# Ward — full site text > Every page of https://valvayn.com/ as Markdown, generated 2026-10-10. Status labels: Available = ships today; Coming = not active yet. # Stop sensitive data at the browser — without collecting it. > Ward is a managed Microsoft Edge extension and admin console. It inspects pastes, uploads and AI prompts locally, enforces your policy at the moment of the action, and sends only metadata to the server. Ward is a managed extension for Microsoft Edge and an admin console. It checks pastes, uploads and AI prompts and applies your policy at the moment of the action. Content stays on the device; only metadata is sent to the server. ## Four areas of protection What ships today and what is coming, labelled plainly. Data protection and extension visibility are available now; web and download threat protection are coming. ### 1. Data protection — Available Stops sensitive company data from leaving through AI prompts, pastes, uploads and form submissions — decided in the browser, at the moment of the action. - Available today: AI prompt protection; Paste and drag-and-drop inspection; File upload inspection; Local DLP detectors and classifications; Corporate vs personal account context; App and AI discovery; Graduated decisions ### 2. Extension protection — Available Shows every browser extension in the organisation, where it comes from, what it may do and what changed — and blocks it through Microsoft Edge policy when an administrator decides to. - Available today: Extension inventory; Publisher and store history; Permission-change alerts; Explainable risk score; Administrator blocking via Edge policy - Coming: Malware scanning and reputation; Automatic blocking ### 3. Web protection — Coming Blocking of phishing, malware and scam sites is coming. Today, company policy can already block or warn on navigation to specific applications and categories. - Available today: Policy-based site and app controls - Coming: Phishing, malware and scam site blocking ### 4. Download protection — Coming Download reputation is coming. Today, company policy can already block, warn on or log downloads by source site and file type. - Available today: Download rules by source site and file type - Coming: Download reputation [All capabilities, with how each was tested](https://valvayn.com/product/) ## How it works ### 1. Inspect locally At a paste, drop, upload or prompt submission, the extension classifies the content on the device with detectors that return counts, never values, and applies your signed policy on the spot. Blocking takes effect before the content reaches the site. Example — local inspection of the synthetic test content used in the validation: - Pasted text: Ward test WARDCANARY-W1 card 4111 1111 1111 1111 - Detector: pci.card — 1 match (Visa prefix, Luhn check passes) - Classification: Payment card data · restricted - Destination: chatgpt.com · generative AI · not confirmed as a work account - Policy: Block sensitive data to personal AI → block - Leaves the device: pci.card × 1, blocked ### 2. Report the decision If the policy acts or sensitive data was found, the extension queues an event and uploads it in the background. Browsing never waits for the server, and allowed, non-sensitive actions produce no event. Example — the metadata event the server receives for a blocked paste (abridged): ```json { "type": "data.paste", "occurredAt": "2026-09-25T02:33:00Z", "action": "paste", "decision": "block", "outcome": "blocked", "severity": "high", "app": { "hostname": "chatgpt.com", "catalogKey": "chatgpt", "category": "genai" }, "account": { "type": "unknown", "domain": null, "identifier": null }, "data": { "classifications": [""], "detectors": [{ "id": "pci.card", "count": 1 }], "maxSensitivity": "restricted", "source": "clipboard" }, "file": null, "policy": { "ruleId": "", "version": 2 }, "inspectMs": 0.2 } ``` ### 3. Review in the console Administrators see the event, the device, the user and the policy that fired, and can route alerts to a SIEM through signed webhooks. Blocked events recorded during the September 2026 validation on real Microsoft Edge and chatgpt.com (this metadata is everything that was stored): | Time (UTC) | Device | Type | Outcome | Detectors | Inspect ms | |---|---|---|---|---|---| | 2026-09-25 02:33 | Edge · Windows | data.paste | blocked | pci.card ×1 | 0.2 | | 2026-09-25 03:20 | Edge · macOS | data.submit | blocked | pci.card ×1 | 3.5 | | 2026-09-25 03:31 | Edge · macOS | data.paste | blocked | pci.card ×1 | 0.3 | | 2026-09-27 06:14 | Edge · Windows (Intune) | data.submit | blocked | pci.card ×1 | 0.6 | | 2026-09-27 06:14 | Edge · Windows (Intune) | data.paste | blocked | pci.card ×1 | 0.2 | ## Deploys to Microsoft Edge with Intune Ward is a Manifest V3 extension that your MDM force-installs, so users cannot remove or disable it. There is no agent to install on the operating system. You create an enrollment token in the console, download the generated configuration and assign it in Intune — [the deployment steps are on the Product page](https://valvayn.com/product/#deployment). On macOS, Ward can optionally create and update the Intune profile through Microsoft Graph — using a dedicated app registration you authorise, and only after you preview and confirm each change. Microsoft Entra ID provides directory groups for policies, single sign-on for administrators, and verification of which user is signed in to each browser. ## Private by design Ward exists to keep company data out of the wrong places, not to watch employees. - **Content stays on the device; only metadata is sent.** Pastes, prompts, files and typed text are inspected in the browser. The telemetry schema has no field that could carry content, and the server rejects unknown fields. - **Allowed, non-sensitive actions produce no event.** Ward reports when a policy acts or sensitive data is detected. - **Only hostnames, never full URLs.** Application discovery is a daily roll-up, not a browsing history — and can be limited to known applications. - **Personal account identifiers are not collected by default.** A personal account is recorded as, for example, “personal, gmail.com”. - **Events are deleted after 180 days by default.** Retention is configurable per organisation. [Read the security and privacy details](https://valvayn.com/security/). ## What has been verified Version 0.1.0 was tested in September 2026 on real Microsoft Edge, the real chatgpt.com and a real Microsoft 365 tenant with Intune — [see the results, and what is not yet validated, on the Product page](https://valvayn.com/product/#verified). [Request access](https://valvayn.com/contact/) · [See how it works](https://valvayn.com/product/) --- Canonical: https://valvayn.com/ · Markdown: https://valvayn.com/index.md · Built: 2026-10-10 # What Ward does today, and what is coming. > What Ward does today and what is coming: data protection for AI prompts, pastes and uploads, extension intelligence, web and download protection, the admin console, Entra ID and Intune deployment. Every capability below carries a status. “Available” ships in the product today. “Coming” is not active in the product yet — some items are available for early access on request, but none should be relied on today. Where a capability has been tested, it also says how: “Validated on real Edge” (exercised on real Microsoft Edge with real services in the September 2026 validation) or “Automated tests” (unit, integration and headless-browser tests, not yet validated in real-world use). ## Data protection Ward decides locally, at the moment a user pastes, drops, uploads or submits something, using a signed policy cached on the device. A rule combines **who** (user, groups), **device** (managed or not), **application** (and whether it is sanctioned), **account** (corporate, personal or unrecognised), **action** and **data** (local DLP classification), and returns allow, log, warn, justify or block. Area status: **Available**. Stops sensitive company data from leaving through AI prompts, pastes, uploads and form submissions — decided in the browser, at the moment of the action. - **AI prompt protection** — Available (tested: Validated on real Edge). Inspects text pasted into or submitted to AI tools (Enter, send button, form submit) and applies the policy decision before the prompt is sent. Validated on chatgpt.com in