Kevros AI Governance Gateway
TaskHawk Systems · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Kevros AI Governance Gateway enforces verifiable governance on every AI agent decision before execution.
Autonomous AI agents are making high-stakes decisions at machine speed. Compliance infrastructure built for human-paced workflows cannot keep up. Kevros closes that gap. Every agent action receives a signed ALLOW, CONSTRAIN, or DENY verdict before it executes. Use cases include agent-initiated trade workflows, automated claims handling, industrial control supervision, and payment authorization. If governance is unreachable, execution halts. No exceptions. No silent failures.
Show the rest of the publisher’s description (21 more lines)
Deploys inside your AWS account using AWS CloudFormation, Amazon ECS on AWS Fargate, Application Load Balancer, Amazon EFS, AWS Secrets Manager, and Amazon CloudWatch. Customer data and signing keys are not transmitted outside your account by default.
Six-Layer Formal Verification
Kevros is the only AI governance offering on AWS Marketplace with end-to-end formal verification of the enforcement kernel. Six independent verification layers spanning model checking, SMT proofs, bounded checks, runtime assertions, cross-language vector regression, and interactive theorem proving collectively explore 1.94 billion system states and produce 71 SMT proofs and 20 mechanically-checked theorems with zero counterexamples and zero unproven assumptions.
Why Kevros
Tamper-evident provenance ledger. Every governance decision is recorded in a hash-chained, append-only ledger on Amazon EFS. Auditors verify chain integrity using the published verifier specification.
Fail-closed architecture. Governance unavailability triggers automatic execution blocking. Agents cannot circumvent oversight under any failure condition.
Dual-lane post-quantum signatures. ML-DSA-87 (FIPS 204) anchors every 100-record block of the hash-chained ledger. SLH-DSA-SHA2-256f (FIPS 205) provides the off-chain co-signing lane on settlement-class events. Quantum-resistant from day one.
Tier-conditioned rate limiting. Per-tier API Gateway UsagePlan throttling at the publisher edge. Free Trial 5 requests per second; Starter 25; Professional 50; Enterprise 200.
ML behavioral drift detection. Latency-drift and semantic-drift monitors flag anomalous agent behavior before violations materialize.
CloudWatch and CEF observability. Container metrics and governance events surface in CloudWatch dashboards. CEF-formatted syslog export for any CEF-capable collector.
Built for AWS
Deploys via AWS CloudFormation as a customer-side stack. Talon classifier inference runs in the TaskHawk publisher account; classifier weights never enter the customer image. Image is signed with cosign against an AWS KMS key; signatures verify against the publisher KMS public key.
Compliance-Aligned Evidence
Generates evidence designed to support governance reviews under NIST AI RMF, EU AI Act risk classification (Annex III), and SOC 2 control families. Hash-chained decision records, post-quantum-signed block roots, and certifier-grade evidence bundles in auditor-ready format.
Kevros provides verifiable technical evidence; it does not replace your compliance program, risk assessment obligations, or legal determinations.
Plans
Free Trial. $0 per month. 1,000 calls. Hash-chained evidence.
Starter. $499 per month. 100,000 calls. Production capacity.
Professional. $1,499 per month. 1,000,000 calls. Adds ML drift plus dual-lane post-quantum signing.
Enterprise. $4,999 per month. 5M inclusive calls plus AWS Marketplace metered overage. Adds fleet drift, CEF syslog export, evidence bundles.
Click Continue to Subscribe to deploy in your AWS account. Typical deployment under 20 minutes.
Highlights
Highlighted by the publisher on AWS Marketplace.
Six-layer formal verification: 1.94B states, 71 proofs, 0 sorry. Zero property violations.
Dual-lane post-quantum signing: ML-DSA-87 (FIPS 204) and SLH-DSA-SHA2-256f (FIPS 205) on every record.
Hash-chained evidence on Amazon EFS. Fail-closed architecture. Deploys in your AWS account.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
16 listed- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
- Units
Refund terms
As stated by the publisher on AWS Marketplace.
TaskHawk Systems, LLC subscription fees are non-refundable, except as required by applicable law. AWS Marketplace subscriptions are also subject to AWS Marketplace refund policies. To request a refund or discuss billing concerns, contact support@taskhawktech.com. We will respond within 2 business days. For full terms, see https://taskhawktech.com/terms.
Sources
Publisher resources
2 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

