Evidra
Product

Four modules, one evidence chain

Knowledge goes in once. Every questionnaire after that is drafted from it, reviewed by the people who own the answers and exported in the buyer's own format with the evidence attached.

Module 1

Knowledge library

Upload the documents your team already trusts. Each one carries a category, an owner, an effective date and an optional expiry date, so an answer drafted from an expired policy is visible as such.

  • Categories: Policy, Product, Security, Legal, Past response and Certification.
  • Ingestion status per document: Uploaded, Processing, Indexed or Failed, with the error shown when a file cannot be read.
  • Page counts and chunk counts after indexing, so you can see what the drafting step can reach.
  • A document viewer that opens at the cited page from any evidence passage.
EvidraKnowledge library, 6 documents
DocumentCategoryEffectiveExpiresStatusPages
Information security policy v4.1Security2026-03-012027-03-01Indexed38
Key management standardSecurity2026-01-152027-01-15Indexed9
Data processing addendum, templateLegal2025-11-10NoneIndexed14
Platform architecture overviewProduct2026-06-02NoneProcessing22
RFP response, regional bank, 2026 Q1Past response2026-02-202026-12-31Indexed61
Penetration test summary letterCertification2026-05-302027-05-30Uploaded4

Illustrative sample. Design partner content will replace this with permission.

Module 2

Questionnaire intake

Upload the questionnaire as you received it: Excel, CSV, Word or PDF. Extraction preserves sections, numbering and answer format constraints such as yes or no fields and character limits.

  • Spreadsheet sources keep the sheet, row and answer column, so the export writes back into the right cell.
  • Text sources keep the paragraph position so the export rebuilds the document in order.
  • Every extracted question can be corrected, merged or removed before drafting starts.
EvidraIntake, Security_questionnaire_2026.xlsx, 48 questions
Sheet: Security. Questions in column B, answers to column D.
No.SectionQuestionFormatLimit
4.1Data protectionWhere is customer data stored, and in which regions?Free text800
4.2Data protectionDescribe how customer data is encrypted at rest and in transit, and how keys are managed.Free text1,200
4.3Data protectionIs customer data logically separated from other tenants?Yes or no with detailNone
5.1Access controlDo you enforce multi factor authentication for administrative access?Yes or noNone

Illustrative sample. Design partner content will replace this with permission.

Module 3

Evidence first drafting

Drafting runs as a background job with progress per question. Each question is matched against your passages, the supporting passages are attached, and the answer is written strictly from them.

  1. 01

    Company knowledge

    Past responses, policies, product documentation and compliance records, uploaded once.

  2. 02

    Ingestion

    Each document is read page by page and split into passages that keep their page numbers.

  3. 03

    Retrieval

    Every question is matched against your passages only, never against the open web.

  4. 04

    Evidence

    The passages that support the answer are attached with document name and page.

  5. 05

    Verified response

    A reviewer confirms the answer, an approver signs it off, and the export carries the evidence.

EvidraDrafting job, 31 of 48
Drafting from the knowledge library31 / 48
  • 4.12 sourcesDrafted
  • 4.22 sourcesDrafted
  • 4.31 sourceDrafted
  • 5.1No evidence found
  • 5.2Drafting
  • 5.3Pending

Illustrative sample. Design partner content will replace this with permission.

EvidraSecurity questionnaire, question 4.2, drafted
4.2Data protectionHigh confidence91%Drafted

Describe how customer data is encrypted at rest and in transit, and how encryption keys are managed and rotated.

Format: Free textLimit: 1200 characters
Answer

Customer data is encrypted at rest with AES-256 using platform managed keys, and in transit with TLS 1.2 or higher. Encryption keys are held in a managed key vault with hardware backed protection. Keys are rotated every 12 months, and immediately if a compromise is suspected. Access to key material is restricted to the platform service identity and is logged.

Evidence2 sources
  • Information security policy v4.1page 12relevance 93%
    All customer data stored by the platform is encrypted at rest using AES-256. Data in transit between customers and the platform, and between platform services, is protected with TLS 1.2 or higher.
  • Key management standardpage 3relevance 88%
    Encryption keys are generated and stored in the managed key vault with hardware backed protection. Keys are rotated on a 12 month schedule and immediately upon suspected compromise. Access to key material is limited to the platform service identity and all access is logged.

Illustrative sample. Design partner content will replace this with permission.

Module 4

Verification and export

Contributors, Reviewers and Approvers work on the same questionnaire with comments and an activity trail on every answer. Approved answers join the answer library for the next questionnaire.

EvidraSecurity questionnaire, question 4.2, approved
4.2Data protectionHigh confidence91%Approved

Describe how customer data is encrypted at rest and in transit, and how encryption keys are managed and rotated.

Format: Free textLimit: 1200 characters
Answer

Customer data is encrypted at rest with AES-256 using platform managed keys, and in transit with TLS 1.2 or higher. Encryption keys are held in a managed key vault with hardware backed protection. Keys are rotated every 12 months, and immediately if a compromise is suspected. Access to key material is restricted to the platform service identity and is logged.

Evidence2 sources
  • Information security policy v4.1page 12relevance 93%
    All customer data stored by the platform is encrypted at rest using AES-256. Data in transit between customers and the platform, and between platform services, is protected with TLS 1.2 or higher.
  • Key management standardpage 3relevance 88%
    Encryption keys are generated and stored in the managed key vault with hardware backed protection. Keys are rotated on a 12 month schedule and immediately upon suspected compromise. Access to key material is limited to the platform service identity and all access is logged.
Activity trail
  1. Sep 18, 2026, 9:12 AM UTCDrafting jobdrafted this answer from the knowledge library: 2 sources, high confidence
  2. Sep 18, 2026, 10:03 AM UTCSecurity reviewercommented

Illustrative sample. Design partner content will replace this with permission.

EvidraExport, Security_questionnaire_2026.xlsx
Format
Security_questionnaire_2026.xlsx, answers written to column D of the Security sheet
Questions
48 answered, 46 approved, 2 approved by override
Evidence appendix
Appendix sheet with 71 cited passages, each with document title and page
Activity
Export recorded in the activity trail with the approver's name and time

Illustrative sample. Design partner content will replace this with permission.

Export writes answers back into the original file format, Excel, CSV, Word or PDF, and adds an evidence appendix that lists every cited passage with its document title and page number. The approver's name and the export time are recorded in the activity trail.

Start your response library

Upload the documents your team already trusts. Every answer that follows is drafted from them, cited and reviewed before it leaves.