Trust Center

Trust, documented.

Last updated: June 2026 · EvolvLabs, LLC

Exolvra is built for buyers whose security team reviews every tool before it ships. This page lays out our security posture plainly: how the self-hosted model works, the controls the product provides, the frameworks it aligns to, and exactly what we can and cannot claim today.

The structural control. Exolvra is self-hosted by default. It runs inside your environment, and in the standard deployment your data and the work your agents do never reach us. The hardest question in a vendor review, "our sensitive data sitting in your cloud," does not exist in this model. You can remove external traffic entirely by running on local open models, fully air-gapped.

Where we stand today (plainly)

We would rather be precise than aspirational. As of this writing, Exolvra is not yet certified under SOC 2, ISO 27001, ISO 42001, or HIPAA. What we have instead:

We will pursue formal certification when an enterprise engagement calls for it, scoped honestly to our model.

What the product provides

Encryption at rest & in transit

SQLCipher full-database encryption plus an AES-256-GCM field layer, layered key management (KMS hook, OS keychain, env, or machine-bound keyfile), and TLS in transit.

Secrets stay out of prompts

A named-secrets vault substitutes values at the wire. A {{secret:NAME}} reference never enters a prompt, a log, or the model context.

Tamper-evident audit

A hash-chained audit log of tool calls and state changes, written in the same transaction as the action, so the trail cannot silently diverge from what happened. Exportable to your SIEM.

Least privilege for agents

A capability resolver, per-agent permissions and integration allowlists, RBAC, and a Cloud Mode that locks agents to network and memory only for multi-tenant use.

Human approvals & governance

Approval workflows, spend budgets, rate tracking, and enforced output review: fourteen guardrails re-drive weak work until it passes.

Secure SDLC & supply chain

4,400+ tests, reviewed builds, signed desktop binaries, pinned dependencies, and a deliberate refusal of repository-supplied shell hooks to block code execution from a repo.

Framework alignment

This is alignment, not certification. It shows which Exolvra controls support each framework in your environment.

Aligned
SOC 2

Encryption, audit, RBAC, approvals, logging, and secure SDLC. The operating-environment controls are yours; we provide the product controls.

Aligned
ISO 27001

The same controls mapped to access control, cryptography, operations, supplier, and logging domains.

Aligned
HIPAA Security Rule

Encryption, access, audit, and integrity controls. Self-hosted means we do not receive PHI, so a BAA may not be required.

On thesis
ISO 42001 (AI)

Enforced review, human approval gates, the agent-action audit trail, and least-privilege agents are exactly the AI-governance controls this standard asks for.

Documented
GDPR / CCPA

Marketing-site controls at /privacy. In the product, you are the controller and the data stays with you.

Self-assessed
CSA STAR Level 1

Our controls mapped to the Cloud Controls Matrix (CAIQ). Available as our questionnaire answer bank.

Shared responsibility

Because Exolvra runs on your infrastructure, the responsibility split differs from a normal SaaS:

AreaOwner
The software: security architecture, encryption, audit, access-control primitives, secure SDLCEvolvLabs
EvolvLabs corporate systems: source code, build and release pipeline, this websiteEvolvLabs
Physical / datacenter / host OS / networkYou
Availability, backups, disaster recovery of the deploymentYou
Identity provider, network access to the app, key custody, your dataYou

Need our security package?

We are glad to share our full control mapping (Cloud Controls Matrix / CAIQ), answer your security questionnaire (CAIQ, SIG, or your own), provide an SBOM, or walk your security team through the architecture. Tell us what your review needs.

[email protected]

This page is a summary of our posture, not legal or audit advice. Certification scope is confirmed with a qualified auditor when we pursue it.