Roadmap
What is not built yet.
Security operations, automated response and offensive tooling are the direction of travel, not current features. They are listed here so the difference stays obvious.
- Near term
Finish what is already built
- Move authentication to a production instance — the current launch blocker
- Run a first live phishing campaign against a real Workspace tenant
- Get extension v0.4.0 through Chrome review
- Write the curriculum the Learn pipeline is waiting for
- Microsoft 365 as a second mail connector; GCP and Azure as further cloud connectors
- Next
An AI SOC analyst
- High-volume log, network, identity and endpoint signals routed to a data lake
- Alert triage, hypothesis-driven hunting and behavioral anomaly agents
- A Business plan with SSO, SCIM and API keys
- SOC 2 Type II as the trust gate for that plan
- Later
Response and offense
- Playbooks and containment, always behind human approval
- An agent may recommend; only an approved playbook executes
- A pentest agent for recon and reproduction steps — not an exploit framework
- MSSP partnerships and white-label