Skip to content
Evolix Aiva

Trust

An honest account of where security posture stands today.

This page states what is true now and what is planned. We do not claim certifications or compliance standards that haven't been completed.

What we do today

Current practices.

Deployment boundaries

The platform is designed to run inside your cloud account and data boundary rather than a shared environment. See Deployment for the reference architecture.

Access control

Connections use credentials scoped to what a specific agent needs, configured per engagement rather than granted broadly by default.

Logging & traceability

Agent actions, tool calls, policy decisions, and human approvals are recorded in a trace, so a completed workflow can be reconstructed after the fact.

Human review

Actions above a defined risk threshold route to a named reviewer before they execute, rather than completing unattended.

Data handling

{{TBD: data retention period, encryption at rest/in transit details, and data processing locations to be confirmed and published here.}}

What is on the roadmap

Not yet in place.

  • Formal third-party security certification (e.g. SOC 2) — not yet completed.
  • Independent penetration testing program — not yet completed.
  • Published subprocessor list with update notifications.
  • Expanded self-serve documentation for security and compliance reviewers.

Subprocessors & DPA

Who else touches the data.

{{TBD: current subprocessor list to be published here.}} A data processing agreement is available for engagements that require one — see the DPA page.

{{TBD: data residency options and current maturity statement to be confirmed by legal/security before publishing region-specific commitments.}}

Security review before a pilot?

Bring your questionnaire — a working session is a faster way to work through it than an email thread.