Although the MeP architecture docs specify that with EVM=0, the reset/NMI vector base is at 0x00000000 it is observed that the vector base is actually at 0x00004000. However, EVA/IVA still work as expected when EVM=1. Both secure_kernel and second_loader set EVM=0 at the start. This is likely modified hardware behavior and the vector base remapping might be done when the bootrom is unmapped.
|0xE0030000||Private:Key Ring Controller|
|0xE0058000||Private:Key Ring Base|
|0xE0070000||Private:Key Ring Reset|