Route
Unity AI Gateway
MCP routing, service policies, wire-level guardrails inside Databricks.
Accountability Infrastructure
Not another AI-SPM dashboard. Aevesa is accountability infrastructure: gateways govern what can happen; we prove what did happen (permit or deny) with liability-receipt/v1 artifacts auditors verify offline, without logging into Cyera, Databricks, or Aevesa.
Agentic Evidence Infrastructure · Prove specialty inside AI-SPM · EU AI Act Art. 12/14/73 export-ready
The Evidence Gap
AI gateways and AI-SPM platforms govern what agents can touch. Aevesa proves what happened.
Intercept and classify layers leave a gap in the architecture diagram: no portable proof an external auditor can verify offline. Regulated teams cannot sign off on agent deployments using vendor-scoped JSON alone. Paste a receipt at verify.aevesa.com and recompute integrity in under 90 seconds. No login required. Aevesa cosigns material decisions to an independent witness log, not another platform dashboard. Production tenants run Assurance Autopilot, nightly cryptographic drift checks with an Assured / Drift badge your CISO can review.
82%
Executives confident policies protect agent actions (Gravitee 2026)
~14%
Deploy agents with full security / IT approval
90s
Offline verify at verify.aevesa.com: the Prove Gap in action
Take the PMM self-assessment · Research sources
verify.aevesa.com · no login · independent verification
Reference architecture
Complement · not replacement
Already routing through an AI gateway and classifying with AI-SPM? Aevesa is the Prove layer your architecture diagram is missing.
Your gateway routes. Your AI-SPM classifies. Aevesa proves what happened.
Most platform diagrams stop at Route and Classify. The Prove box is empty. Aevesa cosigns gateway permit/deny decisions into entryHash + liability-receipt/v1 artifacts anyone verifies offline. Your GRC workflow tool holds classification dossiers; Aevesa feeds Art. 12 runtime proof into that workflow. Example stack below: Databricks + Unity AI Gateway + Cyera + Aevesa. Also works alongside Cloudflare AI Gateway, Portkey, and your existing GRC tools.
Route
MCP routing, service policies, wire-level guardrails inside Databricks.
Classify
Data-centric runtime protection, classification tags, AI-SPM inventory.
Prove
Gateway attest & ledger anchor: portable receipts bound to gateway_decision_id. Witness cosign to independent transparency log.
Verify
verify.aevesa.com · @aevesa/verify. No vendor login.
| Layer | Owner | Output |
|---|---|---|
| RouteRoute + guardrail | Unity AI Gateway | Service policies, MCP routing |
| ClassifyClassify + protect | Cyera AI Guardian | Runtime block, data classification tags |
| ProveAttest + anchor | Aevesa | entryHash + liability-receipt/v1 |
| VerifyIndependent audit | Auditor (no login) | verify.aevesa.com · @aevesa/verify |
Land with gateway attest only (one webhook after permit/deny). Complements Unity AI Gateway, Cloudflare AI Gateway, Cyera AI Guardian, Portkey, and observability or GRC sinks you already run. Expand to MCP receipt-before-action when agents run outside a managed gateway path.
Third-party trademarks. Databricks, Unity AI Gateway, Cyera, Cyera AI Guardian, Portkey, and related marks are trademarks of their respective owners. Diagrams and integration examples describe complementary patterns only; Aevesa is not affiliated with, endorsed by, or sponsored by those vendors unless we state otherwise in a signed agreement.
Aevesa routes every agent intent through two enforcement paths. Routine actions clear in milliseconds. High-stakes actions pause for a human decision, and that decision becomes a tamper-proof activity receipt.
Tamper-Proof Receipt
Every high-risk intervention generates a tamper-proof activity receipt. This isn't just a log entry; it's a non-repudiable artifact.
dh_sha256:a3f9e1c2b804d57f3a91e6c4d2b30e7a1f58c9d6e2a04b73f1c8d5e9a2b30c74
What changes when Aevesa is deployed
Agent actions are unaudited. There is no cryptographic record of what ran or why.
Every action is cryptographically logged in a SHA-256 hash chain, tamper-evident from the first call.
Gateway deny logs live in vendor-scoped Splunk. No portable proof your auditor verifies offline
Audit evidence verified offline in under 90 seconds: paste JSON at verify.aevesa.com, no vendor login
Compliance evidence is assembled manually, often costing weeks of engineer time per audit.
Audit evidence is auto-generated: signed PDF/JSON exports ready on demand.
High-risk agent actions proceed silently. The security team has no visibility or veto.
The security team gets Slack Approve/Deny on every escalation, with full context in one click.
~$4.88M average cost of an uncontrolled incident (IBM Cost of a Data Breach 2024)
Human decisions are sealed as tamper-proof activity receipts: a permanent, auditor-grade record.
