monitoring
PulseGuard
Continuous evaluation of the entities you operate, reported to you rather than enforced for you.
PulseGuard evaluates the current state of the entities your organisation operates, and keeps evaluating them over time. Every Passport already includes evaluation you ask for, or that you raise an event for; PulseGuard is what makes that evaluation continuous, and extends it across more of your estate. It reports what it observes: it is not a safety verdict, not a certification and not a trust claim, and it never changes an identity or its tier.
The things you operate change after you have published them. An endpoint moves, a listing is withdrawn, a binding stops resolving, and the public identity you pointed people at carries on saying what it said last. Without monitoring you find that out when somebody else does. PulseGuard watches the entities you choose and reports what has changed, so the gap between a change and your knowing about it is something you decide rather than something you discover. What you do about a finding stays with you: ECZ-ID reports, it does not enforce.
What this means for SDK
A package you published years ago is still being installed today, from registries whose accounts change hands and whose listings you do not entirely control. PulseGuard watches the publisher identity behind the packages you publish and reports when a registry binding stops resolving, or stops pointing where it used to. It does not audit the code in a release and it is not a supply-chain scanner. It tells you when the picture your consumers can read has changed.
What you already have
- 25 enhanced evaluations, granted once rather than monthly
The ladder
The price is set, but online purchase is not open yet. There is no checkout route for it today. Agreed directly rather than bought online, so the scope and the price are settled with you.
PulseGuard Pro (monthly)
50 monitored entities · 150,000 evaluations a month
£19.99 per monthNo VAT chargedView details(opens in a new tab — trustops.ecocitizenz.com)PulseGuard Business (monthly)
500 monitored entities · 1,000,000 evaluations a month
£79.99 per monthNo VAT chargedView details(opens in a new tab — trustops.ecocitizenz.com)PulseGuard Scale (monthly)
2,500 monitored entities · 5,000,000 evaluations a month
£249.99 per monthNo VAT chargedView details(opens in a new tab — trustops.ecocitizenz.com)PulseGuard Enterprise
How PulseGuard works
- 1.Choose which of the entities you already operate should be watched. They are drawn from the Passports your organisation holds, so nothing new is issued and no identity is created in order to monitor one.
- 2.Each watched entity is evaluated on a schedule, rather than only when you ask. Its bindings are re-read, its record is re-checked, and what is observed now is compared with what was observed before.
- 3.A change produces a finding: what moved, when it was observed, and what it was before. A finding informs you. It never decides identity truth or lifecycle state on its own.
- 4.You decide what a finding means and what happens next, under your own policy and in your own systems. PulseGuard sits outside the execution path, acts on nothing and blocks nothing.
- 5.Watching runs for as long as the entitlement does. Stopping it stops the watching and nothing else: the entities, their Passports and their published records carry on exactly as before.
Limits and conditions
- One paid tier at a time within a billing scope. Tiers replace one another rather than stacking.
- An upgrade replaces the lower tier rather than adding to it: the higher tier's allowances become the ones that apply.
- No tier offers unlimited variable-cost activity. Every plan states the volume it includes.
- Usage is cost-governed: the included volumes are real ceilings, not a soft guideline, so the service cannot run up an unbounded bill on your behalf.
- No VAT charged. EcoCitizenz Ltd is not VAT-registered, so no VAT is added and no VAT invoice is issued.
How PulseGuard differs from the other ECZ-ID products
- LedgerCore
- LedgerCore is evidence of what happened. PulseGuard is observation of what is happening. LedgerCore keeps decisive lifecycle events in a form that shows they have not been altered since they were written, so you can show a third party later what took place; PulseGuard watches current state and tells you when it moves, so you can respond while it is still current. Neither makes the statement inside it true, and holding one does not substitute for the other.
- The Resolver record
- The Resolver record is the live public state of an identity, readable by anyone with no account and no key, and it is free. It answers what is declared right now, for whoever asks, and it remains the only authority on what an ECZ-ID currently says. PulseGuard is for the operator rather than the reader: it re-reads your own records on your behalf and tells you when something changes. It does not make the public record more authoritative, and a record is still not proof — re-check it before you rely on it.