real Edge. Apps with unusual send mechanics may not be intercepted on submit; paste and upload interception do not depend on the app. - **Paste and drag-and-drop inspection** — Available (tested: Validated on real Edge). Every trusted paste and drop (text and files) is inspected locally. Keystrokes are never observed. Paste blocking validated in real Edge on Windows and macOS. - **File upload inspection** — Available (tested: Automated tests). Reads the text of files at upload time: text-like formats, .docx/.xlsx/.pptx, and PDFs (parsed in an isolated extension frame with time and size limits). Not inspected: images, legacy Office formats, archives, encrypted or scanned PDFs, files over the size budget (10 MB by default). Rules can choose to block content that could not be inspected. - **Local DLP detectors and classifications** — Available (tested: Automated tests). Built-in detectors for payment cards (Luhn-checked), U.S. Social Security numbers, email addresses, U.S. phone numbers, cloud and SaaS keys and tokens, private keys, database connection strings with credentials, JWTs and generic secrets — plus custom keyword dictionaries and regular expressions. Detectors return counts, never values. Payment card detection is part of the real-world validation. - **Corporate vs personal account context** — Available (tested: Automated tests). Reads the account an app displays (for example Google’s account button or a SharePoint tenant host) and classifies it as corporate, personal or unrecognised, so policies can treat a personal account differently from a work one. ChatGPT and Claude usually do not display the signed-in email, so they classify as unrecognised. Policies should treat personal and unrecognised alike for those apps. - **App and AI discovery** — Available (tested: Automated tests). Daily roll-up of which applications are used, with which account type, against a built-in catalog of about 65 apps. Unknown hosts that look like AI tools are treated as unreviewed generative AI. Records hostnames only. Organisations can restrict discovery to catalog applications. - **Graduated decisions** — Available (tested: Validated on real Edge). Allow, log, warn, require a business justification, or block. The strongest matching rule wins; relaxations are explicit, scoped, audited, expiring exceptions. Block validated in real Edge; warn and justify are covered by automated browser tests. Example — the block dialog shown to the user (default wording; organisation name illustrative): > **This paste was blocked** > > The content you pasted may contain Payment card data. > > Destination: ChatGPT (not confirmed as your work account) > > Use your approved corporate account for work data. > > Reference: Block sensitive data to personal AI ## Extension protection Ward inventories every extension on enrolled browsers and tracks what each one is, where it comes from, what it may do and what changed. Blocking is enforced by Microsoft Edge policy, which remains authoritative. Area status: **Available**. Shows every browser extension in the organisation, where it comes from, what it may do and what changed — and blocks it through Microsoft Edge policy when an administrator decides to. - **Extension inventory** — Available (tested: Automated tests). Name, ID, version, permissions and host access of every extension on enrolled browsers, with affected devices and users. Exercised end to end in headless Chromium; not yet against real store extensions updating on real Edge machines. - **Publisher and store history** — Available (tested: Automated tests). Publisher, source (Edge Add-ons, Chrome Web Store, self-hosted, unpacked) and store status over time, including removal from a store. Live store lookups are opt-in and rely on an unofficial Edge Add-ons endpoint and the public Chrome Web Store listing page; only the extension ID is sent. - **Permission-change alerts** — Available (tested: Automated tests). Alerts when a new version gains high-risk permissions or all-sites access, changes publisher or update source, or disappears from its store. - **Explainable risk score** — Available (tested: Automated tests). A 0–100 score from declared permissions, site access, source, store status and recent changes; every factor is shown with its points. A risk score, not a verdict: Ward does not label an extension “malware” from these signals. - **Administrator blocking via Edge policy** — Available (tested: Automated tests). An administrator marks an extension Blocked; Microsoft Edge enforces it through policy (ExtensionSettings on macOS, ExtensionInstallBlocklist on Windows). On Windows the generated Intune script must be redeployed after a change; on macOS the Intune profile is pushed after preview. - **Malware scanning and reputation** — Coming. Static analysis of extension packages and reputation data. Early access on request. - **Automatic blocking** — Coming. Rules that block extensions automatically, for example on a known-malicious verdict. Early access on request. ## Web protection Area status: **Coming**. Blocking of phishing, malware and scam sites is coming. Today, company policy can already block or warn on navigation to specific applications and categories. - **Policy-based site and app controls** — Available (tested: Automated tests). Block, warn or require a justification when users navigate to specific applications or categories (for example unsanctioned AI tools). Blocks of known hosts are applied before the page is requested. Blocks that depend on the account type, and blocks of unknown hosts, are applied in the page shortly after it starts loading. - **Phishing, malware and scam site blocking** — Coming. Threat-category blocking based on vetted feeds and organisation deny lists. Early access on request. ## Download protection Area status: **Coming**. Download reputation is coming. Today, company policy can already block, warn on or log downloads by source site and file type. - **Download rules by source site and file type** — Available (tested: Automated tests). Policies act on the source application, file name, type and size of a download before it completes. Download contents are not inspected. - **Download reputation** — Coming. Checking download sources against threat data before the file is saved. Early access on request. ## Admin console and integrations - **Admin console** — Available (tested: Validated on real Edge). Devices, discovery, policies (sentence builder with simulator), classifications, alerts, investigations and extension intelligence in one web console. Enrolled devices and blocked events were observed in the console during the real-world validation. - **Roles and audit log** — Available (tested: Automated tests). Five administrator roles (Owner, Security Admin, Policy Admin, Analyst, Read Only), enforced by the server. Append-only audit log of administrative actions. - **Signed, versioned policy** — Available (tested: Validated on real Edge). Each change compiles an immutable policy version, signed with ECDSA P-256. Devices verify it, can pin the key via MDM, reject rollbacks and keep the last known-good policy offline. - **Alerts and SIEM webhooks** — Available (tested: Automated tests). Rule-based alerts (policy alerts, repeated blocks, heartbeat loss, risky extensions) delivered to SIEM/SOAR through HMAC-signed webhooks. No behavioural analytics (UEBA). - **Microsoft Entra ID directory sync** — Available (tested: Automated tests). Users, groups and memberships read from your tenant (read-only Graph permissions) so policies can target groups. Tested against mocked Microsoft Graph; not yet validated against a live tenant. - **Administrator single sign-on with Entra ID** — Available (tested: Automated tests). OpenID Connect with PKCE. Administrators must already exist in Ward; SSO never creates them. Tested against mocks; not yet validated against a live tenant. - **Device user verification with Entra ID** — Available (tested: Automated tests). Proves which directory user is signed in to the browser using an Entra ID token. Unverified users get every restriction but no identity-scoped exception. Tested against mocks; not yet validated against a live tenant or in Edge. ## Supported browsers | Browser | Platforms | Status | Tested | Notes | |---|---|---|---|---| | Microsoft Edge | Windows, macOS | Available | Validated on real Edge | Primary target. Validated in real Edge 153/154 on Windows (x86-64) and macOS (arm64). | | Google Chrome | Windows, macOS | Available | Automated tests | Same extension build; automated tests run in Chromium. Not yet validated in real Chrome. | | Firefox, Safari | — | Not supported | — | Not supported. | | Unmanaged browsers, native apps, mobile | — | Not supported | — | Ward protects the managed browser only. Block other browsers with your MDM’s app controls if required. | ## Deployment - **Microsoft Intune — Windows** — Available (tested: Validated on real Edge). Ward generates a PowerShell platform script (and a .reg file) that force-installs the extension and delivers its managed configuration. Validated on a real Intune-managed Windows 11 VM: zero-touch enrollment, not removable by the user. Delivery is manual (you upload the script). - **Microsoft Intune — macOS** — Available (tested: Automated tests). Ward generates a .mobileconfig profile you upload as a custom profile. Optionally, after you authorise a dedicated app registration, Ward can create and update the profile via Microsoft Graph — only after you preview and confirm each change. Not yet validated through a real Intune tenant; the Graph push is tested against mocks only. - **Microsoft Edge Add-ons store or self-hosted** — Available (tested: Validated on real Edge). The extension can be published to Edge Add-ons or self-hosted as a signed package with an update manifest. The validation used a self-hosted package with a development signing key; production requires HTTPS and a release key. - **Other MDM / Google Admin console** — Available. Any tool that can set Edge or Chrome extension policies can deliver the same keys. Documented, not validated. ## Real-world validation In September 2026, version 0.1.0 was tested on real Microsoft Edge, the real chatgpt.com and a real Microsoft 365 tenant with Intune — not mocks. Test content was a public test card number. After each round, a full dump of the Ward database and the complete server log were searched for it: zero matches. | Check | Windows, Edge 153 | macOS, Edge 154 | Windows 11 VM via Intune, Edge 154 | |---|---|---|---| | Ward loads in real Microsoft Edge | Yes | Yes | Yes | | Enrolls with the Ward server | Yes (manual) | Yes (manual) | Yes (zero-touch) | | Receives and verifies a signed policy | Yes | Yes | Yes | | A normal ChatGPT prompt still works | Yes | Yes | Yes | | Synthetic card number pasted into ChatGPT is blocked | Yes | Yes | Yes | | Typed card number submitted to ChatGPT is blocked | Not tested | Yes | Yes | | Test content absent from database and server logs | Yes | Yes | Yes | | Metadata event visible in the console | Yes | Yes | Yes | | User cannot remove the extension | Not tested | Not tested | Yes | Not yet validated: - macOS deployment through Intune - Microsoft Entra ID against a live tenant (directory sync, admin SSO, device user verification) - Google Chrome and other browsers - HTTPS transport and a release signing key (the test used plain HTTP on a LAN and a development key) Found during validation: on chatgpt.com the account type was detected as “unrecognised”, never “personal”. Blocking was still correct because the policy covers personal and unrecognised accounts alike — but rules that allow corporate AI accounts should not rely on account detection on ChatGPT yet. [Request access](https://valvayn.com/contact/) · [See how it works](https://valvayn.com/#how-it-works) --- Canonical: https://valvayn.com/product/ · Markdown: https://valvayn.com/product.md · Built: 2026-10-10 # Security and privacy, in plain terms. > What Ward collects and never collects, where metadata is stored and for how long, how the platform and extension are secured, subprocessors, and how to report a vulnerability. Content is inspected locally in the browser and never leaves the device. Only metadata reaches the Ward server. This page explains exactly what that means. ## How data moves 1. A user pastes, drops, uploads or submits something in Microsoft Edge. 2. The Ward extension inspects the content **in the browser**, using detectors that return counts, never values. 3. The extension applies the organisation’s signed policy and, if the policy acts or sensitive data was found, records a **metadata-only event**. 4. Events are queued on the device and uploaded in batches. Browsing never waits for the server. 5. The server enriches events from its own records (it does not trust device claims), stores them and evaluates alert rules. Raw upload batches are emptied as soon as they are processed. ## What is collected, and what never is **Never leaves the device:** - Page contents, prompts, messages, clipboard contents, typed text, form values - File contents - Passwords, cookies, session and OAuth tokens, other sites’ browser storage - Keystrokes (there is no keystroke listener) - Full URLs, paths or query strings — only hostnames - The matched sensitive values themselves (for example the card number) **Sent to the server as metadata:** - Hostname, app category, account type and account domain (discovery, daily roll-up) - Action, decision, outcome, policy, classification names and per-detector match counts - File name, extension, MIME type and size for uploads and downloads (file names can be turned off) - Account identifier (email) for corporate accounts by default; configurable to none or all - The fact that an AI prompt was submitted, without its text (configurable) - Business justification text a user types in a JUSTIFY prompt (users are told it is shared; redacted if it looks sensitive) - Browser profile email, OS, browser and extension versions, installed extensions (enrollment and heartbeat) This is enforced structurally: the telemetry wire schema is strict and has no field that could hold content, and the server rejects unknown fields. Automated tests assert that test secrets never appear in events, database rows or server logs. ## Settings that reduce collection | Setting | Options | Default | |---|---|---| | Discovery scope | All sites, or catalog applications only | All sites (hostnames only, daily roll-up) | | Account identifiers | None, corporate only, all | Corporate only | | File names | On or off | On | | AI prompt metadata (“a prompt was submitted”, no text) | On or off | On | | Event retention | Per organisation | 180 days | ## Where metadata is stored - **Hosting model:** Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request. - **Hosting provider and location:** Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection). - **Database:** PostgreSQL with row-level security per organisation. - **Retention:** events are kept for 180 days by default (configurable) and then deleted by dropping whole monthly partitions. Discovery data is stored as daily roll-ups. ## How the platform is secured - **Tenant isolation in the database.** Every tenant table has a forced row-level-security policy; the application’s database role cannot bypass it, and queries also filter by organisation. Cross-tenant access is covered by dedicated tests. - **Signed policy.** Each policy change produces an immutable version signed with ECDSA P-256. The extension rejects bad signatures, other organisations’ policies, rollbacks and malformed bundles, and keeps the last known-good policy. The verification key can be pinned through MDM. - **Per-device credentials.** No organisation secret ships in the extension. An expiring, revocable enrollment token is exchanged for a device-specific secret (stored hashed, rotated) and one-hour access tokens. - **Administrator access.** scrypt password hashes or Microsoft Entra ID single sign-on; server-side sessions (12 hours absolute, 2 hours idle), CSRF protection, rate-limited sign-in, five roles enforced by the server. - **Secrets at rest.** Integration secrets are encrypted with AES-256-GCM; tokens and device secrets are stored as hashes. - **Audit log.** Administrative actions — sign-ins, policy and classification changes, exceptions, exports, deployment and integration changes — are written to an append-only log. - **Hostile input.** Strict schemas on every API, bounded request sizes, parameterised SQL, rate limits, and SSRF-safe outbound webhooks signed with HMAC-SHA256. - **Transport.** Production deployments require HTTPS for the API. ## How the extension is hardened - **Minimal permissions.