Map, collect, draft, export
Map systems, collect evidence, and draft then export reports. Free includes a SOC 2 draft. Team includes a final exportable report.
SOC 2 and EU CRA programmes, one per product. Collect evidence per control, including runtime evidence from agents in your network. Article 14 reporting is free.
Talk to us · Need intent-preserving reviewable PRs? Request a remediation POC.
Map systems, collect evidence, and draft then export reports. Free includes a SOC 2 draft. Team includes a final exportable report.
Vulnerability handling records (Annex I Part II) and the Article 14 clocks sit in one place: the 24 hour early warning, the 72 hour notification, and the final report. Article 14 reporting is free on every plan.
Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.
01
SOC 2 or EU CRA, one per product.
02
Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.
03
Collect evidence per control, including vulnerability handling records (Annex I Part II) and runtime agent logs.
04
A SOC 2 draft on Free and a final exportable report on Team, plus the Article 14 24 hour early warning, 72 hour notification, and final report, which are free on every plan.
Reports are product outputs, not an audit opinion or certification.
Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.
Your AWS account: data plane
Prompts, virtual keys, spend · VPC · AWS · Azure · GCP
Load balancer
HTTPS into your VPC
In-network gateway
Compute in private subnets
Database
Spend + keys
Secrets
Customer-managed
Model providers
Called through your egress
Agents & tools
Inspected in your account
Outbound HTTPS
Customer-controlled NAT
UnitOne control plane
Tenant config, policy, inventory, evidence
API + console
Registration, spend views, policy, compliance
Tenant database
Inventory + evidence
Key vault
Control-plane secrets
Identity federation
Token exchanged at STS
Customer data plane on the left: agents and apps reach an in-network gateway in your VPC, then models and tools, with customer-controlled egress. UnitOne control plane on the right: API, console, policy, evidence, and spend. Sync uses admin API, identity federation, and webhooks over outbound HTTPS only.
How multi-cloud deploy works? FAQ
Run a SOC 2 or EU CRA programme for one product. Article 14 reporting is free on every plan.
Start free