Skip to content
QDataCloud

Observation is not enforcement

How protection works.

QData Identity Security records and decides. It blocks only on an enforcement path. We do not claim unhackable, 100% secure, or military-grade protection.

Observe

Inventory, owners, decisions, shadow. Seeing an event is not a block.

Enforce

A PEP on the path: SDK, gateway, MCP gateway, sidecar, or connector.

Same decision model. Enforcement only exists where a PEP sits on the request.
SHADOWALLOWDENY

Observation is not enforcement

QData Identity Security can inventory identities, evaluate policy, and record a decision. It blocks an action only when a policy enforcement point is actually in the request path. Shadow mode shows what would have been denied before you enable protect.

Modes

Customers usually move Discover → Monitor → Simulate → Protect. Govern and remediate run alongside. Simulate the deny before you enforce it — otherwise fail-closed never turns on.

  • Discover

    Inventory agents, other NHI, tools, and credentials you register or a connector can see.

    No block

  • Monitor

    Events, audit, and a baseline of what identities actually do.

    No block

  • Simulate

    The same decision as protect, including would-be denies, without blocking the caller.

    No block — shadow

  • Protect

    Runtime authorization on an enforcement path. Fail closed only where a PEP sits.

    Block on a PEP

  • Govern

    Owners, lifecycle, entitlements, and policy you can review.

    Indirect

  • Remediate

    Revoke, disable, rotate, or quarantine objects the product actually controls.

    On controlled objects

Policy enforcement points

A PEP is a required condition, not a feature toggle. If none of these sits on the request, you can still inventory, decide, and simulate. You cannot honestly claim a block.

  • SDK

    A check in the agent or service code, on the path of the action.

  • Security gateway

    A gateway that asks for a decision before the request continues.

  • MCP gateway

    Authorize which agent identity may call which tool, with which arguments.

  • Sidecar

    A process beside the workload that can allow or deny on the path.

  • Connector

    Enforcement in a system you already run — only when that connector exists.

Shadow before protect

Shadow produces the same decision as protect, including would-be denies and would-be approvals, without blocking the caller. Review the trail. Attach a PEP. Then enable enforcement. Skipping simulate is how programs stay in observe forever — or flip fail-closed and break production.

Deny by default is a policy principle

If a check has no matching allow, the decision is deny. That is not scareware and not a claim that every action in the estate is already blocked. You still choose when to leave shadow.

Risk informs the decision. It does not replace it.

Risk in the first release is rule-based. A language model may help explain a draft. It is not the final policy decision point. Full prompts are not the default payload to the SaaS.

This public site

The marketing site has no product session and no tenant data. It is not the control plane. It is operated by ABSGROUP INC., 347 Hudson Bend, Edmonton, Alberta T6V 1R5, Canada. Vulnerability reports: [email protected] or security.txt. How the loop is sold as a product is on QData Identity Security.

Questions

No. Seeing an event is observe. Blocking requires a PEP on the path.

Talk through enforcement honestly

If you need a block, you need a PEP. If you need a quote or a rollout plan, use the form.