Quantum-resistant cryptography, deterministic scanning, and runtime integrity protection.
Shield uses an open-core distribution boundary. Trust-critical formats and standalone agents remain auditable in the public repository; centralized enterprise operations are supplied under a commercial license from a private implementation repository.
The product name remains Vollcrypt Shield. After a commercial agreement,
customers receive a private, prebuilt shield-commercial deployment bundle.
That distribution name distinguishes licensed fleet operations from the
standalone public Shield packages; it does not rename the product.
no_std embedded
agents;These components use GPL-3.0-only OR LicenseRef-Commercial. A commercial
license permits proprietary integration without applying GPL obligations to the
licensee’s own application, subject to the applicable agreement.
shield-commercial Windows/Linux deployment bundles.The private backend has passed synthetic disposable PostgreSQL 17 TLS 1.3 qualification. Customer production qualification still requires that customer’s disposable TLS-enabled staging database. External Slack, Teams, PagerDuty, or SIEM event delivery is disabled unless the customer explicitly authorizes and configures off-device event transmission. The current centralized dashboard is terminal based; a graphical fleet mode is not included in this delivery.
Extensions are not part of the current deliverable unless a signed agreement explicitly includes and schedules them. This public repository intentionally contains no commercial server, storage, administration, or fleet-dashboard source code.
Public agents can produce signed enrollment, summary, witness, and offline records for a licensed fleet deployment. Public clients can verify ML-DSA-signed responses and evidence independently. Publishing these formats does not publish the private service implementation and avoids making the commercial platform a blind trust root.