UnitOne Compliance

SOC 2 and EU CRA programmes, one per product. Collect evidence per control, including runtime evidence from agents in your network. Article 14 reporting is free.

Talk to us · Need intent-preserving reviewable PRs? Request a remediation POC.

Map, collect, draft, export

Map systems, collect evidence, and draft then export reports. Free includes a SOC 2 draft. Team includes a final exportable report.

Annex I Part II and Article 14

Vulnerability handling records (Annex I Part II) and the Article 14 clocks sit in one place: the 24 hour early warning, the 72 hour notification, and the final report. Article 14 reporting is free on every plan.

Runtime evidence

Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.

How UnitOne Compliance works

  1. 01

    Pick a programme

    SOC 2 or EU CRA, one per product.

  2. 02

    Connect your systems

    Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.

  3. 03

    Collect evidence

    Collect evidence per control, including vulnerability handling records (Annex I Part II) and runtime agent logs.

  4. 04

    Draft reports

    A SOC 2 draft on Free and a final exportable report on Team, plus the Article 14 24 hour early warning, 72 hour notification, and final report, which are free on every plan.

Reports are product outputs, not an audit opinion or certification.

Deploy in your network on AWS, Azure, or GCP

Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.

Agents / apps
In-network gatewayin your VPC
Models & tools
Control planepolicy · CRA evidence · spend

Your AWS account: data plane

Prompts, virtual keys, spend · VPC · AWS · Azure · GCP

Load balancer

HTTPS into your VPC

In-network gateway

Compute in private subnets

Database

Spend + keys

Secrets

Customer-managed

Model providers

Called through your egress

Agents & tools

Inspected in your account

Outbound HTTPS

Customer-controlled NAT

UnitOne control plane

Tenant config, policy, inventory, evidence

API + console

Registration, spend views, policy, compliance

Tenant database

Inventory + evidence

Key vault

Control-plane secrets

Identity federation

Token exchanged at STS

Trust boundary: outbound HTTPS only

Customer data plane on the left: agents and apps reach an in-network gateway in your VPC, then models and tools, with customer-controlled egress. UnitOne control plane on the right: API, console, policy, evidence, and spend. Sync uses admin API, identity federation, and webhooks over outbound HTTPS only.

How multi-cloud deploy works? FAQ

Frequently asked questions

What counts as a product?
One SOC 2 system or one EU CRA product. Free covers 1, Team covers 2. More than 2, talk to us.
Where does runtime evidence come from?
Runtime evidence for agents comes from a gateway you deploy in your AWS, Azure, or GCP network, outbound HTTPS only.
Is Article 14 reporting really free?
Yes. Preparing the 24 hour early warning, the 72 hour notification and the final report is free on every plan.
Is Security Remediation included when I start free?
No. Intent-preserving fixes that land as reviewable PRs are a scoped proof of concept. Request a remediation POC if you need that engagement.

Start free

Run a SOC 2 or EU CRA programme for one product. Article 14 reporting is free on every plan.

Start free