Evaident keeps one tamper-evident record of every way your organisation uses AI — approved tools, in-house agents and the unapproved apps nobody told you about — enforces your policy in real time, and lets you prove it to a client, a board or a regulator.
No card required · Demo workspace in under 2 minutes
Not sure what you need? Find your setup in 60 seconds →
The exposure isn't only a regulatory fine — it's a client dispute or a breached NDA when proprietary work ends up in a public model, and no way to show what really happened.
Source code, unreleased work, client data and contracts are likely already going into ChatGPT, Claude, Gemini, Copilot and Grok — sanctioned or not. You can't govern what you can't see.
When a client, partner or board asks “prove you control how AI touches our data”, a PDF policy won't do. You need an immutable record of what actually happened.
Four tools, four export formats, four retention windows — and none of it covers your in-house agents or the unapproved apps nobody told you about. There's no single record.
Three jobs your record does — fed by the three ways AI enters your firm (below). Visibility into every AI surface, real-time control over what leaves your firm, and evidence you can stand behind.
One normalised, searchable record across approved chat tools, in-house agents and the unapproved apps surfaced from logs you already collect. Per person, per department, per tool — including who isn't covered yet.
Route your in-house agents and API tools through the Evaident gateway — a drop-in URL they call instead of the AI vendor. Approved vendors and models, blocking of supported UK PII, common credentials and your own blocked terms (client matter codes, project codenames), out-of-hours rules and an organisation spend cap are enforced before a request ever leaves your firm — and blocked attempts are recorded as evidence.
Every record is sealed to the one before it with a cryptographic signature (HMAC-SHA256), so any tampering is mathematically detectable. One click produces a stamped evidence pack — for a client questionnaire, a board, or a regulator.
The three ways AI enters your firm — each feeding the same unified, tamper-evident record you Know, Govern and Prove above, with every interaction mapped to a person. Import your Microsoft Entra ID or Google Workspace directory and you see not just what AI is used, but who's covered and who isn't.
ChatGPT · Claude · Gemini · Copilot
Connect your approved AI accounts — including Microsoft 365 Copilot — and Evaident pulls each interaction from the vendors' own audit APIs into one tamper-evident record: who, what, when, flagged for review. No agents, no network changes.
Agents · API tools · xAI Grok
Point any in-house agent or API tool — including xAI Grok and any OpenAI-compatible API — at the Evaident gateway, a drop-in URL it calls instead of the vendor. Policy — approved models, supported UK PII, common-credential and blocked-term filtering, an org spend cap — is enforced in real time, breaching requests are blocked before they leave, and exact per-person token usage and cost are captured — streaming or not. Any vendor tier.
DeepSeek · personal accounts · free tools
See which staff use AI tools you never signed off — from the web logs your firewall already collects, forwarded automatically or uploaded. Detection is by destination, so it catches use from a browser, a desktop app or a script. Reads logs you already have; adds no new monitoring.
A closer look
How the in-house route works: your agents and API tools call the Evaident gateway — a drop-in URL they use instead of the vendor’s. Policy is enforced before the request reaches the vendor, and every call is logged — with exact token usage (the units AI is billed in) and per-person cost captured, streaming or not, on any vendor tier.
The programmatic route — for in-house agents and API tools, on any vendor tier. Enterprise chat (ChatGPT, Copilot, Gemini) is captured separately via their audit APIs — no gateway needed.
One line for the board — sanctioned cost and shadow risk, side by side.
Enterprise connectors, gateway, browser extension, automated firewall feed, endpoint agent — answer a few questions and we’ll tailor it.
Four steps from sign-up to a live record. The core setup is account connections and a policy you switch on — no rip-and-replace, no engineering project.
A workspace with realistic demo data in under two minutes. No card, nothing to install.
Pick your AI provider, paste a read-only key, and events start flowing. No code — see the panel.
Tick the boxes — approved vendors, block supported UK PII, credentials and your own terms, a spend cap — and the gateway enforces them in real time for routed tools and agents.
Every interaction lands in one tamper-evident record, ready to search, cost and prove.
