What our products hold
EvolvLabs builds and operates its products end to end, and each has its own data footprint:
- DaycareLogix holds enrollment records, attendance, daily care documentation, medication logs, CACFP meal counts, billing, and staff information for childcare centers and adult day programs.
- Exolvra is self-hosted, so customer code, credentials, and agent activity stay on the customer's own infrastructure. Our hosted footprint is limited to licensing and update delivery.
- SteddyZen is still in development. We'll document its data handling here and on its own site before release.
Records entered into our products belong to the subscribing organizations, not to EvolvLabs. We do not sell personal data and we do not run advertising.
Certifications & assessments
We put these assessments where anyone can check them:
- Cloud Security Alliance STAR Registry listings for our products.
- CAIQ self-assessments covering the full control set.
- AI-CAIQ self-assessments for AI-specific controls, including agent behavior and model-provider handling in Exolvra.
Procurement teams and security reviewers can request completed questionnaires or send their own to security@evolvlabs.ai.
How our products are built
All of our products share the same architectural controls:
- Strict tenant isolation. Every record is scoped to its organization; cross-tenant access is structurally impossible, not just prohibited.
- Role-based access. Defined roles with least-privilege defaults; sensitive fields are gated beyond base access.
- Tamper-evident audit logging. Every material action is recorded in an append-only trail, whether a person or an agent did it.
- Server-side enforcement. Rules are enforced where they can't be bypassed: on the server, never only in the interface.
- Guardrails for automation. In Exolvra, fourteen guardrails sit between AI agents and production, with human review on delivery.
- Accessibility. WCAG 2.1 AA is the baseline for product interfaces and for this website.
Framework alignment
Our controls map to the frameworks reviewers care about. Alignment details per product are documented in each product's trust center.
| Framework | How it applies |
|---|---|
| SOC 2 | Control design across security, availability, and confidentiality criteria. |
| ISO 27001 | Information security management practices and risk treatment. |
| HIPAA | Handling of health information in care documentation (DaycareLogix). |
| CACFP | Point-of-service meal count capture and audit-ready records (DaycareLogix). |
| GDPR / CCPA | Data subject rights, retention limits, and no sale of personal data. |
| WCAG 2.1 AA | Accessibility floor for all product and web interfaces. |
Shared responsibility
Security is a partnership, and the boundary is explicit:
- EvolvLabs manages application architecture, tenant isolation, access enforcement, audit integrity, and vulnerability response.
- Customers manage role assignment within their organization, the accuracy of entered data, device security, and, for self-hosted Exolvra, the infrastructure it runs on.
This website
evolvlabs.ai is a static marketing site served over TLS via Cloudflare. It is separate from production systems, holds no customer data, and sets no third-party advertising trackers.
Product trust centers
Each product publishes its own detailed trust documentation:
- The DaycareLogix Trust Center covers CACFP audit readiness and care-record controls.
- The Exolvra Trust Center covers agent guardrails and self-hosting architecture.