WARDEN
Status & roadmap · updated 3 August 2026

Where we
actually are.

Most companies publish a roadmap. Fewer publish the gaps. If Warden is going to ask a fire service to trust a record it can't see inside, the least we can do is state plainly what is built, what isn't, and what is still wrong. Everything below is checkable, and some of it is uncomfortable.

Stage Pre-production Entity Not yet registered Live deployments None Records sealed Zero
Why this page exists

Warden's entire proposition is that a record should be verifiable rather than taken on trust. That principle is worthless if the company describing itself gets a free pass. So this page is written to the same standard as the verification page: no green ticks that haven't been earned.

01 At a glance

LivePublic site & governance modelPublished and readable by anyone
LiveInteractive console demoSynthetic data, runs in your browser
LiveVerification page & toolingAlgorithm and scripts published
BuiltBackend: schema, RLS, append-only ledgerProvisioned, but in Ireland — see 03
BuiltEd25519 signing (ledger v2)Written and tested, not yet deployed
BuiltExternal anchoring (RFC 3161 + DPO receipt)Written and tested, not yet deployed
NoUK limited companyPre-incorporation
NoDesign-partner brigadeNone engaged
NoReal flight, real recordZero incidents have ever been sealed
NoCyber Essentials · pen test · insuranceNot started

02 Live system feed

The heartbeat — or, right now, the honest silence.

Public cryptographic events only; incident and flight records are not public and never appear here. More about this feed →

03 What is genuinely built

Working code, not slideware — and you can inspect most of it.

Done The governance layer

Role-based command console, human-in-command authorisation gate, append-only event ledger with database triggers that reject UPDATE and DELETE, a seal guard that refuses to reopen a closed incident, and a governed purge that signs its own deletion onto the record.

Done Independent verification

Keyless SHA-256 chaining plus Ed25519 signatures, so a third party can verify a record with a published public key and no secret. Two verifier scripts are downloadable and readable.

Done The data-protection groundwork

A pre-reasoned Art 35 DPIA starter, a lawful-basis position, a no-facial-recognition red line and a live-only-by-default posture — all published rather than promised.

Done Ingestion that is genuinely one-way

Video and telemetry in; no command path out. Warden cannot arm, steer or land an aircraft, so it adds nothing to an operator's airworthiness case.

04 What is wrong or missing

The list we would rather you heard from us.

GapData residency is Ireland, not the UKThe backend sits in eu-west-1. A London (eu-west-2) project is the next infrastructure job, and no pilot data will be accepted before it exists.
GapSigning keys are not in an HSMThe private key would live in an isolated server-side secret, not dedicated key-management hardware. Anchoring bounds the damage a compromise could do; it does not eliminate it.
GapNo independent security assessmentNo penetration test and no Cyber Essentials certification yet. The cryptography has been tested by us, which is not the same as being tested by someone else.
GapNo entity, insurance or processor contractNo UK LTD, no professional indemnity cover, and no Article 28 data-processing agreement drafted. All three are prerequisites for a real pilot, not optional extras.
GapNothing has been proven in the fieldEvery record on this site is synthetic. No aircraft has flown into this system and no commander has ever used it at an incident.

05 What happens next, in order

Sequenced by what blocks what — not by what is most fun to build.

Next Infrastructure & entity

Register the UK limited company with a founder IP assignment; stand up the London region; deploy the asymmetric ledger and the anchoring job. This closes three of the five gaps above.

Then A design partner

One brigade, under a free memorandum of understanding: co-author the DPIA, run one governed test flight, and produce the first real sealed record. What that involves →

Then Independent assurance

Cyber Essentials, a penetration test against the deployed system, and professional indemnity cover — the things that let a public body run supplier due diligence without stopping.

Later Procurement readiness

Article 28 processing agreement, a published commercial model, and a route to market a brigade can actually buy through.

06 Holding us to this

A status page nobody checks is just marketing with worse formatting.

If something here is out of date, wrong, or reads as more flattering than the evidence supports, tell us and we will correct it. The technical claims are the ones to test first: the verification tooling is published precisely so you do not have to believe this page.

Verify the record yourself →  ·  Report a problem →