** Ward does not request access to cookies, history, tabs, the clipboard API, webRequest, scripting, the debugger or native messaging. It inspects pastes through the paste event the user triggers. - **Isolated user interface.** Enforcement dialogs render in a closed shadow root using text only. Business justifications are typed in an extension-origin frame the web page cannot read. - **Isolated file parsing.** PDFs are parsed in a separate extension frame and worker with strict size, work and time limits. Anything that cannot be inspected is reported as “not inspected”, never as clean. - **Fail closed where it matters.** A page can remove or cover Ward’s dialog; the action then stays held or is cancelled — never allowed. The extension is not claimed to be tamper-proof. Resistance to removal comes from force-installation and Edge policy; Ward raises an alert when a device stops reporting. ## Certifications This site makes no claim of third-party certification (such as SOC 2 or ISO/IEC 27001). If you need security documentation for a vendor assessment, contact security@valvayn.com. ## Known limitations We publish what Ward does not do: - Ward protects the managed browser only — not other browsers, native apps or mobile devices. - Images, archives, legacy Office files, encrypted or scanned PDFs and very large files are not content-inspected. Rules can choose to block content that could not be inspected. - ChatGPT and Claude usually do not display the signed-in account, so Ward classifies them as “unrecognised” rather than personal or corporate. - Microsoft Entra ID integrations and macOS deployment through Intune are tested against mocks, not yet against a live tenant. ## Subprocessors See the [subprocessor list](https://valvayn.com/legal/subprocessors/) and the [Data Processing Addendum](https://valvayn.com/legal/dpa/). ## Report a vulnerability Email security@valvayn.com. Our [responsible disclosure policy](https://valvayn.com/security/disclosure/) explains scope and safe harbour; a machine-readable contact is published at [/.well-known/security.txt](https://valvayn.com/.well-known/security.txt). --- Canonical: https://valvayn.com/security/ · Markdown: https://valvayn.com/security.md · Built: 2026-10-10 # Frequently asked questions > Direct answers about Ward: what it sees, what it sends, supported browsers, Intune and Entra ID, AI tools, file types, extensions, retention, certifications and pricing. Short, direct answers. Each links to more detail where it exists. ## What is Ward? Ward is an enterprise browser security platform: a managed Manifest V3 extension for Microsoft Edge that enforces data-protection policy in the browser, plus a control plane and admin console. It stops sensitive data from being pasted, uploaded or submitted to the wrong places — for example company data going into an AI tool through a personal account. ## Does Ward see what employees type, paste or upload? No — content is inspected locally in the browser and never leaves the device. The extension reads pasted text, submitted prompts and uploaded files on the device to classify them; only metadata such as “payment card data, 1 match, blocked” is sent to the Ward server. Ward has no keystroke listener. ## What data does Ward send to its server? Metadata only: the hostname and app category, account type and domain, the action and policy decision, classification names and per-detector match counts, file name, type and size for uploads and downloads, and device information such as OS, browser and extension versions and installed extensions. Full URLs, page content, prompts, clipboard contents, file contents and the matched values themselves are never sent. See [Security & Privacy](https://valvayn.com/security/#collected). ## Which browsers does Ward support? Microsoft Edge on Windows and macOS is the primary, validated target. Google Chrome runs the same extension build and is covered by automated tests, but has not yet been validated in real-world use. Firefox, Safari, native apps and mobile devices are not supported. ## How is Ward deployed? Ward is force-installed into Microsoft Edge by your MDM, typically Microsoft Intune. The console generates a platform script or .reg file for Windows and a .mobileconfig profile for macOS; each carries an enrollment token so devices enroll themselves with no user action. On macOS, Ward can optionally push the profile through Microsoft Graph after you preview and confirm each change. ## Can users remove or disable the Ward extension? Not when it is force-installed by policy: Edge shows no Remove option, which was confirmed on a real Intune-managed Windows device. Ward is not cryptographically tamper-proof; tamper resistance comes from Edge and MDM policy, and the console flags devices that stop reporting. ## Does Ward work with Microsoft Entra ID? Yes. Ward can sync users and groups from Entra ID for group-based policies, offer Entra single sign-on for administrators, and verify which directory user is signed in to each browser. These integrations are covered by automated tests against mocked Microsoft services and have not yet been validated against a live tenant. ## Does Ward block ChatGPT or other AI tools? Only if your policy says so. A typical policy allows AI tools but blocks sensitive data — for example payment card numbers — from being pasted, uploaded or submitted to them through personal or unrecognised accounts. Ward can also block, warn or require a business justification for navigation to specific AI tools, and treats unknown AI-looking sites as “unreviewed” until an administrator classifies them. ## Can Ward tell a corporate AI account from a personal one? For some apps, yes; for ChatGPT and Claude, usually not yet. Ward reads the account an app displays, such as Google’s account button or a SharePoint tenant host. ChatGPT and Claude generally do not display the signed-in email, so Ward classifies them as “unrecognised”, and policies should treat unrecognised like personal for those apps. ## What kinds of sensitive data can Ward detect? Payment card numbers, U.S. Social Security numbers, email addresses, U.S. phone numbers, cloud and SaaS credentials (AWS, GitHub, Slack, Google, Stripe, Azure storage, GCP service accounts), private keys, database connection strings with passwords, JWTs, generic secrets and references to your own corporate domains. Administrators can add keyword dictionaries and regular expressions, and group detectors into classifications with a sensitivity level. ## Which file types can Ward inspect on upload? Text-like files (.txt, .csv, .json, .md, logs, source code), Office Open XML files (.docx, .xlsx, .pptx) and text-based PDFs, up to a configurable size budget (10 MB by default). Images, archives, legacy Office formats, encrypted PDFs and scanned PDFs are reported as “not inspected”; rules can be set to block anything that could not be inspected. ## Does Ward detect malicious browser extensions? Ward shows every extension’s permissions, publisher, store status and changes over time, with an explainable risk score and alerts — but it does not label extensions as malware today. Malware scanning, reputation and automatic blocking are coming. Administrators can already block an extension, which Microsoft Edge enforces through policy. ## Does Ward protect against phishing or malware websites? Not yet — web threat protection and download reputation are coming, with early access on request. Today Ward can block, warn on or require a justification for navigation to specific applications or categories, and apply download rules by source site and file type. ## Does Ward record employees’ browsing history? No. For application discovery Ward records hostnames — never full URLs — as a daily roll-up of counts per application, user, device and account type. Organisations that do not need discovery of unknown applications can restrict it to known catalog applications. ## How long does Ward keep data? Security events are kept for 180 days by default and then deleted; each organisation can change this. Raw telemetry batches are emptied as soon as they are processed. ## Does Ward work offline? Yes. Decisions are made on the device from a cached, signed policy, so enforcement continues without a connection. Events are queued locally and uploaded when the device reconnects. ## Has Ward been tested in the real world? Yes, in a limited validation of version 0.1.0 in September 2026: real Microsoft Edge on Windows and macOS, the real chatgpt.com, and a real Microsoft 365 tenant with Intune on a Windows 11 virtual machine. Synthetic card numbers pasted or submitted to ChatGPT were blocked, and a full search of the Ward database and server logs found no trace of the test content. Not yet covered: macOS through Intune, live Entra ID, Chrome, HTTPS transport and a release signing key. ## Is Ward SOC 2 or ISO 27001 certified? This site makes no certification claim. For a vendor security assessment, contact security@valvayn.com. ## Where is Ward hosted? Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request.. Hosting provider and data location: Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection).. ## How much does Ward cost? Pricing is per protected browser per month and is agreed per customer during the pilot. Contact sales@valvayn.com for a quote. ## How do I report a security vulnerability? Email security@valvayn.com. The [responsible disclosure policy](https://valvayn.com/security/disclosure/) explains scope and safe harbour, and [/.well-known/security.txt](https://valvayn.com/.well-known/security.txt) lists the contact in machine-readable form. ## Does this website use cookies or analytics? No. This website sets no cookies, uses no analytics, and loads no third-party scripts, fonts or embeds. See the [Cookie Notice](https://valvayn.com/legal/cookies/). --- Canonical: https://valvayn.com/faq/ · Markdown: https://valvayn.com/faq.md · Built: 2026-10-10 # Request access > Request access to Ward or contact the team. The form opens your email app; this site does not collect or store what you type. Tell us about your environment. We will reply by email. Email sales@valvayn.com with the subject “Ward access request” and include: - Name - Organisation - Role - Approximate number of browsers - Microsoft Edge / Intune / Entra ID in use (yes/no) - What you want to protect The form on the HTML page only opens your email app; this site does not collect or store what you type. ## Other contacts | Topic | Email | |---|---| | Sales and access | sales@valvayn.com | | Security and vulnerability reports | security@valvayn.com | | Privacy and data protection | privacy@valvayn.com | | Legal | legal@valvayn.com | ## Pricing Pricing is per protected browser per month and is agreed per customer during the pilot. Contact sales@valvayn.com for a quote ## Company Sam Mulliner, doing business as Valvayn, Texas, United States. The full postal address is provided in contracts and on request to legal@valvayn.com.. Valvayn is a sole proprietorship operated by Sam Mulliner in Texas, United States. It is not a registered company and has no company registration number.. --- Canonical: https://valvayn.com/contact/ · Markdown: https://valvayn.com/contact.md · Built: 2026-10-10 # Legal > Ward’s Privacy Policy, Terms of Service, Cookie Notice, Data Processing Addendum, subprocessor list, Acceptable Use Policy and responsible disclosure policy. Policies and agreements for this website and the Ward service. - [Privacy Policy](https://valvayn.com/legal/privacy/) — How Ward handles personal data: this website (no cookies, no analytics), business enquiries, and our role as processor when customers use the Ward service. - [Terms of Service](https://valvayn.com/legal/terms/) — The terms that govern use of this website and of the Ward service, unless a separate signed agreement applies. - [Cookie Notice](https://valvayn.com/legal/cookies/) — This website sets no cookies and uses no analytics or third-party resources. The Ward admin console uses only strictly necessary session cookies. - [Data Processing Addendum](https://valvayn.com/legal/dpa/) — Ward’s Data Processing Addendum (GDPR and UK GDPR): roles, the metadata Ward processes, security measures, subprocessors, transfers, breach notification and deletion. - [Subprocessors](https://valvayn.com/legal/subprocessors/) — Third parties that process personal data on Ward’s behalf, and services Ward connects to on the customer’s instruction that are not subprocessors. - [Acceptable Use Policy](https://valvayn.com/legal/acceptable-use/) — What customers and users must not do with the Ward service, including monitoring beyond legitimate security purposes and attacking the service. - [Responsible Disclosure Policy](https://valvayn.com/security/disclosure/) — How to report a security vulnerability in Ward: scope, rules for good-faith research, safe harbour and what to expect from us. - [security.txt](https://valvayn.com/.well-known/security.txt) — Machine-readable security contact (RFC 9116). --- Canonical: https://valvayn.com/legal/ · Markdown: https://valvayn.com/legal.md · Built: 2026-10-10 # Privacy Policy > How Ward handles personal data: this website (no cookies, no analytics), business enquiries, and our role as processor when customers use the Ward service. Effective date: 10 October 2026. ## 1. Who we are This policy is issued by Sam Mulliner, doing business as Valvayn, Texas, United States. The full postal address is provided in contracts and on request to legal@valvayn.com. (“we”, “us”), the provider of Ward. Contact for privacy questions: privacy@valvayn.com. EU/UK representative: Valvayn has not appointed an EU or UK representative. Ward is offered to organisations in the United States; it is not currently marketed to customers in the EU or UK.. ## 2. What this policy covers - **This website.** What happens when you visit it. - **Business contacts.** What we do with information you send us, for example when you request access. - **The Ward service.** How personal data is handled when an organisation uses Ward. For that data the organisation (your employer, if you use a managed browser at work) decides what is collected and why; we process it on its behalf under our [Data Processing Addendum](https://valvayn.com/legal/dpa/). ## 3. This website - **No cookies, no analytics, no tracking.** This website sets no cookies, uses no analytics or advertising tools, and loads no third-party scripts, fonts, images or embeds. See the [Cookie Notice](https://valvayn.com/legal/cookies/). - **Server logs.** Like any web server, the server that delivers this website may record your IP address, browser user agent, the page requested and the time, to deliver the site and protect it from abuse. These logs are kept for 30 days. Legal basis: our legitimate interest in operating a secure website. - **The contact form does not submit anything to us.** It opens your own email app with a pre-filled message; nothing is sent until you send that email yourself. ## 4. When you contact us If you email us, we receive your name, email address, organisation and whatever you include in your message. We use it to reply, to discuss access to Ward and, if you become a customer, to manage that relationship. Legal basis: our legitimate interests in responding to enquiries and running our business, or taking steps at your request before entering into a contract. We keep this correspondence for as long as needed for those purposes and then delete it. ## 5. The Ward service Ward is designed to collect security metadata, not content. - **Inspected on the device, never sent to us:** page contents, prompts, messages, clipboard contents, typed text, form values, file contents, passwords, cookies and tokens, keystrokes, full URLs, and the sensitive values Ward detects. - **Sent to the Ward server as metadata:** hostnames and application categories, account type and domain, the action and policy decision, classification names and match counts, file names, types and sizes, account identifiers (by default only for corporate accounts), business justifications that users choose to type, and device information such as operating system, browser and extension versions and installed extensions. - **Administrator accounts:** names, email addresses, roles, sign-in credentials (stored as hashes) or a Microsoft Entra ID link, sessions, and an audit log of administrative actions. For this data the customer organisation is the controller and we act as its processor, following its instructions and our [Data Processing Addendum](https://valvayn.com/legal/dpa/). If you use Ward through your employer and want to exercise your rights, contact your employer; we will help them respond. We