Shadow Warden AI — Gateway v7.1 — Explore the API Reference
Business Community Ecosystem

Secure AI Communities
Built for Business

70+ features across 11 modules — federated entity IDs, post-quantum cryptography, SMB governance, agentic commerce, and real-time compliance — all in one ecosystem.

👥
1,240
Active Members
users
8,340
SEP Transfers / Mo
tx
24,500
Published UECIIDs
records
🏅
4.7
Avg. Reputation
/ 5.0

Production data · Updated every 5 minutes

11 Modules

The full ecosystem at a glance

Every module ships production-ready. Click any card to explore features and documentation.

6 features
SEP / UECIID

Cryptographic entity IDs, inter-community peering, Knock invitations, sovereign data pods, and STIX 2.1 audit chain.

🛡
4 features
Post-Quantum Crypto

HybridSigner Ed25519+ML-DSA-65 and HybridKEM X25519+ML-KEM-768. Enterprise-grade FIPS 204/203 compliance.

🏛
4 features
Governance & Intel

Versioned community charter, Z-score behavioral anomaly detection, intelligence reports, OAuth agent discovery.

🏢
5 features
SMB Governance Suite

Eight-module governance toolkit: vendor DPA tracking, cost allocation, budget dashboard, incident register, supplier risk, prompt library, training records, suite wizard.

🔑
4 features
Secrets Governance

Multi-vault connectors (AWS SM, Azure KV, HashiCorp, GCP SM), SQLite inventory, policy engine, lifecycle rotation alerts.

📔
11 features
Obsidian Integration

Auto-scan notes on modify, data class inference, SEP share with UECIID provenance, XAI pipeline sidebar, offline queue.

📊
8 features
Business Intelligence

Eight analytics functions, OLS trend predictions, community benchmarking, 15-min SQLite cache, PDF report builder.

5 features
Semantic Layer

Nine built-in BI models, deterministic SQL generator, self-service tenant catalog, Redis query cache, AI query endpoint.

5 features
Agentic Commerce

UCP/AP2/MCP procurement protocols, multi-agent auction, FIDO2 passkeys, Web3 mandate contract, Commerce Budget Guardian.

📄
6 features
Document Intelligence

MarkItDown converter with SHA-256 Redis cache, data class inference, 50 MB gate, community doc-converter endpoint.

5 features
Compliance Dashboard

19 controls across GDPR/SOC2/ISO27001/HIPAA, real-time gap manager, WebSocket push, SOVA remediation tools.

Architecture

How the modules connect

Click any node to jump to that module's detail section.

graph TB subgraph Core["Core Protocols"] SEP["◈ SEP / UECIID"] PQC["🛡 Post-Quantum Crypto"] end subgraph Gov["Governance & Risk"] Charter["🏛 Charter & Intel"] Behavioral["📡 Anomaly Detection"] end subgraph SMB["SMB Suite"] Vendor["🏢 Vendor Gov"] Cost["💰 Cost Allocation"] Budget["📈 Budget Dashboard"] Incidents["⚠ Incident Register"] Supplier["🔍 Supplier Risk"] Prompts["📚 Prompt Library"] Training["🎓 Training Records"] end subgraph Data["Data & Secrets"] Secrets["🔑 Secrets Gov"] Obsidian["📔 Obsidian"] end subgraph Advanced["Analytics & Commerce"] BI["📊 Business Intel"] Semantic["⬡ Semantic Layer"] Commerce["⚡ Agentic Commerce"] DocIntel["📄 Doc Intelligence"] Compliance["✅ Compliance"] end SEP --> Charter SEP --> PQC Vendor --> BI Incidents --> BI Cost --> Budget Prompts --> Obsidian Training --> Behavioral Semantic --> BI Semantic --> Budget Commerce --> Budget DocIntel --> Incidents Compliance --> Vendor Compliance --> Incidents Charter --> Behavioral

35 Features

Find any feature instantly

Community & Collaboration 19 features
CM-01
SEP / UECIID Protocol shipped

Snowflake→base-62 entity IDs (SEP-{11 chars}). Cryptographically-unique, sortable, collision-free.

CM-02
Inter-Community Peering shipped

Three sharing modes: MIRROR_ONLY, REWRAP_ALLOWED, FULL_SYNC. HMAC-SHA256 handshake. Duplicate guard.

