Accountability Infrastructure

The Prove Layer for Agentic AI

Not another AI-SPM dashboard. Aevesa is accountability infrastructure: gateways govern what can happen; we prove what did happen (permit or deny) with liability-receipt/v1 artifacts auditors verify offline, without logging into Cyera, Databricks, or Aevesa.

Agentic Evidence Infrastructure · Prove specialty inside AI-SPM · EU AI Act Art. 12/14/73 export-ready

The Evidence Gap

Platform logs are vendor-scoped. Proof must be portable.

AI gateways and AI-SPM platforms govern what agents can touch. Aevesa proves what happened.

Intercept and classify layers leave a gap in the architecture diagram: no portable proof an external auditor can verify offline. Regulated teams cannot sign off on agent deployments using vendor-scoped JSON alone. Paste a receipt at verify.aevesa.com and recompute integrity in under 90 seconds. No login required. Aevesa cosigns material decisions to an independent witness log, not another platform dashboard. Production tenants run Assurance Autopilot, nightly cryptographic drift checks with an Assured / Drift badge your CISO can review.

82%

Executives confident policies protect agent actions (Gravitee 2026)

~14%

Deploy agents with full security / IT approval

90s

Offline verify at verify.aevesa.com: the Prove Gap in action

Take the PMM self-assessment · Research sources

Reference architecture

Complement · not replacement

Finish the stack. Don’t replace it.

Already routing through an AI gateway and classifying with AI-SPM? Aevesa is the Prove layer your architecture diagram is missing.

Your gateway routes. Your AI-SPM classifies. Aevesa proves what happened. Most platform diagrams stop at Route and Classify. The Prove box is empty. Aevesa cosigns gateway permit/deny decisions into entryHash + liability-receipt/v1 artifacts anyone verifies offline. Your GRC workflow tool holds classification dossiers; Aevesa feeds Art. 12 runtime proof into that workflow. Example stack below: Databricks + Unity AI Gateway + Cyera + Aevesa. Also works alongside Cloudflare AI Gateway, Portkey, and your existing GRC tools.

Route

Unity AI Gateway

MCP routing, service policies, wire-level guardrails inside Databricks.

Classify

Cyera AI Guardian

Data-centric runtime protection, classification tags, AI-SPM inventory.

Prove

Aevesa

Gateway attest & ledger anchor: portable receipts bound to gateway_decision_id. Witness cosign to independent transparency log.

Layer Owner Output
RouteRoute + guardrail Unity AI Gateway Service policies, MCP routing
ClassifyClassify + protect Cyera AI Guardian Runtime block, data classification tags
ProveAttest + anchor Aevesa entryHash + liability-receipt/v1
VerifyIndependent audit Auditor (no login) verify.aevesa.com · @aevesa/verify

Land with gateway attest only (one webhook after permit/deny). Complements Unity AI Gateway, Cloudflare AI Gateway, Cyera AI Guardian, Portkey, and observability or GRC sinks you already run. Expand to MCP receipt-before-action when agents run outside a managed gateway path.

Third-party trademarks. Databricks, Unity AI Gateway, Cyera, Cyera AI Guardian, Portkey, and related marks are trademarks of their respective owners. Diagrams and integration examples describe complementary patterns only; Aevesa is not affiliated with, endorsed by, or sponsored by those vendors unless we state otherwise in a signed agreement.

Decision Layer

Every Action Has a Path. High-Risk Gets a Human.

Aevesa routes every agent intent through two enforcement paths. Routine actions clear in milliseconds. High-stakes actions pause for a human decision, and that decision becomes a tamper-proof activity receipt.

