Pricing Platform Skills Contact
Security Overview

Built for enterprise
security reviews.

Evidara is designed to pass pharmaceutical enterprise procurement. Full security documentation is available to qualified organizations under NDA. Security questions: celldna1@gmail.com

SOC 2 Type II · Audit In Progress HIPAA Ready · BAA Available GDPR Art. 25 · Privacy by Design 21 CFR Part 11 · Electronic Records EU AI Act · Art. 13 Transparency Pen Test · Not Yet Conducted

Compliance posture

Evidara holds no third-party security certifications today. A SOC 2 Type II audit is in progress; no report has been issued. HIPAA, GDPR, 21 CFR Part 11 and the EU AI Act are regulatory frameworks rather than certification schemes — the entries below describe the controls Evidara implements against each and are self-assessed, not independently audited. Control documentation and evidence are available to enterprise procurement teams under NDA.

In Progress 🛡️
SOC 2 Type II
Audit initiated Q2 2026. Controls documentation complete. Trust service criteria in scope: Security, Availability, Confidentiality. No SOC 2 report has been issued yet, and no bridge letter is available — a bridge letter can only follow a completed audit period. The Type II report will be available under NDA on completion.
Ready 🏥
HIPAA
Business Associate Agreement available for all Team and Enterprise customers. PHI firewall enforced on every input and output. No PHI is stored or logged at any point.
Self-assessed 🇪🇺
GDPR (EU) 2016/679
Privacy by design (Art. 25). Data Processing Agreement template available. Sub-processor list maintained and published below. Named DPO: celldna1@gmail.com
Self-assessed 📋
21 CFR Part 11
Electronic audit trail on every agent call. HMAC-SHA256 signed per row. Input/output hash stored with each audit entry. INSERT-only schema — records cannot be modified.
Self-assessed 🤖
EU AI Act — Art. 13
Transparency requirements met. Every output carries REASONING_TRACE, uncertainty quantification, source provenance, and human_review_required flag. DPIA completed and available.
Not Conducted 🔍
Penetration Testing
No external penetration test has been conducted to date. Planned scope when commissioned: web application, API endpoints, authentication, and data access controls. Results will be available under NDA once a test is complete.

Infrastructure security

🔐
Encryption at rest
All data encrypted at rest using AES-256. Database encryption provided by Supabase (PostgreSQL on AWS). Encryption keys managed by the cloud provider with customer-controlled access policies.
AES-256
🌐
Encryption in transit
All API traffic encrypted via TLS 1.3. HTTPS enforced. HSTS headers on all endpoints. Cloudflare CDN provides DDoS protection and TLS termination at the edge.
TLS 1.3
🔑
API key security
API keys are stored as SHA-256 hashes only — plaintext is never persisted after initial generation. Keys are returned exactly once at creation and cannot be recovered. Revocation is immediate and irreversible.
SHA-256 · Hash-only storage
🧾
Tamper-evident audit trail
Every agent call produces an audit row in a dedicated audit schema. Rows are HMAC-SHA256 signed using a rotating AUDIT_SIGNING_KEY. INSERT-only — no UPDATE or DELETE permissions. Input hash and output hash stored per entry.
HMAC-SHA256 · INSERT-only
🏥
PHI firewall
Automated PHI scanner on all inputs before processing and all outputs before storage. Categories: patient identifiers, names, dates of birth, geographic sub-units, contact information. Outputs containing PHI are blocked and logged — never written to the knowledge base.
HIPAA 45 CFR §164.514(b)(2)
🔒
Access control
Tenant isolation is enforced in the application layer: every read and write is scoped to the caller's organization, resolved from a validated token or API key, and requests that resolve to no organization are rejected rather than defaulted. Row-level security is enabled on all application tables as a backstop against direct database access; note the backend connects with a service-role credential, which bypasses RLS by design, so RLS is defence in depth rather than the primary control. Role-based access control: owner / admin / analyst / viewer.
RLS · RBAC · Org-scoped
🚦
Rate limiting
Per-API-key sliding window rate limiting enforced server-side (not client-side). Default 60 req/min configurable per key. Query quotas enforced at the organization level over a rolling 30-day window. 429 responses include Retry-After headers.
Sliding window · Per-key
🏗️
Infrastructure
Backend hosted on Railway (AWS us-east-1). Database hosted on Supabase (AWS us-east-1). Frontend served via Cloudflare Workers (global edge network). No data leaves AWS us-east-1 except for edge-cached static assets.
AWS us-east-1 · Cloudflare

What we store and what we don't

  • We store: anonymized query metadata (run_id, agent_id, timestamps, token counts), structured evidence outputs, source provenance (PMIDs, NCT IDs), audit trail rows, organization and API key metadata
  • We do not store: raw query text in plaintext after processing, any PHI detected by the scanner, Stripe payment card details (handled by Stripe — we store only customer_id), API key plaintext after generation
  • Retention: Chat conversations and uploaded documents retained for 24 months from creation. Saved queries retained until you delete them or request erasure. Usage events retained for 36 months from creation. Audit trail rows retained for 10 years per EU AI Act Art. 12, append-only, with analyses still referenced by an approved correction retained beyond that window — those corrections are live inputs to future analyses, not archive. Request deletion via celldna1@gmail.com
  • Data residency: All data processed and stored in AWS us-east-1 (US). EU customers: contact us for EU residency options — available on Enterprise plan
  • AI model provider: Anthropic Claude is used for evidence synthesis. Queries are sent to Anthropic API. Anthropic's data processing terms apply. Evidara does not train models on customer data

Sub-processor list

The following third-party sub-processors handle personal data on behalf of Evidara. This list is maintained and updated when sub-processors change.

Supabase
Database, authentication, storage · AWS us-east-1
Anthropic
AI evidence synthesis (Claude API) · US
Railway
Backend compute hosting · AWS us-east-1
Cloudflare
CDN, DDoS protection, edge compute · Global
Stripe
Payment processing · US / EU
GitHub
Source code, CI/CD · US

Last updated: April 2026. Changes notified via email to DPA signatories 30 days in advance.

Uptime, support & response SLAs

Evidara publishes the following service level commitments for all paid plans. Enterprise contracts include SLA terms in the service agreement.

Platform uptime
99.9%
Monthly uptime target · AWS us-east-1 · Measured excluding scheduled maintenance
Enterprise support response
4 hrs
Business hours response SLA for Enterprise tier · Priority queue for critical issues
Security incident notification
72 hrs
Maximum notification time for confirmed breaches · GDPR Art. 33 compliant
  • Scheduled maintenance windows notified 48 hours in advance by email to account contacts
  • Evidence synthesis runtime varies by chain and query — from a few seconds for deterministic retrieval chains to several minutes for a full systematic review. Runtime is not currently measured as a service level commitment
  • Data recovery point objective (RPO): 24 hours · Recovery time objective (RTO): 4 hours
  • Database backups: daily automated · Retained 30 days
  • Incident history and status updates are sent by email to account contacts. Evidara does not currently operate a public status page

Responsible disclosure

Evidara operates a responsible disclosure program. If you discover a security vulnerability, please report it to celldna1@gmail.com before public disclosure.

  • We will acknowledge receipt within 1 business day
  • We target remediation within 30 days for critical vulnerabilities
  • We will credit researchers who report valid vulnerabilities (with their consent)
  • We ask that you do not exploit vulnerabilities beyond the minimum necessary to confirm their existence
  • We do not pursue legal action against good-faith security researchers
Security questions?
For enterprise procurement reviews we provide a pre-filled security questionnaire and architecture diagrams under NDA. No penetration test report exists yet — see the regulatory posture section above for current audit status.