Identify & expand
ShippingContent identity from bytes, accepted interpretations, and recursive assets under explicit budgets.
Roadmap & maturity
PayloadGlass is moving from breadth to productisation. The local analysis engine, evidence graph, risk projections and supported transforms already ship. The next milestone is one coverage-aware, intended-use decision contract shared by the CLI, Guardian, Gateway, Cleanroom and future integrations.
One product spine
Content identity from bytes, accepted interpretations, and recursive assets under explicit budgets.
Observations with derivation, completeness and traceability — how strongly a thing is known, not just that it was seen.
What the content can do, normalised across carriers. A canonical contract with mapping identity and coverage — today bounded and diagnostic, not yet policy authority.
Who or what consumes it, with which privileges, how it arrived, and where it is going.
Whether an absence of findings means anything at all for this content.
One request-specific decision — allow, constrain, review, refuse or transform — over the content-intrinsic graph. The authoritative boundary is being built.
A safer derivative, the residual evidence, and what the transformation preserved or removed.
The same decision applied at the workbench, the CLI, the endpoint or the content boundary.
Current priorities
Product direction
Every surface runs the same engine through shared contracts. AI Context is a profile, Support Bundle Cleanroom is a solution, and email or SharePoint are connectors — not separate products. Maturity is stated per surface rather than averaged into a claim.
Local native analysis, investigation, reporting, querying, explanation and sanitisation — with machine output, batch and directory scanning, diagnostics and shell integration.
Runs the public binary release in CI over repository or build artifacts, emitting JSON, JSONL and SARIF from a single pass. Release and action provenance continue to harden.
The production engine compiled to WebAssembly, running in a local Worker and projected into real investigation areas. Your file's content is never uploaded.
Local monitored-folder and operator workflows with desktop and service surfaces, MCP integration, snapshot-bound acquisition, audit records and a transactional vault. Persisted automation authority and cross-platform polish are incomplete.
The planned customer-deployed control point, not a second analysis engine: a thin connector acquires content and custody context, SIS analyses it, an optional policy-approved verifier runs, and one Content Trust Decision allows, constrains, reviews, refuses or transforms. Connectors supply context; they never grow their own integrity semantics.
Reasoning across an estate over time: how equivalent effects rotate between carriers, versions, senders and campaigns while the underlying capability graph stays the same. Described generically — no product name is committed.
Deliberate boundaries