Where Oxvault is going next
We publish what we are building, what is shipped, and what we are still validating. No marketing dates - we move when it is ready and the design partners say so.
The Board
Shipped → Now → Next → Later
Every item below maps to a tier or a foundational engine improvement. Order can shift based on design-partner feedback and live attack data.
- ● MCP server scanning
150+ rules · 12 MCP CVEs reproduced · 93% precision
- ● Model + AIBOM scanning
Pickle disassembly · ONNX · Safetensors · Sigstore
- ● Remote + CI scanning
github: / hf: / npm targets · GitHub Action · SARIF
- ● Push to Console
oxvault login · push · agent
- ● Gateway runtime proxy
stdio + HTTP · policy engine · rug-pull detection (Pro)
- ● Console dashboard
Findings, overview & history · free, capped
- ● Platform ingest
Receives pushed scans · API keys · re-scan agent
- ● Audit log
Every tool call forwarded, blocked, or alerted
- ● Remote MCP server scanning
Hosted http/sse endpoints · tool-manifest & rug-pull checks
- ● Compliance & AIBOM reports
CycloneDX + model attestation · EU AI Act / NIST evidence
- ● Dashboard caps
Model B entitlement + quota enforcement
- ● RAG corpus scanning
Indirect prompt injection · embedding poisoning
- ● Trust Registry
Signed model + MCP allowlist · Enterprise moat
- ● SSO · SAML · SCIM
Okta · Azure AD · Google Workspace
- ● Air-gapped deploy
Self-hosted control plane · zero egress
- ● SOC 2 + BAA
Type II audit · regulated industries
Directional, not contractual. We ship when it's ready - not by the calendar.
Release Track
Versions, in order.
Each version is a single coherent capability. We do not ship feature-flagged half-builds.
- v0.3.3 MCP scanner
Source SAST · 12 MCP CVEs reproduced · 93% precision
- v0.4.0 AIBOM + model scanning
Pickle disassembly, ONNX integrity, Safetensors, Sigstore + OpenSSF Model Signing, Hugging Face resolver
- v0.5.0 Platform sync
oxvault push · agent · init · remote github: / npm / hf: targets · self-update
- v0.6.0 Authenticated login
oxvault login · API-key auth to the Console and Platform
- v0.7.0 Remote subpath scans
github:owner/repo/subpath sparse fetch · scan any repo path without a full clone
- Live Gateway + Console (Beta)
Runtime proxy (Pro) and the free hosted dashboard are running now, not staged for later
- Next Protect-led: gateway, compliance, remote MCP
Gateway as the daily-driver · compliance & AIBOM reports (EU AI Act / NIST) · remote MCP server scanning (hosted http/sse endpoints)
- Later RAG + Trust Registry + Enterprise
RAG corpus scanning · signed model + MCP allowlist · SSO / RBAC · air-gapped deploy · SOC 2 Type II
Principles
The rails this roadmap rides on
If a feature breaks one of these, it does not ship - no matter how loud the demand.
Local-first stays sacred
Every shipped feature must run locally with zero telemetry. Cloud is opt-in, never required.
OSS core, paid runtime
The scanner is free forever. We monetize runtime protection, team workflows, and compliance - never the detections.
Same engine, three artifacts
MCP servers, ML models, and RAG corpora reuse the same deterministic detection engine. New artifacts land as modules, not forks.
Validated before built
New product surface ships only after design partners sign on. We follow demand - we do not invent it.
Want a feature on this list faster?
Design partners get a direct line to the roadmap. Run the Beta gateway, shape the policy DSL, and lock in Beta pricing while it is still forming.