Trust & Security
Evidion asks regulated organisations to entrust it with their compliance evidence — the very material that proves their accountability. We hold ourselves to the standard we help our clients demonstrate.
Our operating principle is simple: evidence you cannot trust is not evidence. Every design decision in Evidion — where data lives, how it is stored, who can touch it, and how every action is recorded — follows from that principle.
How we protect your evidence
EU data residency
Customer evidence is hosted within the European Union. Data residency is a design constraint, not a configuration option — built for organisations whose regulatory posture requires their compliance artefacts to remain under EU jurisdiction.
Tamper-evident chain of custody
Every piece of evidence captured in Evidion is cryptographically hashed and timestamped at ingestion, then held in write-once (WORM) storage. Evidence cannot be silently altered or deleted after the fact — the integrity of the record is verifiable, which is what makes it usable in front of an auditor or regulator.
Controlled, auditable access
Access follows least privilege: people see only what their role requires, and access itself is logged. Auditors and assessors work through a dedicated portal with scoped, time-bound visibility — they see the evidence they need, and nothing else.
Encryption and data handling
Customer data is encrypted in transit and at rest. Your evidence remains your property: we process it to provide the service, and it is not used for any other purpose. Data is returned or deleted on termination in line with our agreements.
Certification roadmap
GDPR
Evidion operates under the General Data Protection Regulation as an EU-based processor of customer data, with data processing agreements available for all customers.
ISO/IEC 27001
Formal certification of our information security management system is on our certification roadmap. Our internal controls are being built against the standard from the outset, so certification formalises practice rather than retrofitting it.
SOC 2 Type II
SOC 2 attestation is planned alongside ISO 27001. We would rather state our roadmap honestly than imply certifications we do not yet hold — ask us where we are in the process and we will tell you.
Security questions and disclosure
Due diligence
Enterprise security reviews are welcome. We will complete your security questionnaire, walk your team through our architecture and controls, and share our current certification status openly as part of any evaluation.
Responsible disclosure
If you believe you have found a security vulnerability in an Evidion service, please contact us through our contact page with details. We take every report seriously and will respond promptly.
Security posture is easier to demonstrate than to describe. If your team is evaluating Evidion, we are happy to go through all of it in detail.
Speak With Evidion