{
  "$comment": "Machine-readable summary of Ward. status: available | coming | not_supported. validation: real_world | automated | none. Generated from the same source as the website.",
  "name": "Ward",
  "url": "https://valvayn.com/",
  "generated": "2026-10-10",
  "summary": "Ward is a managed Microsoft Edge extension and admin console. It inspects pastes, uploads and AI prompts locally, enforces your policy at the moment of the action, and sends only metadata to the server.",
  "corePromise": "Content is inspected locally in the browser and never leaves the device. Only metadata reaches the Ward server.",
  "statusDefinitions": {
    "available": "Ships in the product today.",
    "coming": "Not active in the product yet; may be available for early access on request. Do not rely on it today.",
    "not_supported": "Not supported."
  },
  "validationDefinitions": {
    "real_world": "Exercised on real Microsoft Edge with real services (September 2026 validation of v0.1.0).",
    "automated": "Covered by unit, integration and headless-Chromium tests only.",
    "none": "Not applicable."
  },
  "pillars": [
    {
      "id": "data-protection",
      "name": "Data protection",
      "status": "available",
      "summary": "Stops sensitive company data from leaving through AI prompts, pastes, uploads and form submissions — decided in the browser, at the moment of the action.",
      "capabilities": [
        {
          "id": "ai-prompts",
          "name": "AI prompt protection",
          "status": "available",
          "validation": "real_world",
          "description": "Inspects text pasted into or submitted to AI tools (Enter, send button, form submit) and applies the policy decision before the prompt is sent.",
          "notes": "Validated on chatgpt.com in real Edge. Apps with unusual send mechanics may not be intercepted on submit; paste and upload interception do not depend on the app."
        },
        {
          "id": "clipboard",
          "name": "Paste and drag-and-drop inspection",
          "status": "available",
          "validation": "real_world",
          "description": "Every trusted paste and drop (text and files) is inspected locally. Keystrokes are never observed.",
          "notes": "Paste blocking validated in real Edge on Windows and macOS."
        },
        {
          "id": "uploads",
          "name": "File upload inspection",
          "status": "available",
          "validation": "automated",
          "description": "Reads the text of files at upload time: text-like formats, .docx/.xlsx/.pptx, and PDFs (parsed in an isolated extension frame with time and size limits).",
          "notes": "Not inspected: images, legacy Office formats, archives, encrypted or scanned PDFs, files over the size budget (10 MB by default). Rules can choose to block content that could not be inspected."
        },
        {
          "id": "dlp",
          "name": "Local DLP detectors and classifications",
          "status": "available",
          "validation": "automated",
          "description": "Built-in detectors for payment cards (Luhn-checked), U.S. Social Security numbers, email addresses, U.S. phone numbers, cloud and SaaS keys and tokens, private keys, database connection strings with credentials, JWTs and generic secrets — plus custom keyword dictionaries and regular expressions. Detectors return counts, never values.",
          "notes": "Payment card detection is part of the real-world validation."
        },
        {
          "id": "identity",
          "name": "Corporate vs personal account context",
          "status": "available",
          "validation": "automated",
          "description": "Reads the account an app displays (for example Google’s account button or a SharePoint tenant host) and classifies it as corporate, personal or unrecognised, so policies can treat a personal account differently from a work one.",
          "notes": "ChatGPT and Claude usually do not display the signed-in email, so they classify as unrecognised. Policies should treat personal and unrecognised alike for those apps."
        },
        {
          "id": "discovery",
          "name": "App and AI discovery",
          "status": "available",
          "validation": "automated",
          "description": "Daily roll-up of which applications are used, with which account type, against a built-in catalog of about 65 apps. Unknown hosts that look like AI tools are treated as unreviewed generative AI.",
          "notes": "Records hostnames only. Organisations can restrict discovery to catalog applications."
        },
        {
          "id": "decisions",
          "name": "Graduated decisions",
          "status": "available",
          "validation": "real_world",
          "description": "Allow, log, warn, require a business justification, or block. The strongest matching rule wins; relaxations are explicit, scoped, audited, expiring exceptions.",
          "notes": "Block validated in real Edge; warn and justify are covered by automated browser tests."
