{
  "schema_version": "2.0",
  "published": "2026-08-24",
  "description": "Canonical public capability registry for Araghatta. This is the single source of truth for what is shipped today. Every marketing page must agree with the state and summary recorded here. The endpoint sensor is observe-only: response today is detect, alert, integrations and per-device pause/revoke; inline endpoint blocking is on the roadmap.",
  "states": {
    "ga": "Generally available",
    "beta": "Beta",
    "not-configured": "Built — connect to enable",
    "roadmap": "On the roadmap"
  },
  "capabilities": [
    {
      "key": "endpoint_discovery",
      "name": "Endpoint AI discovery",
      "state": "ga",
      "label": "GA",
      "summary": "Eleven signal classes of AI on the host — AI CLIs and agents, provider keys, MCP servers and tool scope, IDE assistants, skills, SDKs, installed apps, browser extensions, egress to AI endpoints, vibe-coded repositories and non-human identities.",
      "platforms": [
        "Windows 10",
        "Windows 11",
        "macOS",
        "Linux"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "windows_endpoint",
      "name": "Windows endpoint sensor",
      "state": "beta",
      "label": "Beta",
      "summary": "Windows 10 and 11 client discovery across x64, x86 and ARM64. Observe-only.",
      "platforms": [
        "Windows 10",
        "Windows 11",
        "x64",
        "x86",
        "ARM64"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "windows_server",
      "name": "Windows Server sensor",
      "state": "beta",
      "label": "Beta",
      "summary": "Windows Server 2016–2025 coverage is in beta — same discovery model, hardening in progress.",
      "platforms": [
        "Windows Server 2016",
        "2019",
        "2022",
        "2025"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "linux",
      "name": "Linux endpoint sensor",
      "state": "ga",
      "label": "GA",
      "summary": "Enterprise Linux discovery with eBPF exec/connect telemetry. Observe-only.",
      "platforms": [
        "RHEL",
        "Ubuntu",
        "Amazon Linux",
        "SUSE",
        "Debian"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "macos",
      "name": "macOS endpoint sensor",
      "state": "ga",
      "label": "GA",
      "summary": "macOS discovery on Intel and Apple silicon. Observe-only.",
      "platforms": [
        "macOS Intel",
        "macOS Apple silicon"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "vdi",
      "name": "Virtual desktop coverage",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "VDI and multi-user session coverage is on the roadmap — not shipped today.",
      "platforms": [
        "AVD",
        "Windows 365",
        "Citrix",
        "VMware Horizon"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "containers",
      "name": "Container and Kubernetes coverage",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "Container and Kubernetes coverage is on the roadmap — not shipped today.",
      "platforms": [
        "EKS",
        "AKS",
        "GKE",
        "Docker",
        "containerd"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "aws",
      "name": "AWS organisation and AI discovery",
      "state": "ga",
      "label": "GA",
      "summary": "Least-privilege, read-only AWS organisation connector for AI service, identity and control-plane discovery. Generally available today.",
      "platforms": [
        "AWS Organizations",
        "Bedrock",
        "SageMaker",
        "EKS",
        "Lambda"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "azure",
      "name": "Microsoft Azure cloud and AI discovery",
      "state": "not-configured",
      "label": "On connect",
      "summary": "Built — connect a read-only Entra application to enable. Not scanning Azure until you connect it.",
      "platforms": [
        "Azure",
        "Entra",
        "Azure OpenAI",
        "AI Foundry",
        "AKS"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "gcp",
      "name": "Google Cloud and AI discovery",
      "state": "not-configured",
      "label": "On connect",
      "summary": "Built — connect a read-only GCP service account to enable. Not scanning Google Cloud until you connect it.",
      "platforms": [
        "Google Cloud",
        "Vertex AI",
        "Gemini",
        "GKE",
        "Cloud Run"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "cloud_server_cspm",
      "name": "Sensor-led cloud server CSPM",
      "state": "ga",
      "label": "AWS GA",
      "summary": "Sensor-led cloud security posture management is generally available on AWS today (EC2, Windows Server, Linux). Azure VMs and Google Compute Engine are connect-to-enable.",
