What a CFO, CTO, CIO or compliance lead needs to evaluate Evaident with confidence — what it is, how your data is handled, and why proof, not promises, sits at the centre.
Evaident sits alongside the AI your firm already uses and produces one tamper-evident record of how it’s used: known, governed and provable. It doesn’t replace your tools, and it never becomes another place your client data goes to be processed by a model.
Your record lives in the EU (Amsterdam) by default; US and other regions are available for enterprise. The core audit record, gateway and connectors do not require your data to be sent to a third-party AI model; the optional AI assistant is separately controlled and disclosed.
Connector credentials and vendor keys are encrypted with AES-256-GCM. Transport is TLS. Secrets are never shown back in full once saved.
By default Evaident records who used which AI tool, when, which model, token counts and risk flags — not the content of prompts or responses.
Storing prompt/response text is off by default and enabled per source, with PII redaction on by default (NI numbers, cards, sort codes, IBANs, NHS numbers, emails).
Set a short content-retention window: captured text is purged on your schedule while the tamper-evident integrity record stays verifiable.
SSO via Microsoft or Google; owner/admin/viewer roles. The data API is read-only and key-scoped. The gateway forwards on your own vendor keys.
The record is append-only and HMAC-SHA256 hash-chained: each entry is sealed against the one before it. Any change to a stored record breaks the chain — and you can run a full verification on demand. Evidence packs are stamped with a unique reference and a chain-integrity certificate, so a board, client or regulator can check the maths themselves rather than take your word for it.
Records are append-only during their retention period; expiry and workspace deletion are handled by controlled purge, not silent editing.
HMAC-SHA256 links every event to its predecessor.
Run a full chain check; export a stamped certificate.
Capture depth depends on the route and your settings. By default Evaident records metadata; storing prompt/response content is opt-in and, for full content, approval-gated.
| Capture route | Stored by default | Full content? | Notes |
|---|---|---|---|
Vendor connectors ChatGPT · Claude · Gemini · Copilot | Vendor audit metadata | Only if the vendor API exposes it | Pulled after the fact via official APIs |
Evaident Gateway API tools & in-house agents | Metadata (preview/full by plan) | Yes — by approval (add-on) | Inline; text requests only |
Browser extension Web chat apps | Metadata | Preview/full by policy | Managed deployment |
Firewall / SWG / SIEM logs Shadow-AI discovery | Destination & activity metadata | No | Detection by destination |
Endpoint agent Desktop & off-network apps | Detection metadata only | No | No keystrokes or screenshots |
Event retention and content retention are set separately — the tamper-evident record outlives any stored content, keeping the integrity proof even after content is purged.
Evaident shows how your captured evidence lines up with the frameworks your firm answers to. It’s a posture indicator that supports your compliance function — it does not provide legal advice.
Art. 12 automatic record-keeping and Art. 26(6) ≥6-month log retention — evidenced by an append-only, time-stamped record.
Accountability where staff submit personal data to AI tools — risk-flagged events and a demonstrable control record.
Consumer Duty, SYSC 9 record-keeping and the SRA Code — usage evidence mapped for your compliance consultant.
Evaident is built to the controls regulated firms expect — EU hosting, encryption in transit and at rest, single sign-on with your identity provider, role-based access and a tamper-evident record. We’re glad to complete your security questionnaire.
The trial itself asks little of you: it defaults to metadata-only capture, runs in the EU, needs no card, and you can delete your workspace and its data whenever you choose. Your data is yours.
For procurement and security review, we keep the essentials a click away — and we’ll complete your own questionnaire on request.
How your data is hosted, encrypted, isolated and protected — written for a security reviewer.
Read it →The third-party providers we use, the data involved and where it’s processed — for your DPA.
See the list →Terms, Privacy, Acceptable Use and our Data Processing Agreement — and request a signed DPA.
Open the pack →Spin up a workspace, connect a source, and watch your firm’s real AI usage become a record you can prove.