Skip to main content

Evoriqa is live. Tour the reseller console, or read our security page.

Built for trust from day one

Security and privacy aren't add-ons. Every Evoriqa workspace ships with the controls security reviewers typically ask for, and the guardrails that keep AI actions safe.

Live platform statusuptime and incident history, published

Security baked into every workspace

Not an enterprise add-on — every Evoriqa workspace ships with these controls from day one.

Audit trail

Every security and account event is logged: who did what, when, with CSV export.

GDPR export & erasure

Per-workspace data export and right-to-be-forgotten delete, built in.

Data retention

Set a per-workspace window; a daily job auto-purges old conversations and messages.

Secrets encrypted at rest

Channel credentials are AES-GCM encrypted at rest and are not exposed to the model or to client-side code.

Enforced 2FA

TOTP two-factor enrollment and an enforced login challenge. Google sign-in accounts re-authenticate through Google before sensitive actions.

Outbound safety (allow-list)

Outbound agent actions are restricted to destinations you've explicitly allow-listed, with server-side protections on every outbound request.

Tenant isolation

Strict per-workspace tenant isolation across the platform.

Per-answer reasoning traces

Every AI reply keeps an audit trail — the knowledge it drew on, the prompt it ran, the actions it took — dashboard-only and auto-deleted after 90 days.

Signed webhooks

Inbound provider webhooks are signature-verified; outbound webhooks are HMAC-signed.

Public trust center & DPA requests

A crawlable per-brand trust page — certifications with honest status, controls, sub-processors, and the no-training statement — plus a rate-limited Request-a-DPA form routed to the owning agency or to us.

AI-disclosure attestation

Every chat opened with the AI disclosure on, and every voice call, is stamped as disclosed; the compliance CSV counts attested conversations per chatbot.

Evidence a security team can read

A public trust page under your brand, and per-conversation proof of when visitors were told they're talking to AI.

A public trust center, per brand

Every white-label brand gets an unauthenticated, crawlable trust page — the document a customer's security team reads before they sign.

  • Certifications with honest status — nothing is listed before it is attained
  • The sub-processor list, centrally authored — a reseller can't publish a different one under their brand
  • The no-training-on-customer-data statement, retention, and data residency
  • A rate-limited Request-a-DPA form, routed to the owning agency on a live custom domain, or to us

AI-disclosure attestation

Proof, per conversation, that the visitor was told they were talking to AI — not just a setting you toggled once.

  • Every widget conversation opened with the disclosure on is stamped as disclosed
  • Every voice call is stamped too — the disclosure is spoken before the greeting
  • The compliance CSV exports an attested-conversations count per chatbot — evidence you can hand over, not a claim
  • Blocked topics and visitor-facing source citations round out the answer-time guardrails

Data ownership

Your data stays yours

We don't train foundation models on your content. Channel credentials are encrypted at rest and never exposed to the model. Export or delete your data anytime.

  • Regional deployment available by written agreement
  • Per-workspace retention windows with auto-purge
  • AI action, API request, and webhook logs capped at 90 days
  • Every signed-in device listed, with sign-out-everywhere
  • DPA and subprocessor list available on request

Security questions? We're an open book.

Get the trust details your team needs to say yes.