Get the EVE appAdd it to your home screen EVE AI Core
Deterministic AI Governance Infrastructure

No governed AI action executes without proof.

EVE CoreGuard is a deterministic pre-execution governance runtime for regulated AI. It evaluates every proposed AI action before execution, blocks what policy cannot defend, and produces cryptographically signed evidence for every production decision.

EVE CoreGuard governs every AI action before execution—blocking what policy cannot defend and producing cryptographically signed proof of every decision.

Production Proof
<1 msRule evaluation
ECDSA P-384Signed production records
OfflineIndependent verification
Control mappings ECOA / Reg B SR 26-2 FCRA HIPAA EU AI Act SOC 2 Type IIIn Progress
Authorization Before Execution

Your AI agent authenticated successfully.
That is not the same as being allowed.

An agent can hold a valid credential, connect through an approved path, and still request an operation it must never be permitted to perform. Identity infrastructure cannot make that distinction on its own.

Authentication establishes who or what the agent is.
Authorization determines what the agent is permitted to do.
CoreGuard enforces that authorization before execution — and produces verifiable evidence of the decision.

Declare

Register the agents, tools, APIs and governed resources in scope, with the capability envelope each one is actually entitled to.

Control

Evaluate every proposed action against deterministic policy before it reaches the execution boundary. No language model in the verdict.

Prove

Emit a signed decision record for each verdict — allow or block — that a third party can verify independently.

AI Request
EVE Trust Runtime
BLOCK
<1 ms
Deterministic Rule Evaluation
Signed
Production Decision Records
Pre-Execution
Enforcement by Design
ECDSA P-384
Cryptographic Authority Chain
EVE CoreGuard — Trust Runtime Status (illustrative sample) ALL SYSTEMS OPERATIONAL
Pre-Execution Gate ACTIVE 15 rules loaded  ·  5 red lines sealed
Policy Pack ENFORCING lending_v1 · healthcare_v1 · eu_ai_act_v1
Authority Chain SIGNING ECDSA P-384 · chain pos #4,291
Authority Resolution NOMINAL p50: 0.41ms  ·  p99: 0.87ms
Pre-execution proof

What happens when an agent alters
an authorized transaction

A $50,000 wire is approved by a named human and bound to a single-use certificate. The authorized wire executes once. Then the same certificate is presented again with one field changed. Neither run is a mockup — both come from EVE CoreGuard’s deterministic wire scenario, re-executed live on this page whenever the engine is reachable.

Executed The authorized wire recorded
Request $50,000 → acme-verified-vendor Delegated limit $10,000 — exceeded Human approval REQUIRED Approved by cfo_jane (this exact wire) Certificate ISSUED single-use, bound to $50,000
Execution EXECUTED
executed_count 1
Denied The same certificate, amount changed recorded
Request $50,000 → acme-verified-vendor Delegated limit $10,000 — exceeded Human approval REQUIRED Approved by cfo_jane (this exact wire) Certificate ISSUED single-use, bound to $50,000
Agent submits $500,000 — one field altered Execution DENIED Reason binding mismatch: amount, parameters
executed_count 0

The decision was valid. The certificate was real. Changing one bound field was enough to stop execution — the payment connector was never called.

EVE authorizes the wire it was asked to authorize. Denial happens at execution, where the action is checked against what was actually signed.

What EVE Is Not

Enforcement happens before the action runs.

EVE is not observability, not a dashboard, not an LLM guardrail, and not post-hoc monitoring. Those tell you what an AI system did. EVE decides what it is allowed to do, and refuses the rest.

Not this

  • Observability dashboards
  • Post-hoc monitoring & alerting
  • LLM-based “guardrail” filters
  • Mutable log files & screenshots

EVE

  • Deterministic pre-execution enforcement
  • Signed decision certificate at issuance
  • Rule engine — zero model involvement in the veto
  • Hash-chained, offline-replayable evidence
Trust Architecture

Three-Layer Trust Infrastructure

A cryptographically authoritative trust runtime that resolves authority, routes intelligently, and attests every decision before execution — independent of model behavior.

