One AI chat. Every framework you ship against.

Comply with 18 frameworks. From one conversation.

One AI chat that spans GDPR, DORA, NIS2, the AI Act, ISO 27001, SOC 2, and 12 more — scoped to the regulation you are working on right now. Your documents. Your templates. Audit-ready answers.

18 frameworks covered
EU data residency (eu-west-1)
Frontier-model AI
The problem

You don't do one framework.
You do all of them.

DPOs today don't get the luxury of a single regulation. You ship against GDPR, DORA, NIS2, the AI Act, ISO 27001, SOC 2 — all at once, across overlapping controls, with the same finite team. That is the job now.

Compliance fatigue

Every new regulation brings another 200-page text, another set of controls, another audit cycle. There aren't 18 DPOs on your team — there is one of you.

No single source of truth

Your policies live in one folder, your DPAs in another, your control matrices in a spreadsheet, and your audit evidence wherever someone last saved it. Every question means 20 minutes of hunting.

No time to learn 18 dialects

DORA Article 30 and NIS2 Article 21 sound similar. They aren't. Knowing exactly where they overlap and where they diverge is a full-time job you don't have.

The solution

One AI chat.
Scoped to the regulation you are working on.

Pick one framework. The chat stays inside it — relevant templates, your auto-attached documents, and the right guardrails. Or start a general chat without a framework. 90 substantive compliance templates across 18 frameworks, one conversation, one source of truth.

Framework-scoped AI context

Pick GDPR, DORA, NIS2 or any of the other 15. The chat loads that regulation's templates, pulls your matching documents, and only reasons about the framework you're working on.

Your documents, your templates

Upload your policies, DPAs, contracts, and procedures once. UnnaData auto-attaches the relevant ones to every framework-scoped session. No more hunting through folders mid-audit.

Audit-ready answers

Every answer cites the regulation article, the template clause, or the uploaded document paragraph it drew from. When the auditor asks "why does this control exist?", the chat already wrote your evidence paragraph.

90 compliance templates

Five substantive templates per framework — DPIAs, risk registers, vendor onboarding, incident response, audit checklists. Real content written for DPOs, not placeholder text.

Team collaboration

Invite your compliance team, assign framework ownership, and share sessions with full audit trail visibility. Every message, every document reference, every framework switch is logged.

Usage + token transparency

Per-message token usage, per-framework adoption tracking, per-session audit trails. You see exactly which frameworks your team is working on and what it costs.

All 18 frameworks

One assistant.
Every framework your team ships against.

UnnaData covers 8 EU regulations, 6 global standards, 2 US frameworks, 1 California privacy law, and 1 German IT baseline standard — all in one chat, all cited back to the regulation text.

EU

GDPR

EU regulation

General Data Protection Regulation — EU's primary data protection law covering personal data processing, data subject rights, and cross-border transfers.

EU

DORA

EU regulation

Digital Operational Resilience Act — ICT risk, incident reporting, resilience testing, and third-party risk for financial entities.

EU

NIS2

EU regulation

Network and Information Security Directive 2 — EU-wide cybersecurity obligations for essential and important entities, including incident reporting timelines.

EU

PSD2/PSD3

EU regulation

Payment Services Directives — payment services, strong customer authentication, open banking, and consumer protection.

ISO

ISO 27001

Global standard

Information Security Management System — international certification standard for establishing and continually improving information security.

US

SOC 2

US standard

System and Organization Controls 2 — voluntary AICPA audit framework for security, availability, processing integrity, confidentiality, and privacy.

EU

EU AI Act

EU regulation

Artificial Intelligence Act — AI risk classification, conformity assessment, GPAI obligations, and prohibited practices. Phased rollout through 2026.

ISO

ISO 22301

Global standard

Business Continuity Management — international standard for business impact analysis, continuity planning, and organizational resilience.

PCI

PCI DSS

Global standard

Payment Card Industry Data Security Standard — security standard for organizations handling cardholder data. Network security, encryption, access controls.

EU

MiCA

EU regulation

Markets in Crypto-Assets Regulation — crypto-asset service provider licensing, reserve management, and consumer protection.

DE

BSI IT-Grundschutz

German standard

IT Baseline Protection — German BSI building-block methodology with a dual certification path to ISO 27001.

EU

CRA

EU regulation

Cyber Resilience Act — cybersecurity requirements for products with digital elements, vulnerability handling, and CE marking.

US

NIST CSF 2.0

US standard

NIST Cybersecurity Framework 2.0 — six functions: Govern, Identify, Protect, Detect, Respond, Recover.

CA

CCPA/CPRA

California regulation

California Consumer Privacy Act — consumer data rights, opt-out mechanisms, automated decision-making.

GRC

GRC

Methodology

Governance, Risk, and Compliance — cross-cutting methodology for risk registers, control libraries, and audit preparation.

ISMS

ISMS

Methodology

Information Security Management System — structured approach to scope, security policy, risk methodology, asset inventory, and access control.

TPRM

TPRM

Methodology

Third-Party Risk Management — vendor risk assessment, onboarding, contractual requirements, continuous monitoring, and exit strategy.

