Your GRC platform is your system of record — it catalogs policies, risks, and controls. EVE is the system of enforcement and proof: it turns a policy into a deterministic ALLOW / MODIFY / BLOCK at the moment an AI acts, and returns a signed decision certificate anyone can verify — carrying the external policy that governed it.
You already have a system of record. What most AI stacks lack is a deterministic layer that stops a non-compliant action before it executes and produces evidence an examiner can check. EVE is that layer — it does not replace your GRC platform.
EVE sits at the moment an AI acts. It takes governing policy from wherever you keep it, enforces it deterministically at the runtime, and returns cryptographic proof to the systems your enterprise already runs on. Bring policy from anywhere. Enforce it anywhere AI acts. Return proof anywhere your teams already work.
Chip color reflects what works today: ● available ● beta ● compatible via framework ● on the roadmap. Per-connector detail is below.
Your governance system remains the source of policy. EVE binds each decision to the external policy that governed it, enforces it deterministically, and returns the evidence back to your system of record.
Every certificate carries a governance_provenance block — the external provider,
the external policy id and version, and the EVE policy pack it was bound to — so the decision is traceable to the exact policy that produced it.
We label every connector by what actually works today, grouped by its role in the control point. We do not imply partnership, certification, or endorsement by any vendor listed. “Compatible via framework” means the connection is made through EVE’s documented generic contract or evidence normalization, not a vendor-built integration.
| Governance system | How EVE connects | Availability |
|---|---|---|
| Generic GRC API | Inbound policy pull + signed evidence push over a documented REST contract | Available |
| ServiceNow | Bridge adapter for policy intake and evidence return; live inbound context pull is in beta | Beta |
| Credo AI | Compatible via API — generic governance contract + audited evidence normalization | Compatible via framework |
| OneTrust | Compatible via API — generic governance contract + canonical shape normalization | Compatible via framework |
| Archer | Compatible via API — canonical shape normalization + contract tests (no live vendor client) | Compatible via framework |
| IBM OpenPages | Compatible via API — canonical shape normalization + contract tests (no live vendor client) | Compatible via framework |
| MetricStream | Compatible via API — canonical shape normalization + contract tests (no live vendor client) | Compatible via framework |
| IBM watsonx.governance | Compatible via API — canonical shape normalization + contract tests (no live vendor client) | Compatible via framework |
| Runtime | How EVE governs it | Availability |
|---|---|---|
| OpenAI / Azure OpenAI | Governed model routing: CoreGuard pre-gate returns ALLOW / MODIFY / BLOCK before the model call (opt-in per deployment) | Available |
| Anthropic (Claude) | Governed model routing; a BLOCK never reaches the model | Available |
| AWS Bedrock | Governed routing over the real SigV4 InvokeModel client | Available |
| Google Gemini | Governed routing over the real Gemini inference client | Available |
| Model Context Protocol (MCP) | Per-tool-call enforcement: a tool call must present a single-use EVE-signed authorization or it is refused before execution (opt-in) | Available |
| LangChain / LlamaIndex | Governance-native: each chain / agent / retrieval step is governed and emits signed evidence | Available |
| Any runtime (provider-blind) | The governed model router is model-agnostic — a new runtime is an adapter + capability descriptor, with no change to CoreGuard | Available |
| Azure AI Foundry | Governance-native: governs invocation metadata and emits a signed decision certificate (does not call the vendor) | Available |
| Vertex AI | Governance-native: governs invocation metadata and emits a signed decision certificate (does not call the vendor) | Available |
| Databricks (model serving) | Governance-native: governs invocation metadata and emits a signed decision certificate (does not call the vendor) | Available |
| Salesforce Agentforce | Governance-native: governs agent-action metadata and emits a signed decision certificate (does not call the vendor) | Available |
| Microsoft Copilot Studio | Governance-native: governs agent-action metadata and emits a signed decision certificate (does not call the vendor) | Available |
| Destination | How EVE delivers proof | Availability |
|---|---|---|
| ServiceNow | Creates governed-decision incidents via the Table API | Available |
| Splunk | Ships signed decision events to the HTTP Event Collector | Available |
| Datadog | Ships signed decision logs to the Logs intake API | Available |
| Microsoft Sentinel | Ships signed decision logs to the Logs Ingestion API | Available |
| CrowdStrike Falcon | Ships signed decision logs to Falcon NG-SIEM (LogScale HEC) | Available |
| Palo Alto Cortex XSIAM | Ships signed decision logs to the Cortex HTTP Collector | Available |
| Slack | Posts governed-decision notifications (Block Kit) via incoming webhook | Available (webhook) |
| Microsoft Teams | Posts governed-decision notifications (Adaptive Card) via incoming webhook | Available (webhook) |
| PagerDuty | Triggers incidents from governance alerts via Events API v2 | Available (webhook) |
| Jira | Emits governance evidence for Jira-tracked governance operations (evidence scaffold) | Compatible (evidence scaffold) |
Identity & attribution. Branded IdPs — Microsoft Entra ID, Okta, Ping — attribute decisions through EVE’s standards-based OIDC / SAML / SCIM, not per-vendor API clients.
Organization admins connect a governance system from the in-app Integration Hub → Every connector shows its honest health — connected, configuration required, unavailable, or not configured — and never a fabricated “Connected.” Credentials are stored encrypted at rest and are never returned by the API.
Load a real EVE-signed governed decision — carrying its external policy provenance — and verify the signature yourself against EVE’s published key.