Pricing Platform Skills Contact
Compliance & Regulatory

Compliance documentation.

HIPAA, GDPR, EU AI Act, and 21 CFR Part 11. DPA template and BAA available on request. For compliance questions: celldna1@gmail.com

HIPAA compliance

Evidara is designed as a HIPAA-ready platform. The system is intended for use with de-identified data only. A Business Associate Agreement (BAA) is available for all Team and Enterprise customers.

  • PHI firewall: Automated PHI scanning on every input before processing (18 HIPAA identifiers) and every output before wiki write. Outputs containing PHI are blocked and flagged — never written to the knowledge base.
  • No PHI storage: Evidara is not designed or intended as a PHI storage system. Queries containing PHI will be blocked by the input scanner. Users should de-identify data before submitting queries.
  • Minimum necessary: Data access is scoped to the minimum required for the specific evidence synthesis task. API keys are organization-scoped, and every query is filtered by the caller's organization in the application layer.
  • Audit controls (§164.312(b)): Hardware, software, and procedural mechanisms record and examine activity in information systems that contain or use ePHI. Every agent call is logged with user identity, timestamps, input hash, and output hash.
  • Integrity controls (§164.312(c)): HMAC-SHA256 signing of audit trail rows. INSERT-only schema prevents tampering.
  • BAA: Business Associate Agreement available for Team and Enterprise customers. Contact celldna1@gmail.com to initiate.

GDPR compliance

Evidara processes personal data as a data processor on behalf of customers (data controllers). The assessments below are Evidara's own, based on the platform design and the DPIA completed 27 April 2026. They have not been independently audited.

Art. 5 · Principles
Data minimization — only data necessary for evidence synthesis is processed. Purpose limitation — data is used only for the specific analysis requested. Storage limitation — retention policies enforced.
Met
Art. 25 · Privacy by Design
PHI firewall enforced architecturally. Access controls at database layer (RLS). API keys hash-only storage. Minimum necessary principle in data access scoping.
Met
Art. 28 · Processor obligations
DPA template available. Sub-processor list maintained (see Security page). Processing only on documented instructions. Confidentiality obligations on all personnel.
Met
Art. 32 · Security of processing
AES-256 at rest, TLS 1.3 in transit. Pseudonymization via hashing. Regular security review. Access controls and audit logging.
Met
Art. 33 · Breach notification
Documented breach notification procedure. Controllers notified within 72 hours of confirmed breach. Incident register maintained.
Met
Art. 35 · DPIA
Data Protection Impact Assessment completed for AI-assisted evidence synthesis processing. Summary available below and full document available on request.
Met
Art. 46 · Transfer mechanisms
Data transfers to Anthropic (US) covered by Standard Contractual Clauses. EU residency option available on Enterprise plan.
Partial

DPO contact: celldna1@gmail.com · Data subject requests: celldna1@gmail.com

EU AI Act compliance

Evidara's DPIA classifies the platform as a high-risk AI system under EU AI Act Article 6 and Annex III, used in a regulated industry context. The platform implements transparency and human oversight requirements proactively — ahead of enforcement timelines.

Art. 13 · Transparency
Every output carries: REASONING_TRACE (step-by-step chain of reasoning), data_uncertainty, model_uncertainty, epistemic_uncertainty, source_provenance (PMIDs, NCT IDs, retrieval timestamps), and human_review_required flag. No output is opaque.
Met
Art. 14 · Human oversight
human_review_required flag enforced on every output. Status field explicitly states NEEDS_HUMAN_REVIEW when applicable. No output is designed to be acted upon without human interpretation.
Met
Art. 9 · Risk management
residual_risk level (NEGLIGIBLE · LOW · MODERATE · HIGH · UNRESOLVED) returned on every analysis. WALL_BREACH_LOG records any attempt to override system policy. Contradiction detection flags conflicting evidence.
Met
Recital 47 · Scientific research
Platform is used for pharmaceutical evidence synthesis to inform human decision-making — not for autonomous clinical decisions. All outputs are advisory and require expert interpretation.
Met

Full EU AI Act compliance documentation and DPIA available on request. Contact celldna1@gmail.com

21 CFR Part 11 compliance

The Evidara audit trail is designed to meet the requirements of 21 CFR Part 11 for electronic records and electronic signatures in FDA-regulated environments.

  • §11.10(a) — Validation: Evidence synthesis engine produces validated, reproducible outputs. Input and output hashes stored per run enable reconstruction and comparison.
  • §11.10(b) — Accurate copies: Structured JSON outputs are exportable to PDF and PPTX. Source provenance included in every output enables independent verification.
  • §11.10(c) — Record protection: INSERT-only audit schema. No UPDATE or DELETE permissions on audit.agent_calls table. HMAC-SHA256 signature per row detects tampering.
  • §11.10(d) — Access limitation: API key authentication on all endpoints. Role-based access control (owner/admin/analyst). Row-level security enforced at database layer.
  • §11.10(e) — Audit trail: Every agent call logged with: run_id, agent_id, called_at, completed_at, input_hash, output_hash, comms_pass, wall_breach_log, tokens_used, raw_inbox_id, entry_hmac.
  • §11.10(j) — Training: Platform documentation available. Evidence protocol descriptions provided in-product. Onboarding session included for Team and Enterprise.

DPA template

A standard Data Processing Agreement is available for all customers requiring one. The DPA covers: processing purposes and instructions, technical and organizational measures, sub-processor management, data subject rights support, breach notification procedures, and return/deletion of data on contract termination.

Request DPA template

Our standard DPA template can be sent within 1 business day. For enterprise customers with custom DPA requirements, we will review and respond on your template within 5 business days; external counsel is engaged where required.

DPIA summary

A full Data Protection Impact Assessment was completed for Evidara's AI-assisted evidence synthesis processing. Key findings:

  • Processing purpose: Pharmaceutical evidence synthesis for HEOR, market access, clinical development, and regulatory strategy decision support. No clinical decision-making. No patient-level data processed.
  • Data subjects: Platform users (authenticated researchers and analysts). No patient data is intended to be processed. PHI firewall prevents inadvertent processing if PHI is submitted.
  • Necessity and proportionality: Processing limited to minimum data required for evidence synthesis. No profiling. No automated decisions with legal effect on data subjects.
  • Risks identified and mitigated: (1) Inadvertent PHI submission — mitigated by input scanner. (2) AI model bias in evidence synthesis — mitigated by uncertainty quantification, contradiction detection, and mandatory human review flag. (3) Audit trail integrity — mitigated by HMAC-signed INSERT-only records.
  • Residual risk: LOW to MODERATE. The highest residual risk identified is AI-generated regulatory analysis being acted upon without expert review — mitigated by the mandatory human-review flag on every output. No high-risk processing under GDPR Art. 35(3) was identified; note this is a separate assessment from the EU AI Act classification above.

Full DPIA document available on request to qualified enterprise customers. Contact celldna1@gmail.com

Compliance questions?
We respond to compliance inquiries within 1 business day. For enterprise procurement, we provide pre-filled compliance questionnaires and reference to our legal documentation.