Wardin is a gateway. Point ANTHROPIC_BASE_URL at it and every call gets checked (budget, model allowlist, PII, prompt injection), priced, and written into a SHA-256 hash chain signed with ED25519. Like a blockchain, minus the blockchain: one writer, no consensus. Anyone can check the whole chain offline with an open-source verifier, without a Wardin account.
Anything can write a log line, and anything can edit one later. A Wardin receipt is a fixed set of fields hashed together with the hash of the receipt before it, so changing a past record stops every hash after it from matching. An auditor checks that without asking us.
That matters on a deadline. The EU AI Act's high-risk logging and record-keeping duties land in December 2027 and August 2028, and what they ask for is a durable record of what each AI call did and what was enforced on it. A gateway sitting in the path produces that as a byproduct of doing its job.
Each line is a gate the request passed in the path: identity, budget, model allowlist, injection screen, PII redaction. The last line records what the provider returned. When a gate blocks, the block is what gets recorded, at $0.
Cost is computed at the gateway from the token split, cache-create and cache-read priced separately, and posted to the key and the team that own it while the request is still in flight.
Agent traffic is bucketed into sessions under the key that made it. A merged pull request carrying that session id closes the loop from spend to accepted work, so effectiveness is read off the same record as the cost.
A receipt is the fields of one request (actor, model, tokens, cost, and every check that ran) hashed together with the hash of the receipt before it, then signed with ED25519. Alter a past receipt and every hash after it stops matching.
Export a bundle of the recent chain and it carries its own signing-key registry, so a verifier can check every signature and every link with no network and no Wardin account. That produces Art-12-grade records for gateway-routed traffic. We do not sell a compliance verdict; your auditor still makes that call.
One call returns a contiguous segment of the chain, the signing keys that cover it, and the compliance packs in force at the time.
An open-source binary reads the file. It opens no network connection and asks us for nothing.
Zero means every hash recomputed and every signature checked out. Anything else names the receipt that failed and why.
$ wardin-verify --json evidence-bundle.json { "integrityOk": true, "keysPinned": false, "note": "Integrity proves the chain is untampered and each receipt is signed by its declared key. Authenticity additionally requires pinning these key fingerprints against Wardin's published registry (--keys).", "ok": true, "problems": null, "signingKeys": [ { "keyId": "wardin-receipt-v1", "fingerprint": "8317f5a18afc9c5a" } ], "total": 104, "unpinnedKeys": null, "verified": 104 }
Captured from our own dev tenant on 2026-09-06. The hashes, signature and key id are the real ones, and the bundle carries the untruncated values.
What the verifier proves is integrity: every hash recomputes and every signature checks out under the keys the bundle declares. To prove those are our keys, pin the printed fingerprints against our published registry.
No. No software makes an organization compliant; that is a legal determination for your counsel. What Wardin produces is Art-12-grade runtime records for gateway-routed traffic: a signed, hash-chained, framework-mapped receipt for every request the gateway handles. That is evidence for your audit, not an attestation. Wardin does not hold SOC 2, ISO 27001, or HIPAA certifications and will not claim them; the SOC 2 and ISO 27001 evidence packs map receipts to those controls as input to your own examination.
A gateway your LLM traffic goes through. It checks each request against your budget, model allowlist, PII rules and injection screens before a provider is called, prices it, and writes a signed, hash-chained receipt of what happened, for every gateway-routed request. One receipt, read by security, by finance, and by whoever is asking whether the spend produced anything.
LiteLLM and Portkey are routing layers with their own budget and guardrail features, and both are good at that job. What neither produces is a signed record of the decision. Wardin enforces in the same place (budget hard-stop before the provider is called, model allowlists, prompt-injection screens) and writes every gateway-routed request into an ED25519-signed hash chain that an auditor can verify offline. The receipt is the difference.
Observability tools record what happened after the money is spent. Some can rate-limit, none produce evidence an auditor would accept. Wardin meters cost per team, key, and session, refuses the request that would blow the budget, and signs a hash-chained receipt of the decision either way.
The gateway is not. The offline receipt verifier is: wardin-verify is MIT-licensed at github.com/wardin-ai/wardin-verify, so you can check a signed chain without an account and without trusting us. We will not call the gateway open source until there is a public repo you can clone.
Yes. Point ANTHROPIC_BASE_URL (or your tool's base-URL setting) at the gateway with a Wardin virtual key. No client code changes. Agentic traffic is grouped into sessions so you see cost per task, not noise across thousands of tool-call requests.
Anthropic, OpenAI, AWS Bedrock, and Google Vertex (Gemini), with configurable fallback routing across them. Bring your own provider keys.
Join the waitlist. We onboard teams in small batches so early support stays personal. Reply to the welcome email with what your auditor or finance team is asking for and we will prioritize you.
I built Wardin because the AI audit trails I kept seeing were log tables somebody could edit, and nobody could tell me which requests had actually been checked before they went out.
So the gateway signs. Every request it handles gets a receipt, hashed into a chain and signed with ED25519, with the checks that ran mapped to EU AI Act and NIST controls. That runs today. The durable WORM archive those receipts age into is built and not yet running in production, which is why this is a waitlist and not a signup.
If you're carrying an EU AI Act deadline, tell me what your auditor is asking for. I read every one of these.