Security & governance

Stated plainly: what Evalo does today, and what comes next

Evalo is an early-stage platform. We describe the controls that exist today and label everything else as roadmap. We do not claim certifications we do not hold.

In place today

Authenticated access only

Every procurement project, quotation and report sits behind an authenticated account. Nothing in the application is publicly readable.

Multi-tenant isolation

Data is scoped to an organisation. Records carry their organisation, and access is enforced in the database rather than only in the interface.

Row-level access control

Database row-level security policies govern who can read or change each record, so a user cannot reach another organisation's data.

Role-based permissions

Organisation roles separate administrators, approvers and contributors, with approval limits configurable per organisation.

Auditable decision trail

Requirements, quotations, extractions, scores, recommendations and approvals are recorded so a decision can be reconstructed after the fact.

Deterministic evaluation

Compliance and ranking are computed by rules from stored data. A model cannot override a mandatory requirement or silently change an outcome.

Roadmap — not yet available

Planned governance controls

The following are planned capabilities. They are not implemented today and should not be relied on in a procurement or vendor assessment.

  • Single sign-on (SSO) and SCIM provisioning
  • Customer-configurable data residency
  • Formal third-party security assessment and independent certification
  • Configurable data retention and deletion schedules
  • Exportable, tamper-evident audit logs
  • Fine-grained departmental permission policies

Have a security questionnaire?

Send it through and we will answer it honestly, including the gaps.

Contact us