Reference Scenarios

How EVE Governs Real Decisions

A model makes a recommendation. EVE governs it, issues a signed certificate, and an examiner verifies it independently. The same pattern, in every regulated workflow.

Controls aligned to ECOA / Reg B SR 26-2 FCRA HIPAA EU AI Act NIST AI RMF SOC 2 Type II in progress

You control which decision fields are sent; in VPC and on-prem deployments, governed content and evidence stay inside your boundary. With EU AI Act GPAI-model obligations applicable since 2 August 2025 and high-risk-system obligations phasing in from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) under Regulation (EU) 2026/1744, and with SR 26-2 (the April 2026 interagency model-risk guidance that superseded SR 11-7, applied primarily to banking organizations above $30B in total consolidated assets) excluding generative and agentic AI from its formal scope while still expecting such technologies to be governed, the record has to exist at the moment of the decision.  Trust Center · Security

Framework mappings describe technical control support and evidence capabilities. They do not constitute legal advice, regulatory certification, or a guarantee that a customer’s deployment is compliant. “SOC 2 Type II — In Progress” means an independent SOC 2 Type II audit is engaged (Decrypt CPA, via Scytale) and the observation period is underway; it is not a completed audit or an issued attestation.

Illustrative scenarios using EVE's actual policy packs and evidence pipeline. Names and figures are representative.
Mortgage Underwriting · Lending

An AI-assisted loan decision an examiner can trust

A bank's underwriting copilot uses GPT-4o to recommend approve/deny on consumer mortgages. Compliance needs every AI-influenced decision to be defensible under ECOA / fair-lending exam.

  1. The model recommends
    The copilot (OpenAI via the Integration Hub) returns "approve, confidence 0.91" for applicant #48291.
  2. EVE governs the decision
    CoreGuard evaluates it against lending_v1 + fair_lending_v1 + eu_ai_act_v1 — credit score, DTI, employment verification, and prohibited-basis checks. Deterministic, no LLM in the decision path.
  3. A disposition is returned
    ALLOWED / BLOCKED / MODIFIED with the winning rule and a plain-language justification — surfaced to the officer before the decision is acted on.
  4. A signed certificate is issued
    A Governed Decision Certificate is generated and signed (ECDSA P-384), linking the request, policy version, risk score, and verdict.
  5. Lineage & replay are recorded
    The retrieval source (Snowflake credit features) is recorded as signed lineage; the decision is deterministically replayable to the same verdict.
  6. The examiner verifies — independently
    At exam time, the examiner pastes the certificate into /verify and confirms it against EVE's published key. No EVE account. No live connection to EVE required.
decision : EVE-48291 ALLOWED policy_set : lending_v1 (+ fair_lending_v1, eu_ai_act_v1) risk : LOW (0.21) prohibited_basis: none model : openai/gpt-4o confidence: 0.91 proof_hash : sha256-6cb65e245246ac8cd9f1… signature : kms-ecdsa-p384-9e0c787b2ae0… VERIFIED replay : reproduced (ALLOWED)
Verify a sample record yourself →
Healthcare · Clinical Support

Clinical decision support, governed

A care-management assistant (Claude) suggests a treatment pathway. EVE governs it against healthcare_v1 and telehealth_prescribing_v1 — scope-of-practice, contraindications, and PHI handling — and blocks anything that crosses a clinical boundary. Every suggestion that reaches a clinician carries a signed evidence record.

Banking · AML

Transaction screening with an audit trail

An AML copilot flags a transaction as low-risk. EVE governs it under banking_aml_v1, captures the reasoning and the data it touched, and forwards the governed event to the SOC's SIEM (Splunk / Sentinel). When an investigator asks "why was this cleared?", the answer is a signed, replayable record.

Enterprise · RAG Copilot

Knowledge answers with provenance

An internal copilot (LlamaIndex) answers from company documents. EVE governs the retrieval — recording which sources were cited and verifying citations — so a leaked-data or wrong-source incident has an evidence trail, not a guess. Document access is signed lineage.

Insurance · Claims

Adjudication you can defend

A claims model recommends a denial. EVE governs it under insurance_v1, requires the justification to cite policy terms, and issues a certificate the regulator — or the policyholder's counsel — can verify independently.

Verify our evidence Deploy in your environment Start a design-partner pilot