Privacy Vault
Your data goes in. Sensitive identifiers stay home.
- 01. Zero cookies and built-in consent API
- 02. User authentication with JWT
- 03. Formalized transparency
- 04. User prompt anonymization
- 05. User profile data minimization
- 06. Audience-based access control
- 07. Real-time data management
- 08. Obfuscation of sensitive data
- 09. PII filtering for AI sources
- 10. Source poisoning protection
- 11. Model shielding with isolation for PII
- 12. Real-time model switching and failover
Privacy is not a setting. It is how the platform is built. It is also how Living Memory stays trustworthy.
Posture
Three principles. Equal weight.
01
Data sovereignty.
- EU data residency by default. Your data lives in EU cloud regions you can name.
- PII is filtered and tokenized at the gateway. Identifiers are swapped for safe placeholders before any call to a third-party generative model.
- Your auditor will not have to ask. The architecture answers the question before procurement does.
02
EU AI Act ready.
- Per-decision risk classification. Every AI interaction carries a classification you can read.
- Per-interaction audit trail. Timestamp, decision path, model used, source citation. Stored. Exportable.
- Real-time guardrails. The agent stops at the boundary you set. No surprises.
- Transparency reports your regulator can read. Format and language matter to procurement; the platform produces both.
03
Sector ready.
- Configurable for GDPR, DORA, ISO 42001. Built into the architecture, not bolted on afterwards.
- Configurable for entities supervised by BaFin and AFM. Sector-specific guardrails for finance, HR, payroll, healthcare are configured, not custom-built per customer.
- Independent content silos. One customer's data does not train another customer's agent.
PII = personally identifiable information. Tokenization swaps sensitive values for safe placeholders before they leave your perimeter.
The EU AI Act classifies AI systems by risk and mandates transparency, audit, and human oversight for high-risk systems.
GDPR - EU personal-data law. DORA - EU operational-resilience rules for finance. ISO 42001 - management standard for AI. BaFin / AFM - German and Dutch financial supervisors.
The architecture
Five pillars. One audit trail.
A customer request enters at the left through one of the touchpoints, picks up workspace context, passes through the Privacy Vault, reaches the AI automation layer, and resolves against the EU-resident AI constellation. The data layer underneath shows what each side persists. Compliance is woven through every pillar, not bolted on at the edge.
- Detect and classify
- Filter and mask PII
- Contextual rules
- Tokenize identifiers
- Minimize data
- Vet sources
- Model registry
- Load balancing
- Model routing
- Monitoring
- Evaluation
- Error detection
- Dynamic fail-over
Providers
Clouds
- AWS
- Microsoft Azure
- Google Cloud
Models
- Anthropic
- Cohere
- Gemini
- GPT
- Mistral
- Amazon Titan
Source data
Workspace data
User data
Token vault
Logs
The line
What we do not do.
Conservative buyers do not trust complete confidence. Here is where we draw the line.
No autopilot.
UNLESS never takes irreversible action without a human approving the boundary first.
No black box.
Every output points back to its source. If we cannot show our work, we do not ship the answer.
No surveillance.
Living Memory never records what is not necessary to serve the customer. PII is tokenized at the gateway, not after the fact.
Frameworks
Built to the regulations that matter.
-
EU AI Act
EU regulation classifying AI systems by risk and mandating transparency, audit, and oversight for high-risk systems.
-
GDPR
General Data Protection Regulation - EU framework for personal-data processing. EU residency, lawful basis, subject rights.
-
DORA
Digital Operational Resilience Act - EU rules for ICT risk and operational resilience in financial services.
-
OWASP
Application security practices aligned to the OWASP Top 10 risk model.
Hosted on infrastructure aligned to the AWS Well-Architected Framework - security, reliability, performance, cost, operational excellence.
Inside the product
Compliance, built in.
The Compliance tab in the Unless dashboard is the workspace your legal, DPO, and security teams already wanted. Audit logs, risk classifications, retention rules, sub-processor inventory, transparency reports - all there, all editable, all exportable.
No engineering tickets to read a log. No calendar invite to update a retention rule. The controls regulators ask about live where the people responsible for them work.
Documents
For procurement, in writing.
The system behind the trust posture
Frequently asked questions
Is your chatbot GDPR compliant?
