The V/TO is the single source of truth for where Unicis is going and how we will get there. Every team member should read and understand this document. It is reviewed and updated at every Annual Planning session and checked at every Quarterly session.
Core Values are not aspirational β they describe how Unicis already operates at its best. We hire, review, reward, and part ways with people based on these values.
| Value | What it means in practice |
|---|---|
| Openness by default | We build in the open. Our code, our handbook, and our reasoning are public. We default to transparency internally and externally, including sharing our mistakes. |
| Trust through compliance | We practice what we preach. Unicis holds itself to the same compliance and security standards we help our customers achieve. |
| Small team, big ownership | Every Unician owns their domain completely. We don't wait for permission. We flag problems early, propose solutions, and follow through. |
| EU-first mindset | We build for the European regulatory context β GDPR, NIS2, DORA, CRA β and for the SMEs navigating it. Our infrastructure, our values, and our partnerships reflect this. |
| Honest over comfortable | We give and receive direct feedback. We name problems clearly. We do not let politeness get in the way of progress. |
π‘ Using Core Values: When hiring, ask behavioural questions that surface each value. In performance reviews, assess each value explicitly. When something feels wrong culturally, trace it back to a Core Values violation.
To make compliance effortless, efficient, and transparent for every European SME β so that security, privacy, and risk teams can focus on real work instead of spreadsheet management.
Open-source GRC platform for EU SMEs navigating NIS2, GDPR, ISO 27001, DORA, and CRA.
βBy 2035, Unicis is the default open-source GRC platform for EU SMEs β with 10,000+ active organisations on the platform, a self-sustaining open-source community, and recognised status as a trusted EU digital infrastructure provider.β
This target is ambitious but achievable. It requires consistent execution on product, community, and partnerships β not a step-change pivot.
What does Unicis look like on 1 January 2028?
What must be true by 31 December 2026 for us to be on track for the 3-Year Picture?
β¬150,000 ARR
| Dimension | Definition |
|---|---|
| Company size | 10β250 employees |
| Geography | EU β priority markets: DACH, Nordics, Benelux, Baltics |
| Sector | Technology, fintech, healthtech, SaaS |
| Trigger | NIS2 compliance deadline pressure; ISO 27001 certification in progress; GDPR audit preparation |
| Buyer | CTO, CISO, DPO, or Compliance Lead at an SME without a dedicated GRC tool |
| Pain | Managing compliance in spreadsheets; multiple disconnected tools; no audit trail; cost of enterprise GRC tools |
βThe Unicis Compliance Journeyβ
| Cadence | Activity |
|---|---|
| Weekly | Rocks and Scorecard reviewed in Level 10 meeting |
| Quarterly | Full V/TO review; update 1-Year Plan; set new Rocks |
| Annually | Full V/TO rewrite; update 3-Year Picture; set Annual Rocks |
β See the Scorecard | β See Rocks & Traction | β See Accountability Chart
Last reviewed: Q2 2026 β next review: Q3 2026 Quarterly Session