Trust & security

Security overview

Evaident holds sensitive evidence of how your firm uses AI, so security and confidentiality are built in from the ground up. This page summarises the controls that matter for your due-diligence and security reviews — and we’re glad to complete your security questionnaire.

Data residency & encryption

  • By default your data is hosted entirely within the EU (Amsterdam). US and other-region hosting is available for enterprise customers with specific data-residency requirements — talk to us.
  • Data is encrypted in transit (TLS) and at rest (AES-256). Connector credentials and vendor keys are encrypted, and secrets are never displayed again once saved.

Authentication & access

  • Single sign-on with Microsoft Entra ID or Google — your staff authenticate through your own identity provider, inheriting your multi-factor authentication and conditional-access policies. Two-factor authentication is mandatory on password accounts (app-based TOTP), and an owner or admin can reset a member’s 2FA if they lose their device.
  • Role-based access (owner, admin, read-only viewer). Give auditors and compliance reviewers a live, read-only view rather than exporting data to them.

Tenant isolation

  • Each organisation’s data is fully isolated — one customer can never see another’s.

Tamper-evident evidence

  • Every record is cryptographically hash-chained and independently verifiable, so any alteration to the stored record is detectable. A chain-integrity certificate is included in every evidence pack, so a board, client or regulator can verify it themselves.

Your data, your control

  • By default Evaident records metadata only — not the content of prompts or responses. Capturing content is opt-in per source, with PII redaction on by default.
  • You set retention windows and can purge captured content on your schedule while the integrity record persists.
  • Evaident never trains AI models on your data, and never sells or shares it.

Resilience & backups

  • Regular encrypted backups, including independent off-site copies, with integrity verified on restore so a partial or corrupted restore is detectable, not silent.

Governed egress

  • For API tools and in-house agents, the Evaident gateway enforces your policy — approved vendors and models, UK PII, common-credential and customer-defined blocked-term controls, an organisation spend cap and out-of-hours rules — before any request leaves your environment. Blocked attempts are recorded as evidence.

Compliance posture

  • Evaident maps your captured evidence to the EU AI Act, UK GDPR and FCA/SRA expectations. It supports your compliance function and is not legal advice. We’re happy to complete security and due-diligence questionnaires for your procurement team.

Responsible disclosure

Security-review questions, answered

The questions security and procurement teams ask us most — with straight answers.

Where is our data hosted?
In the EU (Amsterdam) by default, on private networking. A US or other region is available for enterprise customers with specific residency requirements.
Do you train AI models on our data?
No. Evaident is a record-and-governance layer, never a model. We do not train on your data, and we never sell or share it.
Are our connector and vendor API keys stored?
Connector credentials and vendor keys are encrypted at rest with AES-256-GCM and are never displayed again once saved. They're decrypted only server-side to pull your audit data or forward a gateway request.
How are Evaident gateway and API keys stored?
Only as SHA-256 hashes — the secret is shown once at creation and never stored in clear. A leaked database can't reveal a usable key.
Can we purge prompt content but keep the proof?
Yes. Content retention is set separately from event retention. When captured content is purged, the tamper-evident record and its content digest remain, so the chain still verifies.
Does the endpoint agent capture screenshots or keystrokes?
No. It records detection metadata only — which AI app, which user, and duration. No prompts, responses, screenshots or keystrokes.
Does the browser extension read personal-account prompts?
By default it captures metadata only (which tool, when, prompt length) on the devices you deploy it to — including personal/free accounts. It only stores prompt text if you deliberately raise the capture mode, which is your lawful-basis and DPIA decision.
Who can view captured content?
Access is role-based (owner, admin, read-only viewer) and strictly scoped to your organisation. One customer can never see another's data.
Is two-factor authentication enforced?
Yes. App-based two-factor (TOTP) is mandatory for password accounts, across the app, partner portal and operator console — with a short grace period for new users to enrol, after which it's required before they can continue. SSO users inherit MFA from their identity provider. Owners and admins can reset a member's 2FA if they lose their device.
Is legal hold tenant-wide or scoped?
Legal hold is currently tenant-wide: it preserves the whole record and suspends automatic deletion until you release it.
Is there an audit trail of admin actions?
Yes. Administrative actions are recorded, and the underlying evidence record is append-only and hash-chained, so changes are detectable rather than silent.