Evertune enterprise security, SSO, privacy and procurement
A public-evidence review of Evertune Enterprise SSO, identity uncertainty, privacy and AI Retargeting terms, backups, SOC 2 and DPA visibility, audit logs, roles, and data residency.
Quick answer
Does Evertune meet enterprise identity, security, privacy, legal, and procurement requirements?
Evertune publishes Enterprise SSO and an August 2026 privacy policy that covers its customer platform and AI Retargeting data. Public evidence is thinner for the rest of procurement: no SSO protocol, product roles, customer audit logs, selectable data residency, Evertune SOC 2 claim, public trust center, or DPA is currently documented. Its 2024 terms mention routine backups but put responsibility for transmitted data on the customer. Treat Evertune as security-review required, not security-review failed.
Key facts and evidence
- Single sign-on
- Listed on custom Enterprise; protocol and provisioning are not publicEvidence: Evertune pricing and plans, Evertune Help CenterNot publicly verified. The plan page names SSO integration without protocol, provisioning, or identity-provider details.
- SOC 2 and ISO
- No Evertune certification claim or public trust center was foundEvidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy Policy, Evertune Terms of ServiceNot publicly verified. Absence from public pages is not evidence that private assurance documents or negotiated agreements are unavailable.
- Roles and audit logs
- Product roles, RBAC, and customer audit-log behavior are not publicly documentedEvidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy PolicyNot publicly verified. These controls may exist or be contract-specific, but they are not described in the current public product and legal material.
- Data residency
- No customer-selectable hosting region is publicly documentedEvidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy PolicyNot publicly verified. These controls may exist or be contract-specific, but they are not described in the current public product and legal material.
- Privacy policy
- Updated 10 August 2026 and expressly covers the customer platform and AI RetargetingEvidence: Evertune Privacy Policy
- Backups
- Routine backups are stated; schedule, retention, recovery objectives, and liability protection are not promisedEvidence: Evertune Terms of Service
Evertune enterprise procurement checklist
| Control area | Public Evertune evidence | Open procurement item | Required artifact or test |
|---|---|---|---|
| Identity | SSO integration is listed for Enterprise | SAML, OIDC, SCIM, MFA policy, and identity providers are not public | Run IdP login, provisioning, deprovisioning, and break-glass testsEvidence: Evertune pricing and plans, Evertune Help CenterNot publicly verified. The plan page names SSO integration without protocol, provisioning, or identity-provider details. |
| Access and audit | No public product-control specification located | Roles, least privilege, audit events, retention, and export remain undefined | Request a role matrix and sample customer audit-log exportEvidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy PolicyNot publicly verified. These controls may exist or be contract-specific, but they are not described in the current public product and legal material. |
| Assurance | No Evertune SOC 2, ISO 27001, or public trust center claim located | Private reports or current audit work may still exist | Request report scope, period, exceptions, penetration test, and remediation statusEvidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy Policy, Evertune Terms of ServiceNot publicly verified. Absence from public pages is not evidence that private assurance documents or negotiated agreements are unavailable. |
| Privacy and retargeting | Policy covers platform data, pseudonymous ad data, recipients, rights, and retention purposes | A privacy policy is not the same as negotiated controller-processor terms | Complete a data-flow review for platform, panel, content, and advertising modulesEvidence: Evertune Privacy Policy |
| Legal terms | Public terms were last updated in April 2024 | No public DPA or subprocessor schedule was located | Negotiate DPA, security schedule, deletion, incident, transfer, and subprocessor termsEvidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy Policy, Evertune Terms of ServiceNot publicly verified. Absence from public pages is not evidence that private assurance documents or negotiated agreements are unavailable. |
| Resilience and location | Terms mention routine backups | Backup retention, RPO, RTO, restoration tests, and selectable residency are not public | Request hosting regions, recovery evidence, and contractual service objectivesEvidence: Evertune Terms of Service, Evertune pricing and plans, Evertune Help Center, Evertune Privacy PolicyNot publicly verified. These controls may exist or be contract-specific, but they are not described in the current public product and legal material. |
This page evaluates public evidence, not Evertune's private security program and not legal compliance. Missing public documentation should trigger a vendor review, not an automatic rejection.
What does Evertune publicly promise for identity and access?
The current Enterprise plan lists SSO integration. It does not publicly name SAML or OIDC, SCIM provisioning, supported identity providers, MFA enforcement, session controls, or just-in-time user behavior.
Evertune's public materials also do not define user roles, role-based permissions, customer audit events, log retention, or audit export. Buyers should test each required identity lifecycle and permission boundary in a real tenant.
