DROP-IN FOR CLAUDE CODE, CURSOR & CI

Every LLM request your company makes leaves a signed receipt.

Wardin is a gateway. Point ANTHROPIC_BASE_URL at it and every call gets checked (budget, model allowlist, PII, prompt injection), priced, and written into a SHA-256 hash chain signed with ED25519. Like a blockchain, minus the blockchain: one writer, no consensus. Anyone can check the whole chain offline with an open-source verifier, without a Wardin account.

EARLY ACCESS · WE ONBOARD IN SMALL BATCHESANTHROPIC_BASE_URL=https://gw.wardin.ai
THE PATH EVERY REQUEST TAKES--:--:-- UTC · ● SAMPLE · DEV TENANT
INGRESSidentified & keyed
POLICYenforced in-path
ROUTEany provider, one key
LEDGERevery $ posts to a team
EVIDENCEsigned receipt, hash-chained
OUTCOMEStied to business results
12:03:48prod-inferenceclaude-haiku-4-5$0.03PASS ✓
12:03:23frank-macbookclaude-haiku-4-5$0.01PASS ✓
12:03:18carol-macbookclaude-haiku-4-5$0.02PASS ✓
REAL RECEIPTS FROM OUR OWN DEV TENANT, CAPTURED 2026-09-06
WHY A GATEWAY

Logs describe what happened. A receipt proves it.

Anything can write a log line, and anything can edit one later. A Wardin receipt is a fixed set of fields hashed together with the hash of the receipt before it, so changing a past record stops every hash after it from matching. An auditor checks that without asking us.

That matters on a deadline. The EU AI Act's high-risk logging and record-keeping duties land in December 2027 and August 2028, and what they ask for is a durable record of what each AI call did and what was enforced on it. A gateway sitting in the path produces that as a byproduct of doing its job.

ANATOMY OF A RECEIPT

Ten fields. Three people who'll read them.

WARDIN / RECEIPT
REQUEST IDf3fb1ba4…a610
TIMESTAMP2026-09-06 12:03:48 UTC
ACTORprod-inference
MODELclaude-haiku-4-5
AUTHPASS
BUDGETPASS
ALLOWLISTPASS
GUARDRAILPASS
PIIPASS
UPSTREAMPASS
TOKENS23329 / 921
DEBIT$0.0347
PREV HASHb81faf00…0473e741
THIS HASHd475f81f…9b3f76ef
SIGNATUREBltJ2YGC…TjGfAQ==
KEY IDwardin-receipt-v1
ED25519 · SHA-256 CHAIN
REAL RECEIPT · DEV TENANT SEQ 2930
SECURITY READSCHECKS

Each line is a gate the request passed in the path: identity, budget, model allowlist, injection screen, PII redaction. The last line records what the provider returned. When a gate blocks, the block is what gets recorded, at $0.

FINANCE READSDEBIT / ACTOR

Cost is computed at the gateway from the token split, cache-create and cache-read priced separately, and posted to the key and the team that own it while the request is still in flight.

EFFECTIVENESS READSACTOR / MODEL

Agent traffic is bucketed into sessions under the key that made it. A merged pull request carrying that session id closes the loop from spend to accepted work, so effectiveness is read off the same record as the cost.

VERIFY ONE YOURSELF

Download a bundle. Run the verifier. No account.

A receipt is the fields of one request (actor, model, tokens, cost, and every check that ran) hashed together with the hash of the receipt before it, then signed with ED25519. Alter a past receipt and every hash after it stops matching.

Export a bundle of the recent chain and it carries its own signing-key registry, so a verifier can check every signature and every link with no network and no Wardin account. That produces Art-12-grade records for gateway-routed traffic. We do not sell a compliance verdict; your auditor still makes that call.

ED25519
signed at emit time
HASH-CHAINED
tampering is self-evident
S3 · PARQUET
WORM cold tier, Object Lock
01
EXPORT A BUNDLE

One call returns a contiguous segment of the chain, the signing keys that cover it, and the compliance packs in force at the time.

02
RUN THE VERIFIER

An open-source binary reads the file. It opens no network connection and asks us for nothing.

03
READ THE EXIT CODE

Zero means every hash recomputed and every signature checked out. Anything else names the receipt that failed and why.

