Procurement & Vendor Diligence Packet

Last updated: June 2026 · Version 1.0 · For prospective enterprise customers

This page consolidates what an enterprise procurement, information-security, and legal team needs to evaluate EVE AI Core as a vendor: a pre-answered security questionnaire, our sub-processor list, the data-flow architecture, compliance mappings, contract documents, and a step-by-step onboarding checklist. Where a control or certification is not yet in place, this page says so plainly.

How to use this packet

Most diligence questions are answered inline below. For artifacts that we share under NDA — the named sub-processor list, our most recent third-party reports as they become available, penetration-test summaries, and a countersigned MSA/DPA — email [email protected] (commercial) or [email protected] (security). We can typically return a completed CAIQ/SIG-lite within five business days.

1. Vendor & entity facts

Legal entity
EVE NeuroSystems LLC
Product
EVE AI Core · EVE CoreGuard
Registered address
3480 Preston Ridge Rd, Suite 5109, Alpharetta, GA 30005, USA
Primary hosting region
United States
Commercial contact
Security contact
Intellectual property
U.S. Patent Pending — 90 applications filed
Deployment models
SaaS, Customer VPC, Private Cloud, On-Prem

2. Documents in this packet

The following are published and linkable today. Negotiated or NDA-gated documents are noted.

Security Overview →
Encryption, access control, infrastructure, audit logging, retention.
Architecture & Data Flow →
Control-plane diagram: where data enters, how it is governed, what is logged.
Data Processing Addendum →
GDPR Art. 28 terms, sub-processors, SCCs, breach notification, deletion.
Service Level Agreement →
Uptime tiers, latency, incident response, service credits.
Master Service Agreement →
Standard enterprise terms: liability, IP, warranties, term & termination.
Privacy Policy →
What we collect, why, and the rights available to data subjects.
Trust Center →
Verifiable claims, offline evidence verification, stated assumptions.
Patent Portfolio →
The defensibility position behind the governance control plane.

3. Security questionnaire (pre-answered)

Answers reflect EVE AI Core's current posture. Certifications still in progress are labeled honestly — we do not represent a control as achieved until it is.

Data protection

ControlStatusDetail
Encryption in transitIn placeTLS 1.2+/1.3 for all client and inter-service traffic.
Encryption at restIn placeAES-256 for stored data, including audit-log persistence.
Tenant isolationIn placePer-tenant governance state and audit chains; isolation enforced at the application and data layers.
Data residencyIn placePrimary hosting in the United States. Customer VPC, Private Cloud, and On-Prem deployments keep data in the customer's chosen region/boundary.
Data deletion / right to erasureIn placeCustomer-initiated deletion across memory layers; HMAC-signed, hash-chained deletion receipts evidence erasure.

Access & identity

ControlStatusDetail
AuthenticationIn placeJWT-based sessions; scoped API keys for programmatic access.
Multi-factor authenticationIn placeTOTP-based MFA available for accounts; recommended for administrative access.
Role-based access controlIn placeFive roles (Viewer, Operator, Approver, Admin, Platform Admin) with least-privilege enforcement and tenant scoping.
Secrets managementIn placeManaged secrets store; no reliance on environment defaults for production secrets.
Audit loggingIn placeTamper-evident, hash-chained, cryptographically signed (HMAC / Ed25519) decision and administrative event records; 7-year retention available.

Operations & resilience

ControlStatusDetail
Backups & recoveryIn placeAutomated backups with documented rotation; restoration procedures maintained.
Monitoring & alertingIn placeUptime, latency, and error monitoring; customer-visible status at /status.
Incident responseIn placeDocumented incident-response process; severity classification (P1–P4) defined in the SLA.
Breach notificationIn placeNotification without undue delay and within 72 hours of becoming aware (see DPA §9).
Vulnerability disclosureIn placeCoordinated disclosure to [email protected].
Independent penetration testingOn request / scheduledSummaries shared under NDA as they are completed; scope and cadence discussed during diligence.

Certifications & attestations

FrameworkStatusDetail
SOC 2 Type IIIn progressControls aligned; attestation not yet issued. We will not represent it as complete until the report exists.
ISO/IEC 27001PlannedOn the compliance roadmap; not yet initiated for certification.
GDPR / UK GDPRAddressedProcessor terms, SCCs, and breach process in the DPA.
CCPA / CPRAAddressedCovered by the DPA and Privacy Policy.

Honest status: SOC 2 Type II is in progress and ISO 27001 is planned. If your procurement gate requires a completed attestation today, tell us — we will scope a path and timeline rather than overstate readiness.

4. Sub-processors

EVE engages a limited set of sub-processors to operate the Services. Categories and regions are below; an up-to-date named list is available under NDA on request. Optional third-party LLM providers act as sub-processors only for requests the customer elects to route to them (or where the customer supplies its own keys).

CategoryPurposeRegion
Cloud infrastructure / hostingCompute, storage, and network hostingUnited States
Managed data storesOperational databases, caching, audit-log persistenceUnited States
Transactional email / notificationsAccount, security, and billing notificationsUnited States
Payment processingSubscription billing and invoicingUnited States
Error monitoring / observabilityService reliability and incident responseUnited States

Source of truth: DPA §6. Named list on request at [email protected].

5. Data flow & architecture

EVE is a deterministic governance control plane: a proposed action is evaluated against versioned policy before execution, a signed decision-evidence record is produced, and that record is appended to a tenant-bound, hash-chained audit log. The full visual data-flow diagram — including where customer data enters, what is and isn't retained, and how evidence is generated — is on the Architecture & Data Flow page.

6. Compliance mappings

EVE produces the evidence and controls that map to common regulatory obligations. These are mappings to obligations, not legal advice or a certification of compliance for your specific program.

EU AI Act →
Risk classification, obligation mapping, gap analysis, roadmap.
ECOA / FCRA (Lending) →
Adverse-action and fair-lending evidence for credit decisions.
Healthcare →
Governed clinical-AI oversight and audit evidence.
Governed-decision scenarios →
Worked examples across regulated domains.

7. Vendor onboarding checklist

A typical path from first diligence to production:

  1. Intake & NDA — mutual NDA so we can share named sub-processors, test summaries, and draft contracts.
  2. Security review — we return a completed CAIQ/SIG-lite and answer your questionnaire; security team reviews this packet, the Security Overview, and Architecture.
  3. Legal review — redline the MSA, DPA, and SLA; agree liability, residency, and term.
  4. Deployment decision — choose SaaS, Customer VPC, Private Cloud, or On-Prem (see deployment models) based on data-residency and isolation needs.
  5. Pilot — scope one real workflow via the Design Partner Program; produce live signed evidence on your data.
  6. Production — countersign, provision, and roll out with agreed SLAs and support.

Start diligence

Send your security questionnaire or procurement requirements to [email protected], or reach the security team directly at [email protected]. Prefer to evaluate hands-on first? Begin with the Design Partner Program or request a demo.