WHERE VERITY IS GOING
Roadmap.
Shipped and next.
The current product direction. Checked items are live in the version you can download today; ordering can change as feedback reveals higher-priority work.
Toward 1.0
The goal for 1.0 is a dependable, understandable Mac product that users can install, evaluate, purchase, update, and remove without developer assistance.
Shipped as 1.0.0 on September 11, 2026. Checked items are live; unchecked ones stay on the list.
- Shipped: Finish fresh-install validation on supported macOS and hardware combinations.
- Shipped: Harden helper registration, approval, repair, reconnect, and uninstall flows.
- Shipped: Reduce noisy or duplicate incidents from package managers and related filesystem changes.
- Shipped: Polish Protect decisions, pause/resume, trust management, notifications, and explicit Quit behavior.
- Shipped: Add release notes to the signed Sparkle updates.
- Planned: Add a helper version handshake so the app can detect an outdated helper after an update.
- Shipped: Complete accessibility, vault retention, and recovery checks.
- Planned: Complete localization readiness and performance checks.
- Shipped: Keep the signed and notarized DMG, website, license activation, and upgrade policy aligned with the shipped application.
After 1.0
Investigation and control
- Planned: Group related executable, shell configuration, and persistence changes into one incident.
- Planned: Explain package-manager context such as npm or Homebrew when attribution supports it.
- Planned: Add search and filters by path, process, signature, severity, and date.
- Planned: Provide individual management of persistent Always Trust rules.
- Planned: Offer optional timed Protect pauses alongside the existing manual pause-until-resume mode.
- Planned: Export a complete, locally redacted incident bundle for support or external analysis.
- Planned: Guide multi-file recovery when one activity affected several protected paths.
Coverage and signal quality
- Planned: Expand coverage of persistence points such as scheduled jobs and browser extensions where macOS provides reliable signals.
- Planned: Improve local correlation between process ancestry, package operations, file changes, and later executions.
- Planned: Add local knowledge for common legitimate developer-tool operations to reduce alert fatigue.
- Planned: Consider optional online reputation checks with an explicit privacy boundary and an offline-first default.
Agent-driven installs
- Planned: Cover the executable directories that language and agent toolchains install into, such as the per-user bin folders used by Rust, Go, Node, and Python.
- Planned: Let a folder added to the watch list take part in Protect decisions; today Protect covers only the default executable directories.
- Planned: Deliver expanded default coverage to existing installations rather than to first runs alone.
Teams
- Planned: Evaluate shared policies, managed trust rules, and fleet status only after the single-Mac product is stable.
- Planned: Preserve local evidence ownership and make every remotely managed behavior visible to the Mac user.
Product principles
- Report observed facts and uncertainty rather than claiming a file is safe or malicious.
- Keep monitoring data, content history, and analysis local unless the user explicitly exports them.
- Make blocked executions, missing permissions, degraded coverage, and recovery limits visible.
- Prefer reversible actions and explain the exact scope of every persistent trust decision.
Missing a folder you want watched?
Tell me which one: contact.