DOWNLOAD THE EVIDENCE BUNDLE (104 RECEIPTS)
$ wardin-verify --json evidence-bundle.json

{
  "integrityOk": true,
  "keysPinned": false,
  "note": "Integrity proves the chain is untampered and each receipt is signed by its declared key. Authenticity additionally requires pinning these key fingerprints against Wardin's published registry (--keys).",
  "ok": true,
  "problems": null,
  "signingKeys": [
    {
      "keyId": "wardin-receipt-v1",
      "fingerprint": "8317f5a18afc9c5a"
    }
  ],
  "total": 104,
  "unpinnedKeys": null,
  "verified": 104
}
SHA-256 0b3379b179f02baf2590ed6277d9948d0da68a9dd4730886a0d953cf23de00f3

Captured from our own dev tenant on 2026-09-06. The hashes, signature and key id are the real ones, and the bundle carries the untruncated values.

What the verifier proves is integrity: every hash recomputes and every signature checks out under the keys the bundle declares. To prove those are our keys, pin the printed fingerprints against our published registry.

STRAIGHT ANSWERS

Does this make us EU AI Act compliant? No.

Does using Wardin make us EU AI Act compliant?

No. No software makes an organization compliant; that is a legal determination for your counsel. What Wardin produces is Art-12-grade runtime records for gateway-routed traffic: a signed, hash-chained, framework-mapped receipt for every request the gateway handles. That is evidence for your audit, not an attestation. Wardin does not hold SOC 2, ISO 27001, or HIPAA certifications and will not claim them; the SOC 2 and ISO 27001 evidence packs map receipts to those controls as input to your own examination.

What is Wardin, in one sentence?

A gateway your LLM traffic goes through. It checks each request against your budget, model allowlist, PII rules and injection screens before a provider is called, prices it, and writes a signed, hash-chained receipt of what happened, for every gateway-routed request. One receipt, read by security, by finance, and by whoever is asking whether the spend produced anything.

How is Wardin different from LiteLLM or Portkey?

LiteLLM and Portkey are routing layers with their own budget and guardrail features, and both are good at that job. What neither produces is a signed record of the decision. Wardin enforces in the same place (budget hard-stop before the provider is called, model allowlists, prompt-injection screens) and writes every gateway-routed request into an ED25519-signed hash chain that an auditor can verify offline. The receipt is the difference.

How is it different from Helicone or Langfuse?

Observability tools record what happened after the money is spent. Some can rate-limit, none produce evidence an auditor would accept. Wardin meters cost per team, key, and session, refuses the request that would blow the budget, and signs a hash-chained receipt of the decision either way.

Is Wardin open source?

The gateway is not. The offline receipt verifier is: wardin-verify is MIT-licensed at github.com/wardin-ai/wardin-verify, so you can check a signed chain without an account and without trusting us. We will not call the gateway open source until there is a public repo you can clone.

Does it work with Claude Code, Cursor, and other agentic tools?

Yes. Point ANTHROPIC_BASE_URL (or your tool's base-URL setting) at the gateway with a Wardin virtual key. No client code changes. Agentic traffic is grouped into sessions so you see cost per task, not noise across thousands of tool-call requests.

Which model providers are supported?

Anthropic, OpenAI, AWS Bedrock, and Google Vertex (Gemini), with configurable fallback routing across them. Bring your own provider keys.

How do I get access?

Join the waitlist. We onboard teams in small batches so early support stays personal. Reply to the welcome email with what your auditor or finance team is asking for and we will prioritize you.

FROM THE FOUNDER

I built Wardin because the AI audit trails I kept seeing were log tables somebody could edit, and nobody could tell me which requests had actually been checked before they went out.

So the gateway signs. Every request it handles gets a receipt, hashed into a chain and signed with ED25519, with the checks that ran mapped to EU AI Act and NIST controls. That runs today. The durable WORM archive those receipts age into is built and not yet running in production, which is why this is a waitlist and not a signup.

If you're carrying an EU AI Act deadline, tell me what your auditor is asking for. I read every one of these.

Jonathas
Founder, Wardin
EARLY ACCESS · WE ONBOARD IN SMALL BATCHES