Product roadmap

Application security today.
Our direction for tomorrow.

Explore the capabilities available in early access, the QFinch Assistant alpha and our plans for deeper application security. Planned features are not yet available; timing will be shared as development progresses.

Available in Early Access

Your starting point with QFinch.

Start with connected assessments, shared visibility and remediation planning for up to five projects. QFinch is in beta; your onboarding review confirms the coverage for your stack.

Current release · Beta

SBOM

Package inventory, dependency relationships, vulnerability matches and license visibility.

SAST

Supported source-code assessments with finding locations, evidence and fix guidance.

IaC

Configuration assessments for supported infrastructure definitions and affected resources.

Secrets

Potential exposed credentials, redacted evidence and remediation review.

AIBOM

Supported AI component inventory and recorded relationships.

QFinch Assistant Alpha Testing

AI-assisted interpretation of findings, investigation and remediation planning within your workspace. Responses may be incomplete or incorrect; validate them against assessment evidence before acting.

Explore the Assistant →
Review supported scope and limitations →
Future phases · Planned

What comes next.

The following capabilities are roadmap priorities, not current early-access features.

Dynamic application testing · Planned

DAST for running applications

Extend assessment beyond software building blocks to supported, authorized running web applications and APIs.

  • Defined target and authentication scope
  • Endpoint coverage and dynamic finding evidence
  • Findings connected to application context
Governance foundation · Planned

Policy and accountable risk decisions

Extend assessment evidence into organization-wide governance.

  • Versioned policies and evaluation
  • Risk acceptance and expiring exceptions
  • SLA escalation and audit history
Workflow enforcement · Planned

Connect decisions to delivery

Bring policy decisions into supported development workflows.

  • External-tool finding imports
  • Ticket synchronization
  • CI/CD policy gates
Deeper evidence · Planned

Deployment and runtime context

Connect assessed artifacts to where and how they are deployed.

  • Artifact-to-deployment mapping
  • Verified exposure and usage evidence
  • Richer correlation and compliance evidence mapping
Early Access

Start with your application priorities.

30 days. Up to five projects. Complimentary expert assistance.

Register for Early Access