Product 06Enforce

The operational problem Action Shield is designed to solve.

A valid decision made centrally is not enough. The gateway must confirm that the command is still fresh, intended for this device, and valid under the policy available at the physical boundary.

Action Shield is the enforcement boundary close to the device. It verifies the signed envelope, policy version, expiry, nonce, replay state, and destination constraints before forwarding a supported command to an unchanged legacy device.

QUANTUMGUARD / ACTION SHIELDIllustrative product view
Edge gw-03 / MQTT path

Gateway enforcement

Forwarding bounded
Control planeQG-1042gw-03Action ShieldMQTT / chillerDevice 07
Signature valid
Policy qg-prod-17 current
Nonce unused
Destination matched
Enforcement outcomeBounded command forwardedVerified
Example view: the edge re-verifies freshness, destination, and policy before forwarding.

Operational contract

What enters, what Action Shield does, and what leaves.

Inputs

Evidence entering the boundary

  • Ritqo signed envelope
  • Cached policy and trust material
  • Gateway and destination context
Action Shield

Enforce

Re-verify authorization at the edge before a command enters a protected MQTT or device path.

Outputs

Evidence moving forward

  • Forwarded bounded command or refusal
  • Replay and freshness state
  • Enforcement telemetry and evidence

Core capabilities

A focused part of one controlled system.

  1. 01

    Re-verify signatures, expiry, nonce, replay state, destination, and policy binding at the gateway.

  2. 02

    Enforce bounded commands on supported MQTT and controlled edge paths without granting the model direct access.

  3. 03

    Fail closed when the envelope, policy, device state, or local enforcement context is invalid.

  4. 04

    Return enforcement telemetry and refusal evidence to the control plane and Vaqri Proof.

Operational value

What teams gain.

  • Place the final authorization check close to the protected device path.

  • Modernize supported legacy environments without making the AI system a device credential holder.

  • Close the loop with evidence for monitoring, review, pause, and rollback.

Continue through the control loop

Next: Vaqri Atlas