Skip to main content

Roadmap

High-level product roadmap for ThreatWeaver across three time horizons.

Timeline Overview​

Legend: Active items are highlighted. Sections are color-coded by module.


Short Term (Current Quarter)​

Focus: ship and stabilize existing features, improve detection accuracy, close compliance gaps.

InitiativeModuleDescription
AppSec Scanner AccuracyAppSecContinue reducing false positives through heuristic tuning (H1-H16 rules) and AI validation. Target: 95%+ true positive rate across all OWASP categories.
CI/CD DAST IntegrationAppSecShip appsecCiScan API (3 endpoints already built) to enable triggering scans from CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins).
Compliance Report ExportExposure MgmtPDF/CSV compliance reports mapped to PCI-DSS, SOC 2, ISO 27001, and OWASP frameworks. Scheduled and on-demand generation.
Cloud Security MVPCloud SecurityComplete the CSPM integration for AWS, Azure, and GCP. Ship container vulnerability scanning and CIS benchmark scoring.
Identity Security MVPIdentityShip Active Directory and Entra ID connectors. Deliver attack path analysis for Kerberoasting, DCSync, and Golden Ticket scenarios.
AI Security ModuleAI SecurityAI model inventory, risk classification, and governance policy engine for organizations deploying LLMs.

Medium Term (Next 2 Quarters)​

Focus: expand detection capabilities, add new scanning modalities, and deepen integrations.

InitiativeModuleDescription
SAST IntegrationAppSecAdd static analysis capabilities to complement DAST scanning. Correlate SAST findings with DAST runtime evidence for higher confidence.
EASM (External Attack Surface Management)Exposure MgmtAutomated discovery of internet-facing assets, subdomains, exposed services, and shadow IT.
Infrastructure PentestingAppSecExtend scanner agents to test network services, SSH, FTP, SMB, and database ports beyond web applications.
SBOM and Supply ChainExposure MgmtSoftware Bill of Materials tracking with drift detection, dependency vulnerability correlation, and license compliance.
Advanced ReportingPlatformCustomizable report templates, scheduled report delivery, executive dashboards with trend comparison.
Okta and Google Workspace ConnectorsIdentityExpand identity source coverage beyond Active Directory and Entra ID.

Long Term (6-12 Months)​

Focus: market positioning, partner ecosystem, and next-generation capabilities.

InitiativeModuleDescription
Gartner MQ ListingBusinessPosition ThreatWeaver in the Gartner Magic Quadrant for Vulnerability Risk Management and Application Security Testing.
MSP Partner ProgramBusinessMulti-tier partner program for Managed Security Service Providers with white-label options, usage-based billing, and partner portal.
Mobile Application PentestingAppSecExtend scanner agents to test iOS and Android applications, including API backend testing and mobile-specific vulnerability classes.
Autonomous RemediationAI LabsAI-driven auto-fix for common vulnerability patterns (misconfigured headers, missing security controls, outdated dependencies).
Threat Intelligence FeedsExposure MgmtIngest and correlate with third-party threat intel feeds (MITRE ATT&CK, AlienVault OTX, GreyNoise) for contextual risk enrichment.
SOC IntegrationPlatformBi-directional integration with SIEM/SOAR platforms (Splunk, Sentinel, Phantom) for automated incident response workflows.

Completed Milestones​

MilestoneDateOutcome
Multi-tenant architectureMar 2026Schema-per-tenant isolation, RBAC v2, module gating
59-agent scanner pipelineApr 2026Full 6-phase pipeline with AI validation and chain replay
Distributed scan sensorsMar 2026Docker agents for private network scanning via WebSocket tunnels
AI Labs moduleMar 2026Fix planner, ticket writer, executive summary, root cause analyzer
VFP Fix PlannerMar 2026Work package grouping, team assignment, SLA policies, ticket integration
WeaverScore algorithmMar 2026Composite risk scoring with CVSS + EPSS + asset criticality