IBM Cost of a Data Breach 2024 · Ponemon Institute AI Incident Research · conservative $75K/intervention floor used in SAVI dashboard
When Aevesa intercepts a high-stakes action, your team gets an instant Slack alert with agent, tool, payload preview, and ledger entryHash. Approve or deny in one click. The decision anchors to the Sovereign Ledger with a forensic link your auditors can follow.
Differentiation
AI gateways handle routing and classification. Aevesa adds the Prove layer, cosigning permit/deny decisions into tamper-proof receipts you verify offline without trusting any vendor UI.
{
"lvl": "INFO",
"_trace": "chunked…",
"ts": "2026-05-13T18:42:01.883Z",
"svc": "ai-gateway",
"rid": "req_9f2c4a",
"route": "/v1/chat/completions",
"body": "{\"messages\":[…]}",
"model": "gpt-4o",
"latency_ms": 842,
"policy_ref": null,
"signed_decision": null,
"flush": "pending_batch_7"
}
{
"schema": "liability-receipt/v1",
"receipt_id": "sr_01k8q2x7hmz",
"decision": "DENY",
"gateway_decision_id": "dbx-demo-deny-001",
"gateway_event_hash": "sha256:e3b0c44…9c2d",
"entry_hash": "merkle:0x4a91f…",
"integrity": {
"receipt_digest": "sha256:a3f9e1…30c74",
"signature_alg": "Ed25519"
},
"verify": "https://verify.aevesa.com?demo=gateway"
}
Vendor platform logs
Traffic Routing & Rate Limiting
Aevesa Prove layer
Attest + anchor decisions into portable receipts
Vendor platform logs
Operational Telemetry (Logs)
Aevesa Prove layer
Cryptographic Attestation
Vendor platform logs
Mutable JSON Logs
Aevesa Prove layer
Tamper-Proof Activity Receipts
Vendor platform logs
Internal Database Only
Aevesa Prove layer
Independent Public Verification Path · verify.aevesa.com
Vendor platform logs
Observe & log tool calls post-hoc
Aevesa Prove layer
Signed passport + inline deny; fail-closed when critical deps unavailable
Vendor platform logs
Post-incident Reviewer
Aevesa Prove layer
Selective HITL with attested receipt
| Feature | Vendor platform logs | Aevesa Prove layer |
|---|---|---|
| Primary Function | Traffic Routing & Rate Limiting | Attest + anchor decisions into portable receipts |
| Trust Model | Operational Telemetry (Logs) | Cryptographic Attestation |
| Evidence Type | Mutable JSON Logs | Tamper-Proof Activity Receipts |
| Verification | Internal Database Only | Independent Public Verification Path · verify.aevesa.com |
| Tool / MCP path | Observe & log tool calls post-hoc | Signed passport + inline deny; fail-closed when critical deps unavailable |
| Human Role | Post-incident Reviewer | Selective HITL with attested receipt |
Deploy gateways for how traffic flows. Deploy Aevesa for what was permitted. You get proofs your auditors can recompute.
Protocol layer
Open-schema agentic governance, not another monitoring add-on.
Guardrails score text; APoR governs the execution path, including tool calls, bridge traffic, and delegation hops.
Every decision anchors to the Aevesa Ledger (Merkle-secured activity ledger); proof remains independent of production logs.
Forensic-ready packs mapped to EU AI Act prEN drafts, OWASP ASI01-10, and MCPShield coverage, plus the Trust Bundle, Open Evidence API, and independent verification at verify.aevesa.com.
Prove first
Every conversation starts at verify.aevesa.com, not the dashboard. Operators use Aevesa to govern; auditors verify offline.
Mint liability-receipt/v1 artifacts and EU AI Act Art. 12/14 export packs. Anyone verifies integrity at verify.aevesa.com, no Aevesa login required.
Policy, HITL release, and separation-of-duties approvals become evidence inputs: approver identity, reaction time, and rationale bound to the receipt.
One webhook after your AI gateway permit or deny. Cosign decisions into the Aevesa Ledger without replacing routing or classification tools.
MCP receipt-before-action when agents bypass the gateway path: intent binding, schema validation, and kill switch where policy requires inline intercept.
Trust must be open-source. Enforcement must be enterprise-grade.
liability-receipt/v1 standard specification and canonical JSON schemaliability-receipt/v2 encrypted envelope + erasure fields (conformance preview)@aevesa/verify: fully stateless, zero-dependency cryptographic verification engineaegis/1 ledger pre-image, hash-chain verification, and Art. 12 manifest bundlesValue: Auditors, third-party SIEMs, and partners can independently verify the cryptographic integrity of any session receipt offline, free of vendor lock-in.
Developers
@aevesa/verify
Offline
import { verifyReceipt } from '@aevesa/verify'; const result = verifyReceipt(receiptJson); if (result.isValid) { console.log('Session cryptographic integrity verified.'); }
Five inline blocking checks translate policy rules into clear outcomes, not mutable logs you discover after an incident.
