Company/Roadmap

What we are building,
and what we are not.

Themes we are investing in this year, and the things we have decided against. Shipped work lives on the changelog, not here.

This year

Five things we are investing in.

Themes, not ship dates. What has shipped is on the changelog.

01

Lineage everywhere

Close the remaining hops between commit and ingress across more CI systems, registries and cluster types, so source_gap becomes rare instead of common.

Ontology
02

Native engine depth

More framework models for the taint analysers, deeper interprocedural analysis beyond the five call-graph languages, and accuracy benchmarks against the external tools we run alongside.

Engine
03

Runtime corroboration

IAST agents and the eBPF sensor turning static reachability into observed reachability on the same finding.

Runtime
04

Customer-environment execution

Execution clusters as the default answer for regulated customers: simpler onboarding, per-cluster policy, and sensors that speak only to ingest endpoints.

Deployment
05

Attestation of the platform itself

Third-party assessment of SecurityVault's own controls. We hold none today and will not describe one as in progress until an engagement exists.

Trust
06

Regions

EU and Asia-Pacific hosted regions are in design. Self-hosted remains available everywhere.

Hosting
What we are not building

Deliberately not.

A scanner marketplace
Connectors are built into the platform against real stacks. There is no third-party listing programme.
AI that decides
AI triage stays advisory and audited. We will not ship a model that writes dispositions.
A schema per tenant
Tenant isolation is row-level with policies proven in CI. We will not reintroduce per-tenant schemas.
Fail-open modes
There is no configuration that turns an evaluator error or an unsigned callback into an allow, and there will not be.
Shape it

Tell us which hop you need closed.

Roadmap conversations start with the engineering team and a concrete gap in your lineage.