Security, Privacy, and Data Use
Evolusis outlines how data is processed and managed within the platform, designed specifically for security, privacy, and procurement stakeholders, with a clear focus on practical implementation over marketing claims.
Last updated: March 25, 2026 · privacy@evolusis.com
Security & Privacy
Evolusis Trust Center
Evolusis supports enterprise learning and coaching with voice-based role-play, chat, and session analytics. This Trust Center describes the product's data handling, security controls, and privacy practices based on the current application and services.
Scope & Commitments
What this page covers and how to interpret it
Compliance Status
What we can evidence today and what is in progress
Standard DPA available for enterprise customers. Covers sub-processor disclosure, security measures, incident notification, and deletion workflows.
We respond to SIG Lite, CAIQ, and custom questionnaires. Pen test summaries available under NDA.
Security controls are aligned with common control frameworks. Formal certifications are in progress and will be shared when issued.
We support customer compliance requirements (e.g., GDPR/DPDP) via contract addenda and data processing controls.
Access Control
Who can access what — inside your tenant and internally at Evolusis
Product APIs require bearer tokens issued at login. No public API calls are made without authentication.
Learners view their own sessions; admins and managers have organization-scoped access in the UI.
Google and Microsoft OAuth login flows are supported for enterprise SSO integrations.
Periodic access review and least-privilege checks are part of our security program.
Encryption
Data protection in transit and at rest
Product traffic is served over HTTPS/TLS in production environments to protect data in transit.
We use managed infrastructure that provides encryption at rest and key management capabilities.
Passwords are never stored in plaintext. Authentication uses standard hashing practices and token-based session handling.
Network Security
Infrastructure-level controls protecting perimeter and internal traffic
The product is hosted on managed cloud services that provide physical security and availability controls.
Public-facing API endpoints apply protective limits to reduce abuse and automated attacks.
Operational monitoring is used to detect errors and anomalous activity across core services.
Endpoint Security
Controls on devices used by Evolusis employees
Company-managed devices are used to access production systems.
Baseline endpoint protection and device security policies are part of our internal program.
Secure Development (SDLC)
How security is embedded in our engineering process
Changes go through peer review prior to deployment.
Third-party dependencies are monitored and updated as part of regular maintenance.
Sensitive credentials are managed outside of source control.
Security testing and reviews are integrated into release processes.
Vulnerability Management
How we find, triage, and remediate security vulnerabilities
Report vulnerabilities to security@evolusis.com. We triage and respond on a best-effort basis.
We monitor for known vulnerabilities in dependencies and remediate based on severity.
Security configuration and access reviews are performed periodically.
Incident Response
Our process from detection to customer notification
Anomalies from monitoring, user reports, or automated scanning are immediately assigned a severity (P0–P3) and an incident owner. All potential incidents treated seriously until confirmed otherwise.
Affected system, credential, or data pathway isolated to prevent further exposure. For P0/P1, this may include temporary service restrictions. Engineering lead and founder paged immediately.
Forensic log review to establish scope, timeline, and root cause. We identify what data was accessed, by whom, and for how long. Drives the notification scope and remediation plan.
Affected enterprise customers notified within 72 hours of confirmed incident, consistent with DPDP obligations. Includes confirmed scope, data types affected, actions taken, and next steps.
Root cause fixed. Written post-mortem completed for all P0/P1 incidents. Lessons incorporated into security policies. Post-mortem summaries available to enterprise customers on request.
Data We Process
Data types used by the product and why they exist
| Data Type | Category | Purpose | Notes |
|---|---|---|---|
| Name, email, password hash | Identity | Account creation, login, recovery | Used for authentication |
| OAuth provider data | Identity | Single sign-on login | Provider-linked metadata |
| Profile fields (name, phone, role) | Profile | User profile and support | Editable by user/admin |
| Chat messages & conversation IDs | Session Content | Role-play coaching and continuity | Stored for session access |
| Voice recordings & transcripts | Voice | Real-time coaching and feedback | Subject to admin controls |
| Session summaries & scores | Analytics | Progress tracking and reporting | Organization-level reporting |
| Contact form submissions | Support | Customer support and inquiries | Support workflow |
| Admin content (blogs, pages) | Content | Public content management | Published content only |
For detailed retention schedules and deletion workflows, contact privacy@evolusis.com. Enterprise admins can request exports or deletion for organizational data.
AI & Voice Data Processing
How Evo's AI coaching engine handles sensitive session data
Voice data is transcribed to enable coaching. Audio and transcripts are handled as session data for the learner and organization.
Customer session data is not used to train models unless explicitly agreed in writing.
The product does not derive biometric identifiers or voiceprints from audio.
Session prompts are limited to context required for coaching output.
Sub-Processors
Third-party services that process customer data on our behalf
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Cloud Infrastructure | Hosting | Customer data at rest and in transit | Region by contract |
| AI Model Provider | AI Coaching | Role-play transcripts and prompts | Region by contract |
| Speech-to-Text Provider | Transcription | Voice recordings for transcription | Region by contract |
| Email Provider | Notifications | Email addresses and notification content | Region by contract |
| Analytics (Internal) | Product Analytics | Usage events (de-identified where possible) | Region by contract |
Full sub-processor details, locations, and DPA addenda are available on request.
Frequently Asked Questions
Common questions from security and procurement teams