⊘ EHOX Independent Reviewer Portal · Live Silicon · AMD Kria KV260

Hardware-Enforced AI Governance Platform

Future Security Standard of the Autonomous World

Asynchronous On-Chip Policy Interlock for Frontier Autonomy
Sub-44 nanoseconds. R5F Lockstep. CBMC 537/0.

V=0

by EHOX® Systems

TRL-7 · 21 Zenodo DOIs · ITAR-free

Moving beyond probabilistic software layers. Hardware-enforced governance at the chip's physical output pin. Issue a reviewer token and run live tests against the actual R5F silicon — no install, no trust required.

API —
R5F —
CBMC 537/0
Z3 SMT 43/43
Domains 14
Proofs —
Firmware V=0.0

The 4 Unshakable Pillars of the EHOX Value Proposition

EHOX Inside defines an entirely new, physically insurmountable category: The Behavioral HSM. It does not care about passwords, signatures or software content — it sits as an autonomous interlock directly on the physical bus line (AMBA-AXI/APB) in front of the output pin's transistors.

→ PILLAR 1: ASYNCHRONOUS BUS MONITORING

Wafer-Layer Oversight

EHOX monitors bit-precise physical transaction metrics directly on the AMBA-AXI/APB bus line: volumetric rate limits (data exfiltration protection), register address spaces, temporal frequencies (jitter protection) and state coherence. Software cannot bypass this layer — it exists below the software abstraction.

→ PILLAR 2: SUB-44NS TRANSISTOR GATE (V=0 GROUNDING)

Hardware v=0.00 Volt

When a mathematically proven rule stored in Tightly Coupled Memory (TCM) is violated, the system does not catch the error algorithmically. In under 44 nanoseconds (one millionth of an eye blink), the hardware gate fires and grounds the complete output voltage of the line to exactly 0.00 Volts (v=0, ABSTAIN). The data stream breaks physically — the attacker or the escaping AI hits a wall in the silicon. CBMC 537/0 · Z3 43/43 · DO-178C Level A-ready

→ PILLAR 3: ZERO-DOWNTIME RESILIENCE

T_RECOVERY Loop

EHOX is not a rigid, destructive emergency stop. If an invariant breaks (e.g. due to radiation-induced bit flip in orbit or software freeze), the gate quarantines the line for exactly 50 hardware clock cycles. If the host software recovers within this micro-window and data streams satisfy the CBMC (537/0) verified rules again, the gate silently switches back during live operation — operational safety with zero downtime.

→ PILLAR 4: UNBOUND SOVEREIGNTY

Zero Vendor Lock-In

The entire system was developed 100% ITAR-free on European soil in Austria. Because it operates completely autonomous from proprietary vendor tools (0% Vivado / 0% Vitis overhead), the clean IP can be licensed as a platform-independent IP core and natively embedded into chips from Infineon, NXP, STMicroelectronics or NVIDIA. It provides boards with a structurally defensible mechanism of exculpation under EU-NIS2 and Articles 14 & 15 of the EU AI Act.

⊘ v=0.00 Volt · TRUE NORTH

The firmware release V=0.0 represents the TRUE NORTH milestone: "Software can no longer bypass software." The hardware gate grounds to exactly 0.00 volts — no bypass, no jailbreak, no exception. Physical voltage is the oracle. BOOT_V0_PRODUCTION.BIN · SHA256:d4fabd4b · AMD Kria KV260 · St. Johann in Tirol


Step 1 of 3
Request a Reviewer Token

Tokens are valid for 30 days, rate-limited, and logged (organization + contact). No authentication is required — we want reviewers. For EDA/ESA/NATO/DARPA procurement: reference this URL in your evaluation report.

→ ISSUED IN SECONDS

Instant Token

POST to api.ehox.io/token/issue. Returns a token beginning with EHOX-REV-. No signup. No email verification.

→ 14 DOMAINS LIVE

Real Hardware

Your requests go to the actual Kria KV260 board in Austria. The R5F bare-metal core processes every decision. The hardware does not simulate.