Fast Pass
Low Risk → Instant Clearance
  1. 1 Agent submits intent to Aevesa for runtime interception
  2. 2 Heuristic Risk Analyzer scores intent below threshold
  3. 3 Crypto passport issued, action proceeds, SHA-256 entry written to ledger
avg latency: <12ms · fully automated
Slow Pass
High Risk → Human Decision Required
The Hero Feature
  1. 1 Consequence Twin simulates the action in a sandboxed environment
  2. 2 Slack notification fires with Approve / Deny buttons to the security team
  3. 3
    Human decision generates a unique tamper-proof activity receiptrecorded in the Aevesa Ledger
  4. 4 Dashboard timeline shows the full chain: Agent → Intercept → Approval → Receipt
immutable proof · auditor-grade · SOC 2 Type II Ready

Tamper-Proof Receipt

The Cryptographic Activity Receipt

Every high-risk intervention generates a tamper-proof activity receipt. This isn't just a log entry; it's a non-repudiable artifact.

dh_sha256:a3f9e1c2b804d57f3a91e6c4d2b30e7a1f58c9d6e2a04b73f1c8d5e9a2b30c74

  • Immutable: Anchored to the Aevesa Ledger at the moment of approval.
  • Portable: Share receipts with security teams or regulators without exposing underlying payloads.
  • Verifiable: Stakeholders can validate integrity independently via verify.aevesa.com.

What changes when Aevesa is deployed

Agent actions are unaudited. There is no cryptographic record of what ran or why.

Every action is cryptographically logged in a SHA-256 hash chain, tamper-evident from the first call.

Gateway deny logs live in vendor-scoped Splunk. No portable proof your auditor verifies offline

Audit evidence verified offline in under 90 seconds: paste JSON at verify.aevesa.com, no vendor login

Compliance evidence is assembled manually, often costing weeks of engineer time per audit.

Audit evidence is auto-generated: signed PDF/JSON exports ready on demand.

High-risk agent actions proceed silently. The security team has no visibility or veto.

The security team gets Slack Approve/Deny on every escalation, with full context in one click.

~$4.88M average cost of an uncontrolled incident (IBM Cost of a Data Breach 2024)

Human decisions are sealed as tamper-proof activity receipts: a permanent, auditor-grade record.

IBM Cost of a Data Breach 2024 · Ponemon Institute AI Incident Research · conservative $75K/intervention floor used in SAVI dashboard

Human-in-the-Loop

Active Gating: Approve or deny in Slack.

When Aevesa intercepts a high-stakes action, your team gets an instant Slack alert with agent, tool, payload preview, and ledger entryHash. Approve or deny in one click. The decision anchors to the Sovereign Ledger with a forensic link your auditors can follow.

  • Contextual Alerts: Instant visibility into the ‘Why’ behind every interception.
  • Slack Handshake: One-click approve or block override without leaving your workspace.
  • Verified Links: Every alert carries a direct link to the cryptographically signed audit trail in the Evidence Vault.
Slack · #governance-alerts
Slack HITL alert: void_transaction blocked pending sign-off with Approve and Deny buttons, ledger entryHash, and Aevesa forensic entry links
Pending path: HITL_APPROVAL_REQUIRED with one-click Approve / Deny in #governance-alerts.

Differentiation

Gateways Route. Aevesa Attests.

AI gateways handle routing and classification. Aevesa adds the Prove layer, cosigning permit/deny decisions into tamper-proof receipts you verify offline without trusting any vendor UI.

Passive Observability
{
  "lvl": "INFO",
  "_trace": "chunked…",
  "ts": "2026-05-13T18:42:01.883Z",
  "svc": "ai-gateway",
  "rid": "req_9f2c4a",
  "route": "/v1/chat/completions",
  "body": "{\"messages\":[…]}",
  "model": "gpt-4o",
  "latency_ms": 842,
  "policy_ref": null,
  "signed_decision": null,
  "flush": "pending_batch_7"
}
Deterministic Proof Verified
{
  "schema": "liability-receipt/v1",
  "receipt_id": "sr_01k8q2x7hmz",
  "decision": "DENY",
  "gateway_decision_id": "dbx-demo-deny-001",
  "gateway_event_hash": "sha256:e3b0c44…9c2d",
  "entry_hash": "merkle:0x4a91f…",
  "integrity": {
    "receipt_digest": "sha256:a3f9e1…30c74",
    "signature_alg": "Ed25519"
  },
  "verify": "https://verify.aevesa.com?demo=gateway"
}