act as an independent controller only for the limited data we need to manage our contract with the customer (such as billing contacts) and to keep our service secure. Where a customer runs Ward on its own infrastructure, we do not receive this data unless the customer shares it with us, for example in a support request. ## 6. Who we share personal data with - **Subprocessors** that help us run the service, listed on our [subprocessor page](https://valvayn.com/legal/subprocessors/). - **Authorities**, where the law requires it. - **A successor**, if our business is reorganised or sold, under the same protections. We do not sell personal data and do not use it for advertising. ## 7. International transfers Hosting provider and data location: Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection).. Where personal data is transferred outside the UK or the European Economic Area, we use recognised safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. ## 8. How long we keep data - Website server logs: 30 days. - Business correspondence: as long as needed for the purposes above. - Ward service data: as configured by the customer. Security events are deleted after 180 days by default. After a customer’s contract ends we delete service data within 30 days, as set out in the Data Processing Addendum. ## 9. Your rights Depending on where you live, you may have the right to access, correct, delete or restrict the use of your personal data, to object to processing based on legitimate interests, and to data portability. To exercise these rights about data we control, email privacy@valvayn.com. For Ward service data, contact the organisation that deployed Ward. You also have the right to complain to a data protection supervisory authority, such as the Information Commissioner’s Office in the UK or the authority in your EU country. ## 10. Security How we protect the service is described on our [Security & Privacy page](https://valvayn.com/security/). ## 11. Children This website and the Ward service are intended for businesses and are not directed at children. ## 12. Changes We will update this policy when our practices change and show the effective date at the top. Material changes affecting customers are also notified as described in our agreements. --- Canonical: https://valvayn.com/legal/privacy/ · Markdown: https://valvayn.com/legal/privacy.md · Built: 2026-10-10 # Terms of Service > The terms that govern use of this website and of the Ward service, unless a separate signed agreement applies. Effective date: 10 October 2026. ## 1. About these terms These terms are an agreement between Sam Mulliner, doing business as Valvayn (“we”, “us”) and the organisation that uses Ward (“Customer”, “you”). They also govern use of this website. If you and we have signed a separate agreement or order form for Ward, that document prevails where it conflicts with these terms. The person accepting these terms confirms they are authorised to bind the Customer. ## 2. The service Ward consists of a browser extension, a control plane and an admin console (the “Service”). Hosting model: Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request.. The capabilities of the Service and their status are described on our [product page](https://valvayn.com/product/). Features marked “Coming” are not part of the Service until we make them generally available, and we do not commit to delivering them. Early-access or pre-release features are provided as they are, may change or be withdrawn, and should not be relied on for production use unless we agree otherwise in writing. ## 3. Your accounts You are responsible for your administrators, the roles you grant them, keeping credentials and enrollment tokens confidential, and all activity under your accounts. Tell us promptly at security@valvayn.com if you suspect unauthorised access. ## 4. Your responsibilities - **Lawful deployment.** You deploy Ward only on browsers and devices you are entitled to manage, and you are responsible for having a lawful basis to do so, informing your users, and consulting employee representatives where the law requires it. - **Configuration.** You decide which policies, detectors and data-collection settings to use. Ward reduces the risk of data leaving through the browser; it does not guarantee that every piece of sensitive data will be detected, and it does not protect other browsers, native applications or mobile devices. - **Acceptable use.** You comply with our [Acceptable Use Policy](https://valvayn.com/legal/acceptable-use/). ## 5. Your data You own the data you and your users put into the Service (“Customer Data”). We use it only to provide, secure and support the Service. Where we process personal data on your behalf, our [Data Processing Addendum](https://valvayn.com/legal/dpa/) forms part of these terms. By design, the extension inspects content locally and sends us metadata only; see [Security & Privacy](https://valvayn.com/security/). ## 6. Fees Fees, billing periods and payment terms are set out in your order form. Pricing: Pricing is per protected browser per month and is agreed per customer during the pilot. Contact sales@valvayn.com for a quote. ## 7. Our intellectual property We own the Service, including its software and documentation. We grant you a non-exclusive, non-transferable right to use the Service for your internal business purposes during your subscription. You will not copy, modify, resell or reverse engineer the Service except as the law allows. If you give us feedback, we may use it without obligation to you. ## 8. Confidentiality Each party will protect the other’s confidential information with at least reasonable care and use it only to perform under these terms. ## 9. Security We maintain the security measures described on our [Security & Privacy page](https://valvayn.com/security/) and in the Data Processing Addendum. We do not claim any third-party certification unless we state it in writing. ## 10. Warranties and disclaimers We will provide the Service with reasonable skill and care. Detection is based on patterns and signals and can produce false positives and false negatives. Except as expressly stated in these terms, the Service is provided without other warranties, to the extent the law allows. ## 11. Liability Neither party excludes liability that cannot be excluded by law. Subject to that, neither party is liable for indirect or consequential loss, or for loss of profits, revenue or goodwill, and each party’s total liability under these terms is limited to the fees paid by the customer to Valvayn in the 12 months before the event giving rise to the claim. ## 12. Suspension and termination We may suspend access if needed to prevent serious harm to the Service or others, or if you materially breach these terms, and we will tell you promptly why. Either party may terminate for material breach that is not remedied within 30 days of notice. On termination, your right to use the Service ends; we delete Customer Data within 30 days as described in the Data Processing Addendum. Remove the extension from your managed browsers through your MDM. ## 13. Changes We may update the Service and these terms. We will give reasonable notice of changes that materially reduce the Service or your rights. ## 14. Governing law These terms are governed by the laws of the State of Texas, United States, without regard to its conflict-of-laws rules. The courts of the state and federal courts located in Texas, United States have jurisdiction. ## 15. Contact Sam Mulliner, doing business as Valvayn, Texas, United States. The full postal address is provided in contracts and on request to legal@valvayn.com.. Valvayn is a sole proprietorship operated by Sam Mulliner in Texas, United States. It is not a registered company and has no company registration number.. Legal notices: legal@valvayn.com. --- Canonical: https://valvayn.com/legal/terms/ · Markdown: https://valvayn.com/legal/terms.md · Built: 2026-10-10 # Cookie Notice > This website sets no cookies and uses no analytics or third-party resources. The Ward admin console uses only strictly necessary session cookies. Effective date: 10 October 2026. ## This website sets no cookies This website does not set cookies, does not use local storage or similar technologies, and uses no analytics, advertising or tracking tools. It loads