AI accountability for regulated firms

Every AI interaction,
accounted for.

Evaident keeps one tamper-evident record of every way your organisation uses AI — approved tools, in-house agents and the unapproved apps nobody told you about — enforces your policy in real time, and lets you prove it to a client, a board or a regulator.

No card required · Demo workspace in under 2 minutes

Not sure what you need? Find your setup in 60 seconds →

app.evaident.com/app
Events on record
12,840
Tamper-evident chain
Events (30 days)
848
Flagged for review
301
AI spend (30d)
£4,512
Daily activity by vendor
ChatGPTClaudeGemini
Most active people
Katie Lindqvist
Tom Heaton
Priya Nair
James Okafor
Evidence chain VERIFIED12,840 events re-hashed · intact
Works withChatGPT EnterpriseClaude EnterpriseGemini for WorkspaceMicrosoft 365 CopilotxAI Grok+ in-house agents & API tools
The gap you already have

Your biggest AI risk isn't a policy. It's the proof.

The exposure isn't only a regulatory fine — it's a client dispute or a breached NDA when proprietary work ends up in a public model, and no way to show what really happened.

Your people already use AI

Source code, unreleased work, client data and contracts are likely already going into ChatGPT, Claude, Gemini, Copilot and Grok — sanctioned or not. You can't govern what you can't see.

A policy isn't evidence

When a client, partner or board asks “prove you control how AI touches our data”, a PDF policy won't do. You need an immutable record of what actually happened.

Vendor logs don't add up

Four tools, four export formats, four retention windows — and none of it covers your in-house agents or the unapproved apps nobody told you about. There's no single record.

Know. Govern. Prove.

Three jobs your record does — fed by the three ways AI enters your firm (below). Visibility into every AI surface, real-time control over what leaves your firm, and evidence you can stand behind.

Know

See every AI interaction

One normalised, searchable record across approved chat tools, in-house agents and the unapproved apps surfaced from logs you already collect. Per person, per department, per tool — including who isn't covered yet.

  • Unified audit record
  • Directory import & coverage gaps
  • Risk flags: PII, client data, out-of-hours
Govern

Enforce policy in real time

Route your in-house agents and API tools through the Evaident gateway — a drop-in URL they call instead of the AI vendor. Approved vendors and models, blocking of supported UK PII, common credentials and your own blocked terms (client matter codes, project codenames), out-of-hours rules and an organisation spend cap are enforced before a request ever leaves your firm — and blocked attempts are recorded as evidence.

  • Real-time gateway enforcement
  • Block supported UK PII, credentials & terms
  • Org spend cap + per-person reporting
Prove

Show it to anyone who asks

Every record is sealed to the one before it with a cryptographic signature (HMAC-SHA256), so any tampering is mathematically detectable. One click produces a stamped evidence pack — for a client questionnaire, a board, or a regulator.

  • Tamper-evident chain
  • Evidence packs & certificates
  • Per-person cost management
Three sources, one record

Approved tools, your in-house agents, and the apps nobody approved

The three ways AI enters your firm — each feeding the same unified, tamper-evident record you Know, Govern and Prove above, with every interaction mapped to a person. Import your Microsoft Entra ID or Google Workspace directory and you see not just what AI is used, but who's covered and who isn't.

Detect & evidence

Approved AI tools

ChatGPT · Claude · Gemini · Copilot

Connect your approved AI accounts — including Microsoft 365 Copilot — and Evaident pulls each interaction from the vendors' own audit APIs into one tamper-evident record: who, what, when, flagged for review. No agents, no network changes.

Monitor & enforce

In-house Agents & API Tools

Agents · API tools · xAI Grok

Point any in-house agent or API tool — including xAI Grok and any OpenAI-compatible API — at the Evaident gateway, a drop-in URL it calls instead of the vendor. Policy — approved models, supported UK PII, common-credential and blocked-term filtering, an org spend cap — is enforced in real time, breaching requests are blocked before they leave, and exact per-person token usage and cost are captured — streaming or not. Any vendor tier.

