See exactly what survives between the vehicle and the cloud.
Exercise the line-fit TCU boundary across loss of network, constrained links, power recovery, protected overflow, replayed downlink and vehicle-command routing. The lab mirrors the buildable C++20 agent while remaining fully synthetic.
Protected evidence survives a missing link.
Every accepted producer event is identity-, schema-, purpose-, checksum- and clock-qualified before entering the fixed-capacity journal. No link means no batch.
Complete all three gates to expose the result.
- Producer acknowledgement
- not evaluated
- Durable cloud acceptance
- false
- Command executed
- false
- Physical vehicle action
- false
Durability precedes acknowledgement.
A producer receives success only after identity, schema, purpose, checksum and time checks and a durable bounded journal record.
Recovery keeps uncertainty visible.
A power-loss snapshot is revision- and identity-bound. Previously offered records return to journaled—not cloud accepted—after restore.
Downlink never becomes actuation.
FW-04 validates and routes typed requests to their least-privilege owners. It never executes a command or claims a physical vehicle outcome.
Scope electronics, firmware, cloud and lifecycle without hiding their boundaries.
Each module can be program-selected, but identity, revisions, evidence and recovery semantics must remain coherent across all four.