Compliance

Evidarch is not
a certification.

No tool makes you compliant, and a vendor implying otherwise is selling you a risk rather than reducing one. What Evidarch does is produce the record these regimes assume you already keep, in a form that survives somebody doubting it.

RegimeWhat it demandsWhat Evidarch hands over
EU AI Act Automatic logging and traceability across the lifetime of an AI system in use, sufficient to reconstruct what it did. A per-event chained ledger with configurable retention, plus a verifiable head an auditor can re-check.
GDPR Answer subject access requests, erase personal data on request, and evidence a lawful record of processing. A complete subject packet on demand, and erasure that removes content while the proof of processing survives.
ISO/IEC 42001 Demonstrable operational control over AI use, with evidence that monitoring actually ran. Policy rules evaluated at ingest, findings and triage recorded per event, collector health as a first-class signal.
SOC 2 Evidence that the controls you described actually operated throughout the observation window. Continuous collector health, coverage gaps raised as findings, and a signed verification report per period.
Sector rules
HIPAA, PCI DSS, FCA
Show that regulated data did not leave its permitted boundary — or account for it when it did. On-device detection flags regulated shapes at capture, with the finding recorded against an attributable person.
The artefacts

What you actually hand over.

Signed verification report

Events verified, head hash, external anchor status, and every break if there is one. Timestamped and signed. Available as a document to print, or JSON to re-check.

Subject data packet

Everything held about one person across every collector, as structured JSON. Admin-only, and the export itself is written to the audit trail.

Erasure record

What was removed, when, by whom, and on what stated grounds. The chain still verifies afterwards, which is the part that usually surprises people.

Administrative audit trail

Exports, erasures, policy changes, role changes and revoked credentials. The trail covers the people operating the trail.

Coverage evidence

Which collectors reported, how recently, and where a source went quiet. It turns “we monitored continuously” into a claim with data behind it.

Findings register

Every detection with its severity, category and triage state. You can show what was caught and also what was decided about it.

Your obligations, not ours

Deploying this creates duties of its own.

Recording what your staff type is employee monitoring. It is lawful in most places and routine in regulated ones. It is not consequence-free. We would rather you deployed it correctly than quickly.

Notice, and often consent

Most jurisdictions require staff to be told what is monitored and why. Some require their agreement. Works councils in parts of Europe have a formal say before deployment.

Proportionality

Collect what your obligations justify and no more. That is why retention is a policy you set, why attachments have three fidelity levels, and why screen capture stays off until somebody deliberately turns it on.

The record is personal data

A prompt attributed to a named employee is their personal data too. They can ask what you hold about them. The subject packet is built to answer exactly that.

Get sign-off first

Counsel, and your works council where you have one. We can support that conversation with the security model and data boundary in writing. We cannot have it for you.

Next

Bring your auditor's actual question.

The most useful session is with whoever will be asked for this evidence. If the report does not answer their question, better to find that out now.