Roadmap & status

Where the product stands

OgmaProtect is at v0.5.5, in early access. This page is generated from the same claims ledger that polices the rest of the site: if it is not backed by evidence in the source tree, it does not appear here.

In progress

Landing now

The active work is deliberately unglamorous: the pre-commercial audit's findings, remediated durability-first — the failure modes that could brick a router outrank new features. Beside it, the appliance range and its image edition: announced, priced and taking pre-orders, not yet shipping.

  • A ratified, durability-first structural hardening programme derived from the pre-commercial audit is actively landing (storage-failure survivability, crash-safe restore, database resilience, OS-version guards).
  • Ready-built OgmaProtect appliances — Edge 1G, Branch 2.5G and Core 10G, plus CARP/pfsync HA pairs — announced with specifications and ex-VAT pricing and taking pre-orders; pre-installed and burn-in tested, none shipped yet.
  • The appliance image edition: a signed, read-only root on two slots (A/B) with a separate writable /cfg partition for configuration and state; updates stream a signed image onto the inactive slot, verify it against the release manifest before activation, and activate behind two confirmations; a boot that fails three times is designed to switch back to the previous slot without a console (proven in tests, not yet on shipped hardware). Built and signed under the current release manifest and served from the package repository; the first flashed unit and its proof are owed; appliances are offered in either edition, the customer's choice at order time.
  • Appliances take the same signed releases as the software edition; the signing key is pre-installed.
Planned

Designed, not yet built

Scoped and captured in the repository, in no committed order. Nothing here is purchasable or promised for a date.

  • Premium subscription: curated IP and DNS threat feeds for blocking and reporting, entitlement-gated.
  • Scheduled security self-assessment with external-vantage exposure scanning and diffable reports.
  • Traffic shaping / QoS engine (HFSC and fq-codel queues, per-rule queue assignment).
  • Flow export (NetFlow/IPFIX), SNMP agent and historical metrics.
  • Token-authenticated automation API for Ansible/Terraform-style infrastructure-as-code.

Why no dates?

Every change ships through the same pipeline — design contract, implementation, verification on real lab routers, review. Things land when they clear that bar, not when a quarter ends. If you need something on this page sooner, tell us — operator demand genuinely reorders the queue.