Capability roadmap · evidence-led, gate-driven

Build the assurance layer. Integrate the security stack.

The goal is not to copy every scanner. It is to give you one control plane that proves which findings are real, connects source to runtime, and governs remediation across selected analysis and defense engines.

Delivery strategy

Build

Own the trust core

Evidence identity, replay, validator lineage, policy, decisions, attack graphs, tenancy, and audit remain proprietary differentiators.

Integrate

Earn breadth faster

Use isolated adapters for proven SAST, SCA, secret, IaC, container, and DAST engines while normalizing every result into Assure evidence.

Partner

Connect live defense

Integrate established WAAP, WAF, API, bot, and DDoS providers before considering capital-intensive edge infrastructure.

Product objectives

Decision quality and accountable delivery.

Success means you can move from authorized source to a defensible fix with controlled noise, replayable proof, and complete accountability across every security layer.

01

Evidence integrity

Every material claim is source-bound, replayable, independently validated, uncertainty-aware, and attributable.

Measure

Evidence completeness, replay pass rate, escaped false positives, and human overturn rate.

02

Coverage expansion

Code, dependencies, infrastructure, containers, deployed exposure, and runtime controls resolve into one evidence graph.

Measure

Supported ecosystems, correlated findings, reachable-risk precision, and coverage transparency.

03

Operational responsiveness

Assure proposes the smallest safe change, verifies it against immutable evidence, and preserves human approval.

Measure

Time to decision, time to verified fix, reopen rate, and remediation acceptance rate.

Six gated stages · sequence, not calendar promise

No stage advances on narrative confidence.

Each stage ships only after its exit gate passes. Staffing, customer discovery, legal, and threat modeling determine dates; the dependency order below should remain stable.

00
Priority 0 · foundation · identity and tenancy live

Commercial trust boundary

Keep the current product build safe to operate for separate organizations before expanding scanner breadth.

  • Build Hosted Google OIDC and per-tenant isolation are live today. SAML, MFA enforcement, SCIM, RBAC, and service accounts are not.
  • Build Encrypted source custody, customer keys, retention, deletion, backup, and restore controls
  • Build Isolated Linux runner fleet, signed workloads, egress policy, quotas, and kill controls
  • Build Durable queues, idempotency, observability, SLOs, incident controls, and disaster recovery
Exit gate Independent tenant-isolation and runner-escape reviews pass; restore, failover, deletion, and audit-integrity drills meet published objectives.
01
Priority 0 · workflow · check-run projection live

Developer delivery plane

Meet teams where code changes happen and make evidence review part of normal delivery.

  • Integrate GitHub, GitLab, Bitbucket, Azure Repos, webhooks, scheduled scans, and monorepo ownership
  • Build Pull-request checks are live as a coverage-honest check-run projection against a fixture harness. Differential scans, policy gates, baselines, and merge governance are not, and neither is a live GitHub App install.
  • Integrate VS Code/JetBrains, Jira, ServiceNow, Slack/Teams, SIEM, and webhook APIs
  • Build SARIF, CycloneDX, SPDX, and vendor-result ingestion with preserved external provenance
Exit gate Every connector is least-privilege, revocable, replay-safe, and covered by contract, fault-injection, and end-to-end tests.
02
Priority 1 · source breadth · semantic engines live

Multi-language SAST and secret prevention

Close the largest source-analysis gap without diluting Assure’s evidence standard.

  • Build Versioned rule SDK, parser/dataflow contracts, evidence adapters, custom rules, and rule-quality telemetry
  • Integrate Python, Go, Java, and C#/.NET semantic engines are live — a within-module call graph with taint-to-sink propagation, tiered by proof strength. C/C++, Ruby, PHP, Kotlin, Swift, and Rust are not.
  • Build Business-logic, authorization, custody, signing, and financial-flow rules where generic SAST is weakest
  • Integrate Provider patterns are live in every scan. Secret history scanning and pre-receive CI prevention are implemented but not yet exposed as product surfaces, and explicitly authorized validity checks are not implemented at all.
Exit gate Per-language public corpora, private holdouts, challenge cases, citation replay, and regression budgets pass with coverage disclosed by framework.
03
Priority 1 · code to cloud · advisory matching live

Supply chain, infrastructure, and containers

Correlate first-party findings with the components and deployment definitions that make them reachable.

