Security

You bring your hardest questions to EVA. Here is how we make sure they stay yours.

Your chats are never training data

We do not use your conversations to train models, and we contractually rely on providers' no-training API terms.

Prompts never reach our logs

Message content is excluded from application logs and error reports by design — enforced in code, not by policy alone.

Sessions that can't be stolen from the page

Sign-in uses httpOnly cookies invisible to JavaScript, so a compromised script can't exfiltrate your session.

Delete means delete

Account deletion permanently removes your data and leaves only an anonymized proof-of-deletion record (GDPR/KVKK).

Least-privilege infrastructure

Databases are closed to the public internet path, secrets live in a managed vault, and every credential is scoped and rotated.

Auditable money

Credits live in an append-only ledger that physically cannot be edited — every charge is traceable, double-charging is impossible.

Found a vulnerability? Email security@evaonline.ai — we respond fast and appreciate responsible disclosure.

We use analytics cookies to understand how EVA is used and improve it. No chat content is ever collected.