Watchdogs are too slow
Software safety filters search for a response at runtime. Under load or attack, that means timeouts — exactly when every microsecond counts.
EHOX is the guard that can't crash with the AI. It runs on its own processor, with no operating system and no shared software, and checks every command before it reaches the machine. Safe ones pass. Rule breakers are denied. Critical ones wait for a human. Mathematically proven, measured on real hardware, open for anyone to check.
Engineering candidate · design partners wanted for Q4 2026
Autonomous systems are leaving the screen and entering the physical world — power grids, drones, trains. Their AI is powerful, but not deterministic. And the safety filters meant to catch it usually run on the very processor that just failed.
Software safety filters search for a response at runtime. Under load or attack, that means timeouts — exactly when every microsecond counts.
Electronic warfare and cyber attacks target the software layer. Once it's compromised, every safeguard running on top of it goes down with it.
Neural networks can't be tested exhaustively. What you can prove is the boundary they must never cross — and enforce it in hardware.
EHOX separates what is decided from what is allowed. The AI may compute anything — but only proven-safe commands ever reach the actuator.
Safety invariants are verified ahead of deployment with bounded model checking (CBMC) and SMT solving (Z3). At runtime there's nothing left to search — only to enforce.
A dedicated real-time core sits between the application processor and the actuator. Every command is checked against the invariants before it touches the hardware.
On heartbeat loss or a rule violation, the gate decides DENY or ABSTAIN — in 44 ns on the core. It only reopens after 50 consecutive stable cycles (TemporalGuard). Clamping the physical output via FPGA logic is the next integration milestone.
Wherever an AI decision turns into voltage, torque or motion, EHOX is designed to be the last checkpoint — the one that doesn't crash with the software. All domains run on the same reference policy model.
An attacker takes over a water utility's control room and sets the chemical dosing to 100 times normal. Firewall and operating system are bypassed, but the command still has to pass EHOX — and a dose above the limit is designed to be denied.
Power grids, substations, generation plants. If an attack corrupts the control software, EHOX is designed to hold switching commands within verified limits — to prevent blackouts and physical damage.
Drones, guidance systems, space hardware. Effector use stays blocked until a human confirms. If the operator link is jammed, the gate halts instead of releasing without authorisation.
Autonomous trains, vehicles and logistics. Decision logic that cannot change in an over-the-air update — and does not wait for a scheduler under load.
Meaningful human control, outside the software it supervises. EHOX gives you a reviewable hardware boundary and a tamper-evident audit trail, aligned with Article 14 of the EU AI Act.
Every number on this page is published — with a DOI, a reproduction guide and a live API. And it runs on real silicon: bare-metal on the Arm Cortex-R5F cores of an AMD Zynq UltraScale+ MPSoC, with no operating system and no network stack.
Developed in St. Johann in Tirol, Austria. Status: EHOX Inside (Kria-2) is an engineering candidate — not a released or certified product.
Live, public and reproducible.
Formal verificationapi.ehox.io/formal Live system statusapi.ehox.io/v1/status Reviewer access — submit a counter-proofehox.io/reviewer Publications · CC-BY-4.0zenodo.org/communities/ehoxEHOX Inside is an engineering candidate. We're looking for a small number of design partners in defence, aerospace, energy and medical to bring physical enforcement onto real platforms. Tell us about your system — we'll get back to you personally.
Request a scoped evaluation →