The questions security and procurement teams ask us most — with straight answers.
- Where is our data hosted?
- In the EU (Amsterdam) by default, on private networking. A US or other region is available for enterprise customers with specific residency requirements.
- Do you train AI models on our data?
- No. Evaident is a record-and-governance layer, never a model. We do not train on your data, and we never sell or share it.
- Are our connector and vendor API keys stored?
- Connector credentials and vendor keys are encrypted at rest with AES-256-GCM and are never displayed again once saved. They're decrypted only server-side to pull your audit data or forward a gateway request.
- How are Evaident gateway and API keys stored?
- Only as SHA-256 hashes — the secret is shown once at creation and never stored in clear. A leaked database can't reveal a usable key.
- Can we purge prompt content but keep the proof?
- Yes. Content retention is set separately from event retention. When captured content is purged, the tamper-evident record and its content digest remain, so the chain still verifies.
- Does the endpoint agent capture screenshots or keystrokes?
- No. It records detection metadata only — which AI app, which user, and duration. No prompts, responses, screenshots or keystrokes.
- Does the browser extension read personal-account prompts?
- By default it captures metadata only (which tool, when, prompt length) on the devices you deploy it to — including personal/free accounts. It only stores prompt text if you deliberately raise the capture mode, which is your lawful-basis and DPIA decision.
- Who can view captured content?
- Access is role-based (owner, admin, read-only viewer) and strictly scoped to your organisation. One customer can never see another's data.
- Is two-factor authentication enforced?
- Yes. App-based two-factor (TOTP) is mandatory for password accounts, across the app, partner portal and operator console — with a short grace period for new users to enrol, after which it's required before they can continue. SSO users inherit MFA from their identity provider. Owners and admins can reset a member's 2FA if they lose their device.
- Is legal hold tenant-wide or scoped?
- Legal hold is currently tenant-wide: it preserves the whole record and suspends automatic deletion until you release it.
- Is there an audit trail of admin actions?
- Yes. Administrative actions are recorded, and the underlying evidence record is append-only and hash-chained, so changes are detectable rather than silent.