SECURITY & GOVERNANCE

Security begins with the trace boundary.

Prompts, responses, retrieval evidence, tool records, evaluations, and cost data may be sensitive. Evalara confirms the collection and control model before production integration.

01Workspace isolation

A named customer workspace, scoped projects, environments, roles, and administrator-controlled invitations.

02Identity and access

Customer-approved identity design, role boundaries, least privilege, session policy, and periodic access review.

03Telemetry handling

Field purpose, payload controls, redaction boundary, encryption, export, and sensitive-content access.

04Retention and deletion

Retention by environment and data class, deletion workflow, legal requirements, and customer instructions.

05Deployment architecture

Hosting, region, network path, collector, storage, integration, and operational-support requirements.

06Auditability

Administrative access, configuration changes, exports, prompt promotion, evaluation, and release decisions.

SECURITY REVIEW

Requirements become implementation controls.

Evalara does not rely on unsupported public certification claims. Contractual security commitments are confirmed for the selected architecture and scope.

1Data and system map
2Access model
3Payload and redaction
4Retention and exports
5Deployment and operations
6Acceptance evidence
DRAW THE BOUNDARY FIRST

Define what Evalara may collect before anything reaches the workspace.

The security review turns identity, payload, retention, deployment, export, and operational requirements into an agreed implementation design.

Scope a security review