Evidra
Customers and examples

Examples from design partner work

No customer is named on this page and no logo is shown. Names and logos appear only after written agreement. Each example below is a design partner style excerpt rendered by the product itself.

At this stage every example is an illustrative sample built from plain, non customer content, and each is labelled as such under its frame. As design partner projects complete, anonymized excerpts replace the samples one by one, each with the partner's permission on file.
Browse

Open a folder to see the examples

One folder per questionnaire type. Hover or tap to fan the examples out, and open one to read the answer, its evidence and its trail in full.

Security questionnaires

3 examples

Hover or tap

Due diligence questionnaires

2 examples

Hover or tap

Vendor assessments

2 examples

Hover or tap
Example 1

A security questionnaire excerpt

One question from a 48 question security questionnaire: the draft, the two passages it came from with page numbers, the reviewer's comment and the activity trail.

EvidraSecurity questionnaire, question 4.2, design partner style excerpt
4.2Data protectionHigh confidence91%Drafted

Describe how customer data is encrypted at rest and in transit, and how encryption keys are managed and rotated.

Format: Free textLimit: 1200 characters
Answer

Customer data is encrypted at rest with AES-256 using platform managed keys, and in transit with TLS 1.2 or higher. Encryption keys are held in a managed key vault with hardware backed protection. Keys are rotated every 12 months, and immediately if a compromise is suspected. Access to key material is restricted to the platform service identity and is logged.

Evidence2 sources
  • Information security policy v4.1page 12relevance 93%
    All customer data stored by the platform is encrypted at rest using AES-256. Data in transit between customers and the platform, and between platform services, is protected with TLS 1.2 or higher.
  • Key management standardpage 3relevance 88%
    Encryption keys are generated and stored in the managed key vault with hardware backed protection. Keys are rotated on a 12 month schedule and immediately upon suspected compromise. Access to key material is limited to the platform service identity and all access is logged.
Activity trail
  1. Sep 18, 2026, 9:12 AM UTCDrafting jobdrafted this answer from the knowledge library: 2 sources, high confidence
  2. Sep 18, 2026, 10:03 AM UTCSecurity reviewercommented

Illustrative sample. Design partner content will replace this with permission.

Example 2

A DDQ section

Due diligence questionnaires arrive as Word documents with long narrative questions. Extraction keeps the paragraph position, so the export rebuilds the document in order with the answers in place.

This governance question was answered from two documents: the information security policy and the risk committee charter. The approver signed it off, and the answer joined the answer library so the next DDQ reuses it first.

EvidraDue diligence questionnaire, section B.3, approved
B.3GovernanceHigh confidence89%Approved

Describe the organization's information security governance, including the accountable executive, how policies are approved and how often they are reviewed.

Format: Free textLimit: 1500 characters
Answer

The Chief Technology Officer is accountable for information security and reports to the board risk committee each quarter. Security policies are approved by the risk committee and reviewed at least annually, and again after any material change to the platform or to applicable regulation. Each policy names an owner who is responsible for keeping it current.

Evidence2 sources
  • Information security policy v4.1page 2relevance 92%
    The Chief Technology Officer is accountable for information security across the organization and reports on the security program to the board risk committee each quarter. Every policy in this framework names an owner responsible for keeping it current.
  • Risk committee charterpage 1relevance 85%
    The committee approves information security policies and reviews them at least annually, and additionally following any material change to the platform or to applicable regulation.

Illustrative sample. Design partner content will replace this with permission.

Example 3

A vendor assessment, answered from the library

The subprocessor question appears in almost every assessment. Once it is approved, the answer library supplies it first, with its evidence still attached.

And when the library has nothing, the platform says so. The business continuity question on the right was marked No evidence found with a note about which document would answer it, instead of a guess.

EvidraVendor assessment, question 12, reused from the answer library
12Sub-processorsHigh confidence94%Drafted

List the third parties that process customer data on your behalf, the purpose of each, and the region in which processing takes place.

Format: Free textReused from the answer library
Answer

Two third parties process customer data on our behalf. Google Cloud provides authentication, the application database and file storage in the European Union multi region. Vercel provides web hosting, serverless compute and the edge network globally. Changes to this list are published on the security page before they take effect.

Evidence1 source
  • Subprocessor list, September 2026page 1relevance 96%
    Google Cloud: authentication, application database, file storage. Region: European Union multi region. Vercel: web hosting, serverless compute and edge network. Region: global. Changes are published on the security page before they take effect.

Illustrative sample. Design partner content will replace this with permission.

EvidraVendor assessment, question 7.4
7.4Business continuityNo evidenceNo evidence found

Provide the recovery time objective and recovery point objective for the service, and the date of the last full disaster recovery test.

Format: Free text
Answer

No evidence found in your knowledge library.

Nothing was drafted, because no source document supports an answer. A business continuity or disaster recovery plan with stated RTO and RPO values, and the report from the most recent DR test, would answer this question.

No evidence attached.

Illustrative sample. Design partner content will replace this with permission.

Design partnership

What a design partnership looks like

Two or three partners who answer questionnaires every month, working with the founder on real documents under NDA.

What you bring

  • Ten or more real documents: past responses, policies, product documentation, compliance records.
  • One real questionnaire you have to answer anyway.
  • An NDA, signed before anything is uploaded.

What we do

  • Index the documents and draft every question with its evidence.
  • Review the result with you, question by question, and fix what breaks.
  • Export the completed questionnaire in the format it arrived in.

What you get

  • Your questionnaires answered first, with the founder in the loop.
  • Your feedback sets the roadmap.
  • A place on this page only if you agree to it in writing, anonymized or named as you prefer.

Become a design partner

Bring one questionnaire you have to answer anyway. We will answer it with you, with evidence on every line, and you will see exactly where the library is thin.