Dan Sheldon launches EVA Networks to make enterprise network paths expire
The Rhode Island startup creates encrypted paths for approved tasks, then removes the routes, controls and keys when the work ends.
By RuntimeWire Staff · Published
Primary source: PR Newswire
Why it matters
EVA Networks is extending zero-trust from identity permissions to the network path itself. Reliable teardown could reduce the standing routes and tunnels inherited by attackers and operators.

Dan Sheldon brought EVA Networks out of stealth on September 15th with a security platform built to create enterprise network paths on demand and dismantle them after their approved purpose expires.
Sheldon has spent more than two decades working in networking and cloud infrastructure, including roles at World Wide Technology, Prosimo and Aviatrix. Cisco profiled him in 2021 after WWT named him its 2020 East Systems Engineer of the Year. That career put Sheldon inside the long-lived tunnels, routes and firewall policies that large organizations accumulate as applications, vendors and cloud environments are connected.
His founding premise is that zero-trust programs have tightened identity permissions while leaving much of that underlying connectivity intact. "Temporary business requirements should not create permanent infrastructure," Sheldon said in EVA Networks' launch announcement.
EVA Networks calls its model Ephemeral Virtual Access. An application, administrator or automated workload declares the intended connection through an API, infrastructure as code or a user interface. EVA Networks evaluates that request against policy, creates an encrypted tunnel, records the activity and removes the route, access controls and keys after the approved window closes.
That teardown step is the product's central wager. Enterprise networking products commonly govern who or what can traverse a private network. EVA Networks wants the existence of the path itself to carry an expiration condition.
A network connection with an owner and an end date
EVA Networks is targeting the kinds of temporary projects that frequently leave permanent infrastructure behind: a vendor resolving a production incident, an acquired business connecting selected applications, a pharmaceutical workload moving research data into cloud compute, or two applications exchanging data across separate environments.
The platform's lifecycle is straightforward: intent, policy review, encrypted connection, observation and expiration. EVA Networks says it can operate across public clouds, private data centers and on-premises infrastructure while coexisting with existing security products. EVA Networks positions the platform as a replacement for some persistent VPN and site-to-site tunnels, and as a complement to zero-trust network access and privileged-access systems that govern users and credentials.
EVA Networks says it is working with Fortune 50 customers as early adopters. The launch does not identify those customers, describe their deployment status or provide performance data from their environments. The customer claim therefore remains EVA Networks' account of its early traction rather than independently verifiable adoption.
The same limitation applies to the technical benefits. Automatically removing dormant paths should reduce standing reachability in principle, but EVA Networks has not published benchmarks showing deployment speed, operating-cost changes or reductions in exploitable paths. Its website describes post-quantum-aligned security and key purging without supplying enough architectural detail for an outside assessment.
Those questions will matter in regulated enterprises, where an expired connection has to disappear reliably without disrupting an authorized workflow, and where security teams need evidence that every route, policy and key was removed. The audit trail may prove as important as the tunnel automation.
Sheldon is turning an operating complaint into a product
The premise starts with a familiar enterprise problem: permanent interconnection creates configuration debt. Routes, access-control lists and tunnels remain after the original application, employee or partner relationship changes. Engineers then avoid removing them because ownership is unclear and the consequences of deleting the wrong path can be severe.
That diagnosis reflects the incentives inside large IT organizations. Building a connection closes a ticket and enables a project. Removing one can require several teams to reconstruct why it exists. The safest local decision is often to leave the path alone, even when thousands of those decisions produce a network that nobody can fully explain.
EVA Networks attempts to move that cleanup decision into the original policy. The request that creates a path also defines when it should end. If the model works, operators no longer need a later project to discover and retire the connection.
Sheldon's prior enterprise relationships are also visible in EVA Networks' route to market. EVA Networks named World Wide Technology, ePlus, EchoStor Technologies and Layer 8 Security as go-to-market partners. Those channel relationships can place EVA Networks in front of large customers through providers already involved in their infrastructure purchasing and implementation.
World Wide Technology is particularly close to the launch. Sheldon previously worked there, and Brian Gilbert is serving as an adviser to EVA Networks. Gilbert's background includes responsibility for WWT's eastern advisory and technical functions, along with earlier leadership of global network engineering and operations at JPMorgan Chase.
That enterprise-heavy rollout fits the product. EVA Networks requires access to networking, security and application owners, followed by integration with infrastructure that enterprises are reluctant to disturb. A channel partner can help navigate those internal boundaries, though a partner list does not establish production adoption on its own.
AI agents give the pitch a second opening
EVA Networks is extending the model to AI agents through a feature called Ephemeral Agent Paths. EVA Networks says EAP can create time-bound, policy-controlled connections when agents need to call private APIs, reach databases or coordinate across cloud and factory environments.
Agent access has become a crowded networking pitch. Cloudflare introduced Mesh on April 14th to connect users, infrastructure and agents through a private network. Tailscale and ZeroTier already sell encrypted, identity-controlled overlay networks spanning devices, data centers and clouds.
EVA Networks is drawing its distinction around lifecycle automation. Cloudflare Mesh, Tailscale and ZeroTier emphasize persistent private fabrics governed by identity and policy. EVA Networks says it assembles narrower infrastructure for a specific approved task and tears that infrastructure down afterward.
Enterprise deployments will determine whether that difference is substantial. Applications often expect stable addressing and predictable routes, while automated agents can start new tasks quickly and unpredictably. EVA Networks will need to show that it can create and remove paths fast enough for those workloads, preserve observability during short sessions and recover cleanly when a task, policy engine or endpoint fails midway through the connection lifecycle.
Sheldon's argument starts from a concrete flaw in enterprise operations: temporary work routinely leaves permanent plumbing. EVA Networks now has to prove that expiration can become a dependable networking primitive rather than another policy layer that administrators must maintain. If Sheldon succeeds, a network path will look less like fixed infrastructure and more like a governed resource with a purpose, an owner and a scheduled end.