Discover & flag

Unapproved apps (shadow AI)

DeepSeek · personal accounts · free tools

See which staff use AI tools you never signed off — from the web logs your firewall already collects, forwarded automatically or uploaded. Detection is by destination, so it catches use from a browser, a desktop app or a script. Reads logs you already have; adds no new monitoring.

A closer look

The gateway for your in-house agents & API tools

How the in-house route works: your agents and API tools call the Evaident gateway — a drop-in URL they use instead of the vendor’s. Policy is enforced before the request reaches the vendor, and every call is logged — with exact token usage (the units AI is billed in) and per-person cost captured, streaming or not, on any vendor tier.

In-house Agents & API Tools
agents · scripts · SDKs
Evaident Gateway
Approved models only
PII & secrets blocked
Exact tokens & cost logged
Vendor APIs
OpenAI · Anthropic · xAI Grok

The programmatic route — for in-house agents and API tools, on any vendor tier. Enterprise chat (ChatGPT, Copilot, Gemini) is captured separately via their audit APIs — no gateway needed.

Approved AI spend: £4,500Unapproved AI: 14 staff on free accounts

One line for the board — sanctioned cost and shadow risk, side by side.

Find the right setup for your organisation →

Enterprise connectors, gateway, browser extension, automated firewall feed, endpoint agent — answer a few questions and we’ll tailor it.

Getting started

Live in an afternoon — no code required

Four steps from sign-up to a live record. The core setup is account connections and a policy you switch on — no rip-and-replace, no engineering project.

  1. 1

    Sign up

    A workspace with realistic demo data in under two minutes. No card, nothing to install.

  2. 2

    Add a connector

    Pick your AI provider, paste a read-only key, and events start flowing. No code — see the panel.

  3. 3

    Switch on your policy

    Tick the boxes — approved vendors, block supported UK PII, credentials and your own terms, a spend cap — and the gateway enforces them in real time for routed tools and agents.

  4. 4

    Start recording

    Every interaction lands in one tamper-evident record, ready to search, cost and prove.

Add connector
Provider
OpenAI
Anthropic
Copilot
API key (read-only)
sk-proj-••••••••••••3b9a
Connected1,240 events imported

Adding a connector — pick a provider, paste a read-only key, done.

For IT & security

In plain terms: connectors and the gateway put nothing on your endpoints — connectors pull from the vendors’ own audit APIs read-only, and the gateway is an OpenAI-compatible base-URL swap (responses stream straight back through it). Shadow-AI discovery reads the firewall / SWG / SIEM logs you already collect. Two optional add-ons exist only if you want their coverage — a managed browser extension (captures web AI on any plan) and a lightweight desktop agent (native apps and off-network use); deploy them if and when you choose.

For your IT team — the full security & architecture overview →

Inside the platform

From every AI surface to provable evidence

Three ways in, one tamper-evident record, and the outputs that prove it — dashboards, evidence packs and a SIEM-ready feed (for tools like Splunk or Sentinel).

Ingest
Approved AI tools
ChatGPT · Claude · Gemini · Copilot
In-house Agents & API Tools
Agents · API tools · scripts
Unapproved apps (shadow AI)
Firewall · proxy · SWG · SIEM
Platform
Evaident platform
NormaliseGovernSeal
Tamper-evident evidence chain
a9f3
c71d
0b8e
4f22
HMAC-SHA256 · append-only · verifiable
Prove
Dashboards & cost
Usage and spend, per person
Evidence packs
Stamped, with integrity certificate
Compliance mapping
EU AI Act · GDPR · FCA · SRA
app.evaident.com/app/shadow
Approved AI spend (30d)
£4,500
Unapproved AI — people
14
Unapproved access events
212
Services seen
ChatGPT Enterpriseopenai.comApproved
DeepSeekchat.deepseek.comUnapproved · elevated
Perplexityperplexity.aiUnapproved
Character.AIcharacter.aiUnapproved · elevated
Copilotcopilot.microsoft.comApproved

Shadow AI discovery

Approved spend and unapproved tools, side by side — from the web logs you already collect.

app.evaident.com/app/events
Policy blocks (30d)
23
PII stopped
9
Approved vendors
2
policy_blockedpii_detected11:42 · gateway

BLOCKED by governance policy (pii_block): POST /v1/chat/completions

Client NI number detected in prompt — request stopped before it reached the vendor. Attempt recorded.

