Roadmap & Release Centre
Track the transition from the V2 CTEM foundation to attack surface, integrations, AI agents and controlled remediation.
Continuous Threat Exposure Management
Asset inventory, explainable exposure scoring, and threat-intelligence correlation against your own assets.
Live Governed Enforcement (FortiGate/Cato/MISP)
Real, approval-gated writes to FortiGate, Cato and MISP — not simulated. Self-hosted only.
NA1 Platform V2.0 — CTEM Foundation
Unified findings, explainable Exposure Score, assets, domains, certificates, attack paths, agent actions and the security timeline.
V2.0.1 — Commercial Experience
Production public website, searchable documentation portal, V2 roadmap, public changelog and navigation refresh.
V2.1 — External Attack Surface Management
Automated domain, subdomain, certificate and external service discovery with ownership and change monitoring.
V2.2 — Integration Hub
Microsoft Defender, Rapid7, FortiGate and ITSM connectors using common health, permission and audit controls.
SSO / Entra ID for Enterprise
OIDC-based single sign-on for self-hosted deployments.
V2.3 — AI Agents & Investigation
Specialist CTEM, threat intelligence, vulnerability and reporting agents grounded in platform evidence.
V2.4 — Controlled Remediation
Approval-gated ticketing, firewall, Defender and scan actions with dry-run, rollback and validation.
V2.5 — Security Newsroom
AI-assisted daily briefings, cyber news, customer relevance and source-attributed publishing workflows.
V3 — Autonomous Exposure Operations
Long-term vision for policy-governed autonomous exposure reduction across connected security controls.
Hybrid Cloud + Enterprise Bridge
For customers who want a self-hosted instance for their most sensitive site or workload, and a Cloud instance for everything else — one login story, two deployments. The self-hosted side would optionally forward summarised, non-sensitive data (exposure counts, not raw asset hostnames or IOC detail) to a Cloud dashboard for cross-site reporting, while all live enforcement (FortiGate, Cato, MISP) stays local. This is an early idea, not committed work — vote if it would matter to you.
V2 delivery principles
Operational, explainable and controlledScores, recommendations and reports must trace back to tenant-scoped evidence.
Potentially disruptive actions use approvals, scope limits, rollback and post-action validation.
Visible features must produce useful results rather than placeholder pages or inactive controls.