Roadmap · proof stated

What we shipped, what we are finishing, what comes next.

A roadmap is a set of promises, so we label ours. Every item on this page says whether it is shipped, being finished, or planned, and the bottom of the page spells out what each of those words means — so you can hold us to them. A capability described in prose does not count as done.

Shipped · 2026

The decision layer exists.

  • Source-agnostic ingestion — open-source stacks (Wazuh, OpenSearch, Elastic / ELK, ClickHouse), market platforms (Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne, Cortex XDR, Fortinet, Okta, Entra ID, AWS, Azure…), 23 vendor connectors, push webhooks, passive tailing of the SIEM you already run, and custom connectors on request. shipped
  • The Correlation Engine — nine independent strategies look at every alert from different angles and vote on one verdict; recognised attack storylines make a case read as a story; every case keeps a readable decision trace of which signals mattered and what would have changed the outcome. shipped
  • Burst absorption — hundreds of low-severity repeats become one appropriately rated case, and nothing is lost if a component restarts. shipped
  • SIROC, the AI analyst — lists its hypotheses and evidence before its verdict; its cited evidence is checked against the case's own alerts, and an unsupported verdict is downgraded in front of the analyst. Spend caps and circuit breakers keep it inside a budget you set. shipped
  • Sovereignty as a switch you own — a local open-licence model on CPU by default; your own cloud key per task, with admin approval; secrets and personal data redacted before any cloud call; every cloud-bound call recorded in a tamper-proof ledger. shipped
  • The Decision Center — a queue that says what to do next (awaiting triage, SLA at risk, high risk, unassigned critical), SLA clocks, capacity-based auto-assignment, and reports where every number carries the evidence behind it. shipped
  • Three editions, six add-ons — Free, Client and MSSP, quoted per deployment with no per-GB, per-endpoint or per-tenant meter. The MSSP edition keeps one case space per client, enforced at several independent layers, and white-labels. shipped
  • Response under human command — playbooks that pause for approval and resume where they stopped, branching on the answer; remote response agents that keep vendor credentials on your own hosts. Destructive actions always need a person. shipped
  • Vulnerability Operations Centre — findings from several scanners corroborated, a remediation lifecycle with due dates, a risk-acceptance register that expires, and a committee-ready report. shipped
  • Trust you can verify — SSO and MFA, role-based access, a tamper-evident audit trail, secrets encrypted at rest, a software bill of materials, and signed updates that roll back on a failed health check. shipped
  • The engineering feedback loop — when an analyst closes a false positive and says why, that reason lands in a visible engineering backlog, so detection quality improves instead of quietly decaying. shipped
Now

Getting the first estates onto the platform.

  • One-box install on Debian or Ubuntu, Docker or bare metal, with a runbook written from a real installation rather than from a plan. in progress
  • Detection content inside the product — 72 MITRE-mapped detection packs, importable and deployable from a screen. shipped
  • Sharing indicators with peer platforms under traffic-light markings, so an MSSP can contribute to a community without leaking a client. The on-screen marking control is being finished. in progress
  • First vulnerability sweeps run end to end against live scanner sources rather than lab data. in progress
  • A polish pass across every analyst screen, in light and dark. in progress
  • Design-partner programme — the first pilots on real estates, starting with a thirty-minute session on your own telemetry. pilots
Next

Resale, bounded autonomy, and the buyer's view of the trace.

  • MSSP resale — per-client usage views and billing building blocks, so you can package and resell on your own terms. platform
  • Bounded autonomy in response — act inside a policy you set, verify the effect, and roll back automatically when verification fails. Destructive actions still need a person. platform
  • “Why this case” — the decision trace presented for buyers and auditors, not only for the analyst in the queue: the signals, the verdict, and what would have changed it. platform
  • More vulnerability sources — Microsoft Defender and CrowdStrike vulnerability data, so the VOC corroborates across the tools you already own. integrations
  • Self-service GDPR access and erasure, so a data-subject request is a click rather than a project. compliance
  • Case fields you define — capture what your clients or your regulator ask for without waiting for a release. platform
Later

Proof that can be reproduced by someone who is not us.

  • A published triage benchmark that a third party can reproduce — because no credible one exists in this market yet.
  • Outcome metrics published with their denominators, so a number means what it says.
  • Ticketing push into ServiceNow Vulnerability Response.
  • Work toward CE marking under the Cyber Resilience Act, whose deadline is 11 December 2027 — a target, not a claim.
  • A CSPN / SecNumCloud readiness assessment — an assessment, not a claim of qualification.
Deliberately not on the roadmap

What we will not build, and why.

  • A native NDR, EDR or first-party threat-intel feed. Sensors and feeds are what you already own. We are the decision layer above them, and we consume intel from the people who produce it.
  • A vulnerability scanner. Seculogik corroborates scanner findings and decides what to do about them; it does not scan.
  • A SOC without people. Destructive actions such as isolating a host or resetting credentials always need a person, and that floor cannot be lowered by configuration.
  • Software that updates itself. A security product must not change its own code on a signal. Updates are signed, approved by your admin, and roll back on a failed health check.
  • Filing NIS2 or DORA notifications with an authority on your behalf. We produce the evidence and the reports on the regulator's clock; the legal act stays yours.
  • A no-code canvas that draws more than it can run. Every playbook we offer can pause for a person and resume where it stopped. We will not ship a picture of a workflow.
  • A per-GB meter. Your log volume will never drive your bill.
How to read our claims

Three words, three levels of proof.

shipped
Built, and protected by automated checks that fail if the behaviour is ever removed.
live-verified
Observed on a running build against real data stores, not a mock.
in production
Running on a box in service. Only this level counts as “in production”.

Some capabilities on this site are shipped and live-verified in our lab rather than in production at a customer. Ask us which, and we will tell you.

Ask us which