Roadmap & Release Centre
See what's shipped, what's in progress, and vote on what comes next.
Continuous Threat Exposure Management
Asset inventory, explainable exposure scoring, and threat-intelligence correlation against your own assets.
Governed Enforcement (FortiGate/Cato/MISP)
Governed, approval-gated writes to FortiGate, Cato and MISP are proven in our Enterprise reference implementation - real, working code, not a concept. Integration into the unified NA1 platform is planned; not yet available in NA1 today.
NA1 Platform V2.0 — CTEM Foundation
Unified findings, explainable Exposure Score, assets, domains, certificates, attack paths, agent actions and the security timeline.
Exposure Correlation Service
Deterministic, fully explainable risk-story engine correlating findings, assets, CVE intelligence and remediation state into one prioritised view.
CVE Intelligence Library
Canonical CVE record enriched with CVSS, EPSS and CISA KEV status, linked directly into risk stories and affected assets.
V2.0.1 — Commercial Experience
Production public website, searchable documentation portal, V2 roadmap, public changelog and navigation refresh.
V2.1 — External Attack Surface Management
Automated domain, subdomain, certificate and external service discovery with ownership and change monitoring.
V2.2 — Integration Hub
FortiGate and Cato enforcement is proven in our Enterprise reference implementation, with unified-platform integration planned. Microsoft Defender, Sentinel, Rapid7 and OpenCTI connectors, plus common health, permission and audit controls across all of them, remain in progress.
SSO / Entra ID for Enterprise
OIDC-based single sign-on for self-hosted deployments.
V2.3 — AI Agents & Investigation
Specialist CTEM, threat intelligence, vulnerability and reporting agents grounded in platform evidence.
V2.4 — Controlled Remediation
Approval-gated ticketing, firewall, Defender and scan actions with dry-run, rollback and validation.
V2.5 — Security Newsroom
AI-assisted daily briefings, cyber news, customer relevance and source-attributed publishing workflows.
V3 — Autonomous Exposure Operations
Long-term vision for policy-governed autonomous exposure reduction across connected security controls.
Hybrid Cloud + Enterprise Bridge
For customers who want a self-hosted instance for their most sensitive site or workload, and a Cloud instance for everything else — one login story, two deployments. The self-hosted side would optionally forward summarised, non-sensitive data (exposure counts, not raw asset hostnames or IOC detail) to a Cloud dashboard for cross-site reporting, while all governed enforcement (FortiGate, Cato, MISP) stays local. This is an early idea, not committed work — vote if it would matter to you.
V2 delivery principles
Operational, explainable and controlledScores, recommendations and reports must trace back to tenant-scoped evidence.
Potentially disruptive actions use approvals, scope limits, rollback and post-action validation.
Visible features must produce useful results rather than placeholder pages or inactive controls.