Skip to content

convisoappsec/roadmap

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

4 Commits
Β 
Β 

Repository files navigation

Conviso Platform Public Roadmap

Explore the Conviso Platform Public Product Roadmap πŸ§‘β€πŸš€

Our product roadmap provides insights into the features we are developing, their current stages, and our expected delivery timelines. Have any questions or feedback about the roadmap? Share your thoughts via the Conviso Platform support channel.

The roadmap repository is designed to communicate the strategic direction of Conviso Platform. While existing issues are currently read-only, we are actively engaging with customers to gather feedback and improve. Interaction limits are in place to ensure that all contributions are relevant and constructive. We are committed to refining the format of the roadmap and fostering more meaningful discussions about the future of our products and features. If you have feedback on how the issues are presented, please share it through our support channel in the Conviso Platform.

Guide to the Roadmap πŸ“‘

Every item on the roadmap is an issue, with a label that indicates each of the following:

  • A release phase that describes the next expected phase of the roadmap item. See below for a guide to release phases.

  • A feature area that indicates the area of the product to which the item belongs. For a list of current product areas, see below.

  • A feature that indicates the feature or product to which the item belongs. For a list of current features, see below.

Once a feature is delivered, the shipped label will be applied to the roadmap issue and the issue will be closed with a comment linking to the relevant Changelog post.

Release Phases 🚦

Release phases indicate the stages that the product or feature goes through, from early testing to general availability.

  • preview: Publicly available in full or limited capacity. Features mostly complete and documented. Timeline and requirements for GA usually published. No SLAs or support provided.

  • ga: Generally available to all customers. Ready for production use with associated SLA and technical support obligations. Approximately 1-2 quarters from Preview.

Some of our features may still be in the exploratory stages, and have no timeframe available. These are included in the roadmap only for early feedback. These are marked as follows:

  • in design: Feature or improvment in discovery phase. We have decided to build, but are still figuring out how.

  • exploring: Feature or improvment under consideration. We are considering building, and gathering feedback on it.

Roadmap Stages πŸ›£οΈ

The roadmap is arranged on a project board to give a sense for how far out each item is on the horizon. Every product or feature is added to a particular project board column according to the quarter in which it is expected to ship next. Be sure to read the disclaimer below since the roadmap is subject to change, especially further out on the timeline. You'll also find an Exploratory column, which is used in conjunction with the in design and exploring release phase labels for when no timeframe is yet available.

ASPM Focus Areas 🌎

The following is a list of our current product areas:

  • coverage: Comprehensive security testing across development and operational environments, including cloud platforms, containers, and physical infrastructure.
  • testing-orchestration: Integration and control of security tools throughout the application lifecycle based on organizational policies.
  • remediation: Integration with workflow tools and provision of specific guidance for fixing vulnerabilities.
  • correlation: Advanced correlation of vulnerability findings across tools and application components.
  • priorization-triage: Prioritization of vulnerabilities based on risk factors provided by users or inferred from the application.
  • root-cause-identification: Identification of the root cause of vulnerabilities by analyzing data from different application components.
  • risk-management: Overall risk indicators for components or applications.
  • inbuilt-testing-tools: Built-in testing capabilities and integration with existing security tools.
  • software-supply-chain-security: Features for creating software bills of materials (SBOMs), performing standardized control assessments (SCAs), and securing the development environment.
  • ux: Enhancements to the overall user experience.

Features πŸ—ΊοΈ

The following is a list of our current features and products, with distinct labels for filtering:

  • projects: Project management for security, including threat modeling, secure development training, pentests, and projects with predefined requirements. Each project includes steps, objectives, scope, dates, status, and technical reports.
  • vulnerabilities: Vulnerability listing with details such as origin, affected asset, severity, reproduction steps, root cause, evidence, suggested fix, technical references, CWE, and title.
  • security-feed: Security feed with real-time updates on new vulnerabilities, threats, and recommendations.
  • assets: Asset management for tracking and monitoring all application assets.
  • access-control: Access control for managing user permissions, access policies, and activity auditing.
  • dashboard: Dashboard with vulnerability metrics, dates, risk scores, MTTR, and other security KPIs.
  • company-files: Company file management for storing and sharing documents, policies, reports, and resources.
  • plans-usage: General settings for managing plan details, users, notifications, resolution policies, development pipeline lock factors, and API key.
  • security-expert: Direct chat with security experts for questions and security issue resolution.
  • requirements: Security requirement management for defining and tracking policies, controls, and compliance checks.

Disclaimer πŸ—£οΈ

Any statement in this repository that is not purely historical is considered a forward-looking statement. Forward-looking statements included in this repository are based on information available to Conviso as of the date they are made, and Conviso assumes no obligation to update any forward-looking statements. The forward-looking product roadmap does not represent a commitment, guarantee, obligation, or promise to deliver any product or feature, or to deliver any product and feature by any particular date, and is intended to outline the general development plans. Customers should not rely on this roadmap to make any purchasing decision.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published