Where the product stands
OgmaProtect is at v0.5.5, in early access. This page is generated from the same claims ledger that polices the rest of the site: if it is not backed by evidence in the source tree, it does not appear here.
Built, merged and in use today
The full detail, with per-item evidence badges, lives on the features page.
Landing now
The active work is deliberately unglamorous: the pre-commercial audit's findings, remediated durability-first — the failure modes that could brick a router outrank new features. Beside it, the appliance range and its image edition: announced, priced and taking pre-orders, not yet shipping.
- A ratified, durability-first structural hardening programme derived from the pre-commercial audit is actively landing (storage-failure survivability, crash-safe restore, database resilience, OS-version guards).
- Ready-built OgmaProtect appliances — Edge 1G, Branch 2.5G and Core 10G, plus CARP/pfsync HA pairs — announced with specifications and ex-VAT pricing and taking pre-orders; pre-installed and burn-in tested, none shipped yet.
- The appliance image edition: a signed, read-only root on two slots (A/B) with a separate writable /cfg partition for configuration and state; updates stream a signed image onto the inactive slot, verify it against the release manifest before activation, and activate behind two confirmations; a boot that fails three times is designed to switch back to the previous slot without a console (proven in tests, not yet on shipped hardware). Built and signed under the current release manifest and served from the package repository; the first flashed unit and its proof are owed; appliances are offered in either edition, the customer's choice at order time.
- Appliances take the same signed releases as the software edition; the signing key is pre-installed.
Designed, not yet built
Scoped and captured in the repository, in no committed order. Nothing here is purchasable or promised for a date.
- Premium subscription: curated IP and DNS threat feeds for blocking and reporting, entitlement-gated.
- Scheduled security self-assessment with external-vantage exposure scanning and diffable reports.
- Traffic shaping / QoS engine (HFSC and fq-codel queues, per-rule queue assignment).
- Flow export (NetFlow/IPFIX), SNMP agent and historical metrics.
- Token-authenticated automation API for Ansible/Terraform-style infrastructure-as-code.
Why no dates?
Every change ships through the same pipeline — design contract, implementation, verification on real lab routers, review. Things land when they clear that bar, not when a quarter ends. If you need something on this page sooner, tell us — operator demand genuinely reorders the queue.