Trust & security
Trust Center
Evigate is built to handle your most confidential documents (SOC 2 reports, security policies, and past questionnaires). This Trust Center is the single place to understand how we protect them.
At a glance
| Topic | Our posture |
|---|---|
| Data residency | Stored in Mumbai, India on a single-tenant Hostinger VPS |
| Encryption | TLS/HSTS in transit; secrets and BYOK keys are encrypted at rest. Self-hosted options are available for custom environment configurations. |
| AI training | Never trained on your content. Anthropic is under a signed no-training agreement; the conditional Gemini fallback relies on Google's stated no-training terms for that API tier |
| What leaves — at answer time | Only a question + retrieved snippets to Anthropic (or, on the rare failover, Google's Gemini API); never whole documents; nothing with BYOK |
| What leaves — at intake | For scanned/image PDF pages only, the page image + extracted text goes to Anthropic (vision) to identify the questions on it. Born-digital pages don't trigger this |
| Embeddings | Computed locally on our own infrastructure (self-hosted bge-large-en-v1.5) — chunk text never leaves our server |
| Isolation | Per-organization and per-project, enforced on every query and tested in CI |
| Human review | Mandatory; nothing is auto-sent |
| Your control | Self-serve export and full deletion at any time |
| Auth | Email + password, or optional "Sign in with Google" (OAuth 2.0/OIDC); hardened HttpOnly sessions, CSRF, rate limiting, lockout |
| Payments | Paddle (merchant of record); we never store card numbers |
Documentation
Security & data
- Security Overview: full technical posture
- Subprocessors: who receives what, and where
- Responsible Disclosure Policy: report a vulnerability
Privacy & AI
- Privacy Policy: data handling and your rights (DPDP, GDPR, CCPA)
- AI Usage Policy: how AI is used, grounding, citations, no-training
- Cookie Policy: strictly necessary cookies only
- Data Processing Addendum: for customers as controllers
Commercial
- Terms of Service
- Acceptable Use Policy
- Billing Policy · Refund Policy
- Service Level Agreement
- Licensing · Third-Party Licenses
Compliance posture
- Privacy laws: Built to support India's DPDP Act, 2023, the EU/UK GDPR, and CCPA/CPRA. Evigate acts as a data processor/service provider for the content you upload, and a controller for account-related data.
- Data Processing Addendum: Available to customers; see the DPA.
- Certifications: Evigate does not hold formal third-party certifications (e.g., SOC 2 or ISO 27001) at this stage. Enterprise customers requiring certified environments can run Evigate via our self-hosted deployment package to align with their internal compliance frameworks.
*Operator note:* this section should list real certifications (e.g. SOC 2 Type II, ISO 27001) and audit reports only when they exist or are genuinely in progress, with status and dates. If you pursue one, add it here with its current stage.
Frequently asked
- Do you train on our data? No, never, by design. Anthropic is under a signed
no-training agreement; the conditional Gemini fallback relies on Google's stated no-training terms rather than a bespoke signed agreement.
- Can we keep data off third-party AI providers? Yes, use BYOK (your own
Anthropic, OpenAI, Gemini, Ollama, or custom-endpoint key) or self-hosted deployment. Embeddings are always local and never sent to a third party regardless of BYOK.
- Where is our data stored? In the Mumbai, India region, on a single-tenant Hostinger VPS.
- Can we delete everything? Yes, delete any document or purge your entire
organization yourself, at any time.
Contact
Security: security@logethos.com · Privacy: privacy@logethos.com · Sales/support: support@logethos.com
*Effective date: July 31, 2026 · Last updated: 2026-07-21 · Version 1.1*