Roadmap & maturity

Turn the evidence engine into deployable decision products.

PayloadGlass is moving from breadth to productisation. The local analysis engine, evidence graph, risk projections and supported transforms already ship. The next milestone is one coverage-aware, intended-use decision contract shared by the CLI, Guardian, Gateway, Cleanroom and future integrations.

Decide, transform, and prove how untrusted content may be used. “Prove” means inspectable evidence, coverage, policy identity, transformation records and explicit limits — never a guarantee that content is universally safe.

One product spine

The maturity boundary is explicit.

01

Identify & expand

Shipping

Content identity from bytes, accepted interpretations, and recursive assets under explicit budgets.

02

Evidence & authority

Hardening

Observations with derivation, completeness and traceability — how strongly a thing is known, not just that it was seen.

03

Capabilities & effects

Partial

What the content can do, normalised across carriers. A canonical contract with mapping identity and coverage — today bounded and diagnostic, not yet policy authority.

04

Context & exposure

Roadmap

Who or what consumes it, with which privileges, how it arrived, and where it is going.

05

Coverage & support truth

Hardening

Whether an absence of findings means anything at all for this content.

06

Content Trust Decision

Roadmap

One request-specific decision — allow, constrain, review, refuse or transform — over the content-intrinsic graph. The authoritative boundary is being built.

07

Transform & verify

Partial

A safer derivative, the residual evidence, and what the transformation preserved or removed.

08

Control points

Partial

The same decision applied at the workbench, the CLI, the endpoint or the content boundary.

Current priorities

The order this gets built in.

  1. Typed evidence and real snapshot persistence Finish the authority-bearing denominator and per-scan observation completeness, so an absence of findings is only licensed when it has actually been earned.
  2. Capability/effect graph on the production path Move the carrier-independent graph from bounded and diagnostic onto the real path, preserving mapping identity, attribution and coverage.
  3. Converge custody, occurrence, representations and lineage Four distinct questions that were historically flattened into one word.
  4. The Content Trust Request / Decision boundary Consumer, action, destination and exposure belong in a request-specific basis over the content-intrinsic graph — not baked into the content's own record.
  5. Provider-neutral integrity contracts Then the first structured-credential profile. External schemes are integrated as evidence through versioned mappings; they never become the internal model.
  6. The integrity and authenticity decision plane External trust, disclosure, watermark assessment, expected-but-missing assertions and contradiction — typed and coverage-qualified throughout.
  7. Converge the product projections CLI, Workbench, Guardian and MCP over the same contracts, with certified support published rather than asserted.
  8. Cross-format and alternate-view equivalence What a human sees, what a parser extracts and what a runtime executes are distinct until evidence establishes otherwise.
  9. Apply the decision contract to agent, RAG and MCP profiles The same decision, asked by different consumers.
  10. Gateway as the enterprise control point Resolution, compliance and revocation at the content boundary — then transformation with verify-rescan and a canonical attestation.

Product direction

Surfaces, and how far each one actually is.

Every surface runs the same engine through shared contracts. AI Context is a profile, Support Bundle Cleanroom is a solution, and email or SharePoint are connectors — not separate products. Maturity is stated per surface rather than averaged into a claim.

sis CLI

Shipping

Local native analysis, investigation, reporting, querying, explanation and sanitisation — with machine output, batch and directory scanning, diagnostics and shell integration.

GitHub Action

Hardening

Runs the public binary release in CI over repository or build artifacts, emitting JSON, JSONL and SARIF from a single pass. Release and action provenance continue to harden.

Browser Investigation Workbench

Hardening

The production engine compiled to WebAssembly, running in a local Worker and projected into real investigation areas. Your file's content is never uploaded.

Guardian

Partial

Local monitored-folder and operator workflows with desktop and service surfaces, MCP integration, snapshot-bound acquisition, audit records and a transactional vault. Persisted automation authority and cross-platform polish are incomplete.

Gateway — target enterprise control point

Roadmap

The planned customer-deployed control point, not a second analysis engine: a thin connector acquires content and custody context, SIS analyses it, an optional policy-approved verifier runs, and one Content Trust Decision allows, constrains, reviews, refuses or transforms. Connectors supply context; they never grow their own integrity semantics.

Occurrence & campaign intelligence

Speculative

Reasoning across an estate over time: how equivalent effects rotate between carriers, versions, senders and campaigns while the underlying capability graph stays the same. Described generically — no product name is committed.

Deliberate boundaries

What PayloadGlass is not becoming.

Not a universal CDR Not antivirus or EDR Not a DLP replacement Not an email-security replacement Not a runtime LLM firewall Not a hosted public scanner Not a full SharePoint security suite Not enterprise case management