IVD reference architecture
IVD has two prongs that share one operating pattern. IVD-N observes and acts on coordinated traffic behavior before it reaches the protected edge. IVD-ACP evaluates inputs before they inherit trusted authority. The two prongs can be evaluated independently, but both use the same pattern: observe, decide, enforce, and log.
Network-control path
Admission-control path
- Telemetry observation
- Policy decisioning
- Controlled enforcement
- Logs and evidence capture
- Cross-provider suppression earlier in the path
- Third-party carrier FlowSpec acceptance
- Federal lab validation
This reference view is a public evaluation diagram. It shows where IVD decisions and enforcement points sit; it is not a production deployment claim.