Active policy
  • Approved vendors: OpenAI, Anthropic
  • Block supported UK PII, credentials & terms
  • Monthly budget: £6,000
  • Out-of-hours gateway use blocked

Real-time governance

Policy enforced at the gateway — a breaching request is stopped and recorded as evidence.

app.evaident.com/app/cost
AI spend (30d)
£4,512
Premium-model share
38%
Cost per person
£64
Spend by person
Katie Lindqvist · Operations
£412
Tom Heaton · Paraplanning
£305
Priya Nair · Advisory
£249
James Okafor · Research
£171
Sarah Whitfield · Compliance
£120

Cost management

Per-person and per-department spend, premium-model share and billed actuals.

app.evaident.com/app/compliance/systems
On the register
6
High / potential
2
Limited
3
Evidence in place
4
Systems on the register · EU AI Act
Creditworthiness scoring
Annex III (5)(b) · Art. 26
High-riskNo evidence
Client-suitability drafting
Annex III · Art. 6(3)
Potential high-riskEvidence
Client support chatbot
Art. 50
LimitedEvidence
Meeting-notes summariser
Minimal risk
MinimalEvidence
Deterministic, article-referenced posture indicator — a governance aid, not legal advice.

AI system register

A deterministic, article-referenced EU AI Act posture indicator for each AI system — tied to the evidence you already capture. A governance aid, not legal advice.

app.evaident.com/app/reports
Evidence Pack
Ref EVD-2026-0418 · 1 Apr – 30 Jun 2026
Chain VERIFIED
3,402
Events
118
Flagged
100%
Integrity
Integrity certificate · SHA-256
a9f3c71d0b8e4f22e1d7…66a3aa4a829cdcee12f81f00c48673afd39b3a69
Download PDFCSV / JSON

Evidence packs

A stamped export with an integrity certificate — proof, not a policy PDF.

Everything you need to govern AI at work

From shadow-AI discovery to an immutable evidence trail — the full accountability layer.

Unified audit record

All vendors, one normalised timeline. Search by person, department, tool or risk flag.

People & coverage

See AI use by person and department — and who isn't covered yet. Import your directory from Microsoft Entra ID or Google Workspace so coverage gaps are real, not guesswork.

Shadow AI discovery

Surface unapproved AI from the firewall, proxy, secure web gateway (SWG) or SIEM (Splunk, Sentinel) logs you already collect — merged with approved spend in one view.

Capture web AI on any plan

A managed browser extension records ChatGPT, Claude and Gemini use — including Free/Plus/Pro and personal accounts — where there's no vendor audit API. Metadata-only by default.

Real-time governance

Approved vendors and models, supported UK PII, common-credential and customer-defined blocked-term filtering, an organisation spend cap and out-of-hours rules — enforced at the gateway before data leaves.

Cost management

Per-person and per-department AI spend, premium-model share and billed actuals from vendor APIs.

Choose your evidence depth

Metadata, redacted preview, or scoped full prompt & response for gateway traffic, with content retention configured separately.

Tamper-evident chain

Hash-chained, append-only storage with on-demand integrity verification and certificates.

Legal hold & retention

Set retention per evidence depth — and place a legal hold to preserve the whole record for litigation or audit, suspending deletion until you release it.

Evidence packs

Stamped, referenced exports — summary PDF, full CSV/JSON data and an integrity certificate.

Read & SIEM API

Pull the evidence log into Splunk, Sentinel or a warehouse over a read-only, cursor-paginated API.

Compliance mapping

For regulated firms: live mapping to EU AI Act, UK GDPR, FCA Consumer Duty / SYSC 9 and the SRA Code.

AI system register

Deterministic, article-referenced EU AI Act posture indicators for each AI system — prohibited, high-risk, transparency and GPAI routes, with an EU-scope check — tied to the evidence you already capture. A governance aid, not legal advice.

Security your clients can question

An evidence trail you can show, not just a policy you assert

Built to pass the due-diligence questionnaires your clients actually send.

EU data hosting

Your evidence is hosted in the EU (Amsterdam, Netherlands), on a private network — not the public internet.

