Roadmap
Customer Release
Updated July 2026

What should we build now, next, or later?

Start with the phase you care about most, then open the current workstream, the next items, or a request path if something is missing.Tell us what matters.

I want what is shipped now

Review the current working slice first if you need to know what is already available.

I want what is in progress

See the active workstream when you want the immediate product focus.

I want what comes next

Review the next-up phase for the items we expect to tackle after the current cycle.

I want to request something

Send a wishlist item if a gap in the roadmap matters to you now.

Now
Available now
Shipped through Q3 2026

Scan-first security operations workspace

A working portal for point-and-shoot scans, asset/risk workflows, incidents, and AI-assisted review.

  • Tenant workspace with role-based access and audit history
  • Asset inventory for servers, apps, endpoints, identities, and SaaS, with application groups for multi-host systems
  • Risk register, control checklist, and remediation task tracking
  • Point-and-shoot scan jobs with recommendation output in the portal
  • Public and internal IP scan support with ownership proof controls
  • DNS TXT verification path for serverless or agentless ownership approval
  • DNS inventory gap scan to surface IPs and hosts that are not yet under management
  • Security audit service: nmap, OWASP ZAP, Trivy, and Lynis
  • Threat intelligence: indicators, policy modes, allowlists, and block rules
  • Incident workspace with evidence capture, playbooks, and AI summaries
  • Collectors and agents: syslog, firewalld, WordPress, nginx, Next.js, Payload CMS, Kubernetes audit log, Falco runtime detection
  • Cloud collectors: Microsoft Entra ID sign-in monitoring, GCP Cloud Logging and Cloud Functions
  • Companion mobile app (iPhone and Android) for alerts, notifications, and auto-ban review
  • Agent self-update: opt-in scheduled updates plus safe fleet-wide reinstall for collector fixes
  • Weekly review queue, security exports, and recommendation status tracking
  • Multi-workspace support for customers who manage more than one environment
  • AI-assisted analysis with policy controls, consent, redaction, and review gates
  • Support documentation at /support/docs
Now
In progress
In progress: Q2-Q3 2026

Customer release hardening

Improving feature discoverability, onboarding flow, install guidance, and deployment quality so new SMB workspaces see immediate value.

  • Feature and plan messaging alignment across marketing and portal surfaces
  • Guided first-run onboarding with inline actions, not only checklist links
  • Agent package operations hardening: install, upgrade, rollback, troubleshoot
  • Collector token rotation and service-health visibility
  • Registration approval consistency with domain-gate and policy enforcement
Next up
Planned
Target: Q3 2026

Customer rollout and operational readiness

Preparing the product for broader customer onboarding with stable operations, clearer billing transitions, and deeper connector coverage.

  • AI policy UX: redaction preview, consent copy, and policy-aware deletion
  • Cross-workspace review queue and delegated workspace administration
  • Customer plan-change notifications and subscription history timeline
  • Worker health: durable run records, dead-letter visibility, and replay controls
  • Microsoft 365 or Google Workspace configuration posture review (beyond the sign-in and audit log monitoring already shipped)
Later
Planned
Target: Q4 2026+

Customer release expansion

Payment processing, optional observability, DNS and email protection, and network enforcement.

  • Payment provider integration, customer receipts, invoice lifecycle, and dunning
  • Optional hosted observability workspaces with provisioned dashboards and portal deep links
  • DNS and email protection: mailbox posture, phishing intake, domain policy, and allowlist review
  • Network block simulation and production enforcement adapters
  • Managed proxy security with TLS/header posture and human-approved policy
  • Governed AI evaluation and training pipeline with consent, redaction, and model promotion gates

How we sequence the roadmap

Everything above is organized around two product lanes and five enablers that keep them honest. We'd rather ship one lane well than promise breadth we haven't proven.

Product lane

Existing-environment security operations

Secure the hosts, applications, services, containers, and SaaS surfaces you already run: Linux, WordPress/PHP, nginx/Apache, firewalls, VoIP/SIP, Node.js/Next.js, edge/CDN, Kubernetes/Falco, Microsoft Entra ID, Google Cloud, and related logs, using our own collector and agent stack — with alerts and auto-ban review reachable from the companion mobile app.

Product lane

Serverless application security

Secure serverless and managed-platform workloads such as AWS Lambda, Vercel, and Cloudflare Workers, where you own the risk but not the servers, starting with proxy, edge, middleware, and webhook-based collection.

Enabler

Open-source evidence-engine packaging

Use proven open-source scanning, observability, and detection engines without requiring you to become an expert operator of every one of them. Sotiras generates the collector, scan, dashboard, alert, and recovery profile from your own asset inventory.

Enabler

Collector Proof Lab

Mature each collector family with fixtures, safe decoy environments, and real-world installs before we make a support claim about it, so coverage breadth never gets ahead of collector quality.

Enabler

ProtectTheBox

Validate the full protection loop — detect, explain, act, verify, and record the outcome — against known-safe lab scenarios before extending that same promise to production customers.

Enabler

Operational AI

Put AI at every step of the operational workflow so you see fewer raw signals and more guided, reviewed recommendations, with deterministic controls and cost/consent guardrails in front of every high-confidence action.

Enabler

Product support and services

Provide bounded expert support and fixed-scope onboarding, review, incident, and recovery packages, alongside partner/MSP delivery — support that reinforces the product without becoming unbounded outsourced IT.