Limitations & roadmap
Current limitations
- Static analysis only — no claim of completeness for runtime or wire-negotiated crypto
- Not a correctness auditor (padding, IV reuse, side channels)
- Binary / firmware analysis: roadmap
- Runtime / network TLS scanning: roadmap
- Container images and multi-repo aggregation: roadmap
- Full declarative policy engine: early / evolving
- AI-assisted triage: Phase 4; annotate-only when present; off by default
Build plan (from README)
Longer roadmap includes filesystem/container scanning, runtime/network discovery, binary and firmware analysis, org-wide aggregation, cloud KMS/HSM discovery, richer policy/exceptions, and additional CI/GRC exporters.