Roadmap

What we're building and when

Shipped capabilities, active work, compliance milestones, and the longer institutional roadmap. Updated as things land.

Shipped Live
Platform
Governed memory with admission-time policy enforcement
Platform
Signed evidence packs with causal provenance
Platform
Deterministic replay of governed memory state
Platform
Contract authoring and governance evaluation
Platform
Knowledge banks with citation roots and access tiers
Platform
Desktop app — macOS and Linux
Deployment
Managed cloud workspaces — encrypted at rest and in transit
In Progress Now
Compliance
SOC 2 Type I — active readiness work underway
Deployment
Thalamus CLI — fully offline, air-gapped deployment with license-file auth
Integrations
Python and Node SDKs with per-user API keys
Integrations
MCP server endpoint for model-context integration
Planned Near-term
Compliance
SOC 2 Type II — 6–12 month observation period following Type I
Compliance
HIPAA BAA — for qualifying healthcare and research institutions
Compliance
GDPR data processing agreements — for EU institutional deployments
Platform
Role-based access controls and policy management
Platform
SSO — SAML and OIDC enterprise identity integration
Platform
SCIM provisioning — automated user and group management
Platform
Audit log export — JSON and CSV for compliance review
Deployment
Self-hosted VPC — deployment into customer-controlled cloud infrastructure
Integrations
Webhook event streams for governance decisions and audit events
Longer Horizon Future
Compliance
FedRAMP Ready — government and defense agency procurement eligibility
Compliance
IL4 / IL5 alignment — DoD impact level requirements
Deployment
On-premises installer — bare-metal for environments with no cloud access
Integrations
LangChain and LlamaIndex connectors — first-class retriever adapters
Integrations
Embedded OEM licensing — white-label governance for enterprise AI vendors

Next step

Evaluating for institutional deployment?

We scope compliance, deployment, and integration requirements directly. No self-serve required.

View access options →

Admission boundary

Every input policy-checked before it enters governed state

Causal trace

Every decision attributed, linked, and replayable

Auditable ledger

Every state transition committed, exportable as evidence