      "platforms": [
        "AWS EC2",
        "Windows Server",
        "Linux",
        "(Azure VMs and Google Compute Engine on connect)"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "agent_attack_paths",
      "name": "AI-agent cloud attack-path analysis",
      "state": "ga",
      "label": "AWS GA",
      "summary": "AI-agent cloud attack-path analysis is generally available on AWS today (IAM and S3). Azure and Google Cloud are connect-to-enable.",
      "platforms": [
        "AWS IAM and S3",
        "(Azure and Google Cloud on connect)"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "scoring",
      "name": "Explainable, tunable risk scoring",
      "state": "ga",
      "label": "GA",
      "summary": "Deterministic, explainable and tunable risk scoring — every score is auditable to its evidence.",
      "platforms": [
        "Risk scoring",
        "Threat scoring"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "ai_reasoning",
      "name": "Advisory AI reasoning",
      "state": "ga",
      "label": "GA",
      "summary": "Advisory AI reasoning grounded in MITRE ATLAS and ATT&CK. Advisory only — it cannot change the deterministic score or fabricate techniques.",
      "platforms": [
        "MITRE ATLAS",
        "MITRE ATT&CK"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "approved_ai_policy",
      "name": "Approved-AI policy",
      "state": "ga",
      "label": "GA",
      "summary": "Approved-AI policy governance — flag and alert on unsanctioned AI. This is flag-and-alert, not inline endpoint blocking.",
      "platforms": [
        "Allow-list",
        "Deny-list",
        "Alerting"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "content_dlp",
      "name": "Content DLP policy engine",
      "state": "ga",
      "label": "GA",
      "summary": "Server-side content-DLP policy engine: monitor / warn / redact / block decisioning per data class through an inspection API you deploy and control. Inline in-browser enforcement is on the roadmap.",
      "platforms": [
        "Block",
        "Redact",
        "Warn",
        "Allow",
        "Monitor-first"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "policy_governance",
      "name": "Policy governance",
      "state": "ga",
      "label": "GA",
      "summary": "Per-tenant policy governance — approved-AI policy, content-DLP policy and allow-with-acknowledgement, with a tamper-evident audit trail.",
      "platforms": [
        "Policy engine",
        "Audit trail"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "privacy_controls",
      "name": "Privacy and data-minimization controls",
      "state": "ga",
      "label": "GA",
      "summary": "Privacy and data-minimization controls — the sensor never reads prompts, chats or file contents; secret values are fingerprinted at the source and never leave the device.",
      "platforms": [
        "Data minimization",
        "Redaction",
        "Erasure"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "asset_ownership",
      "name": "Asset ownership",
      "state": "ga",
      "label": "GA",
      "summary": "Asset ownership assignment — manual and CSV import today. Auto-sync from IdP / MDM / CMDB is on the roadmap.",
      "platforms": [
        "Manual",
        "CSV import"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "remediation",
      "name": "Remediation workflow",
      "state": "ga",
      "label": "GA",
      "summary": "Risk lifecycle and remediation workflow — assign, track, reopen and evidence remediation with SLA policy.",
      "platforms": [
        "Risk lifecycle",
        "SLA policy"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "api",
      "name": "Versioned REST API",
      "state": "ga",
      "label": "GA",
      "summary": "Versioned /api/v1 REST API with scoped service-account keys over risks, findings, sensors and cloud posture. Generally available today.",
      "platforms": [
        "REST",
        "/api/v1",
        "Service-account keys",
        "Webhooks"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "fleet_ops",
      "name": "Sensor fleet operations",
      "state": "ga",
      "label": "GA",
      "summary": "Sensor fleet operations — enrollment, versioned pinned updates, binary attestation, per-device pause and server-side revoke.",
      "platforms": [
        "Enrollment",
        "Pinned updates",
        "Attestation"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "siem",
      "name": "SIEM and OCSF export",
      "state": "ga",
      "label": "GA",
      "summary": "Outbound SIEM / SOAR export and OCSF is generally available — Splunk, Microsoft Sentinel, QRadar, Elastic, Google Chronicle/SecOps and Amazon Security Lake.",
