# Security and privacy, in plain terms.

> What Ward collects and never collects, where metadata is stored and for how long, how the platform and extension are secured, subprocessors, and how to report a vulnerability.

Content is inspected locally in the browser and never leaves the device. Only metadata reaches the Ward server. This page explains exactly what that means.

## How data moves

1. A user pastes, drops, uploads or submits something in Microsoft Edge.
2. The Ward extension inspects the content **in the browser**, using detectors that return counts, never values.
3. The extension applies the organisation’s signed policy and, if the policy acts or sensitive data was found, records a **metadata-only event**.
4. Events are queued on the device and uploaded in batches. Browsing never waits for the server.
5. The server enriches events from its own records (it does not trust device claims), stores them and evaluates alert rules. Raw upload batches are emptied as soon as they are processed.

## What is collected, and what never is

**Never leaves the device:**

- Page contents, prompts, messages, clipboard contents, typed text, form values
- File contents
- Passwords, cookies, session and OAuth tokens, other sites’ browser storage
- Keystrokes (there is no keystroke listener)
- Full URLs, paths or query strings — only hostnames
- The matched sensitive values themselves (for example the card number)

**Sent to the server as metadata:**

- Hostname, app category, account type and account domain (discovery, daily roll-up)
- Action, decision, outcome, policy, classification names and per-detector match counts
- File name, extension, MIME type and size for uploads and downloads (file names can be turned off)
- Account identifier (email) for corporate accounts by default; configurable to none or all
- The fact that an AI prompt was submitted, without its text (configurable)
- Business justification text a user types in a JUSTIFY prompt (users are told it is shared; redacted if it looks sensitive)
- Browser profile email, OS, browser and extension versions, installed extensions (enrollment and heartbeat)

This is enforced structurally: the telemetry wire schema is strict and has no field that could hold content, and the server rejects unknown fields. Automated tests assert that test secrets never appear in events, database rows or server logs.

## Settings that reduce collection

| Setting | Options | Default |
|---|---|---|
| Discovery scope | All sites, or catalog applications only | All sites (hostnames only, daily roll-up) |
| Account identifiers | None, corporate only, all | Corporate only |
| File names | On or off | On |
| AI prompt metadata (“a prompt was submitted”, no text) | On or off | On |
| Event retention | Per organisation | 180 days |

## Where metadata is stored

- **Hosting model:** Ward-operated: Valvayn hosts the control plane for you. Customer-hosted deployment (the same software on your own infrastructure) is available on request.
- **Hosting provider and location:** Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection).
- **Database:** PostgreSQL with row-level security per organisation.
- **Retention:** events are kept for 180 days by default (configurable) and then deleted by dropping whole monthly partitions. Discovery data is stored as daily roll-ups.

## How the platform is secured

- **Tenant isolation in the database.** Every tenant table has a forced row-level-security policy; the application’s database role cannot bypass it, and queries also filter by organisation. Cross-tenant access is covered by dedicated tests.
- **Signed policy.** Each policy change produces an immutable version signed with ECDSA P-256. The extension rejects bad signatures, other organisations’ policies, rollbacks and malformed bundles, and keeps the last known-good policy. The verification key can be pinned through MDM.
- **Per-device credentials.** No organisation secret ships in the extension. An expiring, revocable enrollment token is exchanged for a device-specific secret (stored hashed, rotated) and one-hour access tokens.
- **Administrator access.** scrypt password hashes or Microsoft Entra ID single sign-on; server-side sessions (12 hours absolute, 2 hours idle), CSRF protection, rate-limited sign-in, five roles enforced by the server.
- **Secrets at rest.** Integration secrets are encrypted with AES-256-GCM; tokens and device secrets are stored as hashes.
- **Audit log.** Administrative actions — sign-ins, policy and classification changes, exceptions, exports, deployment and integration changes — are written to an append-only log.
- **Hostile input.** Strict schemas on every API, bounded request sizes, parameterised SQL, rate limits, and SSRF-safe outbound webhooks signed with HMAC-SHA256.
- **Transport.** Production deployments require HTTPS for the API.

## How the extension is hardened

- **Minimal permissions.** Ward does not request access to cookies, history, tabs, the clipboard API, webRequest, scripting, the debugger or native messaging. It inspects pastes through the paste event the user triggers.
- **Isolated user interface.** Enforcement dialogs render in a closed shadow root using text only. Business justifications are typed in an extension-origin frame the web page cannot read.
- **Isolated file parsing.** PDFs are parsed in a separate extension frame and worker with strict size, work and time limits. Anything that cannot be inspected is reported as “not inspected”, never as clean.
- **Fail closed where it matters.** A page can remove or cover Ward’s dialog; the action then stays held or is cancelled — never allowed.

The extension is not claimed to be tamper-proof. Resistance to removal comes from force-installation and Edge policy; Ward raises an alert when a device stops reporting.

## Certifications

This site makes no claim of third-party certification (such as SOC 2 or ISO/IEC 27001). If you need security documentation for a vendor assessment, contact security@valvayn.com.

## Known limitations

We publish what Ward does not do:

- Ward protects the managed browser only — not other browsers, native apps or mobile devices.
- Images, archives, legacy Office files, encrypted or scanned PDFs and very large files are not content-inspected. Rules can choose to block content that could not be inspected.
- ChatGPT and Claude usually do not display the signed-in account, so Ward classifies them as “unrecognised” rather than personal or corporate.
- Microsoft Entra ID integrations and macOS deployment through Intune are tested against mocks, not yet against a live tenant.

## Subprocessors

See the [subprocessor list](https://valvayn.com/legal/subprocessors/) and the [Data Processing Addendum](https://valvayn.com/legal/dpa/).

## Report a vulnerability

Email security@valvayn.com. Our [responsible disclosure policy](https://valvayn.com/security/disclosure/) explains scope and safe harbour; a machine-readable contact is published at [/.well-known/security.txt](https://valvayn.com/.well-known/security.txt).

---

Canonical: https://valvayn.com/security/ · Markdown: https://valvayn.com/security.md · Built: 2026-10-10
