Policies and trust
The agreements, security posture, and data-handling commitments that govern the service. Each one is kept truthful to what the system actually does.
Start here
What data leaves your environment and to whom, bring-your-own-keys, our no-training and zero-retention provider posture, and tenant and project isolation. The plain-language walkthrough.
How the system protects and handles your data.
Evigate's security posture: data flow and what leaves your environment, encryption, tenant isolation, authentication and session security, upload screening, secrets handling, and your data controls.
The third-party subprocessors Evigate uses, what each one does, what data it receives, and where it is located. Kept in sync with the live application endpoint.
How to report security vulnerabilities to Evigate safely: scope, rules of engagement, our commitments, safe harbor, and what is out of scope.
Evigate's trust center: a single hub for security, privacy, AI transparency, subprocessors, data handling, compliance posture, and how to get answers fast.
The agreements that govern your use of the service.
The agreement governing use of Evigate: accounts, your content, acceptable use, AI drafts and human review, billing through Paddle, warranties, liability, and termination.
How Evigate collects, uses, stores, and shares personal data, our no-training and low-retention posture, the subprocessors involved, and your rights under the DPDP Act, GDPR, and CCPA.
The cookies Evigate uses: strictly necessary authentication and CSRF cookies only, with no advertising or third-party analytics cookies.
The rules for using Evigate responsibly: prohibited content and conduct, security boundaries, fair use of AI and cost controls, and enforcement.
How Evigate uses AI: the RAG pipeline, which models and providers, what data leaves your environment, grounding and citations, abstention, mandatory human review, no-training, and BYOK.
Evigate's Data Processing Addendum covering processing of customer content on your behalf: roles, instructions, security, subprocessors, international transfers (SCCs), data-subject requests, breach notification, audits, and deletion.
Evigate's service-level commitments for the hosted service: availability target, support response targets, maintenance, exclusions, and how self-hosted differs.
How Evigate is licensed: the hosted SaaS subscription license, the self-hosted deployment license, open-source components and their notices, and trademark/brand use.
Plans, charges, and refunds.
How Evigate billing works: Free and paid plans, the $150/month price, usage limits and metering, Paddle as merchant of record, renewals, cancellation, grace periods, and BYOK cost ownership.
Evigate paid subscriptions are non-refundable. The Free plan includes every feature so you can fully evaluate before paying. Billing errors are always corrected, and mandatory consumer rights are unaffected.
How to reach us.
Third-party components, attribution notices, and the change history of this document set.
Open-source components used by Evigate and their licenses, generated from the project's dependency manifests.
Copyright and third-party attribution notices for Evigate, including notices required by the licenses of the open-source components it depends on.
Version history for the Evigate legal and compliance documentation set — every dated change to the policies, what changed, and why.