EVE Trust Services Controlled Preview

Independent trust infrastructure for AI decisions.

EVE Trust Services preserves, witnesses, and verifies governance evidence across models, agents, providers, and time. Now available in controlled preview for selected design partners — hosted verification, cryptographic custody manifests, and externally witnessable evidence infrastructure. Evidence custody and managed witnessing remain subject to production-readiness and contractual approval.

Product architecture

Where EVE Trust Services sits

Every governed AI decision moves through three product layers before an external party verifies it. Each layer has one job.

Input

AI action proposed

A model, agent, or workflow proposes an action that carries risk.

Enforce

EVE CoreGuard evaluates

Deterministic pre-execution enforcement returns ALLOWED, BLOCKED, or MODIFIED.

Prove

EVE Proof signs

The decision becomes a signed certificate — verifiable offline, bound to the policy version.

Preserve

EVE Trust Services witnesses and preserves

Evidence is externally witnessed, held in custody, and kept verifiable over time.

Verify

Auditor or examiner verifies

An external party checks signatures, inclusion proofs, and replay — without trusting the producer.

CoreGuard governs. EVE Proof proves. EVE Trust Services preserves independent trust.

Capabilities

Trust infrastructure, not trust claims

Eight services that keep governance evidence verifiable long after the system that produced it has changed.

Witnessing

External witnessing

Signed Merkle roots submitted to an independent append-only transparency log, so evidence existence is attested outside the producer's control.

Custody

Evidence custody

Long-term preservation of customer-owned evidence chains with strict tenant isolation. Your evidence remains yours — held, not owned.

Proofs

Inclusion proofs

Cryptographic proof that a governance record was included in a previously witnessed evidence root — checkable by any verifier.

Keys

Key lifecycle continuity

Rotation, revocation, and continuity records that preserve trust in old signatures across infrastructure and key changes.

Replay

Deterministic replay services

Reproduce historical governance decisions using the original policy version and evidence context — the same inputs, the same verdict.

Verification

Verifier APIs

Auditors, regulators, customers, and approved third parties validate evidence without any access to signing authority.

Migration

Attested migration

Evidentiary continuity when customers migrate infrastructure, keys, regions, or governance environments — with a signed record of the transition.

Retention

Long-term retention

Regulated retention periods, deletion proofs, and evidence-chain continuity for the full life of the record-keeping obligation.

Assurance vocabulary

Four assurance tiers

A published vocabulary for how much independent verification stands behind a piece of AI decision evidence.

Tier 0
Self-Issued
Evidence issued by the decision producer or platform vendor.
Tier 1
Externally Witnessed
Evidence anchored to an independent append-only transparency log.
Tier 2
Independently Evaluated
Evidence produced through an independent governance instrument, available for evaluator review.
Tier 3
Regulator Accepted
Recognition determined externally through regulatory, supervisory, or recognized assurance processes.
Assurance is derived from verifiable facts, not marketing claims. The tier of any piece of evidence is recomputable by any verifier from the evidence itself. Regulator acceptance cannot be self-declared by the certificate creator — no issuer, including EVE, can issue Tier 3.

Why it matters

Why independent trust matters

A model provider can report what its platform says happened. Independent evidence infrastructure allows another party to verify what happened without relying solely on the model provider.

Provider neutrality

Evidence handling is separated from the systems that produce decisions, so no single vendor's account of events has to be taken on faith.

Cross-model verification

One evidence format and one verification path across every model and agent in your estate — regardless of who built or hosts them.

Cross-cloud continuity

Evidence chains stay verifiable when workloads move between clouds, regions, or deployment models.

Auditor access

Auditors verify signatures and inclusion proofs directly, without requiring access to production systems or vendor cooperation.

Examiner-ready artifacts

Evidence arrives in a form an examiner can independently check: signed, witnessed, replayable, bound to the policy version in force.

Reduced log dependence

Verification does not depend solely on vendor-controlled logs that the vendor could alter, truncate, or lose.

Trust EVE less. Verify the evidence more.

