HIPAA compliance
Evidara is designed as a HIPAA-ready platform. The system is intended for use with de-identified data only. A Business Associate Agreement (BAA) is available for all Team and Enterprise customers.
- PHI firewall: Automated PHI scanning on every input before processing (18 HIPAA identifiers) and every output before wiki write. Outputs containing PHI are blocked and flagged — never written to the knowledge base.
- No PHI storage: Evidara is not designed or intended as a PHI storage system. Queries containing PHI will be blocked by the input scanner. Users should de-identify data before submitting queries.
- Minimum necessary: Data access is scoped to the minimum required for the specific evidence synthesis task. API keys are organization-scoped, and every query is filtered by the caller's organization in the application layer.
- Audit controls (§164.312(b)): Hardware, software, and procedural mechanisms record and examine activity in information systems that contain or use ePHI. Every agent call is logged with user identity, timestamps, input hash, and output hash.
- Integrity controls (§164.312(c)): HMAC-SHA256 signing of audit trail rows. INSERT-only schema prevents tampering.
- BAA: Business Associate Agreement available for Team and Enterprise customers. Contact celldna1@gmail.com to initiate.
GDPR compliance
Evidara processes personal data as a data processor on behalf of customers (data controllers). The assessments below are Evidara's own, based on the platform design and the DPIA completed 27 April 2026. They have not been independently audited.
DPO contact: celldna1@gmail.com · Data subject requests: celldna1@gmail.com
EU AI Act compliance
Evidara's DPIA classifies the platform as a high-risk AI system under EU AI Act Article 6 and Annex III, used in a regulated industry context. The platform implements transparency and human oversight requirements proactively — ahead of enforcement timelines.
Full EU AI Act compliance documentation and DPIA available on request. Contact celldna1@gmail.com
21 CFR Part 11 compliance
The Evidara audit trail is designed to meet the requirements of 21 CFR Part 11 for electronic records and electronic signatures in FDA-regulated environments.
- §11.10(a) — Validation: Evidence synthesis engine produces validated, reproducible outputs. Input and output hashes stored per run enable reconstruction and comparison.
- §11.10(b) — Accurate copies: Structured JSON outputs are exportable to PDF and PPTX. Source provenance included in every output enables independent verification.
- §11.10(c) — Record protection: INSERT-only audit schema. No UPDATE or DELETE permissions on audit.agent_calls table. HMAC-SHA256 signature per row detects tampering.
- §11.10(d) — Access limitation: API key authentication on all endpoints. Role-based access control (owner/admin/analyst). Row-level security enforced at database layer.
- §11.10(e) — Audit trail: Every agent call logged with: run_id, agent_id, called_at, completed_at, input_hash, output_hash, comms_pass, wall_breach_log, tokens_used, raw_inbox_id, entry_hmac.
- §11.10(j) — Training: Platform documentation available. Evidence protocol descriptions provided in-product. Onboarding session included for Team and Enterprise.
DPA template
A standard Data Processing Agreement is available for all customers requiring one. The DPA covers: processing purposes and instructions, technical and organizational measures, sub-processor management, data subject rights support, breach notification procedures, and return/deletion of data on contract termination.
Request DPA template
Our standard DPA template can be sent within 1 business day. For enterprise customers with custom DPA requirements, we will review and respond on your template within 5 business days; external counsel is engaged where required.
DPIA summary
A full Data Protection Impact Assessment was completed for Evidara's AI-assisted evidence synthesis processing. Key findings:
- Processing purpose: Pharmaceutical evidence synthesis for HEOR, market access, clinical development, and regulatory strategy decision support. No clinical decision-making. No patient-level data processed.
- Data subjects: Platform users (authenticated researchers and analysts). No patient data is intended to be processed. PHI firewall prevents inadvertent processing if PHI is submitted.
- Necessity and proportionality: Processing limited to minimum data required for evidence synthesis. No profiling. No automated decisions with legal effect on data subjects.
- Risks identified and mitigated: (1) Inadvertent PHI submission — mitigated by input scanner. (2) AI model bias in evidence synthesis — mitigated by uncertainty quantification, contradiction detection, and mandatory human review flag. (3) Audit trail integrity — mitigated by HMAC-signed INSERT-only records.
- Residual risk: LOW to MODERATE. The highest residual risk identified is AI-generated regulatory analysis being acted upon without expert review — mitigated by the mandatory human-review flag on every output. No high-risk processing under GDPR Art. 35(3) was identified; note this is a separate assessment from the EU AI Act classification above.
Full DPIA document available on request to qualified enterprise customers. Contact celldna1@gmail.com