Evisentra

Security & Trust

You share supplier, product, claim, and evidence details with us. Here is how that data is handled — in plain terms, with nothing claimed that we can't stand behind.

Transport & hosting

The site is served over HTTPS/TLS and runs on a managed cloud platform; application code is version-controlled.

The public site is cookieless

Public pages set no cookies — including no analytics cookies — and store no identifiers in your browser. The only cookie anywhere on the site is a secure, HttpOnly session cookie set when the owner signs in to the private admin area.

Privacy-first analytics

Evisentra uses Cloudflare Web Analytics to understand aggregate website traffic and performance, including pageviews, referring websites, approximate country, browser and device type. It does not use analytics cookies or local-storage identifiers, and Evisentra does not use it to identify or profile individual visitors. We do not use advertising pixels, cross-site behavioural tracking, visitor-identification services, or sell visitor information. Separately, our CDN and hosting providers (Cloudflare, Render) keep short-lived operational request logs (IP, timestamp, path) necessary for security, abuse prevention, and service delivery; these are not marketing analytics and are not used to profile you.

No third-party AI sees your evidence

A reviewer classifies the evidence; the scoring calculation on those finalized inputs is deterministic — public rules and the published rubric, never a model. Any AI assistance is optional, helps only to organize or classify evidence, runs inside Evisentra-controlled infrastructure, and is never sent to a third-party AI provider or used to train AI models.

Evidence handling

Your evidence is held privately, used only for your review, and not shared with other clients. Uploaded files are stored encrypted in a private, access-controlled bucket and are not retained on the web server; each file's SHA-256 fingerprint is recorded so both sides can confirm integrity. Evidence is disclosed to the named independent specialist only after you approve that reviewer and the applicable confidentiality terms, or where required by law.

Access

After scope confirmation and deposit, Evisentra sends a private, expiring upload link by email. Confidential evidence is uploaded through that link and is not attached to ordinary email. The private admin area is behind a username-and-password session login. Named independent reviewers work under agreement and disclose material conflicts before specialist work begins.

Retention & deletion

Retention and deletion are described in our Privacy notice, and you can request deletion of your evidence. A Data Processing Agreement (DPA) and a mutual NDA are available on request before paid evidence intake.

Confidentiality

Evisentra routinely executes mutual nondisclosure agreements (NDAs) before confidential technical or commercial discussions, and is happy to review your organisation's standard NDA as part of procurement. See Legal & procurement, or contact us to start a vendor packet.

Responsible disclosure

Found a security issue? Email [email protected] with details and we will respond. Please do not test against other users' data.

Subprocessors

The third parties that help run the service. We do not sell data, and no third-party AI provider receives your evidence.

Subprocessors and what they process
ProviderPurposeDataRegion
RenderApplication hostingSite + submitted form dataUS
Google WorkspaceEmail & correspondenceContact details, messagesUS
CloudflareDNS / CDN / edge security; private client evidence storage (R2)Request metadata; paid-engagement evidence files (encrypted, private bucket)Global edge

A current subprocessor list and transfer terms are provided in the DPA on request; we give notice before adding a subprocessor that would process client evidence.

Procurement & vendor onboarding

To route a purchase internally, we can provide: our legal entity (Nutavix LLC) and tax form (W-9), a mutual NDA, an MSA/SOW, a DPA, PO/invoice terms, a named security contact, and tax and insurance documentation as applicable at engagement. Contact us to start a vendor packet.

What this page is not: Evisentra is not certified to SOC 2, ISO 27001, or any security standard, and does not claim to be. This page describes current practice honestly; any formal attestation, if pursued, will be stated here with evidence.

Questions from a buyer's security team? Contact us and we'll answer directly.