Security and data

What we do with your data, and what we don’t

Evidence Bank is early software in pilot. This page says what is true today rather than what we intend, because the first thing procurement will do is check.

Read this before a pilot

Sign-in is open during the pilot

Today, anyone who reaches the product’s address can sign in by choosing a name from a list. There are no passwords yet. This is deliberate for pilots, where the cost of account setup outweighs the risk, but it means the address should be treated as confidential and no genuinely sensitive personal data should be recorded.

Microsoft Entra ID sign-in is the next piece of work, and the application is already structured for it: authentication sits behind one interface, so swapping it in changes no page. We will not describe the product as access-controlled until it is.

What is in place today

Where your data lives

  • Stored in a PostgreSQL database hosted by Neon, in the London region.
  • The application runs on Vercel, with server functions in London.
  • Encrypted in transit with TLS, and at rest by the database host.

How teams are separated

  • Every record belongs to exactly one team, and every query is filtered by it.
  • That filter is applied in one place in the data layer, so a page or action cannot forget it.
  • An automated test asserts the rule covers every table that carries an owner.

What leaves the application

  • With AI features off: nothing. Search matches words, and transcripts are typed in by hand.
  • With them on: the transcript you paste, the records relevant to a question, and the text being indexed for meaning-based search.
  • Providers are contracted not to train on your content. Every one is named on the sub-processors page.

Access and deletion

  • Export your content whenever you want it.
  • Ask us to delete it and we will, within 30 days.
  • Admins control who is in their team, and who can edit rather than only read.

Not yet

What we have not done

Listed because the absence matters more than the presence when you are assessing a supplier.

No single sign-on yet

Entra ID is in progress. Until it lands, access is controlled by keeping the address private.

No formal certification

We hold no ISO 27001 or SOC 2 certification, and will not claim one. We are happy to answer a security questionnaire directly.

No uptime commitment

The pilot has no service level agreement. If availability matters contractually, raise it before committing and we will discuss it.

Send us your security questionnaire

We would rather answer it before a pilot than during one. The sub-processor list and the data processing summary are already written.

Security contact: hello@chrisberridge.com