Security & Compliance

Trust Center

Security, compliance, and data protection. Learn how EvalGuard safeguards your AI evaluation data and meets enterprise security requirements.

Performance & reliability

Numbers are published, not claimed. Each link lands on a page with reproducible methodology.

AI-specific security

Purpose-built security features for AI/LLM applications — not retrofitted from traditional AppSec.

Shadow AI Detection

Detect unauthorized AI usage across your org. Monitor which models employees use, flag PII in outbound prompts, and block unapproved providers in real-time.

AI Security Posture Management (AI-SPM)

Discover all AI models deployed, map data flows, detect misconfigurations, and get a unified posture score with actionable recommendations.

Smart AI Copilot

Auto-analyze scan results, prioritize findings by risk, suggest step-by-step fixes with code examples, and map GDPR/HIPAA/OWASP compliance impact.

249 Red Team Attack Plugins

Automated adversarial testing with prompt injection, jailbreak, PII extraction, data exfiltration, and 43 attack strategies — mapped to OWASP LLM Top 10.

5-Layer LLM Firewall

Real-time input/output scanning with PII redaction, injection detection, toxicity filtering, topic restriction, and content moderation.

AI Gateway with SSRF Protection

Route LLM traffic through a secure proxy with DNS rebinding protection, rate limiting, cost tracking, and automatic trace logging.

Compliance frameworks

EvalGuard is built to meet the most rigorous AI security and compliance standards.

OWASP LLM Top 10

Full coverage of all 10 LLM-specific vulnerability categories

NIST AI RMF

Aligned with the NIST AI Risk Management Framework

MITRE ATLAS

Adversarial threat landscape coverage for AI systems

EU AI Act

Aligned with EU AI Act risk assessment requirements

ISO 42001

AI management system standard alignment

India DPDP

Aligned with India's Digital Personal Data Protection Act, 2023

HIPAA

Health Insurance Portability and Accountability Act compliance for healthcare AI

Security features

Enterprise-grade security built into every layer of the platform.

AES-256-GCM encryption

All data encrypted at rest and in transit. Bring Your Own Key (BYOK) supported for enterprise customers.

Zero plaintext storage

Prompts, responses, and evaluation data are never stored in plaintext. All sensitive fields are encrypted before persistence.

Role-based access control

Granular RBAC with predefined roles (Admin, Editor, Viewer) and custom role support for enterprise plans.

Audit logging

Comprehensive audit trail for all user actions, API calls, and configuration changes with tamper-proof storage.

Infrastructure

Flexible deployment options to meet your organization's requirements.

Self-hosted option

Deploy EvalGuard in your own infrastructure with our Helm charts and Docker images. Full air-gapped support.

Data residency

Configurable data residency with region-specific storage. Choose from US, EU, or APAC regions.

End-to-end encryption

All communication between components is encrypted using TLS 1.3. Internal service mesh uses mTLS.

Certifications roadmap

We are actively pursuing industry-standard certifications.

SOC 2 Type II
Planned Q3 2026
HIPAA
Planned Q4 2026
ISO 27001
Planned 2027

Questions about security?

Our security team is available to discuss your requirements, provide compliance documentation, or schedule a security review.

security@evalguard.ai

Trust Center | EvalGuard | EvalGuard™