Evidence-gated
Honest by default.Shipped when proven.
This roadmap shows what is shipped, what is evolving, and what is planned — with the evidence behind each status. No invented commitments. Dates appear only when work is committed.
What we bet on — and what we got wrong.
Every roadmap is a set of bets. This ledger shows them with their outcomes: open, landed, retracted, or punted. Retracted bets stay on the record with their reasoning — a roadmap that hides its misses is a sales page, not a plan.
A dedicated vector service as the semantic primary
RetractedAn external vector service would beat Postgres for semantic recall at scale.
Retracted in favour of pgvector after pgvectorscale benchmarks and the single-store operational win. The migration note and the evidence stay in the repo history.
A small fixed tool surface
RetractedA handful of core tools would cover the surface area an agent needs.
The surface grew to 29 tools under a versioned contract. The old small-surface copy was corrected in the shared-facts registry — the correction is on record.
Signed one-time handoff as the continuity primitive
LandedA signed, one-time packet is the trustworthy way to move working state between tools.
Shipped as Slipstream / Continuity Format v1 — Ed25519 source signature, HMAC destination binding, verify-before-import, one-time consumption.
Abstention over fluency
LandedAn AI memory that says "not evaluated" earns more trust than one that always answers.
Shipped across the memory surface — typed gaps, review states, and the TrustBench suite that measures it.
Managed cloud with tiered pricing
OpenThe managed cloud + tier ladder becomes the commercial surface.
The economics gate decides when this becomes a real price. Open until the evidence exists.
npm one-line install as the entry point
Opennpx @zephr-ai/cli is the designed distribution path.
The package is not published yet; the build-from-source path is the honest one today. Open until the package publishes.
Firecracker microVM devpods
PuntedHosted compute runs in Firecracker microVMs.
Punted behind the tenancy gate and the managed cloud. The isolation design stays on record for when the economics support it.
statuses change only when evidence changes them — retracted bets stay on the record
Shipped, evolving, and planned.
Three durable status groups, each labelled with its real status. The groups describe how proven a thing is, not when it lands. Work moves right only after the prior stage passes its gate — and a planned item inside an evolving group is a fact about that group, not an inconsistency.
- 01
Shipped foundations
Shipped + activeAdmission & scope binding
shippedInstallation admission, immutable scope binding, and the CLI that drives it — shipped.
Fleet
shippedPer-installation fleet profiles, device enrolment contract, and SCPE scope binding — shipped.
Slipstream / continuity
shippedSigned handoff packets and cross-client portability across Claude Code, Cursor, and Codex — shipped.
Trust & security foundations
shippedTrust Firewall, governed mutations, and scope integrity — shipped.
- 02
Evolving product surfaces
In progressOperator console
evolvingLive Memory workspace, policy and contradiction views, and the dashboard surfaces around them.
Review & Guard
evolvingLLM-augmented review layer and the Guard assurance surface — evolving alongside the evidence substrate.
Automation & signals
evolvingUser-defined automation rules bridging Pulse signals to delivery — evolving.
- 03
Evidence-gated future work
PlannedManaged cloud
plannedHosted Postgres backing and cross-machine sync — post-beta, gated on partner evidence.
Public launch
plannedGated on partner evidence and unit economics; no date set.
Shipped foundations
Shipped + active- Admission & scope bindingShipped
Installation admission, immutable scope binding, and the CLI that drives it — shipped.
- FleetShipped
Per-installation fleet profiles, device enrolment contract, and SCPE scope binding — shipped.
- Slipstream / continuityShipped
Signed handoff packets and cross-client portability across Claude Code, Cursor, and Codex — shipped.
- Trust & security foundationsShipped
Trust Firewall, governed mutations, and scope integrity — shipped.
Evolving product surfaces
In progress- Operator consoleEvolving
Live Memory workspace, policy and contradiction views, and the dashboard surfaces around them.
- Review & GuardEvolving
LLM-augmented review layer and the Guard assurance surface — evolving alongside the evidence substrate.
- Automation & signalsEvolving
User-defined automation rules bridging Pulse signals to delivery — evolving.
Evidence-gated future work
Planned- Managed cloudPlanned
Hosted Postgres backing and cross-machine sync — post-beta, gated on partner evidence.
- Public launchPlanned
Gated on partner evidence and unit economics; no date set.
Status is shipped / evolving / planned. For shipped changes release by release, see the changelog; for current capability status, see the platform page.
Every phase is evidence-gated.
No phase opens until the prior phase's evidence passes. This is not a Gantt chart — it is a sequence of proof.
- GATE 1 / 4
Local beta
ShippedFixture walkthrough + local tool surface proven on a clean host.
- GATE 2 / 4
Partner-cohort proof
EvolvingProtocol defined; first reproducible partner runs pending.
- GATE 3 / 4
Managed beta
PlannedContingent on partner-cohort criteria + strict quotas.
- GATE 4 / 4
GA
PlannedSeparate investment decision: unit economics + scaling proof.
Gating rules from docs/STRATEGY.md §“Evidence-gated go-to-market.”
The product clusters, one line each.
The roadmap groups work that is shipped, evolving, and planned. These are the live capability statuses behind each cluster — read from the shared truth registry the platform page uses.
- MemoryShipped
- Slipstreamv1.1 shipped · E2E-proven
- LibraryEvolving · legal gate not built
- SyncShipped · local reconcile
- LensGate layer tested · hosted runtime in design
- ReviewEngine + lenses built · in development
- PulseCore shipped · expanding
- GuardShipped · T3 judge deferred by decision
- FleetInstallation ledger exists · complete profile integrity + revocation planned
- ConnectCLI shipped · web wizard partial
- AgentsBuilt, hardening · never self-confirm
Statuses read from the shared marketing truth registry (lib/platform/shared-facts.ts); the conservative reading wins.
zephr packSee what shipped, and what is current.
For shipped changes release by release, read the changelog. For the current capability status of each surface, read the platform page. This roadmap summarises the durable shape; those pages carry the detail.