What we are building
Roadmap
What we are working on, in the order we think matters.
Last reviewed 31 August 2026
Ordered by what would most change an evaluator’s answer, not by what is easiest to build. Deliberately without promised dates: a public date we miss costs more credibility than a vague one earns, and this platform is small enough that an honest ordering is more useful than a fake schedule.
Now
- Nonce-based CSP and dependency scanning across every shipped image
- External uptime probing with alerting, independent of the platform it watches
- Published incident history, including the ones nobody noticed
Next
- Independent penetration test, with the report summary published
- Verified clean-machine install of the self-hosted distribution, as a CI job
- Disaster-recovery region and a documented, tested restore
Later
- SOC 2 Type I, then Type II
- Contractual SLA with service credits, once the operational record supports one
- Signed release artifacts and a software bill of materials per image
Everything here maps to something on what we don’t do yet. Items leave that page only when they are actually done, not when they are started.