vshld.com · runtime integrity for edge AI

AI left the data center.
Security didn't.

Enterprises spent two decades building chains of trust — and every one of them stops before the AI model. VisionShield closes the last gap across Physical AI, Robotics AI, and Gen AI: models are verified before they run, governed while they run, and every event leaves evidence anyone can independently re-verify.

Physical AI Robotics AI Gen AI verify at model load tamper-evident history default-deny egress
01 · The fragmented market

Five platforms. Five roots of trust. Five token formats.
Zero of them protect the model.

Secure boot verifies firmware. The OS verifies applications. Identity verifies people. Then a multi-million-dollar AI model — the asset actually making decisions — loads into memory, and no one checks anything. Each platform ends its chain of trust at a different layer, in a different format, with a different vendor. The one thing they agree on: none of them go the last step.

Platform
Jetson Orin
Apple A/M
Android SoC
AWS Nitro
x86 + TPM
Silicon root
BootROM
SecureROM
PBL (ROM)
Nitro chip
TPM 2.0
Verified boot
Secure Boot
Boot chain
AVB
Firmware attest
Measured boot
OS / app trust
dm-verity
App notarization
Play Integrity
Enclave attest
Code signing
— every chain of trust stops here · the layer-10 gap —
AI model
unverified
unverified
unverified
unverified
unverified
 
VSHLD
VSHLD
VSHLD
VSHLD
VSHLD
// one verification layer, normalized across every hardware root of trust
FRAGMENT 01

Scanners stop at the download

Model-scanning gateways inspect what you pull from a hub. They say nothing about what is actually executing on a device in the field, months and updates later.

FRAGMENT 02

Signing stops at the publisher

Model-signing standards let a builder vouch for an artifact. Without an enforcement point on the device, a signature nobody checks at load protects nothing.

FRAGMENT 03

Telemetry can't read tensors

Standard firewalls and EDR see sockets and processes — not whether the bytes leaving a camera are signed inference results or raw frames of people's faces.

02 · One control plane

Check it at the door. Watch it while it lives there.
Govern what it sends out.

Three guarantees, mapped to the device lifecycle — each one emitting signed, chained records as it works. The application on the device can be anything; VSHLD governs what it loads, what changes, and what leaves.

GATE · VERIFY

Nothing unapproved runs

At import and load: the artifact's signature and fingerprint are checked against its signed manifest, and the device proves its own health against a hardware root of trust — before the model is ever unlocked.

emits: signed run_record
WATCH · MONITOR

Change never goes unseen

Between events: on-disk models are re-verified against their baselines, processes and sockets are compared to expectations, and drift is reported with before/after fingerprints.

emits: integrity heartbeat · drift alerts
ENFORCE · GOVERN

Nothing leaves ungoverned

At every sync: a declarative egress policy defaults to absolute deny for raw frames, keypoints, and unencrypted gradients — and routes what is allowed only to verified endpoints. Blocks are logged as first-class evidence.

emits: signed egress & denial records
record #4041 ✓ signed⟶ hash ⟶ record #4042 ✓ signed⟶ hash ⟶ record #4043 ✓ signed⟶ hash ⟶
Every record is chained to the one before it. Delete or edit any past event and the chain visibly breaks — that's what makes the history tamper-evident, and what lets an auditor re-verify it without trusting us.
03 · Evidence, not assurances

"No tampering confirmed" is not an answer.

In July 2026, an autonomous AI agent escaped a research sandbox and breached the infrastructure of the world's largest model hub. The strongest assurance available to the market afterward: no tampering with public models was confirmed. An absence of evidence — because the evidence layer doesn't exist.

// the question every AI platform will now be asked: can you prove it?

WITHOUT AN EVIDENCE LAYER

Forensics estimates what probably happened. Logs can be edited by whoever breached the system. The honest answer is a shrug with a confidence interval.

WITH VSHLD

"Were the models touched?" becomes a computation: re-verify every fingerprint against every signed manifest and re-walk the chained history — in minutes, on a machine we don't control.

04 · The proof plan

Measured numbers, whatever they are.

We publish our verification protocol before our results, and we report false-alarm rates alongside catches. A proof that hides its limits isn't proof.

SEPT 2026

Red-team benchmark

Detection and false-alarm rates against realistic tamper scenarios, measured on production-class NVIDIA H100 + Jetson hardware, with on-device overhead reported.

SEPT 2026

Evidence pack v1

Build attestations, signed manifests, verification and egress records — exported, checksummed, and handed to independent experts to re-verify on machines we don't control.

SEPT 2026

Recorded end-to-end walkthrough

A genuine signed model loads and runs. A tampered copy of the same model is refused — and the refusal itself becomes a signed record.

IN PROGRESS

Cloud marketplace availability

Metered, procurement-ready distribution through the major cloud marketplaces. Patents granted and pending on the underlying methods.

05 · Model-agnostic by design

One verification layer.
Physical AI, Robotics AI, and Gen AI.

Most security tooling is built for one kind of model and breaks on the next. VSHLD verifies artifacts and events — not architectures — so the same control plane covers a perception model on a camera, a control policy on a robot, and a language model running on-premises.

DOMAIN 01

Physical AI

vision · perception · sensor fusion

Models that watch the world: cameras, kiosks, inspection lines, smart infrastructure. Verified at load, with raw frames and keypoints blocked at egress by default — so privacy is a provable property, not a policy statement.

Proven in production under biometric-privacy law.
DOMAIN 02

Robotics AI

control policies · planners · autonomy stacks

Models that move the world: arms, AMRs, drones, vehicles. The chain of custody runs from the validated artifact in simulation to the controller on the machine — through every OTA update — so "which model was executing?" is answerable after an incident.

Sim-to-real custody for safety cases and insurers.
DOMAIN 03

Gen AI

LLMs · VLMs · on-prem & edge inference

Models that reason about the world: weights pulled from public hubs, fine-tunes, and private models served in your own environment. Provenance verified at load, and context, prompts, and embeddings governed on the way out.

Artifact integrity and data egress — not prompt-level guardrails, which are a separate discipline.

Why one layer covers all three: a signature proves who vouched for a model. A fingerprint proves the bytes on the device are the ones they vouched for. A chained record proves what happened next. None of those three depend on what the model does — which is why the same agent secures a 4MB detector on a Jetson and a 40GB language model on a rack.

// a hash doesn't care what the model does
06 · Where it runs

Built for AI outside the data center.

Regulated vision fleets

Kiosks, clinics, retail, and facilities running camera AI under biometric-privacy and AI-governance law — where "raw video never leaves the box" must be provable, not promised.

EU AI ACT · BIPA · HIPAA-ADJACENT

Physical AI & robotics

When models operate machinery, "prove which model was executing" is a safety case, an insurance question, and a liability shield. VSHLD is the chain of custody from validation to the factory floor.

SIM-TO-REAL CUSTODY · OTA INTEGRITY

Disconnected & tactical edge

Devices that operate offline, intermittently connected, or in contested environments — where verification must happen locally and the evidence must survive until it can sync.

DIL ENVIRONMENTS · ZERO TRUST AT THE EDGE

Ask us to prove it.

Request the September evidence pack, put your own skeptic on the verification, or bring us a fleet worth protecting. Proof that depends on trusting us isn't proof — so don't.

Request the evidence pack   Become a design partner