  • Integrate Sealed offline advisory matching across npm, PyPI, Maven, and Go is live with real per-ecosystem range semantics, and licenses are classified on every component. Transitive graphs, malicious-package detection, live OSV/CVE/KEV/EPSS feeds, and fix versions are not; reachability marking is implemented but not enabled in a scan.
  • Build CycloneDX/SPDX SBOM inventory, policy, exceptions, provenance, and evidence-preserving advisory updates
  • Integrate Terraform, Kubernetes, CloudFormation, and Dockerfile analysis is live — 31 policy-pack rules including three cross-resource correlations. Helm and general policy-as-code are not.
  • Integrate OCI image, registry, base-image, package, secret, malware, admission, and runtime-context analysis
Exit gate Assure proves dependency and image identity, advisory version, reachability rationale, fix path, and policy decision without executing target source.
04
Priority 2 · deployed truth · ROE safety controls live

Attack surface and authorized DAST

Test what an outside actor can actually reach, under explicit rules of engagement.

  • Build Asset inventory, ownership, DNS/TLS/API discovery, shadow-service review, and authorization records
  • Integrate Proven browser, HTTP, API-schema, and DAST engines in disposable network-isolated runners
  • Build Safe rate limits, test-data controls, evidence capture, and stop conditions are live and fail closed. The authenticated journey recorder is not.
  • Build Source-to-endpoint correlation and cross-layer attack paths with explicit uncertainty
Exit gate No active test starts without owner, target allowlist, scope, window, rate, data policy, emergency stop, and immutable authorization evidence.
05
Priority 2 · closed loop · proposal lifecycle live

Governed remediation and runtime defense

Turn evidence into a verified correction while connecting to defenses that reduce exposure immediately.

  • Build Minimal patch proposals, preview, independent sandboxed verification, named approval, rollback, and post-change replay are live under a revocable rules-of-engagement record. Branch-only pull requests are not — no path in the product writes to a repository at all.
  • Build Campaigns, SLAs, risk acceptance, compliance evidence, executive reporting, and control-effectiveness metrics
  • Partner A signed, idempotent, audited runtime-partner ingest contract is live; it accepts events for audit only and performs no enforcement. WAAP/WAF, API, bot, DDoS, CSPM, EDR, SIEM, and ticketing control integrations are not implemented.
  • Build Verified virtual-patch exchange, source/runtime feedback, control drift, and continuous truth revalidation
  • Build Nice to have · Mosca migration urgency. For each post-quantum migration candidate, capture the data-protection lifetime (x), estimated migration time (y), and planning horizon to a cryptographically relevant quantum computer (z). Flag the candidate when x + y > z, show the inputs and uncertainty, and use the result as a prioritization aid—not as a prediction that a breach has occurred.
Exit gate No source or runtime policy changes without preview, bounded scope, named approver, reversible execution, independent verification, and complete audit history.

Capability register

Every material gap has an owner strategy and a finish line.

Priority reflects dependency order and differentiation, not a committed delivery date.

What “delivered today” records, and what it does not

A capability counts as delivered only where a product surface reaches it — the scan engine, an HTTP route, or a CLI command. Code that exists as a library with no caller outside its own package is not counted, which is why SBOM emission, sealed-inventory CVE matching, the deny-by-default registry-pull gate, secret history scanning, and CI prevention policy appear as gaps rather than as deliveries. Nothing in this column means a row is finished: every definition of done is still open.

