Skip to main content

Limitations & roadmap

Current limitations

  • Static analysis only — no claim of completeness for runtime or wire-negotiated crypto
  • Not a correctness auditor (padding, IV reuse, side channels)
  • Binary / firmware analysis: roadmap
  • Runtime / network TLS scanning: roadmap
  • Container images and multi-repo aggregation: roadmap
  • Full declarative policy engine: early / evolving
  • AI-assisted triage: Phase 4; annotate-only when present; off by default

Build plan (from README)

Longer roadmap includes filesystem/container scanning, runtime/network discovery, binary and firmware analysis, org-wide aggregation, cloud KMS/HSM discovery, richer policy/exceptions, and additional CI/GRC exporters.