      "platforms": [
        "Splunk",
        "Sentinel",
        "QRadar",
        "Elastic",
        "Chronicle",
        "Security Lake"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "slack_jira",
      "name": "Slack and Jira integrations",
      "state": "ga",
      "label": "GA",
      "summary": "Slack ChatOps alerts and Jira ticketing (per-risk tickets and per-sensor epics) are generally available.",
      "platforms": [
        "Slack",
        "Jira"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "edr_itsm_connectors",
      "name": "Certified bidirectional EDR/ITSM connectors",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "Certified two-way EDR and ITSM connectors are on the roadmap. Outbound export (SIEM/OCSF, Slack, Jira, webhook) ships today.",
      "platforms": [
        "EDR",
        "ITSM"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "servicenow",
      "name": "ServiceNow connector",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "A native ServiceNow SecOps/ITSM/CMDB connector is on the roadmap. Outbound webhook and Jira ticketing cover ITSM workflows today.",
      "platforms": [
        "SecOps",
        "ITSM",
        "CMDB"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "vendor_transparency",
      "name": "Vendor cross-tenant access transparency",
      "state": "ga",
      "label": "GA",
      "summary": "Customer-approved, time-bound vendor cross-tenant access with full transparency and an audit record.",
      "platforms": [
        "Access transparency",
        "Audit"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "sso",
      "name": "OIDC single sign-on",
      "state": "ga",
      "label": "OIDC GA",
      "summary": "OIDC single sign-on is generally available — Okta, Entra ID, Google Workspace, Auth0 and standards-compatible OIDC providers. SAML is on the roadmap.",
      "platforms": [
        "Okta",
        "Entra ID",
        "Google Workspace",
        "Auth0"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "saml",
      "name": "SAML single sign-on",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "SAML SSO is on the roadmap. OIDC single sign-on is generally available today and covers the major identity providers.",
      "platforms": [
        "SAML 2.0"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "scim",
      "name": "SCIM 2.0 lifecycle management",
      "state": "ga",
      "label": "GA",
      "summary": "SCIM 2.0 provisioning and deprovisioning is generally available — automated user lifecycle, group-to-role mapping and offboarding-triggered AI-access revocation.",
      "platforms": [
        "Okta",
        "Entra ID",
        "Google Workspace"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "response",
      "name": "Response controls",
      "state": "ga",
      "label": "GA",
      "summary": "Response today is detect + alert + your Slack/Jira/SIEM integrations + per-device pause and server-side revoke, all operator-authorised and audited. In-line endpoint block/quarantine is on the roadmap — the sensor is observe-only.",
      "platforms": [
        "Alert",
        "Pause",
        "Server-side revoke"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "endpoint_enforcement",
      "name": "In-line endpoint block / quarantine",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "In-line endpoint block and quarantine on the host is on the roadmap. The shipped sensor is observe-only; response today runs through alerts, integrations and per-device pause/revoke.",
      "platforms": [
        "Block",
        "Quarantine"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "ownership_autosync",
      "name": "Ownership auto-sync",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "Automatic asset-ownership sync from IdP, MDM and CMDB is on the roadmap. Manual and CSV ownership ship today.",
      "platforms": [
        "IdP",
        "MDM",
        "CMDB"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "signed_releases",
      "name": "Signed sensor releases",
      "state": "not-configured",
      "label": "On procurement",
      "summary": "Every release ships with a SHA-256 hash, an SBOM and a reproducible build pipeline today, and the collector attests each sensor against the published release. Authenticode and Apple Developer-ID code-signing switch on once the signing certificates are procured.",
      "platforms": [
        "SHA-256",
        "SBOM",
        "Reproducible build"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "compliance",
      "name": "Compliance mapping and signed evidence",
      "state": "ga",
      "label": "GA",
