About
The publisher, the lineage, and one rule: say what is true.
The name
Warding
WAR-ding, like "warding off". One word, two syllables. Never Warden, never Ward.
In a lock, the wards are the fixed ridges that stop every wrong key from turning. They do not detect a bad key, log it, or ask it to leave: the key simply cannot rotate.
That is the shape of the product. The policy file lives on the keystone list, so Warding's own gate refuses every tool call that names it, read or write, before anyone is asked. The OS sandbox does not also hide it, and the cases where the gate can be bypassed are listed on /security rather than left for you to find.
The older sense is warding off harm, and a ward: something under protection. Your repository is the ward; Warding is what keeps watch over the house while you are out. That is why the lamp is in the tagline: the story is the night, and the name is the lock.
Publisher
Warding, by Myrmitis.
Warding is published by Myrmitis. Public source, issues and release notes are pending. Read the source publication status.
Warding has no token or coin, and never will.
One fork
Where the code comes from.
Built on Amazon's open-source Kiro agent workspace, published under Apache-2.0 in 2026. Most of the code is theirs; the attribution notice is in NOTICE. Not affiliated with Amazon.
What is ours is thin and named: the harness registry with kiro-cli optional and last, a harness router for spawned subagents, the removal of upstream-owned endpoints from the default build, the brand, and the proof pages on this site. The rest is upstream's, and we do not pretend otherwise. The full account, including what upstream has that we lack, is on the lineage page; the attribution notice is NOTICE, served verbatim on this site.
One rule
Say what is true.
Every claim on this site is either true today or labelled: "in development", "planned", "unverified", or a status word next to an icon. A checkmark links to a dated row on the verification log, and a capability with no row is written as unverified even when we expect it to work.
The build enforces the rule. A test reads every rendered page and fails on the phrases we have decided never to use: the numbers we have not measured, the features that are not built, and the words other companies own. The list is in the repository, next to the pages.
What we do not claim is written down too, and signed: on the security page.
Contact
Reach us.
- Contact Public contact setup is pending.
- Code, issues, discussions Publication pending
- Report a bypass SECURITY.md
Product and security reporting channels must be established before the public source launch.
Review the local beta.
Apache-2.0 source publication is pending. Read the setup notes and verification limits.
Source publication pending
Public source, install commands and downloads are not available yet. A clean install and live workflow are not yet verified.