Platform

How EvidentraIQ works

EvidentraIQ is a Digital Trust Control Tower for small and medium businesses. It is a management intelligence layer: it shows where you stand, what you can prove, what to fix next and whether the fix held — in one system. It does not certify legal compliance and does not claim to eliminate cyber risk.

What is a Digital Trust Twin?

A Digital Trust Twin is EvidentraIQ's structured model of one organisation's trust posture: its answers to 26 fixed questions across six domains, the evidence records behind its claims, its findings and actions, and the history of every assessment. It lets management see the whole picture in one place instead of across spreadsheets and email threads.

Three scores, kept separate

Readiness

How well controls are in place, from your answers. 0–100, higher is better.

Evidence Confidence

How well claimed controls are backed by evidence records. Answers never count as proof; no records means "unknown".

Exposure

Impact-weighted gaps. 0–100, higher means more exposure.

How each score is calculated (versioned methodology)

Six trust domains

AI Governance

Which AI tools are used, who approved them, and whether a human reviews AI-assisted decisions.

Typical evidence: AI use inventory, approval records, staff guidance on AI use.

LAWLaw/RegulationChecked 2026-10-01

Law: Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures to support sufficient AI literacy of their staff and others operating AI systems on their behalf. Whether and how it applies to your organisation depends on your use of AI; EvidentraIQ does not determine applicability.

EvidentraIQ interpretation: the AI governance questions help you see whether AI use is inventoried, approved and reviewed. Other AI Act provisions are not yet verified in our registry and are not covered here. EUR-Lex text · Source Registry

Cyber Readiness

Basic security hygiene and incident preparedness: backups, patching, incident response and recovery.

Typical evidence: Backup test records, incident response plan, patching policy.

Access & Identity

Who can access what: multi-factor authentication, joiner/leaver handling and privileged access.

Typical evidence: MFA configuration export, access review records, offboarding checklist.

Third-Party Risk

Exposure through suppliers and vendors: critical supplier inventory, contracts and data processing agreements.

Typical evidence: Supplier register, signed data processing agreements, supplier review notes.

Data & Privacy

What data is held, where, for how long and who is accountable for it.

Typical evidence: Record of processing, retention schedule, data owner list.

Policies & Evidence

Whether key policies exist, are approved, owned and kept current — and whether evidence is maintained.

Typical evidence: Approved policies with owner and review date, evidence register.

From finding to action

Every gap becomes a finding with problem, business impact, priority, owner, recommended action, evidence required, deadline and retest. Actions move through a controlled lifecycle:

  1. Open — identified, not started.
  2. In progress — someone is working on it.
  3. Ready for retest — the team believes it is fixed.
  4. Closed — only through a passing reassessment retest, never a click.

Reassessment: proving the fix held

A point-in-time assessment goes stale. A reassessment is a new assessment linked to the previous one — earlier answers and scores are never rewritten. An action closes only when the control is now answered "yes" and verified evidence for it was checked within the last 365 days. Previous and current scores are shown side by side.

Available in signed-in workspaces

Value and ROI, without manufactured numbers

Workspaces can estimate value from their own inputs. The default Conservative scenario excludes hypothetical cyber-loss avoidance and shows "Insufficient data" instead of inventing a figure.

Read the ROI methodology

See where your business stands

About 20 minutes, no account needed. Answers stay in your browser.