NA1 Continuous Exposure Management
Product transparency

Roadmap & Release Centre

See what's shipped, what's in progress, and vote on what comes next.

Released8shipped and available
In development2active product work
Testing0release candidates
Customer votes0prioritisation signals
Released Enterprise (self-hosted)

Continuous Threat Exposure Management

Shipped

Asset inventory, explainable exposure scoring, and threat-intelligence correlation against your own assets.

Progress100%
100%
Planned Enterprise (self-hosted)

Governed Enforcement (FortiGate/Cato/MISP)

Shipped

Governed, approval-gated writes to FortiGate, Cato and MISP are proven in our Enterprise reference implementation - real, working code, not a concept. Integration into the unified NA1 platform is planned; not yet available in NA1 today.

Progress0%
0%
Released Cloud

NA1 Platform V2.0 — CTEM Foundation

V2.0

Unified findings, explainable Exposure Score, assets, domains, certificates, attack paths, agent actions and the security timeline.

Progress100%
100%
Released Cloud + Enterprise

Exposure Correlation Service

v3.6.0

Deterministic, fully explainable risk-story engine correlating findings, assets, CVE intelligence and remediation state into one prioritised view.

Progress100%
100%
Released Cloud + Enterprise

CVE Intelligence Library

v3.7.0

Canonical CVE record enriched with CVSS, EPSS and CISA KEV status, linked directly into risk stories and affected assets.

Progress100%
100%
Released Cloud

V2.0.1 — Commercial Experience

V2.0.1

Production public website, searchable documentation portal, V2 roadmap, public changelog and navigation refresh.

Progress100%
100%
Released Cloud

V2.1 — External Attack Surface Management

V2.1

Automated domain, subdomain, certificate and external service discovery with ownership and change monitoring.

Progress100%
100%
In development Cloud + Enterprise

V2.2 — Integration Hub

V2.2

FortiGate and Cato enforcement is proven in our Enterprise reference implementation, with unified-platform integration planned. Microsoft Defender, Sentinel, Rapid7 and OpenCTI connectors, plus common health, permission and audit controls across all of them, remain in progress.

Progress20%
20%
In development Enterprise (self-hosted)

SSO / Entra ID for Enterprise

Next

OIDC-based single sign-on for self-hosted deployments.

Progress35%
35%
Released Cloud

V2.3 — AI Agents & Investigation

V2.3

Specialist CTEM, threat intelligence, vulnerability and reporting agents grounded in platform evidence.

Progress100%
100%
Released Cloud

V2.4 — Controlled Remediation

V2.4

Approval-gated ticketing, firewall, Defender and scan actions with dry-run, rollback and validation.

Progress100%
100%
Backlog Cloud

V2.5 — Security Newsroom

V2.5

AI-assisted daily briefings, cyber news, customer relevance and source-attributed publishing workflows.

Progress0%
0%
Backlog Cloud

V3 — Autonomous Exposure Operations

V3

Long-term vision for policy-governed autonomous exposure reduction across connected security controls.

Progress0%
0%
Backlog Cloud + Enterprise

Hybrid Cloud + Enterprise Bridge

Future

For customers who want a self-hosted instance for their most sensitive site or workload, and a Cloud instance for everything else — one login story, two deployments. The self-hosted side would optionally forward summarised, non-sensitive data (exposure counts, not raw asset hostnames or IOC detail) to a Cloud dashboard for cross-site reporting, while all governed enforcement (FortiGate, Cato, MISP) stays local. This is an early idea, not committed work — vote if it would matter to you.

Progress0%
0%

V2 delivery principles

Operational, explainable and controlled
Evidence first

Scores, recommendations and reports must trace back to tenant-scoped evidence.

Human control

Potentially disruptive actions use approvals, scope limits, rollback and post-action validation.

Working workflows

Visible features must produce useful results rather than placeholder pages or inactive controls.