Encryption everywhere

TLS in transit, AES-256-GCM for stored credentials, API keys held only as hashes.

Tamper-evident by design

HMAC-SHA256 hash chain; integrity re-verified on demand and in every export.

SSO & least privilege

Microsoft & Google sign-in, role-based access, every admin action audited.

Metadata by default. Evaident records who used which AI, when and at what cost — not the content of prompts. Prompt text is stored only if you turn on preview or scoped full-content capture.

Hash-chained record
#1041
a9f3
#1042
c71d
#1043
0b8e
#1044
4f22

Questions, answered

Do we have to be a regulated firm to get value?+

No. Evaident is an AI accountability platform for regulated and data-sensitive organisations: it answers 'who is using which AI, on what, at what cost — and can you prove it?'. That matters to anyone protecting client IP, NDAs and source code, controlling AI spend, or facing client security questionnaires. If you are FCA/SRA-regulated or in EU AI Act scope, Evaident also maps your record to those obligations out of the box — but that's a feature, not the entry ticket.

Do we need ChatGPT Enterprise or Claude Enterprise?+

No. The enterprise audit APIs are the richest source, but you can build the record on any tier: the Evaident Gateway captures any API-based or in-house AI tool on any plan, a managed browser extension captures ChatGPT/Claude/Gemini web use — including Free/Plus/Pro and personal accounts — and Shadow AI discovery works from network logs you already collect. Whatever tier you're on, you can start today.

How does Evaident know who is using AI?+

Two ways, combined. Import your user directory from Microsoft Entra ID or Google Workspace (active staff only — guests and disabled accounts are excluded), and Evaident also discovers people automatically from the activity it captures. The People view then shows AI use by person and department — and crucially, who isn't covered yet, so coverage gaps are real rather than assumed. The directory connector is independent of any AI connector; you can map your people before you connect a single AI source.

How do our team sign in — and is it separate from the people we monitor?+

Yes, they're two different populations and Evaident connects them. 'People' are everyone whose AI use you account for (often hundreds); your 'team' are the colleagues who log in to Evaident. Sign-in is via Microsoft or Google SSO with role-based access, and you can invite a colleague straight from the People directory — they accept and sign in with SSO in one step. Every admin action is itself audited.

How does Shadow AI discovery work — do you install agents?+

No agents, no endpoint software. Evaident reads the per-user web logs your existing stack already produces — a firewall (Palo Alto, Fortinet), a secure web gateway or SASE (Zscaler, Netskope, Cisco Umbrella, Cloudflare), or an export from your SIEM (Splunk, Microsoft Sentinel). Any CSV with a user, a destination and a time works: Evaident auto-detects the columns, classifies destinations against an AI-service catalogue, and shows unapproved tools next to your approved spend.

Where is our data stored?+

In the EU — currently the Amsterdam (Netherlands) region. The database runs on a private network, connector credentials are encrypted at rest, and gateway/API keys are stored only as hashes. EU hosting is appropriate for UK data under the UK's adequacy decision for the EU. See our security overview for the full model.

How long does setup take?+

A demo workspace with realistic data is live in under two minutes. Connecting a live source is a credentials paste; pointing tools at the gateway is a one-line base-URL change. No agents to install, no network changes.

Can Evaident block all AI use?+

No — and we're clear about that. Evaident blocks in real time only on gateway-routed traffic: the in-house tools and agents you point at the Evaident Gateway. Vendor audit logs, the browser extension and Shadow AI discovery detect and evidence activity rather than block it. To stop web AI at the network, use your firewall, SWG, SASE or browser controls — with Evaident as the evidence layer that proves what happened.

Do we have to store prompts and responses?+

No. Metadata is the default — who used which AI, when, which model, token counts and risk flags, never the prompt text. Redacted preview and full prompt-and-response capture are optional evidence-depth settings you turn on per source, with PII redaction on by default. Full-content capture is scoped, approval-led and normally reserved for specific high-risk workflows.

Know, govern and prove your AI — starting today

Spin up a workspace with realistic demo data now. Connect your live AI accounts whenever you're ready.

Questions first? Write to hello@evaident.com