Security & access
Read-only. Revocable. Recorded.
An assurance firm should be held to the same standard it tests against. Here is how Eviqly handles access to your systems and the evidence it gathers.
Authenticate once, read-only
Integrations use read-only credentials scoped to the data needed for the engagement. Eviqly never writes to your systems, and you can revoke access at any moment from your own admin console.
No integration required
If you prefer not to connect systems, you can upload documents or answer questions directly. The same source-tracking applies to every uploaded file.
Immutable audit trail
Every draft, confirmation, and review action is written to an append-only record: who did it, what evidence they used, and when. The deliverable carries that trail with it.
Six-year retention
Signed reports and completion certificates are retained for six years so you can produce them on demand for regulators, partners, or examiners.
SOC 2 Type I
Enterprise-grade trust, independently examined.
Eviqly aligns with SOC 2 Type I security expectations, supporting the due-diligence requirements of banks and their fintech partners. A copy of the report is available under NDA on request.
Controls at a glance
- Encryption in transit and at rest
- Least-privilege, role-based access for Eviqly staff
- Segregated client environments
- Logged access to client evidence
- Documented incident response and vendor review
Have a security questionnaire?
Send it over. We answer with sources attached — the same way we answer everything else.