Ed25519 intent tickets lock the agent's bound mandate. Any material deviation from the bound intent triggers an immediate session revocation.
Static analysis of tool-call payloads ensures malformed schemas and injected parameters are rejected at the edge.
Cryptographic binding between your policy and the LLM endpoint prevents mid-session model-hijacking or unverified routing.
Real-time scanning for PII leakage and policy violations ensures compliance before data egress.
Cross-session analysis detects coordinated, multi-turn prompt injection sequences across your entire agent workforce.
Aevesa runs alongside your AI gateway for runtime interception, tamper-proof activity receipts, and verification, without replacing routing, auth, or quotas.
Request path
Aevesa: the protocol layer enterprises use to govern agents at machine speed.
Sidecar enforcement
<10ms overhead on typical policy paths.
Configurable fail modes
Regulated preset defaults fail-closed on dependency outages; availability mode is explicit opt-in.
Non-custodial
We never touch your provider keys; they stay in your vaults and gateway.
Centralize agentic oversight. The dashboard provides a real-time feed of blocked and permitted agent calls, sovereignty verification panels, and the cryptographic proof backing every decision. Vanguard highlights materially sensitive paths so reviewers can prioritize without leaving the stream.
External audit validation
External reviewers expect continuity between live operations and reproducible artifacts: a visible record of blocked agent paths in the governance stream, and cryptographic proof that survives export. The first frame shows MCP TOOL PDP BLOCKED events with traceable agent identity; the second shows SOVEREIGNTY VERIFIED with entryHash and ASI tags you can verify independently.
Not a testimonial: illustrative validation framing only. Technical detail in the proof model overview.
Every agent action is captured as a SHA-256 signed record, anchored to a tamper-evident log. We don’t just log history; we notarize it.
Tamper-evident, chronologically ordered event records. Each row binds to the prior anchor so silent edits fail verification.
Machine-readable packs designed for forensic auditors and internal review workflows.
EU AI Act runtime proof bundles plus optional GRC webhooks, feeding your Vanta, Drata, or auditor workflow without making sync the product story.
Tamper-evident ledger anchor · Merkle continuity
Enterprise ready
Threat model, fail modes, prEN/OWASP/MCPShield mappings, receipt verification, and PII posture. What security reviews need before a pilot.
Aevesa
Six evidence tiers (Sandbox through Fortress). Start with a verifiable receipt at verify.aevesa.com; scale to Art. 12/14 export packs and Assurance Autopilot. Contact sales for pricing and procurement.
Aevesa
Self-serve governance POC: ship a verifiable receipt to your security buyer
Free to start
Aevesa
Land with gateway attest: one webhook after permit/deny, verifiable receipts from day one
liability-receipt/v1 mint + verify.aevesa.comAevesa
Professional teams with Merkle-tree cryptographic logging and advanced hardening
Aevesa
For compliance-driven organizations standardizing governance, evidence, and identity controls
Aevesa
Enterprise governance with deployment control, custom policy, and white-glove audit execution
Aevesa
Custom deployment for global enterprises: private instance, BYOK, and hands-on audit engineering
KVR-105b · Pay-as-you-Mint
Verification on verify.aevesa.com stays free for auditors and third parties. Production ledger mints consume anchor credits. Email sales@aevesa.com for pack pricing and capacity.
Sandbox includes 1 receipt/mo; paid tiers bundle anchor credits. Contact sales for Vanguard+ allotments.
Contact for anchor creditsSHA-256 Hash Chained
AES-256 Encrypted
Runtime interception, tamper-proof activity receipts, and how Aevesa differs from gateway-only stacks or plain audit logs.
Open full FAQCompliance exports, retention, integrations, and deployment patterns.
Start with the 90-second Evidence Gap demo, then reach out when you want a briefing.
Contact Sales opens a pre-filled email to sales@aevesa.com (no copy and paste required).
Prefer web mail? Open in Gmail or Outlook web
Enterprise Trust
Proof-first governance for regulated teams: mathematical attestation, deployment control, and open evidence for reviewers.
Aevesa binds agent execution to authorized intent and issues tamper-evident receipts your security and audit teams can validate independently, including completely offline via open-source tooling (@aevesa/verify), without relying on a vendor dashboard.
Edge-first enforcement allows verification to run locally without exporting raw agent payloads or prompt text to third-party analytics pipelines. Available in SaaS, dedicated instance, and VPC/on-prem options.
Access the Trust Bundle, Open Evidence API, and liability-receipt specifications to evaluate our threat models, control mappings, and fail-closed behaviors before a pilot.
Compliance-ready infrastructure for Global Standards
Audit-ready infrastructure with complete cryptographic traceability and immutable evidence logs.
Edge-first enforcement with local verification paths. GDPR-aligned data handling and zero customer source code storage.
Enterprise-grade encryption (AES-256) with audit trail integrity and access control federation.
Ed25519
SHA-256
AES-256