What the interception is anchored to.
Two products can both stop an agent mid-action and still be asking different questions of it. Eve Security asks whether this request, read on its own terms, is one a reasonable agent should be making. That is a hard question, they answer it in a way nobody else has patented, and it is not the same question as whether this agent was permitted to do this on behalf of that person.
Three stages over one adjudication path
The platform is organised as three stages, and a buyer evaluating runtime governance is usually shown the third one first. All three run over the same interception path.
- Discoveran inventory of every agent and everything it touches — MCP servers, APIs, agent-to-agent connections and data sources — built by connecting to the existing environment rather than by installing anything. It produces a topology of the full chain from user to agent to MCP server to system, flags unsanctioned agents against approved ones, and scores financial exposure.
- Governonboarding an agent into runtime control and centralising policy across all of them. Policies are generated from what discovery found rather than written from scratch, and they are expressed against the intent and the data in a request rather than as English-language rules, which the vendor argues introduces translation blind spots.
- Enforcethe adjudication itself. Every action is evaluated in real time and resolved to allow, block, modify or interrogate before it reaches a critical system. The whole exchange runs over HTTP with standardised JSON payloads and status codes, which is what makes it gateway-agnostic and agent-agnostic — and what bounds it.
Where Eve Security is strongest
One of the sixteen rows below goes to Eve Security and four more are level. All five follow from the same design decision: adjudicate the request itself, over a transport every agent already speaks, and require nothing of the agent in return.
- Interrogating the agent before it actsthis row goes to them and it is not close. When a request classifies as high or critical risk, the platform generates a structured challenge — five reasoning prompts on intent, necessity, harm, data and alternatives — and the agent has to answer before a retry token is issued. We evaluate the action against policy and against the person behind it; we do not put the question to the agent, and the table scores that difference plainly.
- Standing up without touching anythingno client, no SDK, no code change, no new infrastructure, and policies generated automatically from what discovery finds. That is a level row at the top of the scale, and it is the reason a security team can get a first agent under control the same week. We arrive at the same place by a different route — agentless discovery across five surfaces — and neither approach asks a developer to instrument an agent first.
- Stopping one call, not the agentthe block lands on the individual request while the agent carries on working. That is the row most posture products cannot reach at all, and it is level here. It is also why this comparison is not about whether there is a runtime verdict.
- Adjudicating at the gatewayplain HTTP and JSON status codes, compatible with any conformant agent, gateway or orchestrator. We govern the action rather than the path, and run alongside whatever sits in that path — which is what lets one policy also reach an agent acting on a laptop, where there is no gateway to sit in front of.
A request carries intent. It does not carry a principal.
The discovery topology maps the full chain: user, agent, MCP server, system. So the platform does know that a person stands somewhere behind an agent, and it draws that. What it draws is a map of how things are connected, produced during assessment.
The verdict is a different moment. When a call arrives for adjudication it is an HTTP request with a JSON body, evaluated for what it is asking to do and why. Being agent-agnostic and identity-object-free is the explicit design goal — it is what makes the platform work out of the box for any client. The consequence is that the thing being judged is the request, and the request has no owner in it.
That is why the runtime group is close and the identity group is not. Accountability is not a stricter grade of interception. It is a different object, it has to exist before the call arrives, and no amount of reasoning about a payload will reconstruct it.
Interrogating an agent is not authenticating a person
Consider a finance agent asking to export a payables ledger at two in the morning. The challenge fires, the agent explains that it is running a scheduled reconciliation, the explanation is coherent, a retry token is issued and the export proceeds. Every part of that worked as designed.
The question that was never asked is whether the person this agent runs for is entitled to that ledger, and whether they intended this run at all. A compromised or misdirected agent explains itself as fluently as a correct one, because the explanation is generated by the same system whose behaviour is in question.
Agen resolves the action to a named human first and evaluates entitlement in that context, with five verdict types rather than four — including a step-up challenge that lands on the person, not the agent, and a human approval gate. Those rows are not scored against a missing feature. They are scored against a model that has no principal to challenge.
Where the enforcement point sits
The published architecture is transport-neutral and gateway-agnostic, operating entirely over HTTP. That buys compatibility with anything that speaks the protocol, and it locates enforcement in the path rather than at the surface where the work happens.
Discovery does reach further than enforcement does. Agents are mapped across endpoints, including ones nobody registered, which is why the discovery rows score at the top and the endpoint enforcement row scores a 2. There is no client on the device to stop a local action, and no browser-side control appears anywhere in the product or integration documentation. For a coding agent operating on a developer's machine, that boundary is the whole question.
Deployment beyond SaaS is real but specific: a collaboration with a private-cloud vendor brings runtime governance, enforcement and continuous compliance mapping to that vendor's Kubernetes and cloud-foundation environments. Outside those, no self-hosted option is published.
What is not published
The pricing rows publish here on an absence rather than a number. There is no pricing page in the site or its sitemap, no billing unit anywhere in the public material, and every commercial path is a demo booking or a free risk assessment. That is a normal early enterprise motion and not a criticism — but it means the cost of governing a hundred agents cannot be modelled before a sales conversation, and the rows say exactly that.
One row was dropped rather than scored. A sub-5ms adjudication figure appears on the site, but on a product page whose body copy is still placeholder text, so it is not a published claim and it would be unfair to score them against it in either direction. Our own audit-first rollout row is held pending internal confirmation, so it does not publish on any comparison yet.