Trust & security

Built to be trusted with your firm’s most sensitive AI activity

What a CFO, CTO, CIO or compliance lead needs to evaluate Evaident with confidence — what it is, how your data is handled, and why proof, not promises, sits at the centre.

EU-hosted (Amsterdam)Tamper-evident recordEncrypted at restNo model training on your data
What Evaident is

A record and governance layer — not another AI

Evaident sits alongside the AI your firm already uses and produces one tamper-evident record of how it’s used: known, governed and provable. It doesn’t replace your tools, and it never becomes another place your client data goes to be processed by a model.

EU-hosted, data residency

Your record lives in the EU (Amsterdam) by default; US and other regions are available for enterprise. The core audit record, gateway and connectors do not require your data to be sent to a third-party AI model; the optional AI assistant is separately controlled and disclosed.

Encrypted at rest

Connector credentials and vendor keys are encrypted with AES-256-GCM. Transport is TLS. Secrets are never shown back in full once saved.

Metadata by default

By default Evaident records who used which AI tool, when, which model, token counts and risk flags — not the content of prompts or responses.

Content capture is opt-in

Storing prompt/response text is off by default and enabled per source, with PII redaction on by default (NI numbers, cards, sort codes, IBANs, NHS numbers, emails).

Purge content, keep the proof

Set a short content-retention window: captured text is purged on your schedule while the tamper-evident integrity record stays verifiable.

Least privilege

SSO via Microsoft or Google; owner/admin/viewer roles. The data API is read-only and key-scoped. The gateway forwards on your own vendor keys.

Provable, not just stored

Every figure traces to a record you can independently verify

The record is append-only and HMAC-SHA256 hash-chained: each entry is sealed against the one before it. Any change to a stored record breaks the chain — and you can run a full verification on demand. Evidence packs are stamped with a unique reference and a chain-integrity certificate, so a board, client or regulator can check the maths themselves rather than take your word for it.

Append-only

Records are append-only during their retention period; expiry and workspace deletion are handled by controlled purge, not silent editing.

Hash-chained

HMAC-SHA256 links every event to its predecessor.

Verifiable

Run a full chain check; export a stamped certificate.

Your data

What we store — and what we never do

What Evaident stores

  • Event metadata: person, tool, model, timestamp, token counts, risk flags
  • Cost attribution computed from token counts and vendor billing APIs
  • Prompt/response content — only if you explicitly turn capture on, redacted by default
  • Connector credentials, encrypted at rest, used solely to pull your audit data

What Evaident never does

  • We never train AI models on your data — Evaident is a record layer, not a model
  • We never sell or share your data, or use it for anything beyond your own record
  • We don't need prompt content to work — metadata alone powers most of the platform
  • We don't hold a master key to your AI — the gateway uses keys you provide

What each capture route stores

Capture depth depends on the route and your settings. By default Evaident records metadata; storing prompt/response content is opt-in and, for full content, approval-gated.

Capture routeStored by defaultFull content?Notes
Vendor connectors
ChatGPT · Claude · Gemini · Copilot
Vendor audit metadataOnly if the vendor API exposes itPulled after the fact via official APIs
Evaident Gateway
API tools & in-house agents
Metadata (preview/full by plan)Yes — by approval (add-on)Inline; text requests only
Browser extension
Web chat apps
MetadataPreview/full by policyManaged deployment
Firewall / SWG / SIEM logs
Shadow-AI discovery
Destination & activity metadataNoDetection by destination
Endpoint agent
Desktop & off-network apps
Detection metadata onlyNoNo keystrokes or screenshots

Event retention and content retention are set separately — the tamper-evident record outlives any stored content, keeping the integrity proof even after content is purged.

Compliance posture

Maps to the obligations that matter

Evaident shows how your captured evidence lines up with the frameworks your firm answers to. It’s a posture indicator that supports your compliance function — it does not provide legal advice.

EU AI Act

Art. 12 automatic record-keeping and Art. 26(6) ≥6-month log retention — evidenced by an append-only, time-stamped record.

UK GDPR

Accountability where staff submit personal data to AI tools — risk-flagged events and a demonstrable control record.

FCA / SRA

Consumer Duty, SYSC 9 record-keeping and the SRA Code — usage evidence mapped for your compliance consultant.

Low-risk by design

A trial on your terms

Evaident is built to the controls regulated firms expect — EU hosting, encryption in transit and at rest, single sign-on with your identity provider, role-based access and a tamper-evident record. We’re glad to complete your security questionnaire.

The trial itself asks little of you: it defaults to metadata-only capture, runs in the EU, needs no card, and you can delete your workspace and its data whenever you choose. Your data is yours.

  • 14-day full-platform trial, no card required
  • Metadata-only by default — turn on content capture only if you choose
  • EU-hosted, encrypted in transit and at rest
  • Single sign-on with your identity provider
  • Delete your workspace, subject to any export, retention or legal-hold requirements you configure or agree

See it on your own data in under two minutes

Spin up a workspace, connect a source, and watch your firm’s real AI usage become a record you can prove.