Security & access

Read-only. Revocable. Recorded.

An assurance firm should be held to the same standard it tests against. Here is how Eviqly handles access to your systems and the evidence it gathers.

Access

Authenticate once, read-only

Integrations use read-only credentials scoped to the data needed for the engagement. Eviqly never writes to your systems, and you can revoke access at any moment from your own admin console.

Alternative

No integration required

If you prefer not to connect systems, you can upload documents or answer questions directly. The same source-tracking applies to every uploaded file.

Trail

Immutable audit trail

Every draft, confirmation, and review action is written to an append-only record: who did it, what evidence they used, and when. The deliverable carries that trail with it.

Retention

Six-year retention

Signed reports and completion certificates are retained for six years so you can produce them on demand for regulators, partners, or examiners.

SOC 2 Type I

Enterprise-grade trust, independently examined.

Eviqly aligns with SOC 2 Type I security expectations, supporting the due-diligence requirements of banks and their fintech partners. A copy of the report is available under NDA on request.

Controls at a glance

  • Encryption in transit and at rest
  • Least-privilege, role-based access for Eviqly staff
  • Segregated client environments
  • Logged access to client evidence
  • Documented incident response and vendor review

Have a security questionnaire?

Send it over. We answer with sources attached — the same way we answer everything else.

Contact security