Own the trust core
Evidence identity, replay, validator lineage, policy, decisions, attack graphs, tenancy, and audit remain proprietary differentiators.
Capability roadmap · evidence-led, gate-driven
The goal is not to copy every scanner. It is to give you one control plane that proves which findings are real, connects source to runtime, and governs remediation across selected analysis and defense engines.
Evidence identity, replay, validator lineage, policy, decisions, attack graphs, tenancy, and audit remain proprietary differentiators.
Use isolated adapters for proven SAST, SCA, secret, IaC, container, and DAST engines while normalizing every result into Assure evidence.
Integrate established WAAP, WAF, API, bot, and DDoS providers before considering capital-intensive edge infrastructure.
Product objectives
Success means you can move from authorized source to a defensible fix with controlled noise, replayable proof, and complete accountability across every security layer.
Every material claim is source-bound, replayable, independently validated, uncertainty-aware, and attributable.
MeasureEvidence completeness, replay pass rate, escaped false positives, and human overturn rate.
Code, dependencies, infrastructure, containers, deployed exposure, and runtime controls resolve into one evidence graph.
MeasureSupported ecosystems, correlated findings, reachable-risk precision, and coverage transparency.
Assure proposes the smallest safe change, verifies it against immutable evidence, and preserves human approval.
MeasureTime to decision, time to verified fix, reopen rate, and remediation acceptance rate.
Six gated stages · sequence, not calendar promise
Each stage ships only after its exit gate passes. Staffing, customer discovery, legal, and threat modeling determine dates; the dependency order below should remain stable.
Keep the current product build safe to operate for separate organizations before expanding scanner breadth.
Meet teams where code changes happen and make evidence review part of normal delivery.
Close the largest source-analysis gap without diluting Assure’s evidence standard.
Correlate first-party findings with the components and deployment definitions that make them reachable.
Test what an outside actor can actually reach, under explicit rules of engagement.
Turn evidence into a verified correction while connecting to defenses that reduce exposure immediately.
Capability register
Priority reflects dependency order and differentiation, not a committed delivery date.
A capability counts as delivered only where a product surface reaches it — the scan engine, an HTTP route, or a CLI command. Code that exists as a library with no caller outside its own package is not counted, which is why SBOM emission, sealed-inventory CVE matching, the deny-by-default registry-pull gate, secret history scanning, and CI prevention policy appear as gaps rather than as deliveries. Nothing in this column means a row is finished: every definition of done is still open.
| Capability | Delivered today | Why it matters | Strategy | Stage | Definition of done |
|---|---|---|---|---|---|
| Commercial identity and tenancy | Google OIDC and tenant isolation | Required before customer data can safely share a control plane | Build | P0 · 00 | SSO/SCIM/RBAC and tenant isolation survive independent adversarial testing |
| Repository and delivery connectors | Fixture-harness GitHub check-run only | Removes manual intake and makes scanning continuous | Integrate | P0 · 01 | Least-privilege, revocable connectors with differential scans and durable provenance |
| Multi-language SAST | Python, Go, Java, C# | Closes the largest source-coverage disadvantage | Integrate Build | P1 · 02 | Published language/framework matrix, holdout evaluation, exact citations, and replay |
| Secret prevention | Provider patterns in-scan; history and CI policy unexposed | Stops credential material before it becomes repository history | Integrate | P1 · 02 | History, custom patterns, push prevention, governed bypass, and optional validity checks |
| SCA, licenses, and SBOM | Sealed advisory matching and license policy | Most application risk includes third-party components | Integrate Build | P1 · 03 | Transitive graph, reachability, license policy, signed SBOM, fix advice, and advisory lineage |
| IaC and policy as code | Terraform, Kubernetes, CloudFormation | Finds unsafe infrastructure before deployment | Integrate | P1 · 03 | Major declarative formats, custom policy, exact evidence, and suppressed-risk governance |
| Container and registry security | Dockerfile policy pack | Connects source and dependencies to shipped artifacts | Integrate | P1 · 03 | Layer/package identity, image policy, registry admission, runtime context, and remediation |
| Attack-surface discovery | Nothing yet | Unknown internet-facing assets cannot be governed | Build Integrate | P2 · 04 | Owned asset graph with authorization, confidence, exposure, and change history |
| Authenticated DAST and API testing | ROE-gated scans with evidence and safe stop | Establishes deployed reachability from the outside | Integrate | P2 · 04 | ROE-gated scans, journeys, rate controls, API schemas, evidence, replay, and safe stop |
| Cross-layer attack graph | Nothing yet | Prioritizes chains that source-only or runtime-only products miss | Build | P2 · 04 | Source, dependency, deployment, endpoint, identity, and control edges carry provenance |
| Governed remediation | Full lifecycle, verification, and rollback | Shortens time to fix without silently mutating customer code | Build | P2 · 05 | Smallest-change proposal, human approval, branch isolation, replay, rollback, and audit |
| WAAP/WAF and DDoS feedback | Signed, audit-only partner ingest | Reduces exposure while durable remediation proceeds | Partner | P2 · 05 | Provider-neutral policy exchange, verified virtual patches, telemetry, expiry, and rollback |
| Policy, compliance, and campaigns | Nothing yet | Turns findings into an accountable security program | Build | P2 · 05 | Versioned policy, exceptions, SLAs, controls, evidence packs, trends, and executive views |
| Continuous truth revalidation | Nothing yet | Prevents stale findings and stale fixes from becoming accepted truth | Build | P2 · 05 | Source, dependency, deployment, and control drift automatically trigger bounded replay |
Permanent guardrails
These four hold at every stage above. They are deliberate constraints on what Assure will ship, not gaps waiting to be closed.
Assure may propose and verify changes, but never silently writes to a protected branch or production policy.
Static workflows remain non-executing. Any build or dynamic workflow requires a separate disposable sandbox and explicit authorization.
DAST and validity checks fail closed without ownership, allowlists, limits, stop controls, and immutable approval.
Assure partners with proven WAAP and DDoS providers until customer evidence justifies owning that infrastructure.
Market evidence
Official product material informed capability gaps. Delivery choices remain Q² Assure’s architectural judgment.
Competitor material reviewed 20 July 2026 and not hands-on benchmarked. Delivery state reviewed 20 August 2026 against package source. The roadmap is directional until separately staffed, costed, threat-modeled, and approved. The layer comparison sets this same material against what Assure can prove today.
Roadmap delivery state reviewed 20 August 2026 against package source · competitor material reviewed 20 July 2026
Where this leaves you
You have the whole register: what ships today, what does not, and the gate each stage has to pass. Three ways to check any of it.
67 rules, 554 findings, no repository code executions, the nine coverage entries, six reasons it is built differently, and what the demonstration does not show. Downloads as a PDF you can forward.
Open the one-pager Approved accounts onlyWalk the ladder on real findings. Sign-in is Google, and Assure admits only exact email addresses on the test-user allowlist — if yours is not on it, you will be turned away at the door rather than after it.
Check operator access 1:59 · open to anyoneEpisode 05 reads one finding and replays it against the bytes it cites, recorded from the product. The other six episodes and the complete film are on the same rail.
Open episode 05