Adding a connector — pick a provider, paste a read-only key, done.
In plain terms: connectors and the gateway put nothing on your endpoints — connectors pull from the vendors’ own audit APIs read-only, and the gateway is an OpenAI-compatible base-URL swap (responses stream straight back through it). Shadow-AI discovery reads the firewall / SWG / SIEM logs you already collect. Two optional add-ons exist only if you want their coverage — a managed browser extension (captures web AI on any plan) and a lightweight desktop agent (native apps and off-network use); deploy them if and when you choose.
For your IT team — the full security & architecture overview →
Three ways in, one tamper-evident record, and the outputs that prove it — dashboards, evidence packs and a SIEM-ready feed (for tools like Splunk or Sentinel).
| ChatGPT Enterprise | openai.com | Approved |
| DeepSeek | chat.deepseek.com | Unapproved · elevated |
| Perplexity | perplexity.ai | Unapproved |
| Character.AI | character.ai | Unapproved · elevated |
| Copilot | copilot.microsoft.com | Approved |
Approved spend and unapproved tools, side by side — from the web logs you already collect.
BLOCKED by governance policy (pii_block): POST /v1/chat/completions
Client NI number detected in prompt — request stopped before it reached the vendor. Attempt recorded.
Policy enforced at the gateway — a breaching request is stopped and recorded as evidence.
Per-person and per-department spend, premium-model share and billed actuals.
Creditworthiness scoring Annex III (5)(b) · Art. 26 | High-risk | No evidence |
Client-suitability drafting Annex III · Art. 6(3) | Potential high-risk | Evidence |
Client support chatbot Art. 50 | Limited | Evidence |
Meeting-notes summariser Minimal risk | Minimal | Evidence |
A deterministic, article-referenced EU AI Act posture indicator for each AI system — tied to the evidence you already capture. A governance aid, not legal advice.
A stamped export with an integrity certificate — proof, not a policy PDF.
From shadow-AI discovery to an immutable evidence trail — the full accountability layer.
All vendors, one normalised timeline. Search by person, department, tool or risk flag.
See AI use by person and department — and who isn't covered yet. Import your directory from Microsoft Entra ID or Google Workspace so coverage gaps are real, not guesswork.
Surface unapproved AI from the firewall, proxy, secure web gateway (SWG) or SIEM (Splunk, Sentinel) logs you already collect — merged with approved spend in one view.
A managed browser extension records ChatGPT, Claude and Gemini use — including Free/Plus/Pro and personal accounts — where there's no vendor audit API. Metadata-only by default.
Approved vendors and models, supported UK PII, common-credential and customer-defined blocked-term filtering, an organisation spend cap and out-of-hours rules — enforced at the gateway before data leaves.
Per-person and per-department AI spend, premium-model share and billed actuals from vendor APIs.
Metadata, redacted preview, or scoped full prompt & response for gateway traffic, with content retention configured separately.
Hash-chained, append-only storage with on-demand integrity verification and certificates.
Set retention per evidence depth — and place a legal hold to preserve the whole record for litigation or audit, suspending deletion until you release it.
Stamped, referenced exports — summary PDF, full CSV/JSON data and an integrity certificate.
Pull the evidence log into Splunk, Sentinel or a warehouse over a read-only, cursor-paginated API.
For regulated firms: live mapping to EU AI Act, UK GDPR, FCA Consumer Duty / SYSC 9 and the SRA Code.
Deterministic, article-referenced EU AI Act posture indicators for each AI system — prohibited, high-risk, transparency and GPAI routes, with an EU-scope check — tied to the evidence you already capture. A governance aid, not legal advice.
Sharpest where the stakes are highest — and useful anywhere AI touches sensitive work.
FCA-regulated firms
Evidence how AI assists suitability letters, research and client comms. Map usage to Consumer Duty and SYSC 9, and hand your compliance consultant a clean export at every audit.
Learn more →Law firms
Evidence AI in drafting and research while blocking matter codes, client names and your other defined terms from reaching public models through the gateway — and answer client security questionnaires with proof.