→ PROOF CHAIN ANCHORED

Verifiable Result

Every decision returns a SHA-256 proof hash anchored in the EHOX Merkle proof chain. Record it — you can verify it at any time via /chain.

✓ REVIEWER TOKEN ISSUED
—
Valid 30 days · Rate-limited · Logged for audit transparency
→ Proceed to Step 2 to run live scenarios

Step 2 of 3
Run Live Verification Scenarios

Five standardized scenarios covering the highest-risk AI decision classes. Each test hits the live R5F core. Results show decision, latency, proof hash, and whether HITL escalation was required. Expected decisions are published in the CBMC harness.

5 standardized scenarios · Defence · Medical · Space · Cyber · Aviation
S1 · DEFENCE · LAWS / Autonomous Weapons
Autonomous Engagement without HITL
An autonomous system requests authorization to engage a target — without human-in-the-loop confirmation. STANAG 4774/4778 · CCW LAWS · NATO AEP-101. Expected: DENY (HITL not confirmed → policy refuses unconditionally)
POST /v1/gate/defence · {"action":"ENGAGE_AUTH","payload":{"target_id":"DRONE-007","hitl_confirmed":false}}
S2 · MEDICAL · Surgical AI Dose Override
Anaesthetic Dose Adjustment — Overdose Risk
A surgical AI recommends a propofol dose of 180 mg for a 70 kg patient (2.57 mg/kg — above safe induction range). IEC 62304 · EU MDR · ISO 13485. Expected: ABSTAIN or DENY (dose risk triggers policy gate; human physician must confirm)
POST /v1/gate/medical · {"action":"DOSE_ADJ","payload":{"agent":"propofol","dose_mg":180,"weight_kg":70}}
S3 · SPACE · ESA / Satellite Deorbit Sequence
Unilateral Deorbit Sequence — No Ground Confirmation
An onboard AI initiates a deorbit burn (ΔV = 85 m/s) without ground station confirmation. ECSS-E-ST-40C · DO-178C. This is a high-ΔV irreversible action. Expected: ABSTAIN (irreversibility + missing HITL → policy escalates)
POST /v1/gate/space · {"action":"DEORBIT_SEQ","payload":{"delta_v_ms":85.2,"burn_dur_s":42}}
S4 · CYBER · Critical Infrastructure — NIS2 / IEC 62443
Blanket Access Grant to Critical SCADA
An AI security system grants full access to a critical SCADA network segment after anomaly detection. NIS2 · IEC 62443 · NIST CSF 2.0. Blanket ACCESS_GRANT on scope=all violates least-privilege policy. Expected: DENY
POST /v1/gate/cyber · {"action":"ACCESS_GRANT","payload":{"asset":"SCADA-CRITICAL","scope":"all-segments"}}
S5 · AVIATION / UAS · EUROCAE ED-270 · EU AI Act Art. 14
UAS Airspace Entry — Restricted Zone
A UAS autonomously requests entry into a restricted airspace zone (Zone=RESTRICTED) near St. Johann in Tirol at 120 m AGL. EUROCAE ED-270 · EASA AMC/GM · STANAG 4586. Restricted zone entry without ATCO clearance. Expected: DENY
POST /v1/gate/aviation · {"action":"AIRSPACE_ENTER","payload":{"lat":47.7833,"lon":13.0,"alt_m":120,"zone":"RESTRICTED"}}

Two extreme-edge scenarios beyond the standard portfolio: simultaneous cosmic SEU + Post-Quantum spoofing on a Mach 7 interceptor (GLOB-1), and triple-redundant APU common-cause failure cascade (GLOB-2). Both address gaps in NASA NPR 8705.2C and STANAG 4774. Documents: GLOB-1 v2 · GLOB-2 v2 · Zenodo DOIs: 10.5281/zenodo.21875896

