# Stop sensitive data at the browser — without collecting it.

> Ward is a managed Microsoft Edge extension and admin console. It inspects pastes, uploads and AI prompts locally, enforces your policy at the moment of the action, and sends only metadata to the server.

Ward is a managed extension for Microsoft Edge and an admin console. It checks pastes, uploads and AI prompts and applies your policy at the moment of the action. Content stays on the device; only metadata is sent to the server.

## Four areas of protection

What ships today and what is coming, labelled plainly. Data protection and extension visibility are available now; web and download threat protection are coming.

### 1. Data protection — Available

Stops sensitive company data from leaving through AI prompts, pastes, uploads and form submissions — decided in the browser, at the moment of the action.

- Available today: AI prompt protection; Paste and drag-and-drop inspection; File upload inspection; Local DLP detectors and classifications; Corporate vs personal account context; App and AI discovery; Graduated decisions

### 2. Extension protection — Available

Shows every browser extension in the organisation, where it comes from, what it may do and what changed — and blocks it through Microsoft Edge policy when an administrator decides to.

- Available today: Extension inventory; Publisher and store history; Permission-change alerts; Explainable risk score; Administrator blocking via Edge policy
- Coming: Malware scanning and reputation; Automatic blocking

### 3. Web protection — Coming

Blocking of phishing, malware and scam sites is coming. Today, company policy can already block or warn on navigation to specific applications and categories.

- Available today: Policy-based site and app controls
- Coming: Phishing, malware and scam site blocking

### 4. Download protection — Coming

Download reputation is coming. Today, company policy can already block, warn on or log downloads by source site and file type.

- Available today: Download rules by source site and file type
- Coming: Download reputation

[All capabilities, with how each was tested](https://valvayn.com/product/)

## How it works

### 1. Inspect locally

At a paste, drop, upload or prompt submission, the extension classifies the content on the device with detectors that return counts, never values, and applies your signed policy on the spot. Blocking takes effect before the content reaches the site.

Example — local inspection of the synthetic test content used in the validation:

- Pasted text: Ward test WARDCANARY-W1 card 4111 1111 1111 1111
- Detector: pci.card — 1 match (Visa prefix, Luhn check passes)
- Classification: Payment card data · restricted
- Destination: chatgpt.com · generative AI · not confirmed as a work account
- Policy: Block sensitive data to personal AI → block
- Leaves the device: pci.card × 1, blocked

### 2. Report the decision

If the policy acts or sensitive data was found, the extension queues an event and uploads it in the background. Browsing never waits for the server, and allowed, non-sensitive actions produce no event.

Example — the metadata event the server receives for a blocked paste (abridged):

```json
{
  "type": "data.paste",
  "occurredAt": "2026-09-25T02:33:00Z",
  "action": "paste",
  "decision": "block",
  "outcome": "blocked",
  "severity": "high",
  "app": {
    "hostname": "chatgpt.com",
    "catalogKey": "chatgpt",
    "category": "genai"
  },
  "account": {
    "type": "unknown",
    "domain": null,
    "identifier": null
  },
  "data": {
    "classifications": ["<Payment card data>"],
    "detectors": [{ "id": "pci.card", "count": 1 }],
    "maxSensitivity": "restricted",
    "source": "clipboard"
  },
  "file": null,
  "policy": {
    "ruleId": "<Block sensitive data to personal AI>",
    "version": 2
  },
  "inspectMs": 0.2
}
```

### 3. Review in the console

Administrators see the event, the device, the user and the policy that fired, and can route alerts to a SIEM through signed webhooks.

Blocked events recorded during the September 2026 validation on real Microsoft Edge and chatgpt.com (this metadata is everything that was stored):

| Time (UTC) | Device | Type | Outcome | Detectors | Inspect ms |
|---|---|---|---|---|---|
| 2026-09-25 02:33 | Edge · Windows | data.paste | blocked | pci.card ×1 | 0.2 |
| 2026-09-25 03:20 | Edge · macOS | data.submit | blocked | pci.card ×1 | 3.5 |
| 2026-09-25 03:31 | Edge · macOS | data.paste | blocked | pci.card ×1 | 0.3 |
| 2026-09-27 06:14 | Edge · Windows (Intune) | data.submit | blocked | pci.card ×1 | 0.6 |
| 2026-09-27 06:14 | Edge · Windows (Intune) | data.paste | blocked | pci.card ×1 | 0.2 |

## Deploys to Microsoft Edge with Intune

Ward is a Manifest V3 extension that your MDM force-installs, so users cannot remove or disable it. There is no agent to install on the operating system.

You create an enrollment token in the console, download the generated configuration and assign it in Intune — [the deployment steps are on the Product page](https://valvayn.com/product/#deployment).

On macOS, Ward can optionally create and update the Intune profile through Microsoft Graph — using a dedicated app registration you authorise, and only after you preview and confirm each change. Microsoft Entra ID provides directory groups for policies, single sign-on for administrators, and verification of which user is signed in to each browser.

## Private by design

Ward exists to keep company data out of the wrong places, not to watch employees.

- **Content stays on the device; only metadata is sent.** Pastes, prompts, files and typed text are inspected in the browser. The telemetry schema has no field that could carry content, and the server rejects unknown fields.
- **Allowed, non-sensitive actions produce no event.** Ward reports when a policy acts or sensitive data is detected.
- **Only hostnames, never full URLs.** Application discovery is a daily roll-up, not a browsing history — and can be limited to known applications.
- **Personal account identifiers are not collected by default.** A personal account is recorded as, for example, “personal, gmail.com”.
- **Events are deleted after 180 days by default.** Retention is configurable per organisation.

[Read the security and privacy details](https://valvayn.com/security/).

## What has been verified

Version 0.1.0 was tested in September 2026 on real Microsoft Edge, the real chatgpt.com and a real Microsoft 365 tenant with Intune — [see the results, and what is not yet validated, on the Product page](https://valvayn.com/product/#verified).

[Request access](https://valvayn.com/contact/) · [See how it works](https://valvayn.com/product/)

---

Canonical: https://valvayn.com/ · Markdown: https://valvayn.com/index.md · Built: 2026-10-10
