Enterprise
Runs where your data already is
The question that decides an enterprise purchase is rarely about features. It is about where the software runs, who it lets in, and what it writes down.
Where this is today
- AvailableSelf-hosted deployment. Containers and a volume, with a licence verified offline, so it runs with no route to the internet.
- AvailableHosted. The same product and the same defaults, run by us.
- AvailableSingle sign-on through OIDC. It is what the product runs on, and the role model below is the one being enforced rather than a description of one.
- AvailableThe audit trail. Every analysis, decision, export, policy change and administrative action, with actor, time and origin.
- PlannedWorkspaces — several isolated customers on one deployment. Today a deployment is the boundary: one customer per installation. Every request is already answered inside a tenant and every project belongs to one, but that is internal scoping rather than a way to host several isolated customers on one deployment. Workspaces are specified and are the next piece of the admin work.
- PlannedSAML. The identity provider underneath speaks SAML, and that is not the same statement: EVIDENT has not validated an end-to-end SAML integration and does not claim one. Treated as a requirement to be met when a customer needs it, rather than claimed on a checklist. SCIM is in the same position.
- PlannedRetention and deletion controls. Alongside the assurance material available through due diligence: current subprocessor information on request and the hosted data-flow description while it remains in Preview. The public threat model is still Planned.
- PlannedA local agent, for sources the platform cannot reach. For a source the platform cannot reach from where it runs. Specified in advance, deliberately: it is a design decision worth arguing with before it is code. An air-gapped installation does not need it — that deployment sits inside the network with everything it reads.
Available is in the product today. Preview is built and reachable, and still changing shape. Planned is specified and not built — published in advance so it can be judged before it exists.
What a security review can read
Everything a reviewer needs to evaluate this, and where each of it is, is on trust: what is published, what is provided during security and commercial due diligence, a matrix of who operates which control on a hosted deployment and on your own, and how to report a vulnerability. It is a map rather than more reading.
Deployment
- Self-hosted
- Containers and a volume, on your infrastructure. The licence is a signed code verified offline against a public key, so it works with no route to the internet.
- Hosted
- Run by us, with the same product and the same defaults.
- Local agent
- For networks that will not open a route outward: the agent reads inside your network and sends normalised evidence out, so records never cross the boundary. Specified and planned; not shipped yet.
Identity and access
Single sign-on through OIDC, which is how most enterprises will connect it, with SAML and SCIM treated as requirements to be met when a customer actually needs them rather than as a checklist to claim.
Access is decided by role. A role names a set of permissions, a permission is an operation on a kind of thing, and the token a request carries may narrow that set and can never widen it. The role that administers the platform — people, licences, extensions — is distinct from the one that administers a project, so somebody who runs assessments is not also somebody who can issue licences.
What is written down
- Every analysis, review decision, export, policy change and administrative action, with the actor, the time and the origin of the request.
- Every human decision, immutably: a later decision supersedes an earlier one and both stay readable.
- Every report, naming the analysis run and the build that produced it, so a document can always be traced to the state of the system it describes.
- Never a connection secret, in any log, at any level.
Retention and deletion
Analysis history is the product’s value and also a liability if it is kept forever without a decision. Retention and deletion controls are part of the enterprise work, alongside tenant isolation. Security and procurement material is provided according to its current capability status. Some artefacts are available on request; others remain explicitly Planned.
We would rather write those documents than assert them. Ask, and we will tell you which exist today.