Declare what an AI component is allowed to be. Then prove it still is.
A watchdog with no LLM judge. You write a component's warrant — its baseline config, the capabilities it may hold, the files it must carry, the invariants that must stay true. Warden checks the component's observed state against it and returns a verdict: INTACT, DRIFTED, or BREACHED — naming exactly what broke. Tamper-evident log, re-runnable signed receipt. Runs entirely in your browser.
No LLM judge — pure determinismThird-party re-runnable receiptsOne severe break = BREACHED, unaveragedMutation-gated kernel · witness
01
The check
A live component, agent-alpha, with a warrant on the left and its observed state on the right. Inject a change and watch the verdict move. Everything here is the real kernel running in your browser — the same code the gate proves.
Warrant — what it's allowed to be
Observed — what's actually running
02
The fleet
One warden, many components. monitorStatus folds every warrant + observation into one report — the worst status wins, and a component that should have reported but didn't is UNREPORTED, never quietly counted as fine.
Component
Status
Broken
Severe
03
The log
Every non-intact verdict can be logged. Each entry is hash-chained to the one before it, so the record itself is tamper-evident — edit any past entry and verifyChain names exactly where the chain breaks.
No anomalies logged yet.
04
The receipt
A verdict you can hand to anyone. The receipt carries the warrant, the observed state and the verdict, self-hashed and optionally Ed25519-signed. A third party doesn't trust your word — they re-run the check on the receipt's own inputs. A verdict forged to say INTACT is caught, even if its hash is recomputed.
Issue for the current verdict
Verify a receipt someone sent you
Drop a .json receipt here, or click to choose
05
How it works
01 · declare
Write the warrant
Pin the baseline: the config hash, the capabilities the component may hold, the files it must carry with their hashes, and named invariants at warn or severe.
02 · check
Compare observed state
verifyIntegrity compares observed against the warrant. One severe break — a changed config, an ungranted capability, a missing file, a severe invariant — is a BREACH, and no amount of passing checks averages it away.
03 · prove
Log and receipt it
Append the verdict to a hash-chained log and issue a signed receipt. Anyone can re-run the check and confirm the verdict — no trust in the issuer, no model in the loop.
Is this an antivirus or a runtime sandbox?
No. Warden doesn't sit in the execution path or block anything. It's an attestation layer: you give it a declared warrant and an observed snapshot, and it produces a provable verdict about whether they match. It answers "did this component silently change or exceed its authority?" — deterministically and re-runnably.
Where does the observed state come from?
From wherever you inventory a component — its config file hashed, its granted scopes listed, its files hashed, its runtime invariants read as booleans. Warden is the pure comparison and the proof; collecting the snapshot is the caller's job, which keeps the kernel deterministic and gate-able.
Why no LLM judge?
Because a judge you can't re-run isn't proof. Every verdict here is a deterministic comparison over hashes and booleans, so a third party gets the same answer byte-for-byte. That's the estate's wedge: provable, accountable AI — adversarial mutation proof of the code, and third-party re-run of the result.
Is my data sent anywhere?
No. The kernel is inlined in this page and runs entirely in your browser. Nothing you type is uploaded; the signing uses your browser's own WebCrypto. Close the tab and it's gone.