One gate, in front of everything
EVE CoreGuard is the enforcement plane: it consumes a proposed action, applies the tenant's policy packs, and returns a binding disposition that the evidence plane then signs. The gate cannot be bypassed by what it governs.
One gate, in front of everything
EVE CoreGuard is the enforcement plane: it consumes a proposed action, applies the tenant's policy packs, and returns a binding disposition that the evidence plane then signs.
Where enforcement sits in the stack
EVE CoreGuard is the middle plane of the EVE control-plane stack. Governance decides the policy, CoreGuard enforces it before execution, and EVE Proof attests to what happened — each plane independent and auditable.
Governance decides →
Deterministic policy — the same verdict every time, with a reason. The rules CoreGuard enforces are defined here.
CoreGuard enforces
The pre-execution gate. It blocks, allows, or modifies the action before it reaches the world — fail-closed by default.
Proof attests →
Every decision is signed into a certificate anyone can verify offline. CoreGuard cannot rewrite the evidence — only produce it.
The gate cannot be bypassed by what it governs
Enforcement only means something if it cannot be routed around. EVE CoreGuard is positioned so the proposed action must pass through the gate to reach the downstream system — the tool, the model output, the API call. There is no "fast path" that skips evaluation, and a failure to evaluate resolves to a block, not a pass.
The evidence plane sits strictly downstream: EVE Proof can witness and sign a verdict, but it cannot change one. That separation is deliberate — the system that produces the record is not the system that could be pressured to alter the decision. Read how the evidence is signed and verified on EVE Proof.
Common questions
Where does EVE CoreGuard sit in the architecture?
Can the enforcement gate be bypassed?
Does CoreGuard also produce the audit evidence?
Request a Design Partner Pilot
Put EVE CoreGuard in front of one real, high-stakes AI workflow. We'll stand up a policy pack, wire the gate, and show you blocked actions with signed evidence.