Primary Function

Vendor platform logs

Traffic Routing & Rate Limiting

Aevesa Prove layer

Attest + anchor decisions into portable receipts

Trust Model

Vendor platform logs

Operational Telemetry (Logs)

Aevesa Prove layer

Cryptographic Attestation

Evidence Type

Vendor platform logs

Mutable JSON Logs

Aevesa Prove layer

Tamper-Proof Activity Receipts

Verification

Vendor platform logs

Internal Database Only

Aevesa Prove layer

Independent Public Verification Path  · verify.aevesa.com

Tool / MCP path

Vendor platform logs

Observe & log tool calls post-hoc

Aevesa Prove layer

Signed passport + inline deny; fail-closed when critical deps unavailable

Human Role

Vendor platform logs

Post-incident Reviewer

Aevesa Prove layer

Selective HITL with attested receipt

Deploy gateways for how traffic flows. Deploy Aevesa for what was permitted. You get proofs your auditors can recompute.

Protocol layer

Agent Protocol of Record (APoR)

Open-schema agentic governance, not another monitoring add-on.

Beyond Guardrails

Guardrails score text; APoR governs the execution path, including tool calls, bridge traffic, and delegation hops.

Cryptographic Accountability

Every decision anchors to the Aevesa Ledger (Merkle-secured activity ledger); proof remains independent of production logs.

Evidence-Grade Compliance

Forensic-ready packs mapped to EU AI Act prEN drafts, OWASP ASI01-10, and MCPShield coverage, plus the Trust Bundle, Open Evidence API, and independent verification at verify.aevesa.com.

Prove first

How It Works

Every conversation starts at verify.aevesa.com, not the dashboard. Operators use Aevesa to govern; auditors verify offline.

Prove

Mint liability-receipt/v1 artifacts and EU AI Act Art. 12/14 export packs. Anyone verifies integrity at verify.aevesa.com, no Aevesa login required.

Decide

Policy, HITL release, and separation-of-duties approvals become evidence inputs: approver identity, reaction time, and rationale bound to the receipt.

Attest

One webhook after your AI gateway permit or deny. Cosign decisions into the Aevesa Ledger without replacing routing or classification tools.

Enforce

MCP receipt-before-action when agents bypass the gateway path: intent binding, schema validation, and kill switch where policy requires inline intercept.

Open Governance Protocol

Built on an Open Standard.

Trust must be open-source. Enforcement must be enterprise-grade.

Open source

Kovera Protocol of Record

  • liability-receipt/v1 standard specification and canonical JSON schema
  • liability-receipt/v2 encrypted envelope + erasure fields (conformance preview)
  • @aevesa/verify: fully stateless, zero-dependency cryptographic verification engine
  • aegis/1 ledger pre-image, hash-chain verification, and Art. 12 manifest bundles
  • Reference test profiles and canonical golden spec vectors

Value: Auditors, third-party SIEMs, and partners can independently verify the cryptographic integrity of any session receipt offline, free of vendor lock-in.

Commercial

Aevesa Enterprise Plane

  • Genesis runtime interception (inline blocking and runtime tool-gating)
  • Deterministic Human-in-the-Loop (HITL) cryptographic signing services
  • Multi-tenant Aevesa Ledger write-paths, secure organization isolation, and compliance sinks
  • High-assurance Operator Dashboard and interactive Auditor Portal UX

Developers

Verify any receipt without our platform

TypeScript · @aevesa/verify Offline
import { verifyReceipt } from '@aevesa/verify';

const result = verifyReceipt(receiptJson);
if (result.isValid) {
  console.log('Session cryptographic integrity verified.');
}
Core Technology

The Evidence-Grade Gauntlet · L1-L5

Five inline blocking checks translate policy rules into clear outcomes, not mutable logs you discover after an incident.

