EVA
ProductWho it is forHow it worksSecurityFAQ

Security and control

eva is designed so business context stays within verified account and project boundaries, privileged operations remain server-side, and meaningful changes stay reviewable.

Effective 17 July 2026

Verified access and project boundaries

Account access uses verified authentication. Business records are scoped to the signed-in account and active project, with database row-level security used to enforce ownership boundaries. Retrieval and agent tools receive verified scope from the application rather than accepting identity or project scope from model input.

Protected records and files

Privileged database credentials stay in server-only code and are not exposed to the browser or model-visible tool inputs. Business files use private storage and controlled access paths. Project documents, memories, customer notes, and extracted asset text are treated as untrusted business data, not hidden instructions.

Reviewable action

Meaningful, destructive, or high-impact operations retain explicit review and approval boundaries. Durable work is saved to visible project records so it can be inspected instead of relying on hidden agent memory.

Service providers and ongoing work

eva relies on specialist infrastructure providers for hosting, database, authentication, storage, and email delivery. Provider certifications and compliance programs do not automatically become certifications of eva. Security controls are reviewed as the product evolves, and no system can promise absolute security.

Report an incident or request deletion

The public security contact address is awaiting operator confirmation. Email .

EVA

Your business context, decisions, and agent-assisted work in one calm operating workspace.

  • Privacy
  • Terms
  • Security

© 2026 EVA CEO. All rights reserved.