CascadeGuard Feature Matrix

Internal reference for what ships when. Each feature has a single mark in the column representing its current target.


Secure Images

FeatureDoneIn ProgressV1 LaunchFuture
10 hardened base images on Docker Hub (public)X
Non-root enforcement, SUID stripping, binary removalX
Dual-scanner (Grype + Trivy)X
SBOM generation (SPDX + CycloneDX)X
Image signing (Cosign)X
SLA-driven auto-rebuild (24h critical, 168h high)X
Expanded catalog (25+ images, registered users)X
Rolling-tag-only deprecation (3-month grace)X
Custom hardening profilesEnterprise
Data-driven catalog expansion (pull analytics)X

Public Dashboard

FeatureDoneIn ProgressV1 LaunchFuture
Image catalog with status badgesX
Per-image CVE list by severityX
SBOM viewer with diffX
Rebuild history timelineX
Embeddable README badgesX
Upstream image status (delta vs hardened)X

CLI (Open Source, Free Forever)

FeatureDoneIn ProgressV1 LaunchFuture
images init — scaffold from seed repoX
images validate — validate images.yamlX
images check — discover base images, check driftX
images enrol — add image to monitoringX
tools pin — resolve action tags to SHAsX
tools audit — audit workflow files with policy validationX
tools policy init — scaffold actions-policy.yamlX
scan — discover and analyse container artifactsX
CLI namespace rename (actionstools)X
GitLab supportX
Argo CD supportX

Try-Me / Test-Us Flow

FeatureDoneIn ProgressV1 LaunchFuture
Dockerfile paste scan (no sign-up, rate-limited)X
Email gate to unlock full reportX
Zip upload (sign-up required)X
GitHub repo link (temporary OAuth)X
Git push to temporary remote (UUID-auth)X
7-day report retention + PDF exportX

Secure Tools (CI Pipeline Security)

FeatureDoneIn ProgressV1 LaunchFuture
Action tag-to-SHA pinning (via tools pin)X
Action audit with policy validation (via tools audit)X
Action dependency scanning (Node, Docker, composites)X
Upstream monitoring (tag-move detection)X
Tools in dashboard alongside imagesX
72-hour delay window for new versions (configurable)X
Policy enforcement (deny-by-default, allowlisting)X
GitLab CIX
CircleCI / Jenkins supportFuture

Free Personalised Assessment

FeatureDoneIn ProgressV1 LaunchFuture
Questionnaire-based security profilingX
Weighted vulnerability recommendationsX
AB-testable assessment flowX
Lead capture to HubSpotX

Secure Packages (Phase 2)

FeatureDoneIn ProgressV1 LaunchFuture
Quarantine-based package proxy (pip, npm)Phase 2
48-72 hour hold on new versionsPhase 2
Transparent caching proxy with configurable policiesPhase 2
Maven, Go modules, RubyGems supportPhase 3

Platform & SaaS Tiers

FeatureDoneIn ProgressV1 LaunchFuture
Free (no account)
Public dashboard + CLI + 10 Docker Hub imagesX
Session-based workload comparisonX
Try-Scan one-shot (rate-limited, no history)X
Registered (free account)
Full catalog access (25+ images, comparison only)X
Scan up to 3 own images/month (saved results)X
Email alerts for new CVEsX
Historical trend dataX
Starter ($49/mo)
Scan up to 20 own images/monthX
CI/CD integration (GitHub Actions, GitLab CI)X
Policy-as-code (base image + threshold rules)X
Team access (up to 5 seats)X
Pro ($199/mo)
Unlimited own-image scansX
Private managed registryX
SBOM export + compliance reporting (SOC2, HIPAA)X
Team access (up to 20 seats)X
Enterprise (custom)
Dedicated registry namespace with SLAX
Custom hardening profiles + SSO/SAMLX

Infrastructure & Integrations

FeatureDoneIn ProgressV1 LaunchFuture
Auth: Clerk (GitHub, Gitlab, email, Google OAuth)X
Database: Cloudflare D1X
Processing: Cloudflare Workers + R2X
Abuse prevention: Turnstile CAPTCHAX
Lead gen: HubSpot drip campaignsX
Kargo/ArgoCD/Flux integrationFuture
AI-driven hardening recommendationsFuture
SLSA attestation / supply chain risk scoringFuture

Legend: Done = shipped and working, In Progress = actively being built, V1 Launch = targeted for v1 release, Future/Phase N/Enterprise = roadmap items without firm timeline. Each feature appears once in its target column.

Source PRDs: free-personalised-assessment, secure-actions, upstream-status-integration, test-us-flow. See also: growth-strategy.md (tier pricing), secure-packages.md (Phase 2), managed-image-deprecation.md (lifecycle).