Every LLM call passes through one gateway that enforces policy before the provider is called, meters every dollar to a team, and signs a tamper-evident receipt of what happened. The audit-grade evidence layer for AI — one product, not five stitched together.
Observability tools watch traffic after the fact. Guardrail services score risk but can't stop a request. FinOps platforms see the invoice, not the request. Developer-analytics tools count activity, not outcomes.
Wardin is the audit-grade evidence layer for AI — it enforces, meters, and signs from inside the request path, so a policy violation never reaches a provider, every token has an owner before finance asks, and every call leaves a tamper-evident receipt.
Regulation is turning that receipt from nice-to-have into required: the EU AI Act's high-risk logging and record-keeping duties land in December 2027 and August 2028 — the exact artifact a request-path gateway produces as a byproduct. It's the convergence the category Gartner calls AI TRiSM keeps buying in pieces, and nobody else ships in one path.
PII redaction, injection shields, model allowlists, and budget caps execute before the provider is called. A violation never leaves your network — there is nothing to clean up afterward.
Every dollar posts to a team, a virtual key, and a person — as it's spent, not when the invoice lands. Budgets enforce themselves; month-end closes clean into NetSuite.
The same signed receipt proves whether governed spend produced accepted work — sessions tied to merged-PR outcomes from GitHub. Raw token counts are excluded by design, so you can't game it by burning more.
Each call emits a tamper-evident record — actor, model, policy checks, cost — chained by hash to the one before it. Editing any past record breaks the chain, so an auditor verifies the evidence rather than taking it on trust.
Every check maps to the controls the EU AI Act and NIST AI RMF ask for. Pull a signed evidence bundle for the recent chain in one click, or let a background job carry it into a Wardin-managed, Object Lock WORM store for long-term retention — then hand an auditor an offline verifier that checks the whole chain without a Wardin account. The artifact those record-keeping rules demand — not a compliance certificate, the evidence underneath one.
Five contracts, five dashboards, five places the story can disagree — and still nothing that can stop a bad request.
One gateway in the request path. Policy, ledger, evidence, and outcomes are properties of the same record — they can't disagree.
Nothing un-scanned. Every prompt passed PII and injection checks in-path, and the signed chain proves it — per request, mapped to the framework, kept for the full retention window.
Every token debits a team and a key at request time. Budgets warn at 80% and enforce at 100% — the ledger closes clean without a reconciliation sprint.
Spend lines up against PR acceptance and delivery signals — not token volume. You see which teams turn dollars into shipped work, and which just burn.
The audit-grade evidence layer for AI: one gateway that enforces policy before a request reaches a provider, meters every dollar to a team and a key, and signs a tamper-evident receipt of what happened. That one receipt answers three separate questions — security asks "what left the building," finance asks "who spent it, on what," leadership asks "is it working" — instead of three stitched-together tools each answering one.
LiteLLM and Portkey are proxies — they route requests. Wardin sits in the request path to enforce: budgets hard-stop with an atomic Redis check before the request reaches a provider, policies (model allowlists, prompt-injection screens) block in-path, and every request emits a signed, tamper-evident receipt. If you only need routing, they're great; if you need audit-grade evidence and finance-grade cost attribution from the same request, that's Wardin.
Observability tools tell you what happened after the money is spent — they can't block a request, and they don't produce evidence an auditor would accept. Wardin is enforcement plus evidence: the same gateway that meters cost per team, key, and session can refuse the request that would blow the budget, and signs a hash-chained receipt of the decision either way.
No — no software makes an organization compliant; that's a legal determination for your counsel, not a feature we sell. What Wardin produces is audit-grade, Art-12-grade runtime records for gateway-routed traffic: a signed, hash-chained, framework-mapped receipt for every request the gateway handles. That's evidence, not a compliance attestation, and nothing here is described as shipped until it's actually shipped. Wardin also doesn't hold — and won't claim — certifications like SOC 2, ISO 27001, or HIPAA. Our SOC 2 and ISO 27001 evidence packs map signed receipts to those frameworks' controls as input to your own audit — evidence for an examination, never a claim to hold the report.
Not yet. The gateway may be open-sourced later, but we won't put "open source" on the site until there's a public repo you can actually clone.
Yes — point ANTHROPIC_BASE_URL (or your tool's base-URL setting) at the gateway with a Wardin virtual key. No client code changes. Agentic traffic is grouped into sessions so you see cost per task, not noise across thousands of tool-call requests.
Anthropic, OpenAI, AWS Bedrock, and Google Vertex (Gemini), with configurable fallback routing across them. Bring your own provider keys.
Join the waitlist. We onboard teams in small batches so early support stays personal — reply to the welcome email and tell us what your AI cost chaos looks like, and we'll prioritize you.