Observation is not enforcement
How protection works.
QData Identity Security records and decides. It blocks only on an enforcement path. We do not claim unhackable, 100% secure, or military-grade protection.
Observe
Inventory, owners, decisions, shadow. Seeing an event is not a block.
Enforce
A PEP on the path: SDK, gateway, MCP gateway, sidecar, or connector.
Observation is not enforcement
QData Identity Security can inventory identities, evaluate policy, and record a decision. It blocks an action only when a policy enforcement point is actually in the request path. Shadow mode shows what would have been denied before you enable protect.
Modes
Customers usually move Discover → Monitor → Simulate → Protect. Govern and remediate run alongside. Simulate the deny before you enforce it — otherwise fail-closed never turns on.
Discover
Inventory agents, other NHI, tools, and credentials you register or a connector can see.
No block
Monitor
Events, audit, and a baseline of what identities actually do.
No block
Simulate
The same decision as protect, including would-be denies, without blocking the caller.
No block — shadow
Protect
Runtime authorization on an enforcement path. Fail closed only where a PEP sits.
Block on a PEP
Govern
Owners, lifecycle, entitlements, and policy you can review.
Indirect
Remediate
Revoke, disable, rotate, or quarantine objects the product actually controls.
On controlled objects
Policy enforcement points
A PEP is a required condition, not a feature toggle. If none of these sits on the request, you can still inventory, decide, and simulate. You cannot honestly claim a block.
SDK
A check in the agent or service code, on the path of the action.
Security gateway
A gateway that asks for a decision before the request continues.
MCP gateway
Authorize which agent identity may call which tool, with which arguments.
Sidecar
A process beside the workload that can allow or deny on the path.
Connector
Enforcement in a system you already run — only when that connector exists.
Shadow before protect
Shadow produces the same decision as protect, including would-be denies and would-be approvals, without blocking the caller. Review the trail. Attach a PEP. Then enable enforcement. Skipping simulate is how programs stay in observe forever — or flip fail-closed and break production.
Deny by default is a policy principle
If a check has no matching allow, the decision is deny. That is not scareware and not a claim that every action in the estate is already blocked. You still choose when to leave shadow.
Risk informs the decision. It does not replace it.
Risk in the first release is rule-based. A language model may help explain a draft. It is not the final policy decision point. Full prompts are not the default payload to the SaaS.
This public site
The marketing site has no product session and no tenant data. It is not the control plane. It is operated by ABSGROUP INC., 347 Hudson Bend, Edmonton, Alberta T6V 1R5, Canada. Vulnerability reports: [email protected] or security.txt. How the loop is sold as a product is on QData Identity Security.
Related pages
Authorization
The check itself. This page is when a decision becomes a block.
Open authorizationMCP Security
MCP as a surface, not a magic block.
Open MCP SecurityQData Identity Security
The product this model belongs to.
Explore the platformDevelopers
Where an SDK PEP starts: a conceptual authorization check.
Start building
Questions
Talk through enforcement honestly
If you need a block, you need a PEP. If you need a quote or a rollout plan, use the form.