Kar-Warden · provable integrity

Declare what an AI component is allowed to be. Then prove it still is.

A watchdog with no LLM judge. You write a component's warrant — its baseline config, the capabilities it may hold, the files it must carry, the invariants that must stay true. Warden checks the component's observed state against it and returns a verdict: INTACT, DRIFTED, or BREACHED — naming exactly what broke. Tamper-evident log, re-runnable signed receipt. Runs entirely in your browser.

No LLM judge — pure determinism Third-party re-runnable receipts One severe break = BREACHED, unaveraged Mutation-gated kernel · witness
01

The check

A live component, agent-alpha, with a warrant on the left and its observed state on the right. Inject a change and watch the verdict move. Everything here is the real kernel running in your browser — the same code the gate proves.

Warrant — what it's allowed to be
Observed — what's actually running
02

The fleet

One warden, many components. monitorStatus folds every warrant + observation into one report — the worst status wins, and a component that should have reported but didn't is UNREPORTED, never quietly counted as fine.

ComponentStatusBrokenSevere
03

The log

Every non-intact verdict can be logged. Each entry is hash-chained to the one before it, so the record itself is tamper-evident — edit any past entry and verifyChain names exactly where the chain breaks.

No anomalies logged yet.
04

The receipt

A verdict you can hand to anyone. The receipt carries the warrant, the observed state and the verdict, self-hashed and optionally Ed25519-signed. A third party doesn't trust your word — they re-run the check on the receipt's own inputs. A verdict forged to say INTACT is caught, even if its hash is recomputed.

Issue for the current verdict
Verify a receipt someone sent you
Drop a .json receipt here, or click to choose
05

How it works

01 · declare

Write the warrant

Pin the baseline: the config hash, the capabilities the component may hold, the files it must carry with their hashes, and named invariants at warn or severe.

02 · check

Compare observed state

verifyIntegrity compares observed against the warrant. One severe break — a changed config, an ungranted capability, a missing file, a severe invariant — is a BREACH, and no amount of passing checks averages it away.

03 · prove

Log and receipt it

Append the verdict to a hash-chained log and issue a signed receipt. Anyone can re-run the check and confirm the verdict — no trust in the issuer, no model in the loop.

Is this an antivirus or a runtime sandbox?
No. Warden doesn't sit in the execution path or block anything. It's an attestation layer: you give it a declared warrant and an observed snapshot, and it produces a provable verdict about whether they match. It answers "did this component silently change or exceed its authority?" — deterministically and re-runnably.
Where does the observed state come from?
From wherever you inventory a component — its config file hashed, its granted scopes listed, its files hashed, its runtime invariants read as booleans. Warden is the pure comparison and the proof; collecting the snapshot is the caller's job, which keeps the kernel deterministic and gate-able.
Why no LLM judge?
Because a judge you can't re-run isn't proof. Every verdict here is a deterministic comparison over hashes and booleans, so a third party gets the same answer byte-for-byte. That's the estate's wedge: provable, accountable AI — adversarial mutation proof of the code, and third-party re-run of the result.
Is my data sent anywhere?
No. The kernel is inlined in this page and runs entirely in your browser. Nothing you type is uploaded; the signing uses your browser's own WebCrypto. Close the tab and it's gone.