Evidarch is not
a certification.
No tool makes you compliant, and a vendor implying otherwise is selling you a risk rather than reducing one. What Evidarch does is produce the record these regimes assume you already keep, in a form that survives somebody doubting it.
| Regime | What it demands | What Evidarch hands over |
|---|---|---|
| EU AI Act | Automatic logging and traceability across the lifetime of an AI system in use, sufficient to reconstruct what it did. | A per-event chained ledger with configurable retention, plus a verifiable head an auditor can re-check. |
| GDPR | Answer subject access requests, erase personal data on request, and evidence a lawful record of processing. | A complete subject packet on demand, and erasure that removes content while the proof of processing survives. |
| ISO/IEC 42001 | Demonstrable operational control over AI use, with evidence that monitoring actually ran. | Policy rules evaluated at ingest, findings and triage recorded per event, collector health as a first-class signal. |
| SOC 2 | Evidence that the controls you described actually operated throughout the observation window. | Continuous collector health, coverage gaps raised as findings, and a signed verification report per period. |
| Sector rules HIPAA, PCI DSS, FCA |
Show that regulated data did not leave its permitted boundary — or account for it when it did. | On-device detection flags regulated shapes at capture, with the finding recorded against an attributable person. |
What you actually hand over.
Signed verification report
Events verified, head hash, external anchor status, and every break if there is one. Timestamped and signed. Available as a document to print, or JSON to re-check.
Subject data packet
Everything held about one person across every collector, as structured JSON. Admin-only, and the export itself is written to the audit trail.
Erasure record
What was removed, when, by whom, and on what stated grounds. The chain still verifies afterwards, which is the part that usually surprises people.
Administrative audit trail
Exports, erasures, policy changes, role changes and revoked credentials. The trail covers the people operating the trail.
Coverage evidence
Which collectors reported, how recently, and where a source went quiet. It turns “we monitored continuously” into a claim with data behind it.
Findings register
Every detection with its severity, category and triage state. You can show what was caught and also what was decided about it.
Deploying this creates duties of its own.
Recording what your staff type is employee monitoring. It is lawful in most places and routine in regulated ones. It is not consequence-free. We would rather you deployed it correctly than quickly.
Notice, and often consent
Most jurisdictions require staff to be told what is monitored and why. Some require their agreement. Works councils in parts of Europe have a formal say before deployment.
Proportionality
Collect what your obligations justify and no more. That is why retention is a policy you set, why attachments have three fidelity levels, and why screen capture stays off until somebody deliberately turns it on.
The record is personal data
A prompt attributed to a named employee is their personal data too. They can ask what you hold about them. The subject packet is built to answer exactly that.
Get sign-off first
Counsel, and your works council where you have one. We can support that conversation with the security model and data boundary in writing. We cannot have it for you.
Bring your auditor's actual question.
The most useful session is with whoever will be asked for this evidence. If the report does not answer their question, better to find that out now.