- A certification
- A certification is somebody's judgement that a thing meets a standard. PulseGuard makes no judgement of that kind. It is not a certification: monitoring something does not certify, approve, accredit or endorse you or anything you operate. It records and monitors; it does not vouch. Watching an entity changes neither your organisation's tier nor any child Passport's assurance.
- Your own infrastructure monitoring
- Your existing observability watches whether a system is up, fast and healthy, from inside your infrastructure. PulseGuard watches whether a published identity still matches what it claims — bindings that no longer resolve, listings that have gone, records that have drifted from what they said. The two answer different questions on different sides of your perimeter, and PulseGuard replaces neither your monitoring nor your alerting.
After you buy, and how to change or cancel
What happens after purchase
- The monitoring entitlement is added to your organisation, and the entities you nominate begin being evaluated on a schedule rather than only on request.
- Your ECZ-ID does not change. No Passport is re-minted, duplicated or replaced, and no identifier moves.
- Your organisation's tier does not change. Buying monitoring never makes an organisation VERIFIED or ASSURED, and it never changes the assurance of any child Passport.
- The free baseline is untouched. The evaluation every Passport already includes, its Resolver record and the essential canonical evidence kept for it all continue exactly as before.
- Findings inform you and nothing else. They never decide identity truth or lifecycle state.
Upgrading
Downgrading
Cancelling
PulseGuard — frequently asked questions
- Does PulseGuard make anything safe, approved or compliant?
- No. It is not a certification and it is not a trust claim: it records and monitors, and it does not vouch. Holding it does not certify, approve, accredit or endorse you or anything you operate, and it does not make you compliant with anything.
- If PulseGuard reports nothing, does that mean everything is fine?
- No. The absence of a record is not evidence of danger: it means nothing has been recorded, not that something is wrong. It is not a clean bill of health either. Monitoring narrows the gap between a change and your knowing about it; it does not promise there is nothing to know.
- Does it act on what it finds?
- No. Your own policy decides what to do with the result. ECZ-ID reports; it does not enforce. PulseGuard stays outside the execution path: it blocks nothing, suspends nothing and changes nothing in your systems on your behalf.
- Does monitoring change my organisation's tier, or my Passports' assurance?
- No. Buying capacity or a service never changes a Parent organisation's tier — a DECLARED organisation stays DECLARED until it is independently checked — and it never changes the assurance of any child Passport. A finding informs; it never decides identity truth or lifecycle state.
- Do monitoring tiers stack the way capacity packs do?
- No, and this is the one place the two behave differently. Capacity packs stack: buy more than one and the allowances add together. Monitoring is a tier. One paid tier applies within a billing scope at a time, and an upgrade replaces the lower tier rather than adding to it.
- What does a free Passport already include?
- Evaluation you ask for. A free Passport's state is evaluated on demand, or when you raise an event — nothing runs on a schedule and no monitor is switched on by default. Your organisation is also granted an allowance of enhanced evaluations once, rather than monthly, and the figures are shown above as TrustOps currently states them. Ongoing, scheduled watching is what the paid tiers add.
- Does monitoring consume my organisation's Active Entity Capacity?
- No. Active Entity Capacity counts the entities your organisation actively manages, pooled across the Agent, MCP, Plugin, API, SDK and Service & Workload families and belonging to the organisation rather than to one Passport type; IoT device instances draw on IoT Device Fleet Capacity, which is a separate meter. PulseGuard states its own allowances — the entities it watches and the evaluations it runs — and those are what it is measured against.
- What happens when the included volume runs out?
- Nothing is revoked. Running out of an allowance never destroys or detaches anything that already exists: your Passports, their bindings and their Resolver records are unaffected, because capacity is never identity. Usage is cost-governed — the included volumes are real ceilings rather than a soft guideline, and no tier offers unlimited variable-cost activity — so evaluation stops at the ceiling instead of running up an unbounded bill on your behalf.
