Language:
PRODUCTS
SECTORS
MORE
Quantum Security 🔍 Search Request Access →
CYBERSECURITY · ARCHITECTURE BEFORE REACTION

DENY ENTRY. DENY EFFECT.

An attack should not become a security problem only after data has already been read, aggregated or transferred. immo.quick establishes two independent boundaries: one before a request reaches governed logic, and one immediately before a real effect can occur.

First question: May this request enter? Second question: May this exact effect happen now?
01 · THE CONTROL LOGIC

Not an alert after effect. A decision before effect.

Traditional security models are often strong at establishing who authenticated, what role an account holds and whether behavior appears anomalous. The deeper question is whether a technically reachable path can actually create a production effect. immo.quick deliberately separates access, authority and execution.

REQUESTexternal, internal or automated
BOUNDARY 1 · ADMISSIONcompleteness · freshness · cryptographic origin · scope
GOVERNED STATElaw · jurisdiction · sector · authority · dependencies
BOUNDARY 2 · EXECUTION RIGHTonly closed, current and scope-conformant authority
REAL EFFECTonly through a permitted execution path
DENYmissing or invalid admission conditions
DENYlegally or contextually inadmissible state
DENYno valid Execution Right / stale dependency
DENYunregistered or unauthorized effect path
02 · TWO INDEPENDENT ARCHITECTURES

Core constrains admission. Serverless constrains admission and effect at the edge.

immo.quick Core

A dedicated fail-closed Access Guardian sits in front of the governed compliance pipeline. A request must fully satisfy the required admission conditions before downstream decision logic becomes reachable. Missing required information, stale state or invalid cryptographic origin results in denial before the pipeline.

Principle: A request that fails admission does not reach the governed logic.

immo.quick Serverless Edition

At the edge, a client must first cryptographically demonstrate that it is registered and currently legitimate for the requested surface. Only then do governance gates and Execution Rights follow. Even a successfully attested client does not receive unrestricted execution authority. Effect requires a valid, current, scope-conformant Execution Right and a valid capability derived from it.

Principle: Valid access is not equivalent to valid execution.
An attacker does not only have to get in. They would also have to obtain valid authority for the exact intended effect. Those are two different problems — and two different boundaries.
03 · WHEN CREDENTIALS ARE COMPROMISED

Stolen access must not inherit the authority of the system.

01

Identity ≠ Authority

Successful authentication proves an identity or client state. It does not automatically authorize every downstream action.

02

Reachability ≠ Scope

The fact that a resource is technically reachable does not mean the current request or capability is entitled to use it.

03

Access ≠ Effect

Reading is not exporting. Individual access is not bulk transfer. Administration is not exfiltration. Every effect remains bound to its own permitted scope.

04 · DENY AND PROVE

Denial is primary. Forensics comes after.

immo.quick does not assume that an analyst will detect an attack quickly enough to prevent harm. Where an invalid admission or execution condition is established, the primary response is denial. Forensic capture, reconstruction and internal incident processes then document what was attempted and at which boundary the request ended.

Detection remains valuable. But it is not the final authority over whether an effect may occur.

05 · CURRENT INTERNAL ENFORCEMENT VERIFICATION

Not only architecture text. Behavior under invalid variants.

10
registered production Execution Surfaces
20
defined attack-vector classes
191/191
applicable enforcement test cases successful
0
failures in the current run
Status: internal immo.quick system verification, 5 September 2026. These figures are not a BSI audit, government certification or regulatory endorsement. The figure 191 refers to applicable test cases across 10 surfaces and 20 defined classes; not every class must be applicable to every surface.
06 · CLAIM BOUNDARY

What we claim — and what we explicitly do not.

No architecture can credibly guarantee that an attacker will never reach a technical contact point, that credentials can never be stolen or that zero-day vulnerabilities cannot exist. immo.quick therefore does not claim to replace general network, endpoint or organizational cybersecurity.

The verifiable architectural claim is narrower and stronger: invalid requests should not reach governed logic; and access alone should not authorize a real effect. Where required state is missing, stale, revoked, out of scope or arrives through an unauthorized path, execution fails closed.

Review-status note: only the architecture of the immo.quick Serverless Edition was demonstrably submitted to the BSI for technical consideration on 28 July 2026. The architecture of immo.quick Core was not submitted to the BSI. The submission does not constitute a BSI audit, certification, endorsement or confirmation. Public statements by immo.quick must not be understood as government validation.
07 · DIRECT ANSWERS

Key architecture questions, answered precisely.

What does “Deny Entry. Deny Effect.” mean?

It describes two separate security boundaries: an admission boundary intended to stop invalid requests before governed logic is reached, and an independent Execution Rights boundary intended to prevent access alone from authorizing a real effect.

What is the difference between access and execution authority?

Authentication, role or technical reachability are not automatically sufficient for execution. A real effect requires a currently valid, scope-bound execution basis.

Which architecture was submitted to the BSI?

Only the architecture of the immo.quick Serverless Edition was demonstrably submitted to the BSI for technical consideration on 28 July 2026. immo.quick Core was not submitted to the BSI. This does not constitute a BSI audit, certification or endorsement.

Does immo.quick replace conventional cybersecurity?

No. Network, endpoint, identity and organizational security remain necessary. The additional architectural claim is to constrain unauthorized admission and prevent access from automatically becoming executable authority.

The security boundary belongs before admission — and before effect.

Core and Serverless Edition are independent architectures. Both follow the same institutional principle: technical reachability, identity and privilege do not by themselves create executable authority.

Explore Core →Explore Serverless Edition →Explore Execution Rights →
Request Access →