EVIDENT

Security

What we read, what we never read, and where it goes

You are being asked to point a tool at a production database. This page is written for the person whose job is to say no to that.

The short version: by default EVIDENT reads structure, not rows. It needs no business records to do its primary job, it writes nothing to your systems, and you can run the whole thing on your own infrastructure.

Three analysis modes, and the default is the narrowest

ModeDefaultWhat it can access
Metadata onlyYesSchema, constraints, foreign keys, types and comments
Metadata and profilingOpt inAggregates and statistics — counts, distinctness, null ratios
Metadata and samplesExplicit opt inControlled sample values, for the cases that need them

Read-only, and enforced rather than promised

Connections are made with read-only, least-privilege credentials, and every engine states what its read-only promise actually rests on. Where the driver can enforce it, it is enforced rather than trusted — the SQLite engine, for instance, opens the file read-only at the driver level.

Connection secrets are never written to a log. Credentials are encrypted at rest and bound to the connection they belong to, so a password supplied without a destination is refused rather than stored loose.

The rest of the answers

Can we run it entirely on our own infrastructure?

Yes, and most customers should. It is containers and a volume. The licence is a signed code that is verified offline against a public key, so it works on a network with no route to the internet.

Does our source code leave our network?

In a self-hosted deployment nothing leaves at all. In the hosted service, the repository is read and analysed, and what is retained is the derived model rather than the source.

Who can see what, inside the product?

Access is decided by role. A role names a set of permissions, a permission is an operation on a kind of thing, and the token a request carries can narrow that set but never widen it.

Is there an audit trail?

Yes, over scans, reviews, exports, policy changes and administrative actions — each recording the actor, the time and the origin of the request.

Where do I find the trust artefacts?

On trust: what is published, what is provided during security and commercial due diligence, who operates which control on each kind of deployment, and how to report a vulnerability. It is a map rather than more reading — everything on it is a link or a route to a person.

What about an air-gapped network?

It works today, and it is two questions rather than one. If the platform can be deployed inside the network with the systems it reads, there is nothing to send outward at all: the licence is a signed code verified offline against a public key, so an installation with no route to the internet behaves exactly like one that has it. That is the air-gapped case and it is supported now.

And if the sources are somewhere the platform cannot reach?

That is the different question, and the answer is the local agent: it reads inside the segment and sends normalised evidence outward, so records never cross the boundary. It is specified and Planned. It is not shipped, and this page will say so until it is — an air-gapped deployment does not need it, and a segmented one does.

Are you certified?

We are not going to claim a certification we do not hold. The product is built to the practices described on this page, and we would rather you verify them than take a badge on trust.