        }
      ]
    },
    {
      "id": "extension-protection",
      "name": "Extension protection",
      "status": "available",
      "summary": "Shows every browser extension in the organisation, where it comes from, what it may do and what changed — and blocks it through Microsoft Edge policy when an administrator decides to.",
      "capabilities": [
        {
          "id": "inventory",
          "name": "Extension inventory",
          "status": "available",
          "validation": "automated",
          "description": "Name, ID, version, permissions and host access of every extension on enrolled browsers, with affected devices and users.",
          "notes": "Exercised end to end in headless Chromium; not yet against real store extensions updating on real Edge machines."
        },
        {
          "id": "publisher-history",
          "name": "Publisher and store history",
          "status": "available",
          "validation": "automated",
          "description": "Publisher, source (Edge Add-ons, Chrome Web Store, self-hosted, unpacked) and store status over time, including removal from a store.",
          "notes": "Live store lookups are opt-in and rely on an unofficial Edge Add-ons endpoint and the public Chrome Web Store listing page; only the extension ID is sent."
        },
        {
          "id": "permission-changes",
          "name": "Permission-change alerts",
          "status": "available",
          "validation": "automated",
          "description": "Alerts when a new version gains high-risk permissions or all-sites access, changes publisher or update source, or disappears from its store.",
          "notes": null
        },
        {
          "id": "risk-score",
          "name": "Explainable risk score",
          "status": "available",
          "validation": "automated",
          "description": "A 0–100 score from declared permissions, site access, source, store status and recent changes; every factor is shown with its points.",
          "notes": "A risk score, not a verdict: Ward does not label an extension “malware” from these signals."
        },
        {
          "id": "admin-block",
          "name": "Administrator blocking via Edge policy",
          "status": "available",
          "validation": "automated",
          "description": "An administrator marks an extension Blocked; Microsoft Edge enforces it through policy (ExtensionSettings on macOS, ExtensionInstallBlocklist on Windows).",
          "notes": "On Windows the generated Intune script must be redeployed after a change; on macOS the Intune profile is pushed after preview."
        },
        {
          "id": "malware-reputation",
          "name": "Malware scanning and reputation",
          "status": "coming",
          "validation": "none",
          "description": "Static analysis of extension packages and reputation data.",
          "notes": "Early access on request."
        },
        {
          "id": "auto-block",
          "name": "Automatic blocking",
          "status": "coming",
          "validation": "none",
          "description": "Rules that block extensions automatically, for example on a known-malicious verdict.",
          "notes": "Early access on request."
        }
      ]
    },
    {
      "id": "web-protection",
      "name": "Web protection",
      "status": "coming",
      "summary": "Blocking of phishing, malware and scam sites is coming. Today, company policy can already block or warn on navigation to specific applications and categories.",
      "capabilities": [
        {
          "id": "site-controls",
          "name": "Policy-based site and app controls",
          "status": "available",
          "validation": "automated",
          "description": "Block, warn or require a justification when users navigate to specific applications or categories (for example unsanctioned AI tools). Blocks of known hosts are applied before the page is requested.",
          "notes": "Blocks that depend on the account type, and blocks of unknown hosts, are applied in the page shortly after it starts loading."
        },
        {
          "id": "web-threat",
          "name": "Phishing, malware and scam site blocking",
          "status": "coming",
          "validation": "none",
          "description": "Threat-category blocking based on vetted feeds and organisation deny lists.",
          "notes": "Early access on request."
        }
      ]
    },
    {
      "id": "download-protection",
      "name": "Download protection",
      "status": "coming",
      "summary": "Download reputation is coming. Today, company policy can already block, warn on or log downloads by source site and file type.",
      "capabilities": [
        {
          "id": "download-policy",
          "name": "Download rules by source site and file type",
          "status": "available",
          "validation": "automated",
          "description": "Policies act on the source application, file name, type and size of a download before it completes.",
          "notes": "Download contents are not inspected."
