
Carapace is the action-layer trust boundary that sits on top of Veea's Lobster Trap. AI agents now run at the edge with authority to take destructive actions on production infrastructure — isolate a spine switch, quarantine a node, migrate VMs across sites. Lobster Trap guards the conversation with deep prompt inspection, but a conversation that looks perfectly clean can still end in isolate(spine-switch-sj-01), and a single poisoned log line can trigger a self-inflicted outage with no clear audit of why. Carapace closes that gap. It sits between the agent's reasoning and its tool execution as a fail-closed policy engine that gates the action itself on declared-versus-detected intent, source provenance (trusted telemetry versus untrusted ingested text), and blast radius. It folds Lobster Trap's conversation-layer verdict into its own rule matrix so the two compose into genuine defense-in-depth — Lobster Trap can only ever make Carapace stricter, never looser. An injection-driven destructive action is escalated to QUARANTINE and never reaches the executor: proven live with real Gemini through the real Lobster Trap binary, blocked at $0 versus a ~$47k/minute outage with no trust layer. Every decision lands in a tamper-evident, hash-chained audit trail a regulator could read. It's the ceiling Veea's "floor, not ceiling" challenge asked for — a drop-in trust layer enterprise security teams will actually sign off on, with a 114-test suite and a live Gemini + Three.js demo.
19 May 2026