Skip to content

Roadmap

  • DNS-over-TLS forwarding to the upstreams you choose, with optional per-upstream CA pinning.
  • Blocklists and allowlists from local files (hosts-file lines, AdAway short form and AdGuard ||host^ rules). Allowlists win, and every block names its list.
  • Block responses as configurable addresses or NXDOMAIN.
  • Decoy hostnames: answered locally, never forwarded, and raising an alert that names the client.
  • ward config export, which leaves decoys out by construction.
  • A local, loopback-only dashboard of recent decisions.
  • ward doctor for config and connectivity checks, where every error names its fix.
  • Offline verification of signed update bundles (ward update verify).
  • An external-classifier interface: a sibling process that speaks typed JSON and is isolated from the resolver.
  • Behavioral detector (hostname-only, flag-only). It scores names that miss every list and records flags with reasons. It never blocks. See Behavioral detector.
  • Timing and per-device history: detector signals from query cadence and from what each device normally asks for.
  • Enforcement mode: opt-in blocking on high-confidence verdicts, still decided by the policy engine.
  • LLM explainer: an optional local model that explains a flag in plain language. It never decides.
  • Roaming mode: your laptop keeps using your home Ward when it is off your network, over WireGuard.
  • macOS client: a native client that protects a Mac even with no home appliance.
  • Managed feeds: curated, signed threat-intel lists that your device pulls on a schedule.
Edition Status
Community Available now. Free and open source: everything on this page that has shipped.
Pro Planned. Adds managed feeds, opt-in alert relay (alert metadata only) and roaming mode.
Pro+ Mesh A candidate, not a commitment. Multi-device coverage built on Pro’s roaming.
SMB Later.
Enterprise Later.

No edition sends your traffic anywhere.