Technical & Trust FAQ
Trust questions, answered plainly
Where something is not built or not verified yet, this page says so explicitly rather than implying capability.
Read the scoring and evidence methodology →What EvidentraIQ is
What is EvidentraIQ?
ImplementedEvidentraIQ is a Digital Trust Control Tower for small and medium businesses. It brings readiness, evidence confidence, exposure, remediation actions and reassessment into one management system across six domains: AI governance, cyber readiness, access and identity, third parties, data and privacy, and policies and evidence.
How the platform works →What is Digital Trust Readiness?
ImplementedDigital Trust Readiness is how well an organisation's governance, security, supplier, data and AI practices are in place, based on answers to a fixed set of 26 questions. EvidentraIQ expresses it as a Readiness Score from 0 to 100. It describes internal posture, not legal status.
How is EvidentraIQ different from a cyber assessment?
ImplementedA cyber assessment usually tests technical security at one point in time. EvidentraIQ covers six trust domains, separates what you claim (Readiness) from what you can prove (Evidence Confidence), turns gaps into owned actions and closes them only through reassessment. It does not scan systems and does not replace penetration testing.
Does EvidentraIQ certify compliance?
ImplementedNo. EvidentraIQ does not certify compliance with any law or standard and does not give legal advice. No score is a legal conclusion. Legal decisions remain with you and your advisers.
How the scores work
How are scores calculated?
ImplementedScoring is deterministic: each question has a fixed weight inside its domain and each domain a fixed weight overall. 'Yes' counts fully, 'partly' half, 'no' and 'don't know' zero. The same answers always give the same scores. No AI is involved in calculating any number.
Scoring and evidence methodology →What is Evidence Confidence?
ImplementedEvidence Confidence (0–100) measures how well claimed controls are backed by evidence records — presence, source authority, verification status, freshness and confidence — under a versioned methodology. Answers never count as proof. With no evidence records the score is shown as unknown, not as zero.
What does the Exposure Score mean?
ImplementedExposure (0–100) is the only inverted metric: higher means more exposure. It weights each missing or unconfirmed control by the business impact it could enable. It is a prioritisation aid, not a prediction of incidents or losses.
Evidence, actions and reassessment
What evidence is required?
ImplementedAn evidence record needs the item, its source type, a reference, a checked date and a confidence level. Members can add records as unverified; only a reviewer, admin or owner can mark them verified or rejected. Files are not uploaded in this version — records hold references and metadata.
What happens after an assessment?
ImplementedEach gap becomes a finding with problem, business impact, priority, owner, recommended action, evidence required, deadline and retest. Actions move Open → In progress → Ready for retest. Nobody can close an action with a click.
How does reassessment work?
ImplementedA reassessment is a new assessment linked to the previous one; earlier answers and scores are never changed. On submission, an action ready for retest closes only if the question is now answered 'yes' and verified evidence for that control was checked within the last 365 days.
Do you store our documents?
PlannedNot yet. The current version records evidence references and metadata only. File storage has not been built or security-reviewed.
Value, pricing and data
How is ROI estimated?
ImplementedFrom your own inputs (hours, costs, review volumes), each labelled with its source. The default Conservative scenario uses only customer-provided or observed values, excludes hypothetical cyber-loss avoidance and shows 'Insufficient data' rather than inventing a number. Estimates are never presented as realised value.
ROI methodology →What is included in Essential, Professional and Ultimate?
ImplementedEssential: the guided assessment, three scores with rationale and top findings. Professional adds the Digital Trust Twin, evidence review, a supplier exposure summary and a 30/60/90-day action plan. Ultimate adds onboarding, reassessments, evidence maintenance and management reporting on a monthly subscription.
Prices and package details →Where is our data stored and who can see it?
ImplementedThe public assessment stays in your browser. Signed-in workspaces are stored server-side; every record belongs to one organisation and database policies restrict access to that organisation's members. History and audit entries cannot be edited by users.
Do you make regulatory statements?
ImplementedOnly when a statement is linked to a verified source in our registry and stays within its verified scope. For the EU AI Act, only Article 4 (AI literacy) and the Commission's Article 50 transparency guidance are verified today.
Source Registry →Is payment live?
ImplementedNo. Prices are published, but no payment provider is connected and no card can be charged.