Listing Thumbnail

    Kevros AI Governance Gateway

     Info
    Deployed on AWS
    Cryptographic interlock for autonomous AI agents. Six-layer formally verified kernel issues a signed ALLOW, CONSTRAIN, or DENY verdict before any action executes. Hash-chained evidence. Fail-closed.

    Overview

    Kevros AI Governance Gateway enforces verifiable governance on every AI agent decision before execution.

    Autonomous AI agents are making high-stakes decisions at machine speed. Compliance infrastructure built for human-paced workflows cannot keep up. Kevros closes that gap. Every agent action receives a signed ALLOW, CONSTRAIN, or DENY verdict before it executes. Use cases include agent-initiated trade workflows, automated claims handling, industrial control supervision, and payment authorization. If governance is unreachable, execution halts. No exceptions. No silent failures.

    Deploys inside your AWS account using AWS CloudFormation, Amazon ECS on AWS Fargate, Application Load Balancer, Amazon EFS, AWS Secrets Manager, and Amazon CloudWatch. Customer data and signing keys are not transmitted outside your account by default.

    Six-Layer Formal Verification Kevros is the only AI governance offering on AWS Marketplace with end-to-end formal verification of the enforcement kernel. Six independent verification layers spanning model checking, SMT proofs, bounded checks, runtime assertions, cross-language vector regression, and interactive theorem proving collectively explore 1.94 billion system states and produce 71 SMT proofs and 20 mechanically-checked theorems with zero counterexamples and zero unproven assumptions.

    Why Kevros Tamper-evident provenance ledger. Every governance decision is recorded in a hash-chained, append-only ledger on Amazon EFS. Auditors verify chain integrity using the published verifier specification.

    Fail-closed architecture. Governance unavailability triggers automatic execution blocking. Agents cannot circumvent oversight under any failure condition. Dual-lane post-quantum signatures. ML-DSA-87 (FIPS 204) anchors every 100-record block of the hash-chained ledger. SLH-DSA-SHA2-256f (FIPS 205) provides the off-chain co-signing lane on settlement-class events. Quantum-resistant from day one.

    Tier-conditioned rate limiting. Per-tier API Gateway UsagePlan throttling at the publisher edge. Free Trial 5 requests per second; Starter 25; Professional 50; Enterprise 200.

    ML behavioral drift detection. Latency-drift and semantic-drift monitors flag anomalous agent behavior before violations materialize. CloudWatch and CEF observability. Container metrics and governance events surface in CloudWatch dashboards. CEF-formatted syslog export for any CEF-capable collector.

    Built for AWS Deploys via AWS CloudFormation as a customer-side stack. Talon classifier inference runs in the TaskHawk publisher account; classifier weights never enter the customer image. Image is signed with cosign against an AWS KMS key; signatures verify against the publisher KMS public key.

    Compliance-Aligned Evidence Generates evidence designed to support governance reviews under NIST AI RMF, EU AI Act risk classification (Annex III), and SOC 2 control families. Hash-chained decision records, post-quantum-signed block roots, and certifier-grade evidence bundles in auditor-ready format. Kevros provides verifiable technical evidence; it does not replace your compliance program, risk assessment obligations, or legal determinations.

    Plans Free Trial. $0 per month. 1,000 calls. Hash-chained evidence. Starter. $499 per month. 100,000 calls. Production capacity. Professional. $1,499 per month. 1,000,000 calls. Adds ML drift plus dual-lane post-quantum signing. Enterprise. $4,999 per month. 5M inclusive calls plus AWS Marketplace metered overage. Adds fleet drift, CEF syslog export, evidence bundles.

    Click Continue to Subscribe to deploy in your AWS account. Typical deployment under 20 minutes.

    Highlights

    • Six-layer formal verification: 1.94B states, 71 proofs, 0 sorry. Zero property violations.
    • Dual-lane post-quantum signing: ML-DSA-87 (FIPS 204) and SLH-DSA-SHA2-256f (FIPS 205) on every record.
    • Hash-chained evidence on Amazon EFS. Fail-closed architecture. Deploys in your AWS account.

    Details

    Delivery method

    Type

    Supported services

    Delivery option
    MCP server on Amazon Bedrock AgentCore Runtime
    A2A server on Amazon Bedrock AgentCore Runtime
    Container image (ECS + EKS)

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Kevros AI Governance Gateway

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (4)

     Info
    Dimension
    Description
    Cost/month
    Free Trial
    Evaluation tier with 1,000 included governance calls per month, hash-chained evidence ledger, signed release tokens.
    $0.00
    Starter
    Production tier with 100,000 included governance calls per month, 25 req/sec rate limit, multi-protocol agent access (REST, MCP).
    $499.00
    Professional
    Production tier with 1,000,000 included governance calls per month, ML behavioral drift detection, dual-lane post-quantum signing (ML-DSA-87 + SLH-DSA-SHA2-256f), 50 req/sec rate limit.
    $1,499.00
    Enterprise
    Production tier with 5,000,000 included governance calls per month, fleet-level drift monitoring, CEF-formatted syslog export, certifier-grade compliance evidence bundles, 200 req/sec rate limit.
    $4,999.00

    Vendor refund policy

    TaskHawk Systems, LLC subscription fees are non-refundable, except as required by applicable law. AWS Marketplace subscriptions are also subject to AWS Marketplace refund policies. To request a refund or discuss billing concerns, contact support@taskhawktech.com . We will respond within 2 business days. For full terms, see https://taskhawktech.com/terms .

