Platform
How EvidentraIQ works
EvidentraIQ is a Digital Trust Control Tower for small and medium businesses. It is a management intelligence layer: it shows where you stand, what you can prove, what to fix next and whether the fix held — in one system. It does not certify legal compliance and does not claim to eliminate cyber risk.
What is a Digital Trust Twin?
A Digital Trust Twin is EvidentraIQ's structured model of one organisation's trust posture: its answers to 26 fixed questions across six domains, the evidence records behind its claims, its findings and actions, and the history of every assessment. It lets management see the whole picture in one place instead of across spreadsheets and email threads.
Three scores, kept separate
Readiness
How well controls are in place, from your answers. 0–100, higher is better.
Evidence Confidence
How well claimed controls are backed by evidence records. Answers never count as proof; no records means "unknown".
Exposure
Impact-weighted gaps. 0–100, higher means more exposure.
Six trust domains
AI Governance
Which AI tools are used, who approved them, and whether a human reviews AI-assisted decisions.
Typical evidence: AI use inventory, approval records, staff guidance on AI use.
Law: Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures to support sufficient AI literacy of their staff and others operating AI systems on their behalf. Whether and how it applies to your organisation depends on your use of AI; EvidentraIQ does not determine applicability.
EvidentraIQ interpretation: the AI governance questions help you see whether AI use is inventoried, approved and reviewed. Other AI Act provisions are not yet verified in our registry and are not covered here. EUR-Lex text · Source Registry
Cyber Readiness
Basic security hygiene and incident preparedness: backups, patching, incident response and recovery.
Typical evidence: Backup test records, incident response plan, patching policy.
Access & Identity
Who can access what: multi-factor authentication, joiner/leaver handling and privileged access.
Typical evidence: MFA configuration export, access review records, offboarding checklist.
Third-Party Risk
Exposure through suppliers and vendors: critical supplier inventory, contracts and data processing agreements.
Typical evidence: Supplier register, signed data processing agreements, supplier review notes.
Data & Privacy
What data is held, where, for how long and who is accountable for it.
Typical evidence: Record of processing, retention schedule, data owner list.
Policies & Evidence
Whether key policies exist, are approved, owned and kept current — and whether evidence is maintained.
Typical evidence: Approved policies with owner and review date, evidence register.
From finding to action
Every gap becomes a finding with problem, business impact, priority, owner, recommended action, evidence required, deadline and retest. Actions move through a controlled lifecycle:
- Open — identified, not started.
- In progress — someone is working on it.
- Ready for retest — the team believes it is fixed.
- Closed — only through a passing reassessment retest, never a click.
Reassessment: proving the fix held
A point-in-time assessment goes stale. A reassessment is a new assessment linked to the previous one — earlier answers and scores are never rewritten. An action closes only when the control is now answered "yes" and verified evidence for it was checked within the last 365 days. Previous and current scores are shown side by side.
Available in signed-in workspacesValue and ROI, without manufactured numbers
Workspaces can estimate value from their own inputs. The default Conservative scenario excludes hypothetical cyber-loss avoidance and shows "Insufficient data" instead of inventing a figure.
See where your business stands
About 20 minutes, no account needed. Answers stay in your browser.