        },
        {
          "id": "download-reputation",
          "name": "Download reputation",
          "status": "coming",
          "validation": "none",
          "description": "Checking download sources against threat data before the file is saved.",
          "notes": "Early access on request."
        }
      ]
    }
  ],
  "platform": [
    {
      "id": "console",
      "name": "Admin console",
      "status": "available",
      "validation": "real_world",
      "description": "Devices, discovery, policies (sentence builder with simulator), classifications, alerts, investigations and extension intelligence in one web console.",
      "notes": "Enrolled devices and blocked events were observed in the console during the real-world validation."
    },
    {
      "id": "rbac",
      "name": "Roles and audit log",
      "status": "available",
      "validation": "automated",
      "description": "Five administrator roles (Owner, Security Admin, Policy Admin, Analyst, Read Only), enforced by the server. Append-only audit log of administrative actions.",
      "notes": null
    },
    {
      "id": "signed-policy",
      "name": "Signed, versioned policy",
      "status": "available",
      "validation": "real_world",
      "description": "Each change compiles an immutable policy version, signed with ECDSA P-256. Devices verify it, can pin the key via MDM, reject rollbacks and keep the last known-good policy offline.",
      "notes": null
    },
    {
      "id": "alerts-webhooks",
      "name": "Alerts and SIEM webhooks",
      "status": "available",
      "validation": "automated",
      "description": "Rule-based alerts (policy alerts, repeated blocks, heartbeat loss, risky extensions) delivered to SIEM/SOAR through HMAC-signed webhooks.",
      "notes": "No behavioural analytics (UEBA)."
    },
    {
      "id": "entra-sync",
      "name": "Microsoft Entra ID directory sync",
      "status": "available",
      "validation": "automated",
      "description": "Users, groups and memberships read from your tenant (read-only Graph permissions) so policies can target groups.",
      "notes": "Tested against mocked Microsoft Graph; not yet validated against a live tenant."
    },
    {
      "id": "entra-sso",
      "name": "Administrator single sign-on with Entra ID",
      "status": "available",
      "validation": "automated",
      "description": "OpenID Connect with PKCE. Administrators must already exist in Ward; SSO never creates them.",
      "notes": "Tested against mocks; not yet validated against a live tenant."
    },
    {
      "id": "entra-device",
      "name": "Device user verification with Entra ID",
      "status": "available",
      "validation": "automated",
      "description": "Proves which directory user is signed in to the browser using an Entra ID token. Unverified users get every restriction but no identity-scoped exception.",
      "notes": "Tested against mocks; not yet validated against a live tenant or in Edge."
    }
  ],
  "browsers": [
    {
      "name": "Microsoft Edge",
      "platforms": [
        "Windows",
        "macOS"
      ],
      "status": "available",
      "validation": "real_world",
      "notes": "Primary target. Validated in real Edge 153/154 on Windows (x86-64) and macOS (arm64)."
    },
    {
      "name": "Google Chrome",
      "platforms": [
        "Windows",
        "macOS"
      ],
      "status": "available",
      "validation": "automated",
      "notes": "Same extension build; automated tests run in Chromium. Not yet validated in real Chrome."
    },
    {
      "name": "Firefox, Safari",
      "platforms": [],
      "status": "not_supported",
      "validation": "none",
      "notes": "Not supported."
    },
    {
      "name": "Unmanaged browsers, native apps, mobile",
      "platforms": [],
      "status": "not_supported",
      "validation": "none",
      "notes": "Ward protects the managed browser only. Block other browsers with your MDM’s app controls if required."
    }
  ],
  "deployment": [
    {
      "id": "intune-windows",
      "name": "Microsoft Intune — Windows",
      "status": "available",
      "validation": "real_world",
      "description": "Ward generates a PowerShell platform script (and a .reg file) that force-installs the extension and delivers its managed configuration.",
      "notes": "Validated on a real Intune-managed Windows 11 VM: zero-touch enrollment, not removable by the user. Delivery is manual (you upload the script)."