Layer 1 — Authority
Pre-Execution Authority Resolution
64/022,677 — Anchor Patent
Every action routed through the governed execution path is evaluated before it runs. The charter engine applies 15 deterministic rules against 5 immutable red lines in under 1ms. Hard blocks are structurally immutable — no prompt, runtime instruction, or model output can override them. Authority is resolved, not inferred.
  • 15 charter rules — deterministic, not probabilistic
  • 5 immutable ethical red lines
  • FPGA-targetable veto core (hardware enforcement on the roadmap)
  • Zero LLM involvement in veto decisions
Layer 2 — Routing
Governed Inference Routing
64/022,671 — Routing Patent
Multi-axis routing selects model, provider, and context budget per request class. Cost governance enforces quotas at runtime. Trust budget allocation ensures no request class can consume authority beyond its provisioned tier.
  • Per-tier provider + model configuration
  • Context budget allocation by provider class
  • Runtime cost governance with quota enforcement
  • Automatic fallback on provider failure
Layer 3 — Lineage
Cryptographic Authority Chain
64/022,682 — Compliance Patent
Every governance decision generates an ECDSA P-384-signed certificate with hash-chained provenance. The chain is tamper-evident and independently replayable. Auditors, examiners, and authorized reviewers can verify records offline — each certificate is self-contained and tamper-evident.
  • ECDSA P-384 Decision Certificates
  • Hash-chained audit trail
  • Brier score calibration records
  • Offline verification — no callback needed

See EVE CoreGuard govern a live decision

Type an AI action below. EVE evaluates it against deterministic policy and returns an ALLOW / BLOCK / MODIFY verdict with a signed evidence record — in real time.

Live governance demonstration — not a general-purpose chatbot.

EVE CoreGuard · Live

You are chatting with EVE, an AI system — responses are AI-generated and may be inaccurate. Please don't submit confidential, personal, or regulated data.

EVE COREGUARD · CHARTER ENFORCED · REAL-TIME GOVERNANCE

View Full Demonstration → Apply for a Design Partner Pilot
Governed Domains

Regulated industries.
Structural enforcement.

EVE CoreGuard deploys in lending, healthcare, and enterprise AI where governance must be deterministic, not probabilistic — and where post-hoc filtering is not a defensible compliance posture.

<1 ms
Deterministic rule-evaluation step
Inline
Pre-execution enforcement — every action gated before it runs
Offline
Independent certificate verification — no EVE connectivity required
AWS · Azure
Available on both marketplaces — or self-hosted in your own VPC
Trust Gap

AI systems commit before
authority is resolved

Post-hoc filtering cannot undo a committed action. By the time an LLM outputs a decision, trust has already been assumed — not verified. EVE resolves authority before execution.

01
No Cryptographic Authority
Existing guardrails are semantic filters — probabilistic, prompt-influenced, and producing no verifiable record. When a regulator asks for proof of governance, “we had a system prompt” is not an answer.
02
No Verifiable Audit Trail
Log files are mutable. Screenshots lie. When a regulator asks "prove your AI didn't approve that loan without proper checks," you have nothing cryptographically tamper-evident to show.
03
Governance Lives in Semantics
Policy buried in system prompts is text the model can reason around, hallucinate past, or outright contradict. Deterministic governance requires structural enforcement — not linguistic convention.
Why Now

Under Regulation (EU) 2026/1744 (in force 27 July 2026), EU AI Act high-risk obligations apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). SR 26-2 (the 2026 interagency model-risk guidance that superseded SR 11-7) explicitly excludes generative and agentic AI from its model-risk-management scope, while directing banking organizations to use broader risk-management and governance practices to determine appropriate controls for systems outside it. EVE governs what an agent is allowed to execute — and produces evidence of that enforcement. See a sample examiner evidence pack →

Runtime Authority Engine

Authority Resolution
in 7 Stages

The EVE CoreGuard trust runtime intercepts every AI action, resolves authority against your governance corpus, and returns a signed ALLOW / BLOCK / MODIFY verdict with cryptographic provenance — before the action executes.

