EVE AI Core
EVE AI Core is a deterministic control plane that intercepts every AI action before execution rather than reviewing it afterwards, returning an allow, block or modify verdict against versioned policy packs in under a millisecond, fail-closed and with no language model anywhere in the decision path. Its argument is that a safety layer built on a model can itself hallucinate, so a non-deterministic safety check is not a safety check. Every verdict emits a cryptographically signed certificate bound to the exact policy version in force, appended to hash-chained trails, replayable on demand and verifiable offline by a third party without the vendor in the loop.
It governs agent actions rather than only prompts and responses, refusing unregistered tools, risk-scoring each step and requiring human approval for high-stakes actions. It positions itself as the runtime enforcement and evidence layer beneath an existing model risk programme, for lending, insurance and trading decisions.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
This one needs stating carefully, because the headline claim is the absence of machine learning: the governance path contains none, and 126 enforcement rules evaluate deterministically so the same input always produces the same verdict. That is a design choice about how governance should work, not an absence of AI from the business.
The company exists only because models are in production, and its broader platform runs the AI it governs, with a runtime plane handling model routing, agent orchestration, memory retrieval and response generation alongside persistent identity, long-term memory and agentic behaviour. Determinism is confined to the decision path deliberately.
This is the most explicit oversight architecture in the index because the control sits before the action rather than after it. Every proposed action is intercepted and risk-scored, returning allow, block or modify, and the gate is fail-closed so nothing reaches the world unless it clears.
Agent governance is distinguished properly from prompt guardrails: the control operates on tool invocations, interface calls and data writes rather than text around a model call, unregistered tools are refused outright, and high-stakes steps can require human approval before executing. Kill switches and a stakes classifier sit in the pre-inference plane. The company names the failure mode it rejects precisely, that letting the action through and logging it is exactly the incident one is trying to prevent.
The evidence properties are the strongest in the index and each is specified cryptographically rather than described. Every verdict emits a signed certificate that a third party can verify offline with no vendor service in the loop, decisions append to hash-chained trails aggregated into signed tree structures, and each record is bound to the exact policy version that governed it so a decision can be re-run and confirmed.
That the record survives independently of the vendor is what distinguishes it from immutable logging elsewhere. The company also names a real and under-discussed risk: because behaviour is governed by policy rather than by whichever model sits behind the decision, silent provider updates cannot silently change outcomes.
No customer, institution or deployment is named, and no adoption figure, action volume or outcome measure is published. Eighty-five patent filings and a public code repository demonstrate investment and allow technical inspection, neither of which evidences that a regulated institution has put this in its decision path. For an enforcement layer that sits between AI intent and execution, that absence is the central gap.
Two structural features help: the control plane can be self-hosted, and evidence is verifiable offline without the vendor in the loop, which together limit dependence on the company. Held at C because no boundary statement accompanies them. A system that intercepts every AI action across customers observes what regulated institutions attempt and what gets blocked, and nothing states whether that informs policy packs, is isolated per customer, or is retained.
No data protection agreement, retention schedule, subprocessor list or redaction mechanism was located. The platform sits in the request path for regulated decisions and retains signed records of each one, so what those records contain about the applicant, and how long they persist, is a question the architecture makes unavoidable and the published material does not answer.
A trust centre is published, and the security engineering visible in the code is unusually disciplined for this index: the veto engine imports only standard library modules with no third-party packages at all, plus a deliberate load-time module freeze guard, which removes external dependency risk from the security-critical path entirely. Signing and attestation use named, standard cryptographic primitives. Held at B because no independent audit attestation or certification is named, so the control environment around the code is unevidenced even though the code itself is inspectable.
The regulatory reasoning is deeper than most, if narrower in coverage. It engages the current interagency model risk guidance directly and its predecessor's history, and makes a genuinely sophisticated argument about controls: where validation identifies that a model may produce non-compliant adverse action narratives under certain input conditions, periodic review of a sampled output log is not an adequate control, because the failure is conditional and sampling will miss it, so the control must be a mechanism preventing non-compliant output from reaching a decision-maker at all. Held at B because two regimes are engaged deeply rather than a broad obligation set being mapped, and the company is an infrastructure provider rather than a licensed entity.
Fair lending is addressed at the mechanism level rather than as an aspiration, governing automated credit and underwriting decisions against those obligations and producing a signed record of every approval and denial, with the equal credit opportunity adverse action problem used as the worked example of why prevention beats sampling. Insurance pricing, claims and eligibility models are covered on the same basis. Held at B because the platform enforces the policies a customer writes rather than testing for disparity itself, so no bias metric, fairness evaluation or disparity analysis is offered.
No guarantee, indemnity or correction process was located. The affected consumer benefits indirectly and substantially, since a signed record of every approval and denial bound to the governing policy is the raw material for explaining a decision, and nothing states whether an applicant can obtain that record, what happens if the gate wrongly blocks a legitimate action, or what the vendor stands behind if evidence proves insufficient under examination.
Model agnosticism is architectural rather than aspirational, with a provider registry and the explicit property that providers can be changed or self-hosted without altering the control plane, which directly addresses the third-party model dependency supervisors expect institutions to manage. The dependency disclosure for its own critical path is exceptional, naming the exact standard library imports of the veto engine and confirming no third-party packages. Held at B because no model provider is identified individually, unlike the two vendors here that enumerate theirs.
Integration is aimed at the AI stack, with a provider registry, agent orchestration, tool registration and a unified router, and the deliberate design point is that the control plane is independent of the model behind it so providers can change without touching governance. Held at B because no banking, lending, claims or case management system is named, so how enforcement verdicts and signed evidence reach an institution's own control environment is not described.
Self-hosting is explicitly supported and stated as changing nothing about the control plane, which matters for an institution unwilling to route regulated decisions through a third party, and provider changes are similarly decoupled. Sub-millisecond evaluation implies the gate runs adjacent to the workload rather than as a remote call. Held at B because no hosted region, residency commitment or infrastructure detail is published for customers who do not self-host.
A pricing page exists in the site structure alongside a trust centre and whitepaper, and no pricing, packaging or basis of charge was retrievable. Charging model is material for a control that evaluates every action, since cost could follow action volume, protected applications or seats, and none of it is indicated.
Applicability is described across regulated decision types rather than institution types, covering automated credit and underwriting against fair lending obligations, insurance pricing, claims and eligibility models, and trading, with healthcare named alongside. That framing suits an enforcement layer, which cares about the decision rather than the buyer. Held at B because no institution class, size range or geography is evidenced, and coverage remains a statement of where the control could apply.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to EVE AI Core
The closest documented capability profiles to EVE AI Core in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Deployment Model and Data Residency
Documents GLBA and Data Privacy Posture where EVE AI Core does not
A lighter documented profile than EVE AI Core
Documents AI Safety and Data Stewardship where EVE AI Core does not
Stronger documented coverage on Regulatory Status and Licensure
Documents GLBA and Data Privacy Posture where EVE AI Core does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.