      "summary": "Compliance control mapping and signed, immutable evidence reports — NIST AI RMF, ISO 42001, OWASP LLM and EU AI Act. This is control mapping and evidence, not a certification of your organisation.",
      "platforms": [
        "NIST AI RMF",
        "ISO 42001",
        "OWASP LLM",
        "EU AI Act"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "accessibility",
      "name": "Accessibility",
      "state": "ga",
      "label": "GA",
      "summary": "The console is built to align with WCAG 2.2 AA.",
      "platforms": [
        "WCAG 2.2 AA"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "private_deployment",
      "name": "Dedicated and customer-cloud deployment",
      "state": "ga",
      "label": "GA",
      "summary": "Deployment tiers are options: shared multi-tenant SaaS, dedicated SaaS or customer-VPC/private-connectivity deployment.",
      "platforms": [
        "Dedicated SaaS",
        "Customer VPC",
        "Private connectivity"
      ],
      "last_verified": "2026-08-23"
    },
    {
      "key": "scale",
      "name": "100k+ endpoint fleet scale",
      "state": "roadmap",
      "label": "Roadmap",
      "summary": "Validated 100k+ endpoint-per-tenant fleet scale is on the roadmap. We do not claim it today.",
      "platforms": [],
      "last_verified": "2026-08-23"
    },
    {
      "key": "nhi_governance",
      "name": "Agent & machine-identity governance",
      "state": "ga",
      "label": "GA",
      "group": "Context",
      "summary": "Every AI agent, MCP server and machine key as a governed principal — effective reach (tools, credentials, egress, reachable cloud data), owner, business-criticality and lifecycle. Recertify or schedule decommission; the sensor observes, it does not revoke.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "data_lineage",
      "name": "AI data lineage and reach",
      "state": "ga",
      "label": "GA",
      "group": "Context",
      "summary": "For every cloud data store, which AI agents and workload identities can reach it and via how many attack paths. Permission-permits-access reachability from the cloud graph — not observed retrieval.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "change_risk",
      "name": "Change-risk simulator",
      "state": "ga",
      "label": "GA",
      "group": "Context",
      "summary": "Predict the security effect of a proposed change — widen a workload's access, or expose a store publicly — on the current cloud graph, before you make it. A deterministic blast-radius forecast, not a claim of exploitability.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "supply_chain_trust",
      "name": "AI supply-chain trust registry",
      "state": "ga",
      "label": "GA",
      "group": "Test",
      "summary": "Every AI library, MCP server and skill on the fleet with a trust verdict — known-CVE, unpinned, untrusted source — and a fleet-wide approve/quarantine decision. A release gate over your AIBOM.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "continuous_red_team",
      "name": "Continuous AI red-team",
      "state": "ga",
      "label": "GA",
      "group": "Test",
      "summary": "A curated adversarial pack library aligned to OWASP LLM Top 10 and MITRE ATLAS, run against an authorized target with pass/fail and regression. Runs without an authorized target are clearly labelled samples.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "appsec_cicd_gates",
      "name": "AI code and CI/CD gates",
      "state": "ga",
      "label": "GA",
      "group": "Test",
      "summary": "Per code location, the AI-specific issues a pre-merge gate catches — hardcoded AI secrets, vulnerable or unpinned AI dependencies, untrusted MCP and skills, AI-authored code pending review — and a pass, warn or block verdict.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "execution_traces",
      "name": "AI execution traces (AIDR)",
      "state": "ga",
      "label": "GA",
      "group": "Runtime",
      "summary": "Reconstruct what an AI system did — user, prompt, retrieval, model, agent, tool, resource, outcome — from OpenTelemetry GenAI telemetry. Observe mode for investigation; live response actions need an enforcement point on the roadmap.",
      "last_verified": "2026-08-24"
    },
    {
      "key": "ai_system_register",
      "name": "AI system register and EU AI Act conformity",
      "state": "ga",
      "label": "GA",
      "group": "Govern",
      "summary": "Every AI system in use, classified for conformity: EU AI Act risk tier, provider or deployer role, accountable owner and lifecycle. An accountable, audit-stamped human classification — not an automated legal determination.",
      "last_verified": "2026-08-24"
    }
  ]
}