EU

DSA

EU regulation

Digital Services Act — content moderation, transparency reporting, algorithmic accountability, and platform governance.

Platform

Built for the way
DPOs actually work

UnnaData adapts to your workflow, not the other way around. Powerful enough for enterprise, simple enough to start today.

Documents

Auto-attached & audit-ready

Upload once. Every framework-scoped session pulls the relevant policies, DPAs, and procedures automatically — with match confidence and overlap badges you can click through.

Audit trail

Every message, cited

Every answer tracks the regulation article, template clause, and document paragraph it drew from. Per-message token usage and framework badges on every session — traceability as a first-class feature, not a compliance afterthought.

Trust

Security architecture
a DPO would demand.

UnnaData is built by people who answer the same RFPs you do. Every trust claim below is a shipped v1.0 decision, not a future promise.

EU data residency

Hosted exclusively in AWS eu-west-1 (Ireland). No data transfers outside the European Economic Area. GDPR-native by construction, not by policy.

Security architecture

IDOR-hardened context pipeline (every session ownership-checked at the database layer). Prompt-injection mitigated via XML-tagged system prompt blocks. Every message audit-logged. AES-256 at rest, TLS 1.3 in transit.

Your documents stay yours

UnnaData routes your queries through a frontier AI model under a zero-retention agreement. Your documents are never used to train any AI model. No retention beyond the session unless you save it. Working toward SOC 2 Type II certification.

Continuous compliance

Audit logs on every session. Per-message token usage. Framework badge on every conversation. Per-user and per-company activity feeds. Traceable by design so you can answer the auditor in hours, not weeks.

How it works

Up and running
in minutes, not months

No complex onboarding. No consultants. Sign up, upload your documents, pick a framework, and start asking.

1

Pick your framework

GDPR, DORA, NIS2, or any of the other 15. Or start a general chat with no framework scoping. You can switch frameworks mid-project.

2

Upload your documents

Policies, DPAs, contracts, procedures, audit evidence. UnnaData categorizes them automatically and auto-attaches the relevant ones to every session.

3

Ask anything

Get grounded answers with article citations, template references, and document paragraph pointers. The chat stays inside the framework you picked.

18
Compliance frameworks covered
90
Substantive templates
1
Chat, not 18 tabs
100%
EU data residency
Pricing

Simple, transparent pricing

Start free with one framework at a time. Upgrade to unlock all 18. No hidden fees, no surprises.

Free
For individual DPOs getting started
0
Free forever
  • 1 framework at a time
  • 1 project, 10 documents
  • 50 AI chat messages / month
  • Core compliance templates
Start free
Enterprise
For organizations with advanced needs
Custom
Tailored to your organization
  • Everything in Professional
  • Unlimited team members
  • SSO / SAML authentication
  • Custom framework additions
  • Dedicated account manager
  • SLA & uptime guarantee
Talk to sales
FAQ

Frequently asked questions

Everything you need to know about UnnaData and multi-framework compliance.

You pick one framework at a time — GDPR, DORA, NIS2, the AI Act, ISO 27001, SOC 2, or any of the other 12. The chat loads that framework's templates, auto-attaches the relevant documents from your library, and only reasons about that regulation. Every answer cites the regulation article, the template clause, or the paragraph in your own document it drew from. You can switch frameworks mid-project.

Because DPOs don't get the luxury of one framework. You ship against GDPR, DORA, NIS2, and the AI Act all at once — plus whichever global standards your auditors ask for (ISO 27001, SOC 2, PCI DSS, NIST CSF 2.0). Overlapping controls, overlapping evidence, overlapping deadlines. UnnaData is built for the real job, not a simplified version of it.

Yes. All data encrypted at rest (AES-256) and in transit (TLS 1.3). Hosted exclusively in AWS eu-west-1 (Ireland) with no transfers outside the EEA. Our context pipeline is IDOR-hardened at the database layer so one account can never read another's documents. Prompt injection is mitigated via XML-tagged system prompt blocks. Every message is audit-logged. We are working toward SOC 2 Type II certification.

Yes. Our Free plan is available forever with no credit card required. It includes one framework at a time, 1 project, 10 documents, and 50 AI chat messages per month — enough to meaningfully try a single framework end to end. Professional unlocks all 18 frameworks plus unlimited usage.

UnnaData runs on a frontier-class AI model selected for its strength on nuanced legal and regulatory text — the kind of reasoning multi-framework compliance work demands. We evaluate models continuously and route to whichever combination delivers the best answers under a zero-retention agreement. Your documents are used solely to provide contextual answers and are never used to train any AI model.

You can always start a general chat with no framework scoping — the AI still knows a wide range of regulations and can reason about frameworks outside our 18. You just lose the auto-attached templates and framework-specific guardrails. Enterprise customers can request custom framework additions with dedicated templates and citation anchors.

You can cancel at any time from your account settings. No cancellation fees, no long-term contracts. When you cancel, you keep access until the end of the current billing period. You can export all your data at any time.

Ready to ship compliance
that actually scales?

One AI chat for 18 frameworks. Your documents, your templates, audit-ready answers. Start free — no credit card required.