Technical & Trust FAQ

Trust questions, answered plainly

Where something is not built or not verified yet, this page says so explicitly rather than implying capability.

Read the scoring and evidence methodology →

What EvidentraIQ is

What is EvidentraIQ?

Implemented

EvidentraIQ is a Digital Trust Control Tower for small and medium businesses. It brings readiness, evidence confidence, exposure, remediation actions and reassessment into one management system across six domains: AI governance, cyber readiness, access and identity, third parties, data and privacy, and policies and evidence.

How the platform works →

What is Digital Trust Readiness?

Implemented

Digital Trust Readiness is how well an organisation's governance, security, supplier, data and AI practices are in place, based on answers to a fixed set of 26 questions. EvidentraIQ expresses it as a Readiness Score from 0 to 100. It describes internal posture, not legal status.

How is EvidentraIQ different from a cyber assessment?

Implemented

A cyber assessment usually tests technical security at one point in time. EvidentraIQ covers six trust domains, separates what you claim (Readiness) from what you can prove (Evidence Confidence), turns gaps into owned actions and closes them only through reassessment. It does not scan systems and does not replace penetration testing.

Does EvidentraIQ certify compliance?

Implemented

No. EvidentraIQ does not certify compliance with any law or standard and does not give legal advice. No score is a legal conclusion. Legal decisions remain with you and your advisers.

How the scores work

How are scores calculated?

Implemented

Scoring is deterministic: each question has a fixed weight inside its domain and each domain a fixed weight overall. 'Yes' counts fully, 'partly' half, 'no' and 'don't know' zero. The same answers always give the same scores. No AI is involved in calculating any number.

Scoring and evidence methodology →

What is Evidence Confidence?

Implemented

Evidence Confidence (0–100) measures how well claimed controls are backed by evidence records — presence, source authority, verification status, freshness and confidence — under a versioned methodology. Answers never count as proof. With no evidence records the score is shown as unknown, not as zero.

What does the Exposure Score mean?

Implemented

Exposure (0–100) is the only inverted metric: higher means more exposure. It weights each missing or unconfirmed control by the business impact it could enable. It is a prioritisation aid, not a prediction of incidents or losses.

Evidence, actions and reassessment

What evidence is required?

Implemented

An evidence record needs the item, its source type, a reference, a checked date and a confidence level. Members can add records as unverified; only a reviewer, admin or owner can mark them verified or rejected. Files are not uploaded in this version — records hold references and metadata.

What happens after an assessment?

Implemented

Each gap becomes a finding with problem, business impact, priority, owner, recommended action, evidence required, deadline and retest. Actions move Open → In progress → Ready for retest. Nobody can close an action with a click.

How does reassessment work?

Implemented

A reassessment is a new assessment linked to the previous one; earlier answers and scores are never changed. On submission, an action ready for retest closes only if the question is now answered 'yes' and verified evidence for that control was checked within the last 365 days.

Do you store our documents?

Planned

Not yet. The current version records evidence references and metadata only. File storage has not been built or security-reviewed.

Value, pricing and data

How is ROI estimated?

Implemented

From your own inputs (hours, costs, review volumes), each labelled with its source. The default Conservative scenario uses only customer-provided or observed values, excludes hypothetical cyber-loss avoidance and shows 'Insufficient data' rather than inventing a number. Estimates are never presented as realised value.

ROI methodology →

What is included in Essential, Professional and Ultimate?

Implemented

Essential: the guided assessment, three scores with rationale and top findings. Professional adds the Digital Trust Twin, evidence review, a supplier exposure summary and a 30/60/90-day action plan. Ultimate adds onboarding, reassessments, evidence maintenance and management reporting on a monthly subscription.

Prices and package details →

Where is our data stored and who can see it?

Implemented

The public assessment stays in your browser. Signed-in workspaces are stored server-side; every record belongs to one organisation and database policies restrict access to that organisation's members. History and audit entries cannot be edited by users.

Do you make regulatory statements?

Implemented

Only when a statement is linked to a verified source in our registry and stays within its verified scope. For the EU AI Act, only Article 4 (AI literacy) and the Commission's Article 50 transparency guidance are verified today.

Source Registry →

Is payment live?

Implemented

No. Prices are published, but no payment provider is connected and no card can be charged.