Built for regulated professionals who cannot afford to ask where their data went.
Work securely with confidential data.
Unplex is designed for regulated industries. You can work with sensitive client and business data without anonymisation or external exposure, in any configuration your compliance framework requires.
ISO 27001 Certified
Unplex is ISO 27001:2022 certified. The certificate is publicly available in the Trust Center.
GDPR & DSG Compliant
Hosted within the European Economic Area and in full compliantce with the GDPR. and Swiss DSG
BGFA & BRAO Compliant
Protects professional secrecy under Swiss and German bar regulations.
FINMA Compliant
Meets the data governance and outsourcing requirements applicable to Swiss financial intermediaries.
Single Sign-On via SAML/OIDC. Mandatory two-factor authentication. 256-bit encryption. No password-based access.
Audit Logs
Every agent action, every tool call, every write operation is logged, timestamped, and attributable.
Zero Training Use
Your documents are never used to train AI models, by Unplex or by any sub-processor. Contractually guaranteed in the DPA. Technically enforced by architecture.
Three configurations. One non-negotiable: your data stays within the boundary you define.
Swiss Cloud
The application layer is hosted on Infomaniak infrastructure in Switzerland. AI processing runs on frontier models deployed within the EU/EEA. No US-domiciled processor in the chain. All sub-processors operate within Switzerland or the EU/EEA.
Bring Your Own Key
The application layer runs on Swiss infrastructure. Connect your own model agreements and encryption keys. Unplex is the orchestration layer above it. The model governance is your control.
On-Premises
The entire platform runs inside your own infrastructure on open-source models. Data never traverses an external network. Audit logs, access controls, and retention policies are governed entirely by you.
The questions regulated professionals ask before they sign.
What encryption standards does Unplex use?
All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Access is controlled via Single Sign-On (SAML/OIDC) with mandatory two-factor authentication. No password-based access is permitted.
Is Unplex compliant with DSG, GDPR, and the Client Attorney privilege?
Yes. Unplex is hosted within the EEA and fully compliant with the Swiss nDSG and EU GDPR. A Data Processing Agreement per Art. 28 GDPR is standard in every contract. For law firms, a BRAO/BGFA confidentiality agreement establishing Unplex as an auxiliary person within the scope of attorney-client privilege is available before any engagement begins.
What cloud infrastructure do you use?
The application layer is hosted on Infomaniak infrastructure in Switzerland. AI processing runs on frontier models deployed within the EU/EEA. All sub-processors operate within Switzerland or the EU/EEA. The full sub-processor list is publicly available in the Trust Center.
Do you conduct penetration testing on a regular basis?
Yes. Unplex undergoes regular penetration testing by an independent third party. Results are available to enterprise customers under NDA as part of the security review process.
Are your environments segregated, and is customer data ever used outside of production?
Yes, environments are fully segregated. Complete technical separation is enforced at application, database, storage, and configuration level — cross-tenant access is architecturally excluded. Customer data is never used outside of production, and never used to train AI models by Unplex or any sub-processor. Both commitments are contractually guaranteed in the DPA.
What authentication methods are supported?
Single Sign-On via SAML/OIDC is the standard authentication method. Two-factor authentication is mandatory. Integration with existing identity providers including Microsoft Entra ID (Azure AD) and Okta is supported.
Where is my data hosted and processed?
Application data is hosted on Infomaniak infrastructure in Switzerland. AI processing occurs on frontier models within the EU/EEA. No data is processed outside Switzerland or the EU/EEA. For organisations requiring complete data localisation, on-premises deployment is available — the entire platform runs inside your own infrastructure on open-source models with no external data transfer.
What happens to my data if I cancel
All data remains in your own environment at all times, in your SharePoint tenant, your document management system, or your on-premises infrastructure depending on your configuration. Unplex holds no copies of your documents. Upon contract termination, all associated configuration data and processing logs held by Unplex are deleted according to the retention schedule defined in your DPA.
Serious about data governance?
The full documentation is available in the Trust Center.
We use cookies and similar technologies to help personalise content, tailor and measure ads, and provide a better experience. By clicking Allow ALL you agree to this, as outlined in our Privacy Policy