Whether you call it a chatbot or the Customer Agent, the GDPR posture is the same: Unless is the processor and you remain the controller. Personal data stays in the EU, is screened for PII the moment it enters the platform, and sensitive identifiers are tokenized before any model call. Your end users exercise access, rectification, and erasure rights through your own dashboard, with a human confirming each request before anything changes.
Does the EU AI Act apply to a chatbot like this?
Yes, whether it's a simple chatbot or a fully agentic one. Under the EU AI Act, Unless is the Provider of the AI system and you are the Deployer. Most agentic deployments like the Customer Agent classify as limited-risk, which requires disclosing that the customer is talking to an AI, keeping a per-decision audit trail, and letting a human review or override any output, all of which the platform gives you by default. Where a specific use case is closer to high-risk, we work with you in advance on the additional obligations that apply.
What are the legal requirements for a customer-facing chatbot in the EU?
Three regimes usually apply at once, whether you're running a basic chatbot or an agentic system like the Customer Agent. GDPR governs the personal data it touches, with you as controller and Unless as processor. The EU AI Act governs the AI system itself: disclosure, audit trail, human oversight. And if you're a financial entity, DORA adds ICT risk management, incident reporting, and third-party oversight on top. Unless is built to carry the technical side of all three, not bolted on per deployment.
What are the risks of using a chatbot for customer support, and how does Unless address them?
The usual risks apply to any chatbot, agentic or not: handling personal data without proper filtering, giving answers with no record of why, or taking an action nobody approved. The Customer Agent addresses each directly: PII is filtered and tokenized before any model call, every answer carries a per-decision audit trail your DPO can read, and it never takes an irreversible action without a human approving the boundary first. The OWASP Top 10 LLM risks, prompt injection, insecure output handling, data poisoning, and the rest, are mitigated at the platform level.
Is a GDPR-compliant AI agent the same thing as a GDPR-compliant chatbot?
Functionally, yes. GDPR doesn't classify by label; what matters is who's the controller, who's the processor, and how personal data moves. The Unless Customer Agent carries the same GDPR posture whether your team calls it an agent, an assistant, or a chatbot: EU data residency, PII filtering and tokenization at the gateway, and data subject rights handled through your dashboard.
Does the EU AI Act classify Unless as high-risk?
Not by default. Most agentic deployments, ours included, across acquisition, retention, expansion, and support, classify as limited-risk, which calls for disclosure, human oversight, and a per-decision audit trail rather than the heavier obligations for high-risk systems. If your specific use case does qualify as high-risk under Annex III, we work with you in advance on the additional measures that apply.
Does any third party see our customers' personal data?
This holds regardless of whether you're running a simple chatbot or the full Customer Agent: the model that phrases the final answer never sees personal data, it receives only tokens and filtered text, never a recoverable name, email, or identifier. The one component that does see personal data in the clear is the PII-detection step itself, which is why it's listed as a sub-processor in your DPA, alongside the EU-hosted cloud providers the platform runs on. We don't claim no component ever touches personal data; we can say exactly which one does, and that it isn't the model.
Is Unless ISO 27001 certified?
Not as its own legal entity. The cloud infrastructure Unless runs on is: AWS holds ISO/IEC 27001, 27017, and 27018 certification, audited independently. Unless's own information security management system is modeled after ISO 27001 and 27002:2022, and we're working toward ISO/IEC 42001 for AI management systems specifically.
Is Unless's infrastructure fully sovereign to the EU?
Not yet at the infrastructure layer, and we don't claim otherwise. Unless runs on AWS EU regions today, and we intend to move to AWS's European Sovereign Cloud once it supports what the platform needs. What we can stand on today is the data flow: raw personal data is tokenized and filtered at the gateway, so it never reaches a model in a form a provider could read, regardless of which cloud region sits underneath.
Does DORA apply if we're a regulated financial institution using Unless?
Yes, and Unless is built to support your obligations rather than add to them. Our ICT risk management aligns with ISO 27001 and ENISA guidance, incidents are disclosed under committed timelines, the platform undergoes annual penetration testing, and subcontractors are disclosed with audit and termination rights you retain.
Bring your DPO. Bring your auditor. Bring your hardest question.
The architecture, the badges, and the documents on this page are the short version. Talking to our team is where the specifics get answered.