CTEM and Live Enforcement
Continuous Threat Exposure Management and live, governed FortiGate/Cato/MISP enforcement for self-hosted Enterprise deployments.
Every published release alongside the roadmap items currently in progress.
Continuous Threat Exposure Management and live, governed FortiGate/Cato/MISP enforcement for self-hosted Enterprise deployments.
Trust Centre, Security Centre, Compliance Centre, Platform Status, Integration Catalogue, Release Centre, ROI Calculator and Customer Success Dashboard.
Customer onboarding health, plan assignment, feature controls and improved tenant operations.
Removes the SaaSControlService dependency from migration 339 and verifies normal Update Centre installation.
Prevents SaaS Control failures when migration 338 was skipped and corrects scheduler readiness file detection.
Tenant lifecycle controls, organisation invitations, quota visibility and customer control centre.
Provider hierarchy, organisation switcher, active tenant context and tenant-aware routes.
Morning Security Briefing, exposure trends, daily snapshots and guided workspace onboarding.
Adds the searchable documentation portal, corrected V2 roadmap, standalone changelog, refreshed exposure-management branding and expanded public navigation.
Unified exposure management, attack surface inventory, explainable scoring, validation, attack paths and governed agent actions.
Adds governed agent tasks, approval policies, playbooks, ticket workflows, rollback and post-action validation.
Adds exposure validation, knowledge graph relationships, attack-path prioritisation, control-effectiveness evidence, retesting and explainable risk-reduction calculations.
Adds governed Microsoft Defender, Rapid7, FortiGate and Cato connector foundations, connector health, synchronisation jobs, evidence ingestion and correlation, and approval-gated action requests.
Adds ASM dashboard, domain and certificate monitoring, discovery evidence and exposure lifecycle timeline.
Introduces the CTEM Command Centre, explainable Exposure Score, unified asset and exposure records, AI recommendations, connector and ticket abstractions, and approval-led agent tasks.
Adds board-ready vector PDFs, branded dashboards, charts, risk gauges, AI-assisted threat storytelling, scheduled delivery and digital integrity.
Adds one-click customer provisioning, path-based tenant portals, guided onboarding, trial assignment and welcome-email tracking.
Corrected scheduled briefing state handling and separated test deliveries from production delivery status.
Introduced Brand Protection, stored report artefacts, clean URLs and expanded automated testing.
Adds a public product roadmap, customer feature voting, changelog, known-issues transparency and launch-focused release controls.
Production public website, searchable documentation portal, V2 roadmap, public changelog and navigation refresh.
Automated domain, subdomain, certificate and external service discovery with ownership and change monitoring.
Microsoft Defender, Rapid7, FortiGate and ITSM connectors using common health, permission and audit controls.
OIDC-based single sign-on for self-hosted deployments.
Specialist CTEM, threat intelligence, vulnerability and reporting agents grounded in platform evidence.
Approval-gated ticketing, firewall, Defender and scan actions with dry-run, rollback and validation.
AI-assisted daily briefings, cyber news, customer relevance and source-attributed publishing workflows.
Long-term vision for policy-governed autonomous exposure reduction across connected security controls.
For customers who want a self-hosted instance for their most sensitive site or workload, and a Cloud instance for everything else — one login story, two deployments. The self-hosted side would optionally forward summarised, non-sensitive data (exposure counts, not raw asset hostnames or IOC detail) to a Cloud dashboard for cross-site reporting, while all live enforcement (FortiGate, Cato, MISP) stays local. This is an early idea, not committed work — vote if it would matter to you.