Compliance posture
Evidara holds no third-party security certifications today. A SOC 2 Type II audit is in progress; no report has been issued. HIPAA, GDPR, 21 CFR Part 11 and the EU AI Act are regulatory frameworks rather than certification schemes — the entries below describe the controls Evidara implements against each and are self-assessed, not independently audited. Control documentation and evidence are available to enterprise procurement teams under NDA.
Infrastructure security
What we store and what we don't
- We store: anonymized query metadata (run_id, agent_id, timestamps, token counts), structured evidence outputs, source provenance (PMIDs, NCT IDs), audit trail rows, organization and API key metadata
- We do not store: raw query text in plaintext after processing, any PHI detected by the scanner, Stripe payment card details (handled by Stripe — we store only customer_id), API key plaintext after generation
- Retention: Chat conversations and uploaded documents retained for 24 months from creation. Saved queries retained until you delete them or request erasure. Usage events retained for 36 months from creation. Audit trail rows retained for 10 years per EU AI Act Art. 12, append-only, with analyses still referenced by an approved correction retained beyond that window — those corrections are live inputs to future analyses, not archive. Request deletion via celldna1@gmail.com
- Data residency: All data processed and stored in AWS us-east-1 (US). EU customers: contact us for EU residency options — available on Enterprise plan
- AI model provider: Anthropic Claude is used for evidence synthesis. Queries are sent to Anthropic API. Anthropic's data processing terms apply. Evidara does not train models on customer data
Sub-processor list
The following third-party sub-processors handle personal data on behalf of Evidara. This list is maintained and updated when sub-processors change.
Last updated: April 2026. Changes notified via email to DPA signatories 30 days in advance.
Uptime, support & response SLAs
Evidara publishes the following service level commitments for all paid plans. Enterprise contracts include SLA terms in the service agreement.
- Scheduled maintenance windows notified 48 hours in advance by email to account contacts
- Evidence synthesis runtime varies by chain and query — from a few seconds for deterministic retrieval chains to several minutes for a full systematic review. Runtime is not currently measured as a service level commitment
- Data recovery point objective (RPO): 24 hours · Recovery time objective (RTO): 4 hours
- Database backups: daily automated · Retained 30 days
- Incident history and status updates are sent by email to account contacts. Evidara does not currently operate a public status page
Responsible disclosure
Evidara operates a responsible disclosure program. If you discover a security vulnerability, please report it to celldna1@gmail.com before public disclosure.
- We will acknowledge receipt within 1 business day
- We target remediation within 30 days for critical vulnerabilities
- We will credit researchers who report valid vulnerabilities (with their consent)
- We ask that you do not exploit vulnerabilities beyond the minimum necessary to confirm their existence
- We do not pursue legal action against good-faith security researchers