    },
    {
      "id": "intune-macos",
      "name": "Microsoft Intune — macOS",
      "status": "available",
      "validation": "automated",
      "description": "Ward generates a .mobileconfig profile you upload as a custom profile. Optionally, after you authorise a dedicated app registration, Ward can create and update the profile via Microsoft Graph — only after you preview and confirm each change.",
      "notes": "Not yet validated through a real Intune tenant; the Graph push is tested against mocks only."
    },
    {
      "id": "edge-addons",
      "name": "Microsoft Edge Add-ons store or self-hosted",
      "status": "available",
      "validation": "real_world",
      "description": "The extension can be published to Edge Add-ons or self-hosted as a signed package with an update manifest.",
      "notes": "The validation used a self-hosted package with a development signing key; production requires HTTPS and a release key."
    },
    {
      "id": "other-mdm",
      "name": "Other MDM / Google Admin console",
      "status": "available",
      "validation": "none",
      "description": "Any tool that can set Edge or Chrome extension policies can deliver the same keys.",
      "notes": "Documented, not validated."
    }
  ],
  "identity": {
    "provider": "Microsoft Entra ID",
    "features": [
      "entra-sync",
      "entra-sso",
      "entra-device"
    ]
  },
  "dataHandling": {
    "contentLeavesDevice": false,
    "inspectedLocally": [
      "Pasted and dropped text and files",
      "Text submitted to AI tools and (where a policy targets it) forms",
      "Text extracted from uploaded files"
    ],
    "transmittedMetadata": [
      "Hostname, app category, account type and account domain (discovery, daily roll-up)",
      "Action, decision, outcome, policy, classification names and per-detector match counts",
      "File name, extension, MIME type and size for uploads and downloads (file names can be turned off)",
      "Account identifier (email) for corporate accounts by default; configurable to none or all",
      "The fact that an AI prompt was submitted, without its text (configurable)",
      "Business justification text a user types in a JUSTIFY prompt (users are told it is shared; redacted if it looks sensitive)",
      "Browser profile email, OS, browser and extension versions, installed extensions (enrollment and heartbeat)"
    ],
    "neverTransmitted": [
      "Page contents, prompts, messages, clipboard contents, typed text, form values",
      "File contents",
      "Passwords, cookies, session and OAuth tokens, other sites’ browser storage",
      "Keystrokes (there is no keystroke listener)",
      "Full URLs, paths or query strings — only hostnames",
      "The matched sensitive values themselves (for example the card number)"
    ],
    "eventRetentionDefaultDays": 180,
    "retentionConfigurable": true
  },
  "realWorldValidation": {
    "version": "0.1.0",
    "dates": [
      "2026-09-25",
      "2026-09-27"
    ],
    "covered": [
      "Microsoft Edge 153/154 on Windows (x86-64) and macOS (arm64)",
      "chatgpt.com",
      "Microsoft 365 tenant with Intune (Windows 11 VM, zero-touch enrollment)"
    ],
    "results": [
      "Synthetic card number blocked at paste and at submit",
      "Test content found 0 times in a full database dump and the server log",
      "Force-installed extension not removable by the user"
    ],
    "notCovered": [
      "macOS via Intune",
      "Live Entra ID",
      "Google Chrome",
      "HTTPS transport and release signing key"
    ],
    "knownIssue": "ChatGPT account type is detected as unrecognised, not personal."
  },
  "certifications": [],
  "certificationsNote": "No third-party certification is claimed.",
  "hostingModel": "Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request.",
  "hostingLocation": "Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection).",
  "pricing": "Pricing is per protected browser per month and is agreed per customer during the pilot. Contact sales@valvayn.com for a quote",
  "contact": {
    "sales": "sales@valvayn.com",
    "security": "security@valvayn.com",
    "privacy": "privacy@valvayn.com"
  },
  "links": {
    "product": "https://valvayn.com/product/",
    "security": "https://valvayn.com/security/",
    "faq": "https://valvayn.com/faq/",
    "llms": "https://valvayn.com/llms.txt"
  }
}
