secure, accountable, and transparent AI-powered interactions.