The first question every enterprise security review asks: "Can I run this in my environment?" Yes. EVE's governance control plane meets your data-residency and isolation requirements — and produces the same signed, independently verifiable evidence in every model.
You control which decision fields are sent; in VPC and on-prem deployments, governed content and evidence stay inside your boundary. With EU AI Act GPAI-model obligations applicable since 2 August 2025 and high-risk-system obligations phasing in from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) under Regulation (EU) 2026/1744, and with SR 26-2 (the April 2026 interagency model-risk guidance that superseded SR 11-7, applied primarily to banking organizations above $30B in total consolidated assets) excluding generative and agentic AI from its formal scope while still expecting such technologies to be governed, the record has to exist at the moment of the decision. Trust Center · Security
Framework mappings describe technical control support and evidence capabilities. They do not constitute legal advice, regulatory certification, or a guarantee that a customer’s deployment is compliant. “SOC 2 Type II — In Progress” means an independent SOC 2 Type II audit is engaged (Decrypt CPA, via Scytale) and the observation period is underway; it is not a completed audit or an issued attestation.
Deployment changes where EVE runs — never what it proves. The evidence contract is identical everywhere.
SaaS is generally available today. VPC, Private Cloud, and On-Prem are delivered through design-partner and enterprise engagements — contact us to scope your environment.