Learn more →IP-sensitive firms
Your highest AI risk is unreleased work, source code or client IP landing in a public model. Evaident gives you an immutable record proving your teams control and monitor AI access.
MSPs & compliance partners
Help clients discover shadow AI, control internal AI tools, and produce AI-posture reports and evidence for client, insurer and regulatory reviews — without building a platform yourself.
Learn more →Built to pass the due-diligence questionnaires your clients actually send.
Your evidence is hosted in the EU (Amsterdam, Netherlands), on a private network — not the public internet.
TLS in transit, AES-256-GCM for stored credentials, API keys held only as hashes.
HMAC-SHA256 hash chain; integrity re-verified on demand and in every export.
Microsoft & Google sign-in, role-based access, every admin action audited.
Metadata by default. Evaident records who used which AI, when and at what cost — not the content of prompts. Prompt text is stored only if you turn on preview or scoped full-content capture.
No. Evaident is an AI accountability platform for regulated and data-sensitive organisations: it answers 'who is using which AI, on what, at what cost — and can you prove it?'. That matters to anyone protecting client IP, NDAs and source code, controlling AI spend, or facing client security questionnaires. If you are FCA/SRA-regulated or in EU AI Act scope, Evaident also maps your record to those obligations out of the box — but that's a feature, not the entry ticket.
No. The enterprise audit APIs are the richest source, but you can build the record on any tier: the Evaident Gateway captures any API-based or in-house AI tool on any plan, a managed browser extension captures ChatGPT/Claude/Gemini web use — including Free/Plus/Pro and personal accounts — and Shadow AI discovery works from network logs you already collect. Whatever tier you're on, you can start today.
Two ways, combined. Import your user directory from Microsoft Entra ID or Google Workspace (active staff only — guests and disabled accounts are excluded), and Evaident also discovers people automatically from the activity it captures. The People view then shows AI use by person and department — and crucially, who isn't covered yet, so coverage gaps are real rather than assumed. The directory connector is independent of any AI connector; you can map your people before you connect a single AI source.
Yes, they're two different populations and Evaident connects them. 'People' are everyone whose AI use you account for (often hundreds); your 'team' are the colleagues who log in to Evaident. Sign-in is via Microsoft or Google SSO with role-based access, and you can invite a colleague straight from the People directory — they accept and sign in with SSO in one step. Every admin action is itself audited.
No agents, no endpoint software. Evaident reads the per-user web logs your existing stack already produces — a firewall (Palo Alto, Fortinet), a secure web gateway or SASE (Zscaler, Netskope, Cisco Umbrella, Cloudflare), or an export from your SIEM (Splunk, Microsoft Sentinel). Any CSV with a user, a destination and a time works: Evaident auto-detects the columns, classifies destinations against an AI-service catalogue, and shows unapproved tools next to your approved spend.
In the EU — currently the Amsterdam (Netherlands) region. The database runs on a private network, connector credentials are encrypted at rest, and gateway/API keys are stored only as hashes. EU hosting is appropriate for UK data under the UK's adequacy decision for the EU. See our security overview for the full model.
A demo workspace with realistic data is live in under two minutes. Connecting a live source is a credentials paste; pointing tools at the gateway is a one-line base-URL change. No agents to install, no network changes.
No — and we're clear about that. Evaident blocks in real time only on gateway-routed traffic: the in-house tools and agents you point at the Evaident Gateway. Vendor audit logs, the browser extension and Shadow AI discovery detect and evidence activity rather than block it. To stop web AI at the network, use your firewall, SWG, SASE or browser controls — with Evaident as the evidence layer that proves what happened.
No. Metadata is the default — who used which AI, when, which model, token counts and risk flags, never the prompt text. Redacted preview and full prompt-and-response capture are optional evidence-depth settings you turn on per source, with PII redaction on by default. Full-content capture is scoped, approval-led and normally reserved for specific high-risk workflows.
Spin up a workspace with realistic demo data now. Connect your live AI accounts whenever you're ready.
Questions first? Write to hello@evaident.com