Shipped, and
what's next.
Most vendors blur the line between what runs today and what's coming. We won't. Here's what's live in the product right now, and what's still on the roadmap — labeled plainly, so you never have to guess which is which.
Live in the product today.
Everything below runs on the real container path now. Each one is something you can use this week — and, where it produces evidence, re-verify yourself.
No-route sandbox SHIPPED
Every run executes in its own Docker container on an internal-only network with no route to the internet. The agent physically can't open an outbound connection — the only thing it can reach is the broker.
Sole-egress BYOK broker & vault SHIPPED
Your provider keys live encrypted in a per-tenant vault and never enter the container. One broker holds them, injects at call time, and is the only path out — policy-checked for known model and budget on every call.
Host kill-switch & budget caps SHIPPED
A host-authoritative watchdog outside the sandbox SIGKILLs a run on demand, on a budget breach, or on lost heartbeat. Per-run and per-tenant cost caps stop spend cold — an escaped agent can't stop the thing that kills it.
Ed25519-signed, offline-verifiable audit SHIPPED
Every prompt, tool call, output, routing decision, and kill is Ed25519-signed and hash-chained. Export the run and re-verify every event offline with the standalone verifier. Move one byte and verification fails.
Multi-agent collaboration SHIPPED
Run multiple agents together on a task, with every hand-off and message captured into the same signed chain. The collaboration is governed by the same sandbox, broker, and caps as a single run.
Team RBAC & org hard-stop SHIPPED · TEAM
Owner, reviewer, and viewer roles with separation of duties on destructive actions, one org-wide actor-stamped signed chain, and an organization budget hard-stop. Seat caps of Solo 1, Team 5, Business 20.
800-171 / CMMC mapping & OSCAL export SHIPPED · BUSINESS
The signed runtime evidence maps to NIST 800-171 and CMMC controls and exports as re-verifiable OSCAL / eMASS. CMMC is self-assessed; the export checks offline, so an assessor can verify the evidence themselves.
On the roadmap, not shipped.
These are not in the product today. We list them so you can plan around what's real now — and hold us to what we've said is coming.
SOC 2 Type II
A SOC 2 Type II attestation is targeted for Q3 2026 — not in hand today. Until the audit completes and a report exists, we won't claim it. Our current posture is CMMC self-assessed and the offline-verifiable audit chain.
TARGETED · Q3 2026SSO / SAML
Single sign-on with SAML is on the roadmap for organizations that need it, but it is not available yet. Today, access is managed through accounts and Team role-based access control.
PLANNED · NOT YETPer-tenant policy editor
A self-serve editor to author and tune per-tenant policies is planned but not shipped. The current policy checks — known model, budget caps, kill-switch — are enforced at the broker today; custom authoring comes later.
PLANNED · NOT YETDeeper integrations
Tighter hooks into CI, ticketing, and downstream GRC tooling are on the roadmap. Today the signed export is portable and re-verifiable on its own; the connectors that automate where it lands are still to come.
PLANNED · NOT YETWe tell you what’s real. If it runs today, it’s on the shipped list and you can re-verify it yourself. If it’s coming, it’s labeled planned — never dressed up as live. Honesty is the feature.
Use what's
real today.
Everything on the shipped list runs now. Start a sandboxed agent, export the signed proof, and re-verify it offline. Solo $29 · Team $544 · Business $1,779.