Stage 1
Intercept
Proposed action intercepted before it executes
0.05ms
Stage 2
Normalize
NFKC normalization + stakes classification
0.12ms
Stage 3
Enforce
Governance corpus evaluated deterministically
0.28ms
Stage 4
CRD Score
Confidence-Reality Divergence
0.08ms
Stage 5
Resolve
Canonical verdict — ALLOW / BLOCK / MODIFY
0.04ms
Stage 6
Attest
ECDSA P-384 certificate sealed — chain advanced
0.06ms
Stage 7
Dispatch
Approved action released — only after proof is sealed
0.03ms
Sub-Millisecond
Pre-Execution Authority Resolution
The trust runtime sits in the hot path in front of the execution boundary — before the model call for input governance, and before the tool call, transaction, or API action for agents. Full authority resolution — charter evaluation, CRD scoring, verdict binding — completes in under 1ms. Minimal application overhead on production traffic.
Governance Corpus
Domain-Specific Governance Primitives
Governance corpora encode regulatory requirements as deterministic rules — not prompts, not heuristics. Lending, healthcare, trading, and enterprise security corpora ship out of the box. Enterprise corpora available on contract.
Authority Lineage
Independently Replayable Audit Chain
Every verdict is hash-chained and ECDSA P-384-signed. Chain integrity is computable by any party without contacting EVE. Regulators replay the full authority chain offline — tamper-evident records built for independent audit.
Authority Lineage

Every decision is a
signed authority record

Governance decisions are cryptographically bound at issuance. The authority chain is independently replayable — years after the decision, by any verifying party, without EVE involvement. Trust is in the chain, not the system.

EVE CoreGuard — Decision Certificate Verification
$ eve-proof verify --cert cert_20260331_a4f2c3.json Loading certificate chain...   Certificate cert_20260331_a4f2c3 Decision ALLOW Action loan_approval :: amount=$50,000 :: policy=lending_v1 Timestamp 2026-03-31T14:22:17.841Z Latency 0.71ms Rules lending.credit_score_check=PASS  lending.dti_ratio_check=PASS CRD Score 0.08 (within threshold)   Signature kms-ecdsa-p384:a4f2c3e9b1d8f076a2c5e4b3d9f1a8c2e7b4d6f0a3c8e5b2 Chain pos #4,291  (prev: b9e1a7f3...) Chain INTACT  (4,291 entries verified)   ✓ Certificate VALID — signature matches, chain intact, decision unaltered Verification completed offline — no EVE connectivity required

Illustrative certificate. Verify a real signed record at /verify.

3 founding partner slots open

Govern one real workflow.
60 days.
Signed evidence you verify yourself.

A small cohort of regulated operators running EVE CoreGuard on one real workflow before general availability — direct founder access, priority onboarding, and a policy pack built for your regulation. We are not pretending to have a wall of customer logos; we do not have one yet. This is how the first ones get made.

Apply for the Founding Partner Program

Or start the standard $37,500 pilot — qualify in five minutes and get a tailored plan instantly →

Technical Reference

Infrastructure deep dives

Architecture specifications, compliance integration guides, and enforcement pattern documentation for regulated AI infrastructure teams.

Engineering

How We Built a Deterministic Governance Runtime with Sub-1ms Enforcement

Engineering a governance gate that runs before governed execution, adds under 1 ms of rule-evaluation latency, and produces the same verdict for the same input every time.

Read article →
Compliance

EU AI Act Compliance Guide for High-Risk AI Systems

A practitioner's guide to Article 9 risk management and enforcement requirements under the EU AI Act.

Read guide →
Tutorial

EVE CoreGuard API Tutorial: Integrate in Under 10 Lines

Step-by-step integration guide — REST API, Python SDK, and sidecar proxy deployment patterns.

Read tutorial →
Banking

SR 11-7 and AI Model Risk: The Enforcement Layer Banks Are Missing

Federal Reserve model risk requirements and why financial institutions need deterministic enforcement for LLM deployments.

Read article →
View all articles →    Browse documentation →

Governance Surfaces

Explore the EVE AI Core governance surface

One deterministic enforcement-and-evidence plane, described for the decision you're evaluating — each links back to the same EVE CoreGuard gate and EVE Proof evidence layer.

Infrastructure Grade

Govern AI
before it acts.

EVE CoreGuard deploys as a sidecar proxy, REST API, or SDK integration. Deterministic governance corpus, cryptographic authority chain, and independently replayable audit lineage. Contact us for an enterprise architecture review against your regulated AI deployment.

Available on AWS Marketplace → and Microsoft Azure Marketplace →