Enterprise diligence
Aevesa Trust Bundle
Technical evidence pack for security reviews and pilot diligence: infrastructure topology, fail-mode matrix, EU AI Act prEN alignment, OWASP Agentic controls, MCPShield coverage, and published SLOs.
Technical evidence only, not legal advice or an EU AI Act conformity certificate. Customers remain responsible for system classification and legal assessment.
Enterprise trust & operational sovereignty
- Verification-first governance. Tamper-evident receipts bound to authorized intent; validate offline with
@aevesa/verifywithout relying on a vendor dashboard. - Deployment control & data minimization. Edge-first enforcement; verification can run locally without exporting raw agent payloads or prompt text to third-party analytics. SaaS, dedicated instance, and VPC/on-prem options.
- Open evidence for reviewers. This bundle, the Open Evidence API, and
liability-receiptspecifications for threat models, control mappings, and fail-closed behavior review before a pilot.
Receipt-before-action invariant Phase 2
1Agent invokes
tools/call → MCP bridge forwards to governance gate.↓
2Gate runs AttestMCP schema pin, supply-chain scan, FDLP, lineage, behavioral preflight.
↓
3Permit commit:
commitToolPermitReceiptOrThrow() writes MCP_TOOL_GOVERNANCE_ALLOWED with pepInvariant: receipt_before_action/v1.↓
4Only after
entryHash returns → downstream tool executes. Offline verify via @aevesa/verify.↓ fail-closed branch
✕Ledger unavailable → tool blocked; deny row best-effort. Conformance:
npm run test:phase2-conformance.Fortress PDP & autonomy ladder Phase 3
- Out-of-process PDP. Optional
aevesa-pdp-sidecar: policy decisions in an isolated process an RCE-compromised app cannot rewrite (docker compose --profile fortress). - Evidence-based autonomy. Agents earn write authority from verifiable receipt history (Observer → Autonomous tiers via
GET /api/v1/governance/evidence-portfolio/:agentId). - GDPR v2 erasure. Art. 12 packs include crypto-shred erasure certificates; Merkle chain stays intact. Fortress tier: HSM-backed DEK wrap (roadmap).
Dual-vendor architecture · Cyera + Databricks AI-SPM Phase 4
Core documents (Phase 1 + 2a)
- Infrastructure, HA & fail modes
- EU AI Act prEN conformance matrix
- OWASP ASI01-10 control matrix
- MCPShield coverage matrix 70% documented
- Consolidated threat model
- PEP / PDP architecture
- Art. 14 human oversight checklist
- Receipt-before-action conformance open standard
- Open standards index open standard
- Cryptographic vs declarative evidence open standard
- receipt-before-action/v1 badge & spec
- Conformance Lab v1: open programs & interop