Where it fits

Built for regulated environments

EVE Trust Services is designed for organizations whose AI decisions are subject to supervision, examination, or formal audit.

Banking & Lending Insurance Healthcare Government Defense Critical Infrastructure Regulated Enterprise AI

SR 11-7 model risk management

Supports model risk management practice with preserved, independently verifiable records of how governed model decisions were enforced and evidenced over time.

NIST AI RMF

Helps operationalize the Govern and Measure functions with durable evidence of enforcement outcomes, policy versions, and verification history.

EU AI Act evidence and conformity processes

Provides artifacts for record-keeping and post-market monitoring processes: witnessed evidence roots, inclusion proofs, and replayable decision records.

SOC 2 control environments

Provides artifacts for control operation and evidence-retention activities within an existing SOC 2 control environment.

EVE Trust Services supplies evidence infrastructure and verification artifacts. It does not certify compliance, and framework alignment does not constitute a compliance guarantee or a legal opinion.

Ownership & privacy

Your evidence. Your data. Our custody.

Independent trust infrastructure only works if the customer keeps ownership and the witness sees no secrets.

Customers retain ownership

Customers retain ownership of their evidence and decision data at all times. Custody is a service, not a transfer of rights.

Tenant evidence stays isolated

Each tenant's evidence chains are held in strict isolation. No cross-tenant access, aggregation, or correlation.

No public disclosure required

EVE Trust Services does not require public disclosure of prompts, outputs, policies, or customer records to deliver external witnessing.

Logs receive roots, never content

External transparency logs receive cryptographic roots and required verification metadata — never raw decision content.

Consent-gated benchmarking

Any aggregated benchmark use of evidence requires explicit customer consent and anonymization. No silent reuse.

Deletion with proof

When retention ends, deletion is executed against the customer's policy and evidenced — without breaking the continuity of the surrounding chain.

EVE is the custodian and verification instrument — never the owner. EVE Trust Services holds and witnesses customer evidence; it does not collect, own, or operate a global database of customer decisions.

Verification workflow

How an auditor or examiner verifies a decision

Six steps from a single decision record to an independently checkable conclusion.

1

Retrieve the decision certificate

The verifier obtains the signed decision certificate from the customer's evidence store or export.

2

Resolve to a witnessed evidence root

The certificate resolves to an evidence root previously witnessed in the independent transparency log.

3

Check signature validity

The verifier checks the certificate's signature against the published verification key material — no signing authority required.

4

Validate the inclusion proof

The verifier validates the cryptographic proof that this record was included in the witnessed root.

5

Replay the decision

The original policy version and decision context can be replayed to confirm the recorded verdict is reproducible.

6

Independent evaluator issues any opinion

Any formal opinion on the evidence is issued by an independent evaluator — not by EVE.

Division of responsibility: EVE supplies the evidence infrastructure — certificates, witnessing, proofs, replay. Independent auditors and validators issue formal opinions.

Status

What exists today, what is being built

EVE Trust Services builds on evidence infrastructure that already ships with EVE CoreGuard and EVE Proof. Status is stated plainly.

Available foundation

Shipping in EVE CoreGuard and EVE Proof

  • Signed decision certificates
  • Offline verification
  • Policy version binding
  • Hash-chained evidence
  • Merkle aggregation
  • Assurance vocabulary
Controlled preview

EVE Trust Services core

  • Hosted verifier API (structured valid / invalid / indeterminate results)
  • Inclusion-proof and coverage APIs
  • Signed custody manifests
  • Signing-key registry and revocation
  • SDK offline trust verification (eve-coreguard 0.2.0)
  • External transparency-log witnessing (preview; disabled by default)
In development

Toward general availability

  • Scheduled witnessing operations with monitoring and incident runbooks
  • Long-term custody services (contractual and operational foundations)
  • Auditor portal integration and evaluator credentials
  • Attested evidence migration and extended retention policies

Make every governed AI decision independently verifiable.

Design partners shape the witnessing, custody, and verifier surface before general availability. They generate decisions. EVE preserves the proof.