Roadmap
What we're shipping, what's next, and what we're thinking about. No committed dates — we'd rather ship right than ship on time.
Something missing? Tell us what you need →
In Beta
Shipped and available — may have rough edges. Feedback welcome.
ReBAC (Relationship-based Access Control)
PolicyDefine resource ownership, team membership, and project access via 1-hop relationship policies. Evaluated at retrieval time with a 60s result cache.
API Keys
AuthCreate and revoke named API keys from the dashboard. Keys are bcrypt-hashed at rest; plaintext shown exactly once on creation.
Vertex AI Search connector
ConnectorHybrid + keyword + vector retrieval from Google Discovery Engine data stores. Supports global and regional locations.
Azure AI Search connector
ConnectorRanked BM25