no third-party scripts, fonts, images or embeds; every file comes from this website’s own domain. The only script on the site opens and closes the navigation menu on small screens and stores nothing. Because nothing non-essential is stored on your device, there is no cookie banner to accept or decline. ## The Ward admin console The Ward admin console is a separate application used by customers’ administrators. It uses only strictly necessary cookies: | Cookie | Purpose | Lifetime | |---|---|---| | Session cookie | Keeps an administrator signed in. HttpOnly, SameSite=Strict, limited to the API path. | Ends after 2 hours of inactivity, or 12 hours at most, or at sign-out | | Sign-in flow cookie | Protects the Microsoft Entra ID single sign-on flow while it is in progress | The duration of the sign-in | ## The Ward browser extension The extension does not set cookies on websites and does not read them. It keeps its own configuration, policy and event queue in the browser’s extension storage, which websites cannot access. ## Changes If we ever add analytics or any non-essential technology to this website, we will update this notice first and ask for consent where the law requires it. Questions: privacy@valvayn.com. --- Canonical: https://valvayn.com/legal/cookies/ · Markdown: https://valvayn.com/legal/cookies.md · Built: 2026-10-10 # Data Processing Addendum > Ward’s Data Processing Addendum (GDPR and UK GDPR): roles, the metadata Ward processes, security measures, subprocessors, transfers, breach notification and deletion. Effective date: 10 October 2026. ## 1. Parties and scope This Data Processing Addendum (“DPA”) forms part of the agreement between Sam Mulliner, doing business as Valvayn (“Processor”, “we”) and the customer (“Customer”) for the Ward service (the “Agreement”). It applies when we process Customer Personal Data on the Customer’s behalf in providing the Service — in particular when we host the Ward control plane for the Customer, and when the Customer gives us access to its data for support. Where the Customer hosts Ward on its own infrastructure, we do not process Customer Personal Data through the Service; this DPA then applies only to data the Customer chooses to share with us, for example in a support request. ## 2. Definitions “**Data Protection Law**” means the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as retained in UK law (“UK GDPR”) with the UK Data Protection Act 2018, and other data protection laws that apply to the processing. “**Customer Personal Data**” means personal data we process on the Customer’s behalf under the Agreement. “**Subprocessor**” means a third party we engage to process Customer Personal Data. “Controller”, “processor”, “data subject”, “personal data breach” and “processing” have the meanings given in Data Protection Law. ## 3. Roles The Customer is the controller of Customer Personal Data (or a processor acting for its affiliates, in which case we are its subprocessor). We are the processor. We act as an independent controller only for the limited data needed to manage our contract with the Customer and to secure our service, as described in our [Privacy Policy](https://valvayn.com/legal/privacy/). ## 4. Customer instructions We process Customer Personal Data only on the Customer’s documented instructions. The Agreement, this DPA and the Customer’s configuration of the Service — its policies, detectors, integrations, data-collection settings and retention period — are the Customer’s instructions. We will tell the Customer if we believe an instruction infringes Data Protection Law. If the law requires us to process data otherwise, we will inform the Customer first unless the law prohibits it. ## 5. Customer responsibilities The Customer is responsible for having a lawful basis for deploying Ward, for informing its users, for consulting employee representatives and carrying out a data protection impact assessment where the law requires it, and for choosing data-collection settings proportionate to its purposes. The Service offers settings that reduce collection: discovery limited to catalog applications, no account identifiers, no file names and no AI-prompt metadata. ## 6. Confidentiality We ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide, secure and support the Service. ## 7. Security We implement the technical and organisational measures in [Annex 2](#annex-2). We may update them provided the overall level of protection is not reduced. ## 8. Subprocessors The Customer gives general authorisation for us to engage Subprocessors. The current list is published at [/legal/subprocessors/](https://valvayn.com/legal/subprocessors/). We will give at least 30 days' notice of a new Subprocessor; the Customer may object on reasonable data protection grounds, and if we cannot address the objection the Customer may terminate the affected part of the Service. We impose data protection terms on each Subprocessor that are no less protective than this DPA, and remain responsible for their performance. ## 9. International transfers Where Customer Personal Data is transferred outside the UK or the European Economic Area to a country without an adequacy decision, the parties rely on the European Commission’s Standard Contractual Clauses (2021/914) and, for UK data, the UK International Data Transfer Addendum, which are incorporated by reference. ## 10. Assistance Taking into account the nature of the processing, we assist the Customer with data subject requests, data protection impact assessments and prior consultations. Administrators can search and export event metadata in the console, which helps answer access requests; we forward to the Customer any data subject request we receive about Customer Personal Data. ## 11. Personal data breaches We notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information the Customer reasonably needs to meet its own obligations, and we take reasonable steps to contain and remedy it. ## 12. Return and deletion During the Agreement, Customer Personal Data is deleted according to the Customer’s retention settings (security events: 180 days by default). When the Agreement ends, we delete Customer Personal Data within 30 days, unless the law requires us to keep it. Before then the Customer may export its data using the console’s export features. ## 13. Audits We make available the information reasonably necessary to demonstrate compliance with this DPA, including answers to security questionnaires. The Customer may conduct an audit, on reasonable notice and no more than once a year unless required by a supervisory authority or following a personal data breach, at its own cost and subject to confidentiality. We do not claim third-party certifications unless we state them in writing. ## 14. General Liability under this DPA is subject to the limitations in the Agreement. If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data. This DPA lasts as long as we process Customer Personal Data. ## Annex 1 — Details of processing | Item | Details | |---|---| | Subject matter | Providing the Ward browser security service | | Duration | The term of the Agreement plus the deletion period in section 12 | | Nature and purpose | Enforcing the Customer’s browser data-protection policy; recording and displaying security events; discovering applications and browser extensions in use; alerting; administration and audit | | Data subjects | The Customer’s employees and contractors who use managed browsers with Ward (“end users”); the Customer’s administrators | | End-user data | Browser profile email and, where configured, directory identifiers from Microsoft Entra ID (name, email/UPN, object ID, group memberships); account identifiers for corporate accounts (all, or none, if the Customer chooses) | | Device and browser data | Device label, operating system, browser and extension versions, managed status, installed extensions and their permissions, policy status and heartbeat times | | Security event metadata | Time, hostname, application and category, account type and domain, action, decision and outcome, policy, classification names and match counts, file name, type and size, business justification text typed by the user | | Discovery data | Daily counts per application, user, device and account type | | Administrator data | Name, email, role, password hash or Entra