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    MCP server on Amazon Bedrock AgentCore Runtime

    Supported services: Learn more 
    • Amazon Bedrock AgentCore
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    Maintenance and security-hardening release for Kevros AI Governance Gateway across all delivery options: ECS/EKS, A2A server on Amazon Bedrock AgentCore Runtime, and MCP server on Amazon Bedrock AgentCore Runtime.

    This version upgrades all AWS Marketplace launch paths to the same v4.6.1 container artifact and updates the ECS/EKS CloudFormation path to use the latest v4.6.1 digest-pinned image.

    What changed:

    • Tightened Budget-Attestation parsing with bounded signature-set handling to reduce parser amplification risk while preserving the existing post-quantum verification model.
    • Hardened macaroon budget-caveat validation so non-finite numeric values are rejected fail-closed.
    • Improved request-body canonicalization for edge-case HTTP methods so signed request binding remains consistent across supported transports.
    • Improved audit attribution semantics: unverified operator_id and agent_id claims are recorded as claimed identities until signature verification succeeds.
    • Added Protocol 427 discovery/readiness metadata to the public agent descriptor for agent-budget aware clients.
    • Added crawler and agent-discovery directives so well-known discovery paths remain accessible while admin/operator surfaces remain excluded from indexing.
    • Added bounded response-timing equalization for verification paths.

    Compatibility:

    • No breaking changes to the A2A API surface.
    • No breaking changes to the MCP tool list.
    • No change to AWS Marketplace product code, entitlement model, tier limits, or billing dimensions.
    • Existing v4.6.0 customers can move to v4.6.1 by updating the image reference and redeploying.

    Recommended for all new deployments and for existing v4.6.0 evaluators.

    Additional details

    Usage instructions

    DEPLOYMENT (Typical: 15 to 20 minutes)

    Deploy via Amazon Bedrock AgentCore Runtime as an MCP server. The Kevros container exposes governance tools via the Model Context Protocol that MCP-protocol agents in your AgentCore environment can discover and invoke. A2A and MCP surfaces are both present in the same container; AgentCore Runtime selects which transport to expose externally.

    Use image: 709825985650.dkr.ecr.us-east-1.amazonaws.com/taskhawk-systems/kevros-a2a-gateway:4.6.1

    Configure AgentCore Runtime to expose the MCP transport. The container reads the AWS Marketplace contract dimension at startup using AWS_MARKETPLACE_PRODUCT_CODE and resolves your tier entitlement against marketplace-entitlement:GetEntitlements.

    Core MCP tools:

    • verify: submit a proposed action and receive a signed ALLOW, CONSTRAIN, or DENY decision.
    • attest: create a hash-chained provenance attestation with post-quantum anchor metadata.
    • bind: bind an intent to an agent action chain for intent-tracked verification.
    • verify-outcome: verify the outcome of a previously issued release token.
    • bundle: retrieve a certifier-grade evidence bundle for an audit window.
    • verify-token: verify a release token out-of-band.
    • health/status/check-peer: health, operational state, and peer attestation verification.

    Extended governance_* tools are available when MCP_FULL_TOOLS=true. Administrative tools require an X-Admin-Key header matching A2A_ADMIN_KEY before requests reach the tool handler.

    Tier features:

    • Free Trial: 1,000 tool calls per month, 5 req/sec
    • Starter: 100,000 tool calls per month, 25 req/sec
    • Professional: 1,000,000 tool calls per month, 50 req/sec, ML behavioral drift detection, dual-lane post-quantum signing
    • Enterprise: 5,000,000 tool calls per month, 200 req/sec, fleet drift monitoring, CEF syslog export, certifier-grade evidence bundles

    Documentation: https://www.taskhawktech.com/developers  Support: support@taskhawktech.com  Security disclosures: security@taskhawktech.com 

    Resources

    Support

    Vendor support

    Support is provided directly by TaskHawk Systems, LLC.

    Contact

    Email: support@taskhawktech.com  Web: https://www.taskhawktech.com/company  Documentation: https://www.taskhawktech.com/developers 

    Response Times

    Free Trial: best-effort, business hours (Monday through Friday, 9:00 AM to 5:00 PM US Eastern), 2 business day response. Starter: 1 business day response on technical issues. Professional: 8 business hours response on technical issues; 4 business hours on production-impacting issues. Enterprise: priority support; 4 business hours response on technical issues; 1 business hour on production-impacting issues.

    Scope of Support

    Deployment assistance for the AWS CloudFormation stack, configuration of governance policies, integration support for REST and MCP agent endpoints, troubleshooting of Kevros runtime behavior, and guidance on evidence ledger verification.

    Customers are responsible for their own AWS account configuration, IAM permissions, network connectivity, and AWS service costs (Amazon ECS on AWS Fargate, Amazon EFS, Application Load Balancer, AWS Secrets Manager, Amazon CloudWatch). AWS service issues are routed to AWS Support per your AWS Support plan.

    Security incident reporting: security@taskhawktech.com  or follow the disclosure process at

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.