CM-03
Knock-and-Verify Invitations shipped

72-hour Redis-backed one-time invitation tokens. Invitee identity verified before member enrollment.

CM-04
Reputation Engine shipped

5-badge system: NEWCOMER → TRUSTED → CONTRIBUTOR → EXPERT → ELITE. Anonymised leaderboard (GDPR-safe).

CM-05
Charter & Governance shipped

Versioned community charters (DRAFT→ACTIVE→SUPERSEDED). Member acceptance tracking. Compliance scoring.

CM-06
Behavioral Anomaly Detection shipped

Z-score anomaly scoring. NORMAL/ELEVATED/CRITICAL thresholds. 30-day rolling baseline. SQLite event store.

CM-07
OAuth Agent Discovery shipped

14-provider OAuth catalog. Scope-based risk scoring. ALLOW/MONITOR/BLOCK verdicts. Redis-backed policy.

CM-08
Community Intelligence Reports shipped

Weighted risk score: 40% transfer rejection + 35% anomaly + 25% governance gap. SAFE→CRITICAL labels.

CM-09
STIX 2.1 Tamper-Evident Audit shipped

SHA-256 prev_hash chain per community. Genesis block. OASIS STIX JSONL export for SIEM ingestion.

CM-35
AI Incident Register shipped

STIX 2.1-linked AI incident journal. Severity: LOW/MEDIUM/HIGH/CRITICAL. Auto-log from filter BLOCK events. Status transitions: open→investigating→resolved→closed. Every incident appended to STIX audit chain.

CM-36
Supplier AI Risk Assessment shipped

5-criteria composite scoring: data access, AI capability, compliance posture, peering history, disclosure recency. Risk labels: LOW/MEDIUM/HIGH/CRITICAL. Derived from sep_transfers velocity — no external API calls.

CM-37
Shared Prompt Library shipped

UECIID provenance on every prompt. Injection screening via POST /filter before save. Versioning, community sharing via Causal Transfer Guard. 6 endpoints at /prompt-library/*.

CM-38
Employee AI Training Records shipped

HMAC-SHA256 attested completion records (VAULT_MASTER_KEY). Expiry tracking, compliance report. Behavioral anomaly hook on ai_training_completed. 5 endpoints at /training/*.

CM-40
Agentic Commerce Protocols (UCP/AP2/MCP) integration shipped

Secure AI-driven procurement with mandate controls, vendor validation, and BI analytics. UCP store discovery, AP2 signed spending mandates, MCP agent intent bridge, Vendor Governance integration, Cost Allocation recording, STIX audit chain per order.

CM-41
Web3 On-Chain Mandates (Ethereum/Polygon) shipped

SmartContract mandate deployment via eth_tester/Sepolia. IPFS metadata storage. Immutable on-chain audit trail for AI spending.

CM-42
Multi-Agent Procurement Auction (Claude/Gemini/GPT) shipped

Parallel vendor proposals from 3 AI providers. Supplier risk scoring. Winner selection by composite score.

CM-43
Tax & Invoice Engine (VAT/GST/Sales Tax) shipped

EU VAT OSS, US Sales Tax (50 states), UK VAT, SG GST, AU GST. PDF invoices via ReportLab stored in MinIO.

CM-44
FIDO2 Passkeys for AP2 Mandate Signing shipped

WebAuthn Passkey registration and authentication. Optional FIDO gate on mandate execution. Phishing-resistant.

CM-45
shadow-warden-sdk Python Package shipped

pip install shadow-warden-sdk. ShadowWardenClient + SecureAgent mixin. Any AI agent gets mandate controls in 3 lines.

Integrations 14 features
IN-01
Obsidian Plugin v4.19 shipped

Auto-scan notes on save. Share via SEP UECIID. XAI pipeline visualization. Offline publish queue. Sidebar view.

IN-02
Slack Integration shipped

Slash command handler with HMAC-SHA256 verification. HIGH/BLOCK + share alerts via webhook.

IN-03
LangChain Callback shipped

Duck-typed WardenCallback for seamless LangChain pipeline integration. Zero config change required.

IN-04
SIEM Integration shipped

Splunk HEC + Elastic ECS format. Custom field mappings. SOC 2 Type II evidence ingestion.

IN-05
GitHub Actions CI shipped

Test matrix (3.11/3.12) + lint + Docker smoke + mutation testing. Coverage gate ≥75%.

