ROADMAP

What we're building next.

Honest, public, no-marketing-team roadmap. Shipped items are linked to a live commit. Planned items have a real why behind them.

In progress 3Shipped 15Planned 9

In progress

3

Pro Features

Domain comparison view

Side-by-side grade matrix and overlaid score charts for up to 4 domains.

Custom scan profiles

Define exactly which checks run on which domains — useful for staging vs production environments.

Customer Surface

Onboarding tour

First-visit walkthrough of scan → verify → monitor → cmd+k for new dashboard users.

Shipped

15

Customer Surface

Linear-tier dashboard redesign

2026-04

Full v3 redesign of /dashboard and /admin with neutral palette, light + dark themes, Cmd+K palette, keyboard shortcuts, mobile drawer.

Domain timeline + score history

2026-04

Per-domain detail page with KPI strip, score trend, issues over time, full scan history table, notes, tags.

Insights analytics dashboard

2026-04

Customer-facing trends with time-range selector, score chart, scans/day, issues/day, grade distribution, top domains.

Compliance dashboard

2026-04

PCI-DSS, SOC 2, ISO 27001 evaluations across all your verified domains in a single grid view.

Pro Features

Bulk scan workspace

2026-04

Paste up to 20 domains and scan them in parallel. Pro feature with live results table.

Auto-remediation snippets

2026-04

Copy-pasteable starter templates for DMARC, SPF, DKIM, MTA-STS, HSTS, CSP, X-Frame-Options, Referrer-Policy.

Webhook delivery audit log

2026-04

Full record of every webhook fired with status code, response, latency. Test button included.

Slack + Discord webhooks

2026-04

Native blocks/embed payloads when the destination URL is hooks.slack.com or discord.com.

PDF report download

2026-04

Enterprise WeasyPrint reports downloadable from the dashboard with one click.

Platform

PWA support

2026-04

Install to home screen, offline shell, service worker. Manifest + cache layers shipped.

Role-based access (User/Dev/Admin)

2026-04

Real role column on users with token-version revocation. Admins can promote/demote inline.

Customer testimonial submission + admin moderation

2026-04

Public form, admin review queue, featured-on-homepage flag, public API for the marketing site.

Domain notes + tags

2026-03

Inline-editable notes and tag chips on every verified domain. Up to 12 tags per domain.

API keys + public API v1

2026-03

Programmatic scan + result fetch with HMAC-signed webhook delivery and per-key revocation.

Teams + invitations

2026-03

Multi-user organisations with role-based access and invite-by-email flow.

Planned

9

Pro Features

Subdomain enumeration

Given a verified parent domain, automatically discover and scan all subdomains on a schedule.

Scan diff

Compare any two scans of the same domain — what changed between Tuesday and today, line by line.

GitHub Action

Block PRs that drop your security score below a configurable threshold. Drop-in workflow.

Integrations

PagerDuty incident routing

Page on-call automatically when a critical CVE is discovered on a monitored domain.

Linear / Jira issue creation

Auto-create tickets for new findings and close them when the next scan shows the fix landed.

Zapier + Make support

Connect CQwerty Shield to 5,000+ apps via the existing webhook system.

Platform

White-label for MSPs

Run CQwerty Shield under your own brand for managed service provider customers.

SOC 2 Type II certification

Real audit, not just an overlay. Q3 2026.

Threat intelligence feed

Augment scans with live threat intel from CTI feeds, not just CVE/KEV.

Got a request?

We read every email. If you want something on this list, tell us what and why — and we'll prioritise it.

Send us your idea →