UKVPM Technology & R&D Programme

    COREHAVEN™

    AI, Resilience & Applied R&D

    Corehaven is a UKVPM Ltd technology and R&D programme developing resilient digital systems for risk awareness, preparedness and the safe integration of artificial intelligence.

    Within the programme, Corehaven Guardian is an evidence-driven assurance layer for evaluating and governing AI-assisted and agentic operations in security- and resilience-sensitive environments. Its core controls are a working foundation, under continued development and validation.

    A working platform for applied research

    Corehaven is not only a concept. Its development platform combines risk information, preparedness tools and AI-assisted guidance in one environment, giving the programme somewhere real to research, build and demonstrate AI and resilience capabilities.

    It is an active R&D platform and demonstrator environment. It has not been deployed by government or public-sector organisations.

    Working foundation

    Preparedness assessment

    Structured readiness assessments that help users understand how prepared they are and what to do next.

    Working foundation

    Climate adaptation and risk scoring

    Scoring that relates climate-related risk to adaptation and preparedness measures.

    Working foundation

    Location-aware risk information

    Risk information presented in the context of a user's location.

    Working foundation

    AI-assisted guidance

    AI-assisted preparedness guidance, designed to direct safety-critical situations towards emergency support and human help rather than relying on the model alone.

    The problem

    AI agents that can act need more than chatbot safety

    Increasingly capable AI agents can access information, use tools, call APIs, run workflows, make recommendations and initiate actions with real consequences.

    Controlling what a model says is no longer enough. Organisations need a reliable way to understand and govern what an agent is about to do, before it does it, and to account for it afterwards.

    Questions an organisation needs to answer

    1. 1Which agent is operating, and on whose behalf?
    2. 2What is it attempting to do?
    3. 3Which tools and data can it reach?
    4. 4What evidence supports the proposed action?
    5. 5Is the action permitted by policy?
    6. 6How risky is it in this specific context?
    7. 7Does a person need to decide?
    8. 8What happened afterwards, and can it be shown?

    COREHAVEN Guardian

    Evidence-based AI agent assurance

    Guardian is a controlled assurance layer between AI agents and the tools, data and systems they act on. Rather than trusting an agent's own judgement, it assesses each proposed operation against evidence, context and policy, and keeps an accountable record of the outcome.

    Guardian's decisions are driven primarily by deterministic policy and risk controls. AI can contribute to an assessment where appropriate, but it does not replace those controls.

    1. 01

      AI or agent request

      An AI-assisted system or agent proposes an operation, such as calling a tool, retrieving data or starting a workflow.

    2. 02

      Context and evidence

      The request is gathered with its operational context and the evidence it relies on.

    3. 03

      Guardian assessment

      Evidence is checked, input is screened for manipulation and contextual risk is assessed.

    4. 04

      Risk and policy controls

      Guardian policies, permissions and data boundaries are applied deterministically.

    5. 05

      Decision

      The operation is allowed, blocked, quarantined or held for human review. Blocked and quarantined operations raise an incident.

      • Allow
      • Block
      • Quarantine
      • Human review
    6. 06

      Controlled action

      Only an authorised operation proceeds to the tool or system concerned.

    7. 07

      Auditable record

      The assessment, evidence, decision and outcome are kept as a tamper-resistant record for review and accountability.

    Conceptual flow. It illustrates the assurance approach, not the internal implementation.

    Built for both security and resilience

    Safe agent adoption depends on two things at once: resisting deliberate misuse, and behaving predictably when things go wrong without any attacker involved. Guardian is designed to address both.

    Cybersecurity

    • Malicious or manipulated inputs
    • Prompt injection
    • Excessive permissions
    • Unauthorised tool use
    • Agent identity
    • Policy enforcement
    • Data boundaries
    • Evidence integrity and auditability

    Operational resilience

    • Unavailable or degraded services
    • Incomplete or conflicting evidence
    • Model or provider failure
    • Safe fallback behaviour
    • Escalation when confidence is low
    • Operational continuity
    • Failure containment
    • Recovery

    Human oversight by design

    Guardian is not intended to replace human decision-making. Its role is to make sure the right decisions reach the right people, with the evidence they need, and that accountability is preserved. The core approval and escalation mechanism is a working foundation; broader organisational approval workflows are in active development.

    • Risk-based escalation
    • Approval for consequential operations
    • Human-in-the-loop pathways
    • Human-on-the-loop monitoring
    • Decisions recorded with their evidence
    • Auditable, accountable operation

    Independent of any single AI provider

    Model ecosystems change quickly. Guardian and Corehaven's controlled AI access layer are being developed to remain independent of any single model provider, applying the same policies, evidence controls and audit record whichever AI service is in use.

    Current capability and development status

    Guardian's core controls are working foundations within the Corehaven development platform, supported by automated functional and security testing. They are not a finished commercial product or a certified service, and development and validation continue.

    Each capability is labelled by its current status and described at a conceptual level only.

    Working foundation
    Implemented in the current development platform and exercised in testing. Not a claim of production certification.
    In active development
    Partly built and being extended, integrated or hardened.
    Research objective
    A question we are investigating. Outcomes are not yet established.
    Potential application
    A context where the work may be applied in future. Not a current deployment.

