Product roadmap

Building toward enterprise
posture management.

See what has been developed for soft launch, what is in alpha testing and where QFinch is headed next. Planned capabilities are not current deliverables; delivery dates have not been committed.

Phase 01 · Soft launch

Developed for early access.

Evaluate the current platform through selective early access. QFinch remains in beta: assessment scope varies by project and supported inputs, and results require review.

Current release · Beta

SBOM

Package inventory, dependency relationships, vulnerability matches and license visibility.

SAST

Supported source-code assessments with finding locations, evidence and fix guidance.

IaC

Configuration assessments for supported infrastructure definitions and affected resources.

Secrets

Potential exposed credentials, redacted evidence and remediation review.

AIBOM

Supported AI component inventory and recorded relationships.

QFinch Assistant Alpha Testing

AI-assisted interpretation of findings, investigation and remediation planning within your workspace. Responses may be incomplete or incorrect; validate them against assessment evidence before acting.

Explore the Assistant →
Review supported scope and limitations →
Future phases · Planned

What comes next.

The following capabilities are roadmap priorities, not current early-access features.

Dynamic application testing · Planned

DAST for running applications

Extend assessment beyond software building blocks to supported, authorized running web applications and APIs.

  • Defined target and authentication scope
  • Endpoint coverage and dynamic finding evidence
  • Findings connected to application context
Governance foundation · Planned

Policy and accountable risk decisions

Extend assessment evidence into organization-wide governance.

  • Versioned policies and evaluation
  • Risk acceptance and expiring exceptions
  • SLA escalation and audit history
Workflow enforcement · Planned

Connect decisions to delivery

Bring policy decisions into supported development workflows.

  • External-tool finding imports
  • Ticket synchronization
  • CI/CD policy gates
Deeper evidence · Planned

Deployment and runtime context

Connect assessed artifacts to where and how they are deployed.

  • Artifact-to-deployment mapping
  • Verified exposure and usage evidence
  • Richer correlation and compliance evidence mapping
Early Access

Start with your application priorities.

30 days. Up to five projects. Complimentary expert assistance.

Register for Early Access