# Unique AI for Security & Compliance Officers

Unique is purpose-built for the financial services industry, with security and compliance at its core. We adhere to a data minimization principle and apply Swiss and EU regulatory standards - among the most stringent globally - across all our markets.

## Independently validated certifications

- **SOC 2 Type 2**  
  Security, availability & confidentiality
- **ISO 27001**  
  Information security management
- **ISO 9001**  
  Quality management & continuous improvement
- **ISO 42001**  
  AI management system standard
- **FINMA**  
  Swiss financial market regulatory compliance

## Country-specific regulatory coverage

- 🇨🇭 **Switzerland**  
  FINMA Circulars 2018/3, 2023/1, nFDAP
- 🇺🇸 **United States**  
  SEC, OCC, SR 11-7, GLBA, NY SHIELD, US Cloud Act
- 🇬🇧 **United Kingdom**  
  FCA SYSC 8, FSMA 2000, UK GDPR
- 🇸🇬 **Singapore**  
  MAS TRM, PDPA, MAS AI Guidelines

## Built for regulated industries

Although Unique operates as a technology provider rather than a regulated financial institution, our compliance framework is intentionally designed to meet or exceed the regulatory requirements our financial services clients face — including SEC, FCA, MAS, and FINMA expectations.

## Explore the sections

- [IT Security](https://docs.unique.ai/security-and-compliance/it-security)  
  Our risk-based security approach, 24/7 SOC monitoring, bug bounty program, vulnerability patch management, device management, OWASP Top 10 for LLM considerations, access controls, and business continuity planning.
- [AI Governance Framework](https://docs.unique.ai/security-and-compliance/ai-governance-framework)  
  How we ensure responsible, transparent use of GenAI — our MCP Governance Framework, Unique AI Policy, our view on the EU AI Act, and alignment with the AI Verify Foundation.
- [Compliance](https://docs.unique.ai/security-and-compliance/compliance)  
  Compliance Layer 3.0, policies and processes, certification details, and the coverage matrix mapping our controls to SOC 2, ISO 27001, ISO 9001, ISO 42001, and GDPR/nFDAP.
- [Data Protection](https://docs.unique.ai/security-and-compliance/data-protection)  
  Data retention and deletion policies, data export procedures for recordings, and guidelines for sharing secret or sensitive information with the Unique platform.