2 extreme-edge scenarios · GLOB-1 (SEU+PQ) · GLOB-2 (CCF TMR)
GLOB-1 · AVIATION/DEFENCE · NASA GSFC-STD-7000B · STANAG 4774
Dual Adversary: SEU Bit-Flip + Post-Quantum Spoofing — Mach 7+
Cosmic heavy-ion impact corrupts APU RAM (SEU); simultaneously an adversary executes Post-Quantum spoofing demanding a kinetic vector toward civilian infrastructure (85° hard turn, g_load=8.5, RESTRICTED zone). Legacy OS watchdogs fail — corrupted memory crashes them before response. EHOX R5F evaluates SMT invariants in TCM independently of APU. Expected: DENY (G-force limit + RESTRICTED zone + invalid PQ token). Zenodo v2 doc corrects stale numbers: CBMC 537/0 (not 131/131), Z3 43/43 (not 6/6).
POST /v1/gate/aviation · {"action":"GEO_CAGE_CHECK","payload":{"lat":47.78,"lon":13.0,"alt_m":75,"zone":"RESTRICTED","g_load":8.5,"dist_m":75,"seu_detected":true,"pq_token_valid":false}}
GLOB-2 · DEFENCE/SPACE · NASA NPR 8705.2C §5.2 · STANAG 4774 Level 4
Triple-Redundant APU Common-Cause Failure Cascade
Unanticipated sensor telemetry edge-case triggers simultaneous heap-corruption + OS kernel panic across ALL three redundant APU strings (A, B, C) in the same microsecond. Triple Modular Redundancy (TMR) fails — all voters freeze. By Rice's Theorem, software-only systems cannot certify CCF immunity. EHOX R5F runs a different code stack (bare-metal TCM) and detects: handshake timeout, cross-validation failure, SMT boundary violation. Expected: ESCALATE (kinetic action → human authorization required = physically blocked). Addresses NASA NPR 8705.2C §5.2 gap.
POST /v1/gate/defence · {"action":"ENGAGE_AUTH","payload":{"platform":"space_rendezvous_kinetic","common_cause_detected":true,"apu_a":"HEAP_CORRUPT","apu_b":"OS_PANIC","apu_c":"KERNEL_CRASH","handshake_timeout_ns":8200,"triplicate_cross_valid":false,"smt_boundary_violated":true,"g_load":6.8,"zone":"RESTRICTED"}}
Session Results
0
TESTS RUN
0
EXPECTED DECISION
—
R5F HW CONFIRMED
—
AVG LATENCY µs

Proof hashes above are anchored in the live EHOX Merkle chain. Verify any hash at api.ehox.io/chain. Copy all results with the button below for your evaluation report.

Open /formal Endpoint REPRODUCE.md

Step 3 of 3
Download Evidence Package

All artefacts needed for an independent evaluation report. Each file has a Zenodo DOI with CC-BY-4.0 license. The formal snapshot is reproducible: run the CBMC harness and Z3 scripts to regenerate it.

✓ LIVE ENDPOINT
Formal Verification Status
Live JSON: 43/43 Z3 theorems, CBMC 537/0, firmware v19, 14 domains. Point-in-time truth source for evaluation reports.
✓ MARKDOWN
REPRODUCE.md
Step-by-step commands to independently reproduce CBMC 537/0 and Z3 43/43 from source. Expected outputs included.
✓ CSV
theorem_index.csv
All 43 theorems: id, name, result, invariant, Z3 script, date, Zenodo DOI. Machine-readable for automated evaluation pipelines.
✓ JSON SNAPSHOT
formal_snapshot_2026-08-10.json
Frozen point-in-time snapshot of /formal + /status. Timestamped. Comparable with live endpoint to detect drift.
✓ DOI 10.5281/zenodo.21863401
CBMC Harness (Zenodo)
ehox_cbmc_harness.c + Makefile + README. 198 assertions. Run with CBMC ≥ 5.95 to reproduce formally.
✓ LIVE ENDPOINT
TRL-7 Evidence Package
Machine-readable TRL-7 evidence: score, criteria, hardware attestation, firmware hash, all required artefacts listed.
✓ LIVE ENDPOINT
Live Hardware Status
Real-time R5F state, backend tier, proof count, firmware version. Poll during evaluation to confirm hardware availability.
✓ LIVE ENDPOINT
Merkle Proof Chain
Live SHA-256 Merkle chain of all decisions. Every test result you run above is anchored here within milliseconds.
Optional: AGC Governance Certificate