L1 · Intent Binding

Ed25519 intent tickets lock the agent's bound mandate. Any material deviation from the bound intent triggers an immediate session revocation.

L2 · Schema Enforcement

Static analysis of tool-call payloads ensures malformed schemas and injected parameters are rejected at the edge.

L3 · Provider Attestation

Cryptographic binding between your policy and the LLM endpoint prevents mid-session model-hijacking or unverified routing.

L4 · Content Redaction

Real-time scanning for PII leakage and policy violations ensures compliance before data egress.

L5 · Collective Defense

Cross-session analysis detects coordinated, multi-turn prompt injection sequences across your entire agent workforce.

Architecture

Where Aevesa sits in the request path.

Aevesa runs alongside your AI gateway for runtime interception, tamper-proof activity receipts, and verification, without replacing routing, auth, or quotas.

Request path

Flow from App through Gateway and Aevesa mediator to LLM App Gateway Aevesa (Mediator) LLM

Aevesa: the protocol layer enterprises use to govern agents at machine speed.

Sidecar enforcement

<10ms overhead on typical policy paths.

Configurable fail modes

Regulated preset defaults fail-closed on dependency outages; availability mode is explicit opt-in.

Non-custodial

We never touch your provider keys; they stay in your vaults and gateway.

Sovereign Visibility

Your Entire AI Workforce. One Governance Dashboard.

Centralize agentic oversight. The dashboard provides a real-time feed of blocked and permitted agent calls, sovereignty verification panels, and the cryptographic proof backing every decision. Vanguard highlights materially sensitive paths so reviewers can prioritize without leaving the stream.

External audit validation

External reviewers expect continuity between live operations and reproducible artifacts: a visible record of blocked agent paths in the governance stream, and cryptographic proof that survives export. The first frame shows MCP TOOL PDP BLOCKED events with traceable agent identity; the second shows SOVEREIGNTY VERIFIED with entryHash and ASI tags you can verify independently.

Not a testimonial: illustrative validation framing only. Technical detail in the proof model overview.

Evidence Vault

Signed Evidence & Compliance Sync.

Every agent action is captured as a SHA-256 signed record, anchored to a tamper-evident log. We don’t just log history; we notarize it.

SHA-256 Aevesa Ledger anchoring

Tamper-evident, chronologically ordered event records. Each row binds to the prior anchor so silent edits fail verification.

JSON + PDF exports

Machine-readable packs designed for forensic auditors and internal review workflows.

Art. 12/14 export packs

EU AI Act runtime proof bundles plus optional GRC webhooks, feeding your Vanta, Drata, or auditor workflow without making sync the product story.

app.aevesa.com · evidence vault
Aevesa Evidence Vault: sovereignty verification with entryHash, public truth ASI tags, and Merkle chain proof continuity check

Tamper-evident ledger anchor · Merkle continuity

Enterprise ready

Trust Bundle

Threat model, fail modes, prEN/OWASP/MCPShield mappings, receipt verification, and PII posture. What security reviews need before a pilot.

Aevesa

Offline-verifiable proof for every material agent action, with a dashboard for operators, not auditors.

Six evidence tiers (Sandbox through Fortress). Start with a verifiable receipt at verify.aevesa.com; scale to Art. 12/14 export packs and Assurance Autopilot. Contact sales for pricing and procurement.

Aevesa

The Sandbox

Self-serve governance POC: ship a verifiable receipt to your security buyer

Free to start

  • · 1 Shareable Tamper-Proof Receipt / mo
  • · 100 Guarded Actions / mo Automated pause after 100 actions to prevent unintended cost or drift
  • · Single Developer Workspace
  • · Baseline Policy Checks
  • · Self-Guided Documentation Access
Start free Build the governance loop yourself with a Tamper-Proof Receipt and verify.aevesa.com included

Aevesa

Operational Shield

Land with gateway attest: one webhook after permit/deny, verifiable receipts from day one

