WHERE VERITY IS GOING

Roadmap.
Shipped and next.

The current product direction. Checked items are live in the version you can download today; ordering can change as feedback reveals higher-priority work.

Toward 1.0

The goal for 1.0 is a dependable, understandable Mac product that users can install, evaluate, purchase, update, and remove without developer assistance.

Shipped as 1.0.0 on September 11, 2026. Checked items are live; unchecked ones stay on the list.

  • Shipped: Finish fresh-install validation on supported macOS and hardware combinations.
  • Shipped: Harden helper registration, approval, repair, reconnect, and uninstall flows.
  • Shipped: Reduce noisy or duplicate incidents from package managers and related filesystem changes.
  • Shipped: Polish Protect decisions, pause/resume, trust management, notifications, and explicit Quit behavior.
  • Shipped: Add release notes to the signed Sparkle updates.
  • Planned: Add a helper version handshake so the app can detect an outdated helper after an update.
  • Shipped: Complete accessibility, vault retention, and recovery checks.
  • Planned: Complete localization readiness and performance checks.
  • Shipped: Keep the signed and notarized DMG, website, license activation, and upgrade policy aligned with the shipped application.

After 1.0

Investigation and control

  • Planned: Group related executable, shell configuration, and persistence changes into one incident.
  • Planned: Explain package-manager context such as npm or Homebrew when attribution supports it.
  • Planned: Add search and filters by path, process, signature, severity, and date.
  • Planned: Provide individual management of persistent Always Trust rules.
  • Planned: Offer optional timed Protect pauses alongside the existing manual pause-until-resume mode.
  • Planned: Export a complete, locally redacted incident bundle for support or external analysis.
  • Planned: Guide multi-file recovery when one activity affected several protected paths.

Coverage and signal quality

  • Planned: Expand coverage of persistence points such as scheduled jobs and browser extensions where macOS provides reliable signals.
  • Planned: Improve local correlation between process ancestry, package operations, file changes, and later executions.
  • Planned: Add local knowledge for common legitimate developer-tool operations to reduce alert fatigue.
  • Planned: Consider optional online reputation checks with an explicit privacy boundary and an offline-first default.

Agent-driven installs

  • Planned: Cover the executable directories that language and agent toolchains install into, such as the per-user bin folders used by Rust, Go, Node, and Python.
  • Planned: Let a folder added to the watch list take part in Protect decisions; today Protect covers only the default executable directories.
  • Planned: Deliver expanded default coverage to existing installations rather than to first runs alone.

Teams

  • Planned: Evaluate shared policies, managed trust rules, and fleet status only after the single-Mac product is stable.
  • Planned: Preserve local evidence ownership and make every remotely managed behavior visible to the Mac user.

Product principles

  • Report observed facts and uncertainty rather than claiming a file is safe or malicious.
  • Keep monitoring data, content history, and analysis local unless the user explicitly exports them.
  • Make blocked executions, missing permissions, degraded coverage, and recovery limits visible.
  • Prefer reversible actions and explain the exact scope of every persistent trust decision.

Missing a folder you want watched?
Tell me which one: contact.

Get Verity