Skip to content

Invariants

These rules come from Ward’s engineering invariants. A change that breaks one is treated as a bug, even if every test passes.

  1. The AI is a classifier, never a decider. Detectors return a typed verdict. A deterministic, exhaustively cased policy engine maps verdicts to actions. No model output touches connection state directly.
  2. No flow data leaves the device. This holds at every tier. Paid tiers add feeds that your device pulls, and opt-in alerts that carry alert metadata only.
  3. The update channel is pull-only. Your device initiates every update connection, and Ward accepts no inbound connections on that path. When the update channel ships, updates are signed and verified before use; today ward update verify checks a bundle offline.
  4. Decoys never leak. A configuration exported from an instance with decoys never contains the decoy hostnames.
  5. No silent drops. Every block names the rule and list that caused it. Today you override a block with an allowlist entry. A one-click override in the dashboard is coming.
  6. Every error names a fix. Ward’s startup errors, logs and dashboard tell you what to do next, not just what went wrong.
  7. One binary. ward is the resolver, the dashboard and the CLI in a single process. The only exception is an external model, which runs as a separate sibling process so a prompt injection cannot reach the resolver.