  • Gateway Attest Webhook (Unity, Cloudflare, Portkey-class)
  • liability-receipt/v1 mint + verify.aevesa.com
  • MCP receipt-before-action (expand path)
  • 30-Day Audit Log Retention
Contact Sales
Merkle-Secured Ledger

Aevesa

Vanguard

Professional teams with Merkle-tree cryptographic logging and advanced hardening

  • Merkle-Tree Cryptographic Audit Logging
  • Tamper-Evident Log Chain with Root Hash Export
  • TeamPCP Supply Chain Attack Mitigations
  • Vanguard-Tier Security Hardening Features
  • Evidence of Care Programme Features
Contact Sales
Recommended

Aevesa

Compliance-in-a-Box

For compliance-driven organizations standardizing governance, evidence, and identity controls

  • EU AI Act Art. 12/14 Export Packs
  • GRC-compatible evidence feed (when you configure webhooks)
  • Signed Audit Evidence Exports
  • Role-Based Access Control
Contact Sales

Aevesa

The Sovereign

Enterprise governance with deployment control, custom policy, and white-glove audit execution

  • Dedicated Instance
  • Private Cloud, VPC, or On-Prem Deployment
  • Custom Policy Engine & Control Mappings
  • White-Glove Audit Support
  • SSO / SAML, Procurement & Contractual SLA Terms
Contact Sales

Aevesa

The Fortress

Custom deployment for global enterprises: private instance, BYOK, and hands-on audit engineering

  • Private Instance (VPC or On-Prem)
  • Customer-Managed Keys (BYOK)
  • White-Glove Audit Support
  • Custom Policy Engine Development
Contact Sales

KVR-105b · Pay-as-you-Mint

Anchor credit packs

Verification on verify.aevesa.com stays free for auditors and third parties. Production ledger mints consume anchor credits. Email sales@aevesa.com for pack pricing and capacity.

Sandbox includes 1 receipt/mo; paid tiers bundle anchor credits. Contact sales for Vanguard+ allotments.

Contact for anchor credits
SHA-256 Hash Chained
AES-256 Encrypted
SOC 2 Type II Ready

Frequently Asked Questions

Runtime interception, tamper-proof activity receipts, and how Aevesa differs from gateway-only stacks or plain audit logs.

Open full FAQ

Compliance exports, retention, integrations, and deployment patterns.

Ready to see Aevesa in action?

Start with the 90-second Evidence Gap demo, then reach out when you want a briefing.

Contact Sales opens a pre-filled email to sales@aevesa.com (no copy and paste required).

team@aevesa.com

Prefer web mail? Open in Gmail or Outlook web

Enterprise Trust

Enterprise Trust & Operational Sovereignty

Proof-first governance for regulated teams: mathematical attestation, deployment control, and open evidence for reviewers.

Verification-First Governance

Aevesa binds agent execution to authorized intent and issues tamper-evident receipts your security and audit teams can validate independently, including completely offline via open-source tooling (@aevesa/verify), without relying on a vendor dashboard.

Deployment Control & Data Minimization

Edge-first enforcement allows verification to run locally without exporting raw agent payloads or prompt text to third-party analytics pipelines. Available in SaaS, dedicated instance, and VPC/on-prem options.

Open Evidence for Reviewers

Access the Trust Bundle, Open Evidence API, and liability-receipt specifications to evaluate our threat models, control mappings, and fail-closed behaviors before a pilot.

Built for Enterprise

Compliance-ready infrastructure for Global Standards

SOC 2 Type II Ready

Audit-ready infrastructure with complete cryptographic traceability and immutable evidence logs.

GDPR-Aligned Protocol

Edge-first enforcement with local verification paths. GDPR-aligned data handling and zero customer source code storage.

HIPAA Compliant Architecture

Enterprise-grade encryption (AES-256) with audit trail integrity and access control federation.

Production fail-closed default
MCP gate p99 ≤ 8 ms (harness)
Crypto Ed25519 SHA-256 AES-256