Procurement & Vendor Diligence Packet

Last updated: June 2026 · Version 1.0 · For prospective enterprise customers

This page consolidates what an enterprise procurement, information-security, and legal team needs to evaluate EVE AI Core as a vendor: a pre-answered security questionnaire, our sub-processor list, the data-flow architecture, compliance mappings, contract documents, and a step-by-step onboarding checklist. Where a control or certification is not yet in place, this page says so plainly.

How to use this packet

Most diligence questions are answered inline below. For artifacts that we share under NDA — the named sub-processor list, our most recent third-party reports as they become available, penetration-test summaries, and a countersigned MSA/DPA — email [email protected] (commercial) or [email protected] (security). We can typically return a completed CAIQ/SIG-lite within five business days.

1. Vendor & entity facts

Legal entity
EVE NeuroSystems LLC
Product
EVE AI Core · EVE CoreGuard
Registered address
3480 Preston Ridge Rd, Suite 5109, Alpharetta, GA 30005, USA
Primary hosting region
United States
Commercial contact
Security contact
Intellectual property
U.S. Patent Pending — 90 filed U.S. provisional applications
Deployment models
SaaS, Customer VPC, Private Cloud, On-Prem

2. Documents in this packet

The following are published and linkable today. Negotiated or NDA-gated documents are noted.

Security Overview →
Encryption, access control, infrastructure, audit logging, retention.
Architecture & Data Flow →
Control-plane diagram: where data enters, how it is governed, what is logged.
Data Processing Addendum →
GDPR Art. 28 terms, sub-processors, SCCs, breach notification, deletion.
Service Level Agreement →
Uptime tiers, latency, incident response, service credits.
Master Service Agreement →
Standard enterprise terms: liability, IP, warranties, term & termination.
Privacy Policy →
What we collect, why, and the rights available to data subjects.
Trust Center →
Verifiable claims, offline evidence verification, stated assumptions.
Patent Portfolio →
The defensibility position behind the governance control plane.

3. Security questionnaire (pre-answered)

Answers reflect EVE AI Core's current posture. Certifications still in progress are labeled honestly — we do not represent a control as achieved until it is.

Data protection

ControlStatusDetail
Encryption in transitIn placeTLS 1.2+/1.3 for all client and inter-service traffic.
Encryption at restIn placeAES-256 for stored data, including audit-log persistence.
Tenant isolationIn placePer-tenant governance state and audit chains; isolation enforced at the application and data layers.
Data residencyIn placePrimary hosting in the United States. Customer VPC, Private Cloud, and On-Prem deployments keep data in the customer's chosen region/boundary.
Data deletion / right to erasureIn placeCustomer-initiated deletion across memory layers; HMAC-signed, hash-chained deletion receipts evidence erasure.

Access & identity

ControlStatusDetail
AuthenticationIn placeJWT-based sessions; scoped API keys for programmatic access.
Multi-factor authenticationIn placeTOTP-based MFA available for accounts; recommended for administrative access.
Role-based access controlIn placeFive roles (Viewer, Operator, Approver, Admin, Platform Admin) with least-privilege enforcement and tenant scoping.
Secrets managementIn placeManaged secrets store; no reliance on environment defaults for production secrets.
Audit loggingIn placeTamper-evident, hash-chained, cryptographically signed (Ed25519 in production; HMAC for self-hosted SDK integrity) decision and administrative event records; 7-year retention available.

Operations & resilience

ControlStatusDetail
Backups & recoveryIn placeAutomated backups with documented rotation; restoration procedures maintained.
Monitoring & alertingIn placeUptime, latency, and error monitoring; customer-visible status at /status.
Incident responseIn placeDocumented incident-response process; severity classification (P1–P4) defined in the SLA.
Breach notificationIn placeNotification without undue delay and within 72 hours of becoming aware (see DPA §9).
Vulnerability disclosureIn placeCoordinated disclosure to [email protected].
Independent penetration testingPlannedSummaries shared under NDA once completed; scope and cadence discussed during diligence.

Certifications & attestations

FrameworkStatusDetail
SOC 2 Type IIReadinessControls aligned; attestation not yet issued. We will not represent it as complete until the report exists.
ISO/IEC 27001PlannedOn the compliance roadmap; not yet initiated for certification.
GDPR / UK GDPRAddressedProcessor terms, SCCs, and breach process in the DPA.
CCPA / CPRAAddressedCovered by the DPA and Privacy Policy.

Honest status: SOC 2 Type II is at the readiness stage and ISO 27001 is planned. If your procurement gate requires a completed attestation today, tell us — we will scope a path and timeline rather than overstate readiness.

4. Sub-processors

EVE names its infrastructure and functional sub-processors below. The authoritative list is published at /subprocessors; a copy is also available under NDA on request. Optional third-party LLM providers act as sub-processors only for requests the customer elects to route to them (or where the customer supplies its own keys).

Sub-processorService providedRegion
Amazon Web Services, Inc. (AWS)Cloud compute, storage, managed database, container, secrets, and network hostingUnited States
Cloudflare, Inc.Edge network, CDN, DNS, TLS termination, and DDoS protectionGlobal edge (US-configured origin)
Sub-processorService providedRegion
Amazon RDS (PostgreSQL); Redis, MongoDB, Pinecone where enabledOperational databases, caching, vector / semantic stores (where not provided directly by AWS)United States
Twilio SendGridTransactional email — account, security, billing notificationsUnited States
StripeSubscription billing and payment processingUnited States
Sentry (where configured)Error monitoring and service reliabilityUnited States

Source of truth: /subprocessors and DPA §6. Some entries operate only where the relevant feature is enabled.

5. Data flow & architecture

EVE is a deterministic governance control plane: a proposed action is evaluated against versioned policy before execution, a signed decision-evidence record is produced, and that record is appended to a tenant-bound, hash-chained audit log. The full visual data-flow diagram — including where customer data enters, what is and isn't retained, and how evidence is generated — is on the Architecture & Data Flow page.

6. Compliance mappings

EVE produces the evidence and controls that map to common regulatory obligations. These are mappings to obligations, not legal advice or a certification of compliance for your specific program.

EU AI Act →
Risk classification, obligation mapping, gap analysis, roadmap.
ECOA / FCRA (Lending) →
Adverse-action and fair-lending evidence for credit decisions.
Healthcare →
Governed clinical-AI oversight and audit evidence.
Governed-decision scenarios →
Worked examples across regulated domains.

7. Vendor onboarding checklist

A typical path from first diligence to production:

  1. Intake & NDA — mutual NDA so we can share named sub-processors, test summaries, and draft contracts.
  2. Security review — we return a completed CAIQ/SIG-lite and answer your questionnaire; security team reviews this packet, the Security Overview, and Architecture.
  3. Legal review — redline the MSA, DPA, and SLA; agree liability, residency, and term.
  4. Deployment decision — choose SaaS, Customer VPC, Private Cloud, or On-Prem (see deployment models) based on data-residency and isolation needs.
  5. Pilot — scope one real workflow via the Design Partner Program; produce live signed evidence on your data.
  6. Production — countersign, provision, and roll out with agreed SLAs and support.

Start diligence

Send your security questionnaire or procurement requirements to [email protected], or reach the security team directly at [email protected]. Prefer to evaluate hands-on first? Begin with the Design Partner Program or request a demo.