Fourteen capabilities, what exists today, why each matters, its delivery strategy, its stage, and its definition of done
Capability Delivered today Why it matters Strategy Stage Definition of done
Commercial identity and tenancy Google OIDC and tenant isolation Required before customer data can safely share a control plane Build P0 · 00 SSO/SCIM/RBAC and tenant isolation survive independent adversarial testing
Repository and delivery connectors Fixture-harness GitHub check-run only Removes manual intake and makes scanning continuous Integrate P0 · 01 Least-privilege, revocable connectors with differential scans and durable provenance
Multi-language SAST Python, Go, Java, C# Closes the largest source-coverage disadvantage Integrate Build P1 · 02 Published language/framework matrix, holdout evaluation, exact citations, and replay
Secret prevention Provider patterns in-scan; history and CI policy unexposed Stops credential material before it becomes repository history Integrate P1 · 02 History, custom patterns, push prevention, governed bypass, and optional validity checks
SCA, licenses, and SBOM Sealed advisory matching and license policy Most application risk includes third-party components Integrate Build P1 · 03 Transitive graph, reachability, license policy, signed SBOM, fix advice, and advisory lineage
IaC and policy as code Terraform, Kubernetes, CloudFormation Finds unsafe infrastructure before deployment Integrate P1 · 03 Major declarative formats, custom policy, exact evidence, and suppressed-risk governance
Container and registry security Dockerfile policy pack Connects source and dependencies to shipped artifacts Integrate P1 · 03 Layer/package identity, image policy, registry admission, runtime context, and remediation
Attack-surface discovery Nothing yet Unknown internet-facing assets cannot be governed Build Integrate P2 · 04 Owned asset graph with authorization, confidence, exposure, and change history
Authenticated DAST and API testing ROE-gated scans with evidence and safe stop Establishes deployed reachability from the outside Integrate P2 · 04 ROE-gated scans, journeys, rate controls, API schemas, evidence, replay, and safe stop
Cross-layer attack graph Nothing yet Prioritizes chains that source-only or runtime-only products miss Build P2 · 04 Source, dependency, deployment, endpoint, identity, and control edges carry provenance
Governed remediation Full lifecycle, verification, and rollback Shortens time to fix without silently mutating customer code Build P2 · 05 Smallest-change proposal, human approval, branch isolation, replay, rollback, and audit
WAAP/WAF and DDoS feedback Signed, audit-only partner ingest Reduces exposure while durable remediation proceeds Partner P2 · 05 Provider-neutral policy exchange, verified virtual patches, telemetry, expiry, and rollback
Policy, compliance, and campaigns Nothing yet Turns findings into an accountable security program Build P2 · 05 Versioned policy, exceptions, SLAs, controls, evidence packs, trends, and executive views
Continuous truth revalidation Nothing yet Prevents stale findings and stale fixes from becoming accepted truth Build P2 · 05 Source, dependency, deployment, and control drift automatically trigger bounded replay

Permanent guardrails

Capabilities we will not fake to move faster.

These four hold at every stage above. They are deliberate constraints on what Assure will ship, not gaps waiting to be closed.

No ungoverned auto-fix

Assure may propose and verify changes, but never silently writes to a protected branch or production policy.

No arbitrary source execution

Static workflows remain non-executing. Any build or dynamic workflow requires a separate disposable sandbox and explicit authorization.

No active test without ROE

DAST and validity checks fail closed without ownership, allowlists, limits, stop controls, and immutable approval.

No invented edge network

Assure partners with proven WAAP and DDoS providers until customer evidence justifies owning that infrastructure.

Market evidence

Roadmap inputs, not copied slogans.

Official product material informed capability gaps. Delivery choices remain Q² Assure’s architectural judgment.

Competitor material reviewed 20 July 2026 and not hands-on benchmarked. Delivery state reviewed 20 August 2026 against package source. The roadmap is directional until separately staffed, costed, threat-modeled, and approved. The layer comparison sets this same material against what Assure can prove today.

Roadmap delivery state reviewed 20 August 2026 against package source · competitor material reviewed 20 July 2026