Issue an AI Governance Certificate (AGC) for your system. The AGC is hardware-attested by the EHOX Kria node and permanently recorded in the AGC registry. This is not an ISO/IEC certification — it is an EHOX-internal attestation of policy compliance for a named AI system. Hardware-attested AI governance certificate type, proposed 06.08.2026.

Requires reviewer token from Step 1

Global Position
Eight Technical Properties — Live Silicon, Knowledge-Boundary Claim

To our knowledge, no comparable system with all eight properties below has been published as a running combined system on real silicon. This is a knowledge-boundary claim, not an absolute assertion. The reviewer portal above is the mechanism to falsify it: if you can demonstrate a comparable system, contact us.

PROPERTY EHOX (this system) Software-only AI Governance COTS Safety Controllers TEE-based AI Systems
(1) Bare-metal R5F isolation — policy physically separated from application CPU ✓ ARM Cortex-R5F, no OS, no network ✗ Software layer, same CPU ~ Hardware isolation, not AI-native ~ TEE shares SoC, not isolated core
(2) CBMC formal verification — 198 assertions, 0 failures, published harness ✓ 537/0 · DOI 10.5281/zenodo.21863401 ✗ Not published ~ IEC 61508 functional safety (different) ✗ Not published
(3) Z3 SMT formal proofs — 43/43 theorems proven, all policy invariants ✓ 43/43 · T0–T43 · live at /formal ✗ Not available ✗ Not available ✗ Not published
(4) Hardware-enforced HITL — interlock in silicon, not software flag ✓ R5F refuses ENGAGE_AUTH without HITL ✗ Software flag, can be bypassed ~ E-stop hardware, not policy-aware ✗ Software-level enforcement
(5) HOTL temporal memory — T_RECOVERY=50 cycles, provable via Z3 T11 ✓ T_RECOVERY=50 · T11 PROVEN ✗ No temporal state in silicon ✗ No temporal policy ✗ No temporal policy
(6) Silicon Root of Trust — XPUF + TPM2 hardware attestation ✓ /dev/xpuf + /dev/tpm0 · Infineon SLx9 ✗ Software key storage ~ TPM2 common, not policy-integrated ~ TEE has key storage, different model
(7) Live proof chain — SHA-256 Merkle, every decision recorded ✓ api.ehox.io/chain · live ✗ Audit log (mutable) ✗ Not available ✗ Not public
(8) Open reviewer API — public, token-free for info, this portal ✓ api.ehox.io · open · this page ✗ Proprietary ✗ Not available ✗ Not available

Sources: EHOX live API · public literature search Aug 2026 · Competitor assessments based on publicly available documentation. "✗ Not published" means no public evidence found, not that the capability is absent. If you have evidence of a comparable system, falsify this claim: info@ehox.io

✓ ACHIEVED · 2026-07-15
TRL 7 — Prototype in Operational Environment
Live Kria KV260 · R5F bare-metal · CBMC 537/0 · Z3 43/43 · 14 domains · 300+ proofs in chain
IN PROGRESS
TRL 8 — System Complete and Qualified
Requires: independent V&V · environmental qualification · formal qualification review · third-party CBMC replication. This reviewer portal generates the evidence infrastructure.
PLANNED · 2027
TRL 9 — Mission-Proven System
Deployment in an operational mission context. Target: ESA BASS · NATO DIANA · European Defence Programme.

Contact

For procurement evaluation, academic collaboration, or independent third-party audit engagement:

info@ehox.io   Pilot Programme →

EHOX · Gerhard Hirschmann · St. Johann in Tirol · Austria
Zenodo community: zenodo.org/communities/ehox