Autonomous cyber defence
Intelligence can recommend. Authority must be earned.
WARDOG is an AI-native cyber defence project whose aim is to maintain a defensible security state rather than to produce another queue of alerts. Its cycle is observe, reconstruct, hypothesise, verify, contain, remediate, prove and learn.
Visit WARDOGwardog.ai(opens in a new tab)WARDOG is an AI-native cyber defence project whose aim is to maintain a defensible security state rather than to produce another queue of alerts. Its cycle is observe, reconstruct, hypothesise, verify, contain, remediate, prove and learn.
The architecture separates reasoning from authority: bounded AI investigation reconstructs what happened and tests hypotheses against evidence, while a deterministic policy gate decides whether any resulting action may be taken, at what scope, and with what record.
The problem
Detection tooling produces isolated alerts that describe fragments of an incident. Analysts spend their time reconstructing context, and even a correct response leaves little verifiable proof that the underlying state was actually restored.
Intended users
Modern businesses, their security teams, and the MSPs who defend multi-tenant estates.
What WARDOG does.
Security-state graph
A continuously maintained model of identities, endpoints, sessions and their relationships, held as one connected state rather than separate logs.
Bounded AI investigation
Reasoning that reconstructs an incident, forms hypotheses and tests them against evidence, within explicit bounds.
Deterministic policy and authority gate
AI never holds arbitrary execution rights; every action is authorised, scoped and signed by a deterministic gate.
Authorised defensive response
Containment and remediation targeted at the specific session, grant, process or host involved.
Verification of remediation
Verification of the resulting state after remediation, rather than assuming the action succeeded.
Machine-checkable evidence
An evidence record of what changed and why, produced as part of the response rather than written up afterwards.
- Investigation works from connected state, not isolated alerts.
- Authority to act is deterministic and separate from AI reasoning.
- Response is scoped to the exact affected object.
- Remediation is verified, not assumed.
- Fewer alerts to triage and a clearer account of each incident.
- Evidence that a security state was restored, in a form that can be checked.
- A consistent defence model across tenants for MSPs.
Reasoning proposes, authority disposes
WARDOG's differentiator is the boundary between the two: bounded multi-agent investigation may recommend, but only a deterministic gate with verified authority can authorise, scope and sign an action — and the resulting state is then verified.
- Connected security-state graph across identities, endpoints and sessions.
- Hypothesis testing against evidence rather than heuristic scoring alone.
- Deterministic authorisation with scoped, signed actions.
- Post-remediation state verification with a machine-checkable record.
Early access and in development — not generally available. Descriptions here are the project's design intent; no operational protection outcome, third-party certification or measured detection performance is claimed.
Visit WARDOGwardog.ai(opens in a new tab)