Roadmap
Shipped
Section titled “Shipped”- DNS-over-TLS forwarding to the upstreams you choose, with optional per-upstream CA pinning.
- Blocklists and allowlists from local files (hosts-file lines, AdAway short form and AdGuard
||host^rules). Allowlists win, and every block names its list. - Block responses as configurable addresses or NXDOMAIN.
- Decoy hostnames: answered locally, never forwarded, and raising an alert that names the client.
ward config export, which leaves decoys out by construction.- A local, loopback-only dashboard of recent decisions.
ward doctorfor config and connectivity checks, where every error names its fix.- Offline verification of signed update bundles (
ward update verify). - An external-classifier interface: a sibling process that speaks typed JSON and is isolated from the resolver.
- Behavioral detector (hostname-only, flag-only). It scores names that miss every list and records flags with reasons. It never blocks. See Behavioral detector.
Coming soon
Section titled “Coming soon”- Timing and per-device history: detector signals from query cadence and from what each device normally asks for.
- Enforcement mode: opt-in blocking on high-confidence verdicts, still decided by the policy engine.
- LLM explainer: an optional local model that explains a flag in plain language. It never decides.
- Roaming mode: your laptop keeps using your home Ward when it is off your network, over WireGuard.
- macOS client: a native client that protects a Mac even with no home appliance.
- Managed feeds: curated, signed threat-intel lists that your device pulls on a schedule.
Editions
Section titled “Editions”| Edition | Status |
|---|---|
| Community | Available now. Free and open source: everything on this page that has shipped. |
| Pro | Planned. Adds managed feeds, opt-in alert relay (alert metadata only) and roaming mode. |
| Pro+ Mesh | A candidate, not a commitment. Multi-device coverage built on Pro’s roaming. |
| SMB | Later. |
| Enterprise | Later. |
No edition sends your traffic anywhere.