Evose
Security

Compliance

MLPS · GDPR · ISO 27001 · industry compliance

Evose actively supports the following compliance frameworks.

Framework Support Matrix

FrameworkStatusPrivate bonus
MLPS Level 2
MLPS Level 3Data localization + physical isolation
GDPRData center can be specified
ISO 27001
SOC 2 Type II Roadmap
HIPAAPath-ready (Private + setup)Private only
PCI DSSPath-ready (Private + setup)Private only

MLPS (Multi-Level Protection Scheme)

For mainland China deployments.

Level 2

ControlEvose meets it
Identity authenticationSSO + strong password + lockout
Access controlRBAC + ACL
Security auditFull operation audit + tamper-proof
Data integrityEncrypted transport · checksums
Data confidentialityTLS · DB encryption

Level 3

In addition to Level 2:

ControlMeasure
Intrusion preventionWAF · IDS / IPS
Malicious codeFile-upload scanning
Centralized controlSIEM integration · alerting
Data backupCross-region DR + RPO/RTO drills

GDPR

6 Key Compliance Areas

RequirementEvose implementation
LawfulnessDPA (Data Processing Agreement) template provided
Data minimizationOnly essential business fields are collected
Purpose limitationDefined uses; no secondary processing
Data subject rightsAccess / rectification / erasure / portability / restriction
Data securityEncryption + access control + audit
Data localizationPrivate deployment can specify the data center

Cross-Border Transfer

Cross-border only when using a SaaS LLM. Recommended approaches:

  • Pick vendors with EU nodes (Azure EU / Anthropic EU)
  • Self-hosted models (no egress at all)
  • Configure SCCs (Standard Contractual Clauses)

ISO 27001

Control family mapping (partial):

FamilyEvose implementation
A.5 Security policySecurity policy + desktop policy
A.8 Asset managementResource inventory + classification
A.9 Access controlRBAC + ACL + resource policy
A.10 CryptographyTLS + AES-256 + field-level encryption
A.12 Operations securityChange management + backup + monitoring
A.13 Communications securityTLS · network segmentation
A.16 Incident managementAudit + vulnerability response SLA

HIPAA (U.S. Healthcare)

Under Private:

  • Data physically isolated (own GPU running Embedding / LLM)
  • Full audit (who looked at which PHI)
  • Encrypted transport + at-rest encryption
  • BAA (Business Associate Agreement) template

PCI DSS

Evose does not directly process card payments (SaaS billing is handled by professional gateways). If your business involves card data, strongly recommend:

  • Don't put card data in Agents / Workflows / knowledge bases
  • Use a tool to call a licensed gateway (Stripe / UnionPay) so the gateway tokenizes before data enters Evose

Data Processing Agreement (DPA)

In SaaS mode, Evose is the Processor; you are the Controller. Provided:

  • DPA template (signable)
  • Sub-processor list (model vendors, CDN, monitoring)
  • Cross-border SCCs (EU customers)

Third-Party Audit

  • Penetration testing report (annual)
  • ISO 27001 certificate (estimated 2026 Q3)
  • SOC 2 report (roadmap)

Next Steps

On this page