Champion enablement · Internal use
Champion Enablement Kit
Everything your internal champion needs to advocate for Aevesa when you are not in the room. Share this page with your platform lead, security architect, or compliance engineer. They can print or save as PDF and forward sections to Legal, IT, Finance, and the CISO.
Sales enablement only, not legal advice. Aevesa aligns exports to common EU AI Act Art. 12/14 evidence patterns; customers remain responsible for system classification and conformity assessment.
1. Executive summary
Aevesa is the independent Prove layer for production AI agents: runtime enforcement plus offline-verifiable evidence that Legal, Compliance, and auditors can trust without logging into a vendor dashboard.
The problem
- Agents with tool access can change systems of record (payments, records, PHI, orders).
- Gateways and guardrails govern routing and model boundaries, but leave a Prove gap: no portable proof of what executed, under which policy, with which human authority.
- Most enterprises have agent policies on paper; few have full security sign-off to deploy agents in production.
What Aevesa adds
- Route → Classify → Prove: keep your gateway and AI-SPM; add Aevesa as the Prove layer on the architecture diagram.
- Intercept: block or pause high-risk tool paths before side effects.
- Decide: structured human-in-the-loop when policy requires it.
- Prove: tamper-evident receipts on the Aevesa Ledger, verifiable at verify.aevesa.com with no Aevesa login.
Business case (for economic buyer)
| Risk without Prove layer | Outcome with Aevesa |
|---|---|
| Agent production blocked; AI ROI stalled in pilot | Legal and Compliance sign-off with auditor-verifiable artifacts |
| Post-incident forensics on vendor-scoped logs | Receipt-before-action + offline integrity check in under 90 seconds |
| EU AI Act Art. 12/14 retrofit after architecture freeze | Automatic logging + human oversight packs mapped to evidence patterns |
| Single-threaded Slack approvals with no chain of custody | HITL bound to cryptographic receipt and approval identity |
Recommended land motion
Start with a 90-second Evidence Gap demo and a scoped attest or MCP proof-of-value. Expand to Art. 12/14 export packs and Assurance Autopilot once the security engineer validates offline verify.
2. Stakeholder talking points
Use the card that matches who your champion is briefing. Lead with Prove, not feature lists.
CISO / Security engineering
Pain: Agent blast radius, MCP supply chain, tool abuse at runtime.
Say: "If the ledger cannot commit, the tool does not run. Receipt-before-action is the invariant. Your team can verify a gateway deny receipt in 90 seconds without trusting our UI."
Demo: Evidence Gap + Developer verifier guide.
Compliance / Legal / Internal audit
Pain: Art. 12 logging and Art. 14 human oversight evidence; vendor-scoped JSON exports.
Say: "Your GRC tool holds the workflow. Aevesa holds the proof. Auditors paste a receipt at verify.aevesa.com and recompute integrity offline."
Attach: Trust Bundle, Enterprise verification guide.
CFO / Economic buyer
Pain: AI investment blocked; compliance retrofit cost; incident liability.
Say: "We are not buying another AI-SPM platform. We are unblocking production agent ROI with evidence Legal already asked for. Land is a scoped POC; expand when attest is live."
Frame: Cost of delayed agent deployment vs. cost of one unprovable high-risk action.
AI platform / Engineering lead (your champion)
Pain: Risk committee wants an architecture diagram with governance; MCP agents outside gateway path.
Say: "Keep Unity AI Gateway, Portkey, or Cyera for route and classify. Aevesa is the Prove layer: intercept, HITL, ledger receipts. Complement, not rip-and-replace."
Next step: Design partner / Fortress briefing.
Procurement / Vendor risk
Pain: Security questionnaire, DPA, proof of independent verification.
Say: "Open evidence: liability-receipt schema, public verify portal, Trust Bundle with OWASP ASI and EU AI Act prEN mappings. Verification does not require exporting raw prompts to a third-party analytics vendor."
3. Comparison sheet
Share when the buying committee asks "why not just use what we have?"
| Capability | Status quo (logs + policy PDF) | Gateway + guardrails only | + Aevesa Prove layer |
|---|---|---|---|
| Pre-execution block on tool calls | ✗ | Partial | ✓ |
| HITL bound to evidence chain | ✗ | ✗ | ✓ |
| Offline auditor verification | ✗ | ✗ | ✓ |
| Tamper-evident receipt chain | ✗ | ✗ | ✓ |
| EU AI Act Art. 12/14 export patterns | Manual | Partial | ✓ |
| Complements existing gateway / Cyera | N/A | ✓ | ✓ |
Kill line for platform logs: "Platform logs are vendor-scoped autopsy reports. Aevesa receipts verify offline with no Cyera login, no Databricks access, no trust in our dashboard."
4. Objection handling
Pre-answer the objections that stall deals in Legal, Security, and Procurement.
We already have an AI gateway (Portkey, Palo Alto, Unity AI Gateway).
We have prompt guardrails (Lakera, cloud safety SKUs).
We want one AI-SPM vendor, not another tool.
Microsoft released an Agent Governance Toolkit. Why not build in-house?
Our Cyera / UAG demo was enough for security.
We do not have production agents yet.
EU AI Act is too early for us.
How is this different from LangSmith / Langfuse traces?
Security review will take quarters.
What if we only use Copilot with read-only access?
5. Internal email template
Your champion can copy, personalize names, and send to their CISO, Head of Compliance, or platform steering committee.
6. Mutual action plan
Track progress with your Aevesa contact. Adjust dates to your procurement calendar.
- Week 1Champion shares this kit + Evidence Gap demo link with Security and Compliance stakeholders.
- Week 1Security engineering validates offline verify (developer guide).
- Week 230-minute briefing with platform + security + compliance (Aevesa SE optional).
- Week 2Compliance receives Trust Bundle + sample Art. 12/14 export structure review.
- Week 3Scoped POC kickoff: gateway attest webhook or MCP intercept path defined.
- Week 4POC exit: one production-representative receipt verified offline by internal audit or security.
- Week 5Commercial: security questionnaire, DPA, and economic buyer ROI review.
- Week 6+Expansion decision: Vanguard / Compliance-in-a-Box tier, GRC integration, Fortress if VPC required.
POC success criteria (agree in writing)
- At least one high-risk path intercepted or approved with HITL.
- Receipt verifies at verify.aevesa.com without Aevesa dashboard access.
- Compliance stakeholder confirms export fits their auditor workflow.
7. Conformance badge embed
Paste into slides, Notion, or partner microsites. 58 gateway checks (36 webhook + 22 OTLP) with Big Four vendor coverage.
PowerPoint / Keynote / PDF (static)
Insert picture from URL:
https://aevesa.com/assets/badges/conformance-gateway-58.svg
Live slide footer (script)
Open copy-paste page with live previews · Guide: docs/sales/CONFORMANCE_BADGE_EMBED.md