Invariants
These rules come from Ward’s engineering invariants. A change that breaks one is treated as a bug, even if every test passes.
- The AI is a classifier, never a decider. Detectors return a typed verdict. A deterministic, exhaustively cased policy engine maps verdicts to actions. No model output touches connection state directly.
- No flow data leaves the device. This holds at every tier. Paid tiers add feeds that your device pulls, and opt-in alerts that carry alert metadata only.
- The update channel is pull-only. Your device initiates every update connection, and Ward accepts no inbound connections on that path. When the update channel ships, updates are signed and verified before use; today
ward update verifychecks a bundle offline. - Decoys never leak. A configuration exported from an instance with decoys never contains the decoy hostnames.
- No silent drops. Every block names the rule and list that caused it. Today you override a block with an allowlist entry. A one-click override in the dashboard is coming.
- Every error names a fix. Ward’s startup errors, logs and dashboard tell you what to do next, not just what went wrong.
- One binary.
wardis the resolver, the dashboard and the CLI in a single process. The only exception is an external model, which runs as a separate sibling process so a prompt injection cannot reach the resolver.