ID link, sessions, audit log entries | | Not processed | Page contents, prompts, clipboard contents, typed text, form values, file contents, passwords, cookies, full URLs, and the matched sensitive values — these are inspected on the device and never sent | | Special category data | Not intended. File names or justification text could incidentally reveal such data; the Service redacts values that look sensitive, and the Customer can turn off file-name collection | | Retention | Set by the Customer; security events 180 days by default; raw upload batches are emptied as soon as processed | ## Annex 2 — Technical and organisational measures - **Data minimisation by design:** content is inspected on the device; the event schema has no field for content and unknown fields are rejected; allowed non-sensitive actions produce no event. - **Tenant isolation:** row-level security enforced by the database for every tenant table; the application role cannot bypass it. - **Access control:** five administrator roles enforced by the server; scrypt password hashing or Entra ID single sign-on; server-side sessions with idle and absolute timeouts; CSRF protection; rate-limited sign-in. - **Encryption:** integration secrets encrypted with AES-256-GCM; tokens and device secrets stored as hashes; HTTPS required for the production API. - **Integrity:** policies signed with ECDSA P-256 and verified by the extension; per-device credentials that rotate and can be revoked. - **Logging:** append-only audit log of administrative actions; server logs redact credentials. - **Secure development:** strict input validation, parameterised queries, bounded request sizes, automated tests for tenant isolation and for the absence of content in stored data and logs; security reviews with findings fixed and regression-tested. - **Hosting and operations:** The control plane runs on hardware operated by Valvayn on a private network in Texas, United States, behind a reverse proxy and Cloudflare; it is reachable only over HTTPS. The database is not exposed to the internet. Production access is limited to the operator, over SSH. The database is backed up nightly and before every deployment, and backups are kept for 35 days on access-controlled storage. Stored secrets (policy-signing keys, integration credentials, webhook secrets) are encrypted at rest with a master key that is not stored in the database.. ## Annex 3 — Subprocessors See [/legal/subprocessors/](https://valvayn.com/legal/subprocessors/). --- Canonical: https://valvayn.com/legal/dpa/ · Markdown: https://valvayn.com/legal/dpa.md · Built: 2026-10-10 # Subprocessors > Third parties that process personal data on Ward’s behalf, and services Ward connects to on the customer’s instruction that are not subprocessors. Effective date: 10 October 2026. ## Current subprocessors | Subprocessor | Purpose | Personal data | Location | Applies to | |---|---|---|---|---| | Cloudflare, Inc. | Edge network in front of the Ward control plane and website: DNS, TLS termination, DDoS protection | Connection metadata (IP addresses, request headers) of browsers and administrators connecting to Ward; encrypted request contents in transit | United States and Cloudflare's global edge locations | Ward-operated SaaS only | | Porkbun LLC | Email forwarding for Valvayn's contact addresses (sales@, security@, privacy@, legal@) | Names and business contact details of people who email Valvayn, and whatever they choose to include | United States | All customers | Hosting model: Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request.. Where a customer hosts Ward itself, the hosting subprocessors above do not apply to it. ## Services that are not our subprocessors - **Microsoft Entra ID, Microsoft Graph and Intune.** Ward connects to the customer’s own Microsoft tenant, using app registrations the customer creates and authorises. Microsoft acts under the customer’s own agreement with Microsoft. - **SIEM and webhook destinations.** Alerts are sent only to endpoints the customer configures. - **Browser extension stores (optional, off by default).** When the customer enables live store lookups, Ward sends only extension IDs to Microsoft Edge Add-ons and the Chrome Web Store. No personal data is sent. ## Changes We give at least 30 days' notice before adding a subprocessor, as set out in the [Data Processing Addendum](https://valvayn.com/legal/dpa/). To be notified, email privacy@valvayn.com. --- Canonical: https://valvayn.com/legal/subprocessors/ · Markdown: https://valvayn.com/legal/subprocessors.md · Built: 2026-10-10 # Acceptable Use Policy > What customers and users must not do with the Ward service, including monitoring beyond legitimate security purposes and attacking the service. Effective date: 10 October 2026. ## Purpose Ward is built to protect company data in the browser while collecting as little about people as possible. This policy applies to every customer, administrator and user of the Ward service and forms part of our [Terms of Service](https://valvayn.com/legal/terms/). ## You must not - Deploy Ward on browsers or devices you are not entitled to manage, or without the notices and consultations the law requires. - Use Ward to monitor individuals for purposes other than protecting your organisation’s data and systems, or in breach of employment, privacy or data protection law. - Configure Ward — for example custom detectors, justification prompts or webhooks — to capture content, credentials or personal data beyond what the Service is designed to collect. - Attempt to access another organisation’s data, bypass tenant isolation, or probe, scan or test the Service except under our [responsible disclosure policy](https://valvayn.com/security/disclosure/). - Interfere with or overload the Service, or circumvent its rate limits or security controls. - Reverse engineer the Service except as the law allows, or resell or share access without our agreement. - Use the Service to break the law, including export control and sanctions laws. ## Enforcement We may suspend access that breaches this policy, as described in the [Terms of Service](https://valvayn.com/legal/terms/). Report suspected misuse to legal@valvayn.com. --- Canonical: https://valvayn.com/legal/acceptable-use/ · Markdown: https://valvayn.com/legal/acceptable-use.md · Built: 2026-10-10 # Responsible Disclosure Policy > How to report a security vulnerability in Ward: scope, rules for good-faith research, safe harbour and what to expect from us. Effective date: 10 October 2026. ## Report a vulnerability Email **security@valvayn.com**. Include a description, the affected component and version, steps to reproduce, and the impact you believe it has. If you need to send details encrypted, say so in your first message and we will arrange a secure channel. Our contact details are also published at [/.well-known/security.txt](https://valvayn.com/.well-known/security.txt). ## Scope - The Ward browser extension. - The Ward control plane: extension API, management API and admin console. - This website. Out of scope: denial-of-service testing, social engineering, physical attacks, findings in third-party services (such as Microsoft Entra ID or browser extension stores) — please report those to their owners — and reports from automated scanners without a demonstrated impact. ## Rules for good-faith research - Test only against your own organisation or test accounts. Never access, modify or keep other people’s data; if you encounter it, stop and tell us. - Do not degrade the service for others. - Give us reasonable time to fix the issue before disclosing it publicly. We will agree a disclosure date with you. ## Safe harbour If you act in good faith and follow this policy, we will not pursue or support legal action against you for your research, and we will work with you to understand and fix the issue. ## What to expect - An acknowledgement within 3 business days. - An assessment and, where we confirm the issue, a fix and regular updates on progress. - Public credit once the issue is fixed, if you would like it. - Rewards: Valvayn does not currently offer monetary rewards for vulnerability reports. Researchers who report responsibly are credited with their permission.. --- Canonical: https://valvayn.com/security/disclosure/ · Markdown: https://valvayn.com/security/disclosure.md · Built: 2026-10-10