Roadmap

public roadmap
living document

Where Driftlock is headed — three columns, no marketing cadence.

The roadmap is a status board, not a release announcement. The Now column lists what ships to every customer today, the Next column lists what is in build against a real cohort, and the Later column lists what is still scoped or in research. Items move left-to-right as work ships; per-row badges stay honest about where each one sits.

What "Now" means

In every customer deployment today — audited, signed, and replayable from a sandbox run id.

What "Next" means

Quarter or two out. The contract is settling against a real cohort, not invented in a deck.

What "Later" means

Six months out or further. Some are scoped, some are still research — both are honest about it.

Status board

Three columns, in order.

Each card carries one window of work. Per-row badges tell the reader what shape that work is in today — shipping, in build, planned, or research — so a single drift from its column does not silently desync the page.

Now

Now
5 items

Shipping to every customer today. Audited, signed, and replayable from a sandbox run id.

  • item

    Watcher inputs

    Four upstream signal surfaces — GitHub repos, CI pipelines, dependency feeds, and on-call alerts — fan into a single triage watcher that owns reachability, not just dependency matching.

    shipping
  • item

    Hermetic sandbox + byte-stable diff

    Per-run hermetic Nix/Bazel builds inside the customer VPC. The same trigger re-run yields the same patch, the same patch yields the same SBOM — verifiable by replaying the sandbox run id.

    shipping
  • item

    Cosign-signed commit (KMS-resident key)

    Cosign / Sigstore OIDC signature against the GitHub App identity. The private half never leaves the customer KMS — Enterprise swaps to HSM, same Rekor-logged claim payload.

    shipping
  • item

    CycloneDX SBOM on every dependency-touching PR

    CycloneDX 1.5 in JSON and XML, cosign-signed and landed in the customer artifact registry. Platform+ tier ships it on every PR; downstream tooling (deps.dev, Dependency-Track, Grype) reads it directly.

    shipping
  • item

    Seven-column audit trail (replayable by run id)

    Every audit-linked PR carries the same seven fields — trigger, triage, diff, sandbox result, approver chain, signature, SBOM hash — replayable from the sandbox run id without a Driftlock-managed control plane.

    shipping

Next

Next
4 items

Quarter or two out. Built against a real cohort; the contract is settling, not invented.

  • item

    Self-hosted Platform roll-out cohort

    First-cohort self-hosted Platform deployment inside a customer VPC. Limited seats; gated on Platform tier commit and a 10-day scoped trial against one real monorepo.

    in build
  • item

    Topology-aware shared test cache (GA)

    Per-package test cache, keyed off the topology graph the watcher already maintains. Cache hits skip the sandbox run when the affected package boundary and the diff hash are unchanged.

    in build
  • item

    Per-repo signing key + rotation (Platform tier)

    One cosign key per repository on Platform, rotating on the customer clock. Older signatures still verify against their Rekor entries after rotation — buyers months into a rotation cycle do not lose signed PRs.

    in build
  • item

    Signed SBOM on every PR — Team tier

    Promote the signed CycloneDX emission from a Platform+ per-repo add-on to a default on the Team tier. Same SBOM contract, same signed-document landing surface, every dependency-touching PR.

    in build

Later

Later
4 items

Six months out or further. Some are scoped, some are still research — both are honest about it.

  • item

    HSM-backed signing keys on Enterprise

    Swap the KMS-resident private key for an HSM-backed key on Enterprise, with a custom policy surface for the rotation cadence and approver gate. Same wire format — same Rekor-logged claim payload.

    planned
  • item

    SCIM + custom IdP federation

    SCIM provisioning for Okta / Entra ID / Google Workspace plus a custom IdP federation path for buyers whose identity stack sits behind a non-standard SAML/OIDC layer.

    planned
  • item

    Audit-locked retention tier lifts beyond 7y / 10y

    Extend the default 7-year hot + 10-year cold retention tiers for buyers whose audit cadence runs longer. Tier selection lives at the workspace level, signed and recorded onto the same audit-trail row.

    research
  • item

    Air-gapped deployment runbook (compliance pack)

    Documented deployment of Driftlock into an air-gapped VPC: artifact transfer path, KMS bootstrap, sandbox image registry mirror, and a regulator-replayable rollout runbook shipped under NDA.

    research

living document · last edited August 3, 2026

Stay close to the work

Pair the roadmap with the governance explainer and the changelog.

The roadmap names the windows; the governance page enumerates the seven columns a regulator replays; the changelog records the weekly update as work ships. Drop your buyer or platform-security email below and we'll send a note when the next cohort opens — same inbox that scoped your trial.

Now · Next · Later
per-row status
updated as work ships · not on a marketing cadence

Get the cohort update

Buyer or platform-security email only — one note per cohort opening, no follow-up sequence.