IN-14
VS Code extension — inline risk annotation on selected text shipped

5 commands (Ctrl+Shift+W scan selection, scan file concurrent, scan clipboard, clear, settings). 4 decoration tiers (LOW/MEDIUM/HIGH/BLOCK) with coloured gutter, background tint, and inline after-text verdict. Code Lens above HIGH/BLOCK lines. Concurrent file scan (configurable 1–16 workers). Rich hover: flags + secrets found + request ID. Output channel log. Auto-scan on save. v5.2.0.

IN-15
GitHub Actions integration — pre-commit hook that scans commit message + diff planned

Automatically scan every commit message and diff for secrets, injection patterns, and policy violations before code is merged, using a Shadow Warden GitHub Actions workflow.

IN-16
Jira integration — auto-create security tickets on HIGH/BLOCK verdicts planned

Automatically create Jira issues for HIGH/BLOCK verdicts with full XAI causal chain and remediation guidance embedded directly in the ticket.

IN-17
Microsoft Teams slash command — /warden equivalent for Teams channels planned

Bring Shadow Warden into Microsoft Teams with a /warden slash command that scans text, shows verdicts, and lets teams respond to security incidents without leaving the conversation.

IN-18
Notion integration — scan Notion pages via API, write risk tags as properties planned

Automatically scan Notion pages for secrets, injection patterns, and policy violations, then write risk verdicts back as page properties for easy triage.

IN-19
STIX/TAXII feed consumer — ingest external threat intel from any TAXII 2.1 server planned

Consume threat intelligence from any TAXII 2.1 server, automatically ingesting STIX indicators and observables into Shadow Warden's detection pipeline for enhanced threat correlation.

IN-21
OpenTelemetry SDK library — WardenSpanProcessor for any OTel-enabled app shipped

WardenSpanProcessor (sync ThreadPoolExecutor) + WardenAsyncSpanProcessor (asyncio tasks). Extracts span name, string/numeric attributes, event messages — forwarded to /filter. Bounded queue (max 512), shutdown drain, force_flush(), on_finding callback, configurable min_risk + skip_span_names. REST: GET /sdk/status, GET /sdk/stats, POST /sdk/ping. Tier: Pro+.

IN-22
MISP syslog bridge — route MISP ZMQ feed into Shadow Warden syslog sink shipped

Bridge MISP's ZMQ event feed directly into Shadow Warden's syslog sink. ZMQ subscriber (pyzmq, multipart frame support) + HTTP pull fallback. Domain IoCs forwarded as dnsmasq-style syslog lines to UDP 5514 for real-time correlation with passive DNS telemetry. Stats at GET /misp/stats. One-shot sync via POST /misp/sync. Auto-starts in lifespan when MISP_ZMQ_URL or MISP_API_URL+KEY is set.

IN-25
SMB AI Governance Suite shipped

Single-wizard provisioning of all 7 SMB modules. SMBProvisionResult with UECIID + STIX chain ID. get_suite_health() aggregates all module stats. 3 endpoints at /smb-suite/*. Streamlit 6-tab dashboard at page 10.

Business Intelligence 1 features
CM-39
Business Intelligence Module shipped

8-category analytics: AI usage, threats, vendor scorecards, cost optimisation, compliance scoring, community benchmarking, predictive incident analytics, custom report builder. SQLite-cached 15min TTL. FastAPI router at /business-intelligence.

Agentic Commerce 1 features
M2M-01
M2M Commerce Store shipped

Full seller-side architecture for AI agents to trade autonomously. Dynamic pricing, Redis reservations, AP2 payments, STIX audit, budget guardian integration.

Activity

Community growth

New members, SEP transfers, and incidents — last 6 months.

Where to work with communities

Three interfaces — pick the one that fits your workflow.

🌐
Tenant Portal

Full community management — join, peer, share, manage members, configure governance.

Open Portal
📟
SOC Dashboard

Real-time community activity, SEP transfer timeline, incident feed, compliance posture.

Open Dashboard
📈
Streamlit Analytics

Deep-dive BI: 8-tab community intelligence, benchmark percentiles, predictive trend charts.

Open Analytics
No credit card required for Starter

Ready to join a secure
AI community?

Start free with Starter and upgrade when your community needs more members, SEP transfers, or advanced compliance controls.