Security & trust
Built for the people who ask hard questions.
Evidero is designed with the assumption that a CISO will scrutinise every layer. Here is what we built and how it works.
Trust pillars
EU data residency
All customer data is hosted in Frankfurt, Germany on AWS EU regions. No cross-border transfers. No optional EU mode that has to be configured. EU-only by default.
Tenant isolation at the database layer
PostgreSQL row-level security on every table. Every query is scoped to the authenticated company's ID before any data is returned. Cross-tenant access is structurally impossible, not just logically prevented.
AI without leakage
We use OpenAI's EU API endpoint to generate embeddings, one-way mathematical vectors derived from short fragments of policy text. The full document text never leaves our EU infrastructure. The agreement with OpenAI is zero-retention: API inputs are not stored and not used for training. OpenAI is named on our public sub-processor list. We are evaluating EU-hosted alternatives and will migrate when quality matches.
Encryption everywhere
AES-256 encryption at rest. TLS 1.3 in transit. Keys managed via AWS KMS with automated rotation.
Architecture
How a document moves through Evidero.
Every step happens inside EU infrastructure. Nothing leaves your tenant boundary in a form that can be read by another customer or by a model that learns from it.
Detail
For the CISO who wants to read the wiring diagram.
Frankfurt only. AWS EU regions. No US fallback. No cross-border transfers under any condition.
Three role tiers: platform admin, company admin, employee. JWT validation on every edge function. Role claims determine access scope.
Every framework-affecting action is logged immutably with timestamp, user and source reference. Logs are tenant-isolated and exportable.
JWT-based authentication. SSO available for Enterprise tier (SAML / OIDC).
Daily encrypted backups. Point-in-time recovery within seven days. Restores tested on a regular cadence.
AWS Frankfurt (infrastructure), Supabase EU (database, auth, storage), OpenAI EU endpoint (embedding generation only, zero-retention, no training), Resend EU (transactional email), Cloudflare (DNS / edge).
Architecture aligned with SOC 2 and ISO 27001 standards. Formal certification on the roadmap.
Email security@evidero.io with any security concerns. We acknowledge within one business day.
Still curious
Have a security question we haven’t answered?
Send us your security questionnaire. We respond within 24 hours, every answer cited to the underlying control.
Email hello@evidero.ioOr book a demo