    Working foundations

    Working foundation

    Agent and tool governance

    A structured registry and control layer defining which AI-assisted systems and tools may operate, and in which authorised contexts.

    Working foundation

    Evidence validation

    Operations are linked to identified evidence, and unsupported or invented evidence is rejected or controlled.

    Working foundation

    Evidence trust classification

    Evidence is assigned a trust level that informs how far a decision may rely on it.

    Working foundation

    Prompt-injection detection

    Guardian safety checks identify prompt injection and other manipulated input before an operation proceeds.

    Working foundation

    Contextual risk assessment

    Each proposed operation is assessed against the agent, the tool, the evidence and the operational context.

    Working foundation

    Policy-based decisions

    Deterministic, policy-driven decision logic across multiple Guardian policies. AI may inform an assessment but does not replace these controls.

    Working foundation

    Allow, block and quarantine

    Every assessed operation receives an explicit outcome. Blocked and quarantined operations raise an incident for review.

    Working foundation

    Human approval and escalation

    Consequential or uncertain operations can be held for a person to approve before they proceed.

    Working foundation

    Tamper-resistant decision records

    Guardian assessments and decisions are kept as tamper-resistant, integrity-protected records designed to resist later rewriting.

    Working foundation

    Append-only evidence

    Evidence is held in an append-only form, so the basis for each decision remains traceable.

    Working foundation

    Controlled AI access

    AI services are reached through a centralised access layer with model and provider abstraction, and consequential operations require Guardian authorisation.

    Working foundation

    Controlled model access and routing

    Model allowlisting and policy-governed, risk-aware routing, with fallback handling, provide a foundation for applying consistent organisational controls across different AI services.

    Working foundation

    AI operational logging and oversight

    AI and Guardian activity is logged, with administrative oversight of operations and decisions.

    In active development

    In active development

    Multi-agent governance

    Extending governance from individual agents to agents that interact with one another.

    In active development

    Behavioural risk analysis

    More sophisticated analysis of how an agent behaves over time, not only what it requests.

    In active development

    Tool-chain analysis

    Assessing risk across sequences of tool calls rather than each call in isolation.

    In active development

    Advanced evidence provenance

    Richer tracing of where evidence came from and how it has been handled.

    In active development

    Organisational approval workflows

    Public-sector-style approval routes, delegation models and multi-level governance.

    In active development

    Cross-organisational policy

    Policy structures that can be shared or layered across organisations.

    In active development

    Assurance for security leaders

    Deeper automated assurance and reporting to support risk-based decisions by security leaders.

    In active development

    Resilience simulation

    Exercising behaviour under degraded, failing or conflicting conditions.

    In active development

    Expanded adversarial testing

    Broader and more systematic testing of controls against deliberate misuse.

    In active development

    Wider integrations

    Connecting Guardian controls to a wider range of tools, services and environments.

    Open research questions

    Research objective

    Some of the most important questions in agent assurance remain unresolved across the field. Current R&D explores:

    • Assurance for large-scale multi-agent systems
    • Trust interoperability between organisations
    • Standardised assurance for public-sector AI agents
    • Advanced, explainable models of agent risk
    • Systematic resilience evaluation across heterogeneous AI ecosystems
    • Reusable and open assurance frameworks

    Designed for high-trust environments

    Potential application

    Corehaven's combination of resilience services and AI assurance is relevant wherever AI must operate within clear accountability. Potential application contexts include:

    • Local government
    • Public-sector AI services
    • Emergency management and resilience planning
    • Citizen-facing digital services
    • Internal organisational AI agents
    • Regulated or security-sensitive organisations

    These are potential applications under exploration, not current deployments.

    The R&D team

    Corehaven is multidisciplinary. The programme draws on UKVPM's experience across digital platforms, artificial intelligence, media technology, cybersecurity, systems thinking and resilience.

    Corehaven is one of the ventures of UKVPM founder Ali Jam.

    Research leadership and academic experience

    Corehaven's multidisciplinary R&D work is supported by Dr Zainab Saleh, who leads Research, Innovation and Strategic Partnerships at UKVPM Ltd and is a Senior Lecturer in Aerospace Engineering and Faculty Bidding Champion at Kingston University London.

    Her research spans aerospace engineering and multidisciplinary innovation, bringing relevant expertise in complex systems, engineering research, resilience and technical validation. She currently co-leads a multidisciplinary project focused on supporting SMEs in achieving net-zero emissions.

    Her UKVPM role is independent of her university appointment. Her Kingston University position is held independently and does not imply institutional participation or endorsement of Corehaven by Kingston University.

    Collaborate on COREHAVEN

    We welcome conversations with organisations, researchers and technology partners interested in AI assurance, resilience and evaluation of the programme. Further technical detail is shared with evaluators and partners under appropriate arrangements.

    Corehaven is an active R&D programme under continued development and validation. Capabilities are described conceptually and labelled by status. This page is not a statement of certification, accreditation or production deployment.