One compliance platform.
Three ways to deploy.
Unicis ships as a fully managed SaaS, an open-source self-hosted platform, and native Atlassian Marketplace apps. Choose the deployment that fits your team — or combine them.
Pick your deployment — same platform, your terms
Unicis Platform — SaaS
Fully managed cloud · Community, Premium & Ultimate plans
The fastest way to get your compliance programme running. Unicis SaaS is fully managed — no infrastructure to provision, no updates to apply. Sign up and start tracking controls within minutes.
Unicis Platform — Self-hosted
Open-core · Apache 2.0 · Your infrastructure
Deploy Unicis on your own servers, private cloud, or air-gapped environment. The open-core means you can inspect every line of code, extend the platform with custom modules, and never worry about vendor lock-in.
Unicis Atlassian Apps
Jira & Confluence · Atlassian Marketplace · Forge-native
Bring compliance into your existing Atlassian workspace. Unicis apps for Jira and Confluence let your teams manage GDPR records, transfer impact assessments, cybersecurity controls, and security awareness — without leaving the tools they already use.
SaaS vs Self-hosted vs Apps — at a glance
| Feature | SaaS | Self-hosted | Apps |
|---|---|---|---|
| Deployment | Managed cloud | Your infrastructure | Atlassian Cloud |
| Setup time | Minutes | Hours (Docker / K8s) | Minutes |
| Data residency | EU (Estonia) | Your choice | Atlassian-managed |
| Source code | Open-core | Full open-source | Open-core (Forge) |
| SSO / SAML | All paid plans | All plans | Via Atlassian |
| API access | Premium & Ultimate | All plans | Marketplace API |
| Best for | SMEs, startups, scale-ups | Regulated & public sector | Atlassian-first teams |
Find the right solution for your situation
Whether you're an open-source advocate, need workflow automation, or running compliance at enterprise scale — Unicis has a tailored answer.
Open-Source Compliance Platform
Unicis is open-core — the compliance platform you can inspect, self-host, and trust. No black boxes. Compare us to Vanta and Drata.
GRC Automation
Automate repetitive compliance work with our open REST API, webhooks, and native integrations with n8n, Zapier, Make, and Jira.
Enterprise Compliance
SSO/SCIM, multi-tenant architecture, on-premise deployment, dedicated support, and cross-framework mapping for complex organisations.
11 frameworks — one platform across all products
Every framework is available across SaaS, Self-hosted, and Atlassian Apps. Track controls once — get coverage across every standard you need.
MVSP
Minimum Viable Secure Product
Baseline security checklist for B2B software. Defines the minimum security posture expected from enterprise-ready products.
GDPR
General Data Protection Regulation
EU regulation for personal data protection and privacy. Covers data processing, consent management, and cross-border transfers.
ISO/IEC 27001
Information Security Management Systems (2022)
International standard for establishing and maintaining an information security management system (ISMS).
EU NIS2
Directive (EU) 2022/2555 NIS 2
EU directive on cybersecurity measures for essential and important entities across critical sectors.
CIS Controls
CIS Critical Security Controls v8.1
Prioritised set of actions to protect organisations and data from known cyber-attack vectors — 18 controls, 153 safeguards.
BSI C5
Cloud Computing Compliance Controls Catalogue (C5:2020)
German BSI standard for cloud computing compliance. Mandatory for cloud services used by German government agencies.
OWASP ASVS
Application Security Verification Standard v5
Framework for testing web application technical security controls across 3 verification levels and 14 security chapters.
ISO/IEC 42001
AI Management System Standard
The world's first international standard for AI Management Systems — covering AI risk, transparency, bias, and EU AI Act readiness.
NIST CSF 2.0
NIST Cybersecurity Framework 2.0
Voluntary US cybersecurity framework covering Govern, Identify, Protect, Detect, Respond, and Recover — 6 functions, 106 subcategories.
SOC 2
SOC 2 Type I & II
Trust service criteria for security, availability, processing integrity, confidentiality, and privacy of customer data.
PCI DSS
Payment Card Industry Data Security Standard v4.0.1
Global security standard for organisations that store, process, or transmit payment card data — 12 requirements.
Not sure which product is right for you?
Talk to us — we'll help you choose the right deployment, plan, and framework coverage for your team's needs.
Record of Processing Activities
Transfer Impact Assessment
Privacy Impact Assessment
Cybersecurity Controls
Cybersecurity Risk Management
Interactive Awareness Program