Frequently asked questions

Short, direct answers. Each links to more detail where it exists.

What is Ward?

Ward is an enterprise browser security platform: a managed Manifest V3 extension for Microsoft Edge that enforces data-protection policy in the browser, plus a control plane and admin console. It stops sensitive data from being pasted, uploaded or submitted to the wrong places — for example company data going into an AI tool through a personal account.

Does Ward see what employees type, paste or upload?

No — content is inspected locally in the browser and never leaves the device. The extension reads pasted text, submitted prompts and uploaded files on the device to classify them; only metadata such as “payment card data, 1 match, blocked” is sent to the Ward server. Ward has no keystroke listener.

What data does Ward send to its server?

Metadata only: the hostname and app category, account type and domain, the action and policy decision, classification names and per-detector match counts, file name, type and size for uploads and downloads, and device information such as OS, browser and extension versions and installed extensions. Full URLs, page content, prompts, clipboard contents, file contents and the matched values themselves are never sent. See Security & Privacy.

Which browsers does Ward support?

Microsoft Edge on Windows and macOS is the primary, validated target. Google Chrome runs the same extension build and is covered by automated tests, but has not yet been validated in real-world use. Firefox, Safari, native apps and mobile devices are not supported.

How is Ward deployed?

Ward is force-installed into Microsoft Edge by your MDM, typically Microsoft Intune. The console generates a platform script or .reg file for Windows and a .mobileconfig profile for macOS; each carries an enrollment token so devices enroll themselves with no user action. On macOS, Ward can optionally push the profile through Microsoft Graph after you preview and confirm each change.

Can users remove or disable the Ward extension?

Not when it is force-installed by policy: Edge shows no Remove option, which was confirmed on a real Intune-managed Windows device. Ward is not cryptographically tamper-proof; tamper resistance comes from Edge and MDM policy, and the console flags devices that stop reporting.

Does Ward work with Microsoft Entra ID?

Yes. Ward can sync users and groups from Entra ID for group-based policies, offer Entra single sign-on for administrators, and verify which directory user is signed in to each browser. These integrations are covered by automated tests against mocked Microsoft services and have not yet been validated against a live tenant.

Does Ward block ChatGPT or other AI tools?

Only if your policy says so. A typical policy allows AI tools but blocks sensitive data — for example payment card numbers — from being pasted, uploaded or submitted to them through personal or unrecognised accounts. Ward can also block, warn or require a business justification for navigation to specific AI tools, and treats unknown AI-looking sites as “unreviewed” until an administrator classifies them.

Can Ward tell a corporate AI account from a personal one?

For some apps, yes; for ChatGPT and Claude, usually not yet. Ward reads the account an app displays, such as Google’s account button or a SharePoint tenant host. ChatGPT and Claude generally do not display the signed-in email, so Ward classifies them as “unrecognised”, and policies should treat unrecognised like personal for those apps.

What kinds of sensitive data can Ward detect?

Payment card numbers, U.S. Social Security numbers, email addresses, U.S. phone numbers, cloud and SaaS credentials (AWS, GitHub, Slack, Google, Stripe, Azure storage, GCP service accounts), private keys, database connection strings with passwords, JWTs, generic secrets and references to your own corporate domains. Administrators can add keyword dictionaries and regular expressions, and group detectors into classifications with a sensitivity level.

Which file types can Ward inspect on upload?

Text-like files (.txt, .csv, .json, .md, logs, source code), Office Open XML files (.docx, .xlsx, .pptx) and text-based PDFs, up to a configurable size budget (10 MB by default). Images, archives, legacy Office formats, encrypted PDFs and scanned PDFs are reported as “not inspected”; rules can be set to block anything that could not be inspected.

Does Ward detect malicious browser extensions?

Ward shows every extension’s permissions, publisher, store status and changes over time, with an explainable risk score and alerts — but it does not label extensions as malware today. Malware scanning, reputation and automatic blocking are coming. Administrators can already block an extension, which Microsoft Edge enforces through policy.

Does Ward protect against phishing or malware websites?

Not yet — web threat protection and download reputation are coming, with early access on request. Today Ward can block, warn on or require a justification for navigation to specific applications or categories, and apply download rules by source site and file type.

Does Ward record employees’ browsing history?

No. For application discovery Ward records hostnames — never full URLs — as a daily roll-up of counts per application, user, device and account type. Organisations that do not need discovery of unknown applications can restrict it to known catalog applications.

How long does Ward keep data?

Security events are kept for 180 days by default and then deleted; each organisation can change this. Raw telemetry batches are emptied as soon as they are processed.

Does Ward work offline?

Yes. Decisions are made on the device from a cached, signed policy, so enforcement continues without a connection. Events are queued locally and uploaded when the device reconnects.

Has Ward been tested in the real world?

Yes, in a limited validation of version 0.1.0 in September 2026: real Microsoft Edge on Windows and macOS, the real chatgpt.com, and a real Microsoft 365 tenant with Intune on a Windows 11 virtual machine. Synthetic card numbers pasted or submitted to ChatGPT were blocked, and a full search of the Ward database and server logs found no trace of the test content. Not yet covered: macOS through Intune, live Entra ID, Chrome, HTTPS transport and a release signing key.

Is Ward SOC 2 or ISO 27001 certified?

This site makes no certification claim. For a vendor security assessment, contact [email protected].

Where is Ward hosted?

Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request.. Hosting provider and data location: Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection)..

How much does Ward cost?

Pricing is per protected browser per month and is agreed per customer during the pilot. Contact [email protected] for a quote.

How do I report a security vulnerability?

Email [email protected]. The responsible disclosure policy explains scope and safe harbour, and /.well-known/security.txt lists the contact in machine-readable form.

Does this website use cookies or analytics?

No. This website sets no cookies, uses no analytics, and loads no third-party scripts, fonts or embeds. See the Cookie Notice.