Does Evertune publish SOC 2, ISO 27001, a trust center, or a DPA?
We did not find those Evertune claims or artifacts in the current public pricing, Help Center, privacy policy, or terms. That is a public-evidence finding only. An Enterprise sales team may provide private assurance material under NDA or negotiate a DPA.
Procurement should ask for the exact legal entity and product scope, audit period, exceptions, penetration testing, subprocessor list, security schedule, breach terms, deletion obligations, transfer mechanism, and document renewal dates.
How does Evertune's AI Retargeting change the privacy review?
Evertune's August 2026 policy says AI Retargeting may use pseudonymous browser identifiers, browsing or network activity, general location, and inferences supplied by partners. It describes sharing with advertising and service partners and provides state-law rights and partner opt-out routes.
That is a different data flow from a brand visibility dashboard. Buyers using advertising modules should map controller and processor roles, lawful basis, disclosures, partner responsibilities, retention, opt-out propagation, geography, and whether their own customer data enters audience activation.
What is public about backups, recovery, and data residency?
The April 2024 terms state that Evertune performs routine backups, but they make users responsible for transmitted data and waive claims for loss or corruption. They do not provide public recovery objectives or a detailed retention promise.
We also found no public customer-selectable data-residency commitment. Ask for primary and backup regions, encryption key ownership, RPO, RTO, restoration test results, deletion propagation, and the order-form terms that override general website language.
Evidence and method
Enterprise SSO is explicit but narrow
The pricing page confirms an identity feature while leaving protocol, provisioning, enforcement, and administration details for technical review.
Evidence: Evertune pricing and plans, Evertune Help CenterNot publicly verified. The plan page names SSO integration without protocol, provisioning, or identity-provider details.Privacy material is current
Evertune updated its policy in August 2026 and directly addresses the customer platform, AI Retargeting categories, recipients, rights, and retention purposes.
Evidence: Evertune Privacy PolicyPublic assurance remains limited
Current public product, help, and legal sources do not provide the common enterprise assurance artifacts buyers often need to complete vendor review.
Evidence: Evertune pricing and plans, Evertune Help Center, Evertune Privacy Policy, Evertune Terms of ServiceNot publicly verified. Absence from public pages is not evidence that private assurance documents or negotiated agreements are unavailable.Not publicly verified. These controls may exist or be contract-specific, but they are not described in the current public product and legal material.Website terms set a weak backup baseline
Routine backups are mentioned, but the same clause places responsibility on the user and does not publish recovery or retention commitments.
Evidence: Evertune Terms of ServiceHow we checked this page
We treated plan features, security assurance, identity protocols, product access controls, privacy disclosures, advertising data, legal terms, backups, and residency as separate procurement questions.
- 1. Read Evertune's current pricing, public Help Center index, August 2026 privacy policy, and April 2024 terms for explicit commitments and document dates.
- 2. Recorded controls not found in public material as not publicly verified and avoided claiming that private evidence or negotiated terms are unavailable.
- 3. Compared Trakkr only from its current official security page, preserving Trakkr's statement that it does not claim its own SOC 2 certification.
- Limitation: We did not receive an Evertune security questionnaire, trust portal access, audit report, penetration test, architecture diagram, DPA, subprocessor list, or negotiated order form.
- Limitation: This is a public-evidence procurement guide and is not a security audit, certification assessment, or legal opinion.
When is Evertune or Trakkr the stronger procurement fit?
Evertune may be the stronger fit when the buyer needs its panel research, repeated sampling, advertising activation, and dedicated enterprise service, and the vendor can satisfy the private security review. Public documentation alone is not enough to clear common assurance gates.
Trakkr has the clearer public technical-control baseline: TLS 1.3, AES-256, row-level isolation, RBAC, MFA, deletion, and regional isolation are documented. Trakkr also explicitly says it does not currently claim its own SOC 2 certification, so buyers with a vendor-certification hard gate must evaluate both products carefully.
Yes, Evertune lists SSO integration on Enterprise. It does not publicly specify SAML, OIDC, SCIM, supported identity providers, or provisioning behavior.
No Evertune SOC 2 claim was found in the public sources checked. That does not prove a private report or active audit is unavailable, so ask the vendor directly.
Not in the current public product and Help Center material checked. Request the exact roles, permissions, event coverage, retention, export, and administrator access model.
A customer-selectable data-residency region is not publicly documented. Buyers with residency requirements should put primary, backup, and processing regions into the contract.
Sources and related reading
See how AI talks about your brand
Enter your domain to get a free AI visibility report in under 60 seconds.