Evidiam
Security & trust

For a system of record, trust is the product.

Evidiam holds the evidence a regulator or sponsor bank will examine. The architecture is built around four promises: your data is isolated, the record can't be quietly altered, every judgment is attributable to a person, and every accepted artifact stays under your control.

Isolation

Your tenant is walled off in the database itself.

Every program runs under Postgres row-level security, enforced by a non-superuser application role. Tenant scope is set per transaction; one tenant can never read another's records, even through application bugs.

Tamper-evidence

An append-only record you can verify.

Every material event is written once into a per-tenant hash chain, where each entry seals the one before it. Alter a past record and the chain breaks. Verification is a function you can run, not a promise you have to take.

Attribution

Every judgment carries a name.

Dispositions, decisions, and sign-offs record who acted, in what role, and when. AI-assisted items are labeled. The sign-off chain is enforced in order, by the roles your template requires.

Ownership

The evidence is yours to keep.

Evidiam is neutral by design. Your accepted record is structured the same way for every sponsor bank, exportable on demand, and not locked inside the party that examines you.

The posture

Stated plainly.

No vague assurances. Here is how the system actually behaves.

Tenant isolation
Postgres row-level security, non-superuser app role
Evidence integrity
Append-only, per-tenant SHA-256 hash chain
Integrity check
Chain verification you can run on demand
Google Drive access
Viewer-only folder sharing; Evidiam inventories and profiles files but does not edit them
Data access
Read-only evidence folders, read-only warehouse role, SELECT-only
Write-back
None. Evidiam never writes to source systems
Payment rails
None. Evidiam never moves money
AI authority
Drafts only. No final action without human sign-off
Review links
Token-scoped, expiring, revocable, and scoped to one period
Token storage
Bearer tokens are hashed at rest and shown once at creation
External views
Frozen signed packets only. Reopened drafts are not exposed
Accepted artifacts
Snapshot version, state hash, and PDF SHA-256 are pinned
Public verification
Packet hash and PDF verification without an app account
Offline bundle
Accepted packet, manifest, and verification data are downloadable
Access logs
External profile and packet downloads are recorded per tenant
Auditability
Full event history per tenant, exportable
Data handling

What Evidiam stores, and what it leaves alone.

Folder access is read-only. Evidiam stores the evidence record around the files so the fintech can answer the bank and reuse the trail.

Request record

DD checklists, audit requests, pasted request text, extracted asks, source references, duplicates, exclusions, owners, due dates, and response notes.

Evidence index

File names, source location, metadata, hashes when available, document profiles, table-of-contents signals, classifications, restricted flags, and match suggestions.

Decision trail

Human approvals, gap decisions, evidence attachments, signed judgments, AI-draft provenance, reviewer comments, and bank acceptance history.

Shared artifacts

Exported response packets, manifests, verification bundles, packet hashes, access logs, and the scoped trust profile the fintech chooses to share.

Explicit limits

  • Evidiam does not edit, move, rename, or delete client files in Google Drive, SFTP, or other source repositories.
  • Evidiam does not require write access to systems of record and does not move money.
  • Evidiam does not turn AI drafts into final regulatory judgments without human approval.
AI governance

The model never holds the pen.

AI drafts rationale and narrative from your data, and it is constrained to your real records, with source excerpts that guard against invention. But a draft is not a decision. Every regulatory judgment is reviewed and signed by a named officer before it becomes part of the record, and that gate is enforced by the system, not left to discipline.

External proof

Shared evidence stays controlled.

Evidiam exposes accepted proof without exposing live work. Public surfaces are scoped, logged, revocable, and tied to frozen artifacts.

Reviewer portal

A bank reviewer can open a scoped link, download the examination binder, accept the packet, or request changes.

Trust profile

A prospective sponsor bank can inspect accepted packets without an Evidiam account and match each PDF to its pinned hash.

Verification report

Accepted packets expose the sign-off chain, acceptance record, event integrity, and per-domain digests.

Access trace

Views and downloads are written to an external access log so the fintech can see who opened shared proof.

Verification Report
Accepted-packet proof bundle
Sanitized
Chain
Valid
Acceptance
Pinned
Bundle
Ready
Verifiable contents
Accepted packet PDF
Manifest and event digests
Sign-off chain
External access
Views4
Downloads2
ExpiresJul 31
On the roadmap

Formal attestations, in progress.

SOC 2 and the supporting control program are underway. We'd rather tell you exactly where we are than imply a badge we haven't earned yet. Ask us for the current status.

SOC 2 · in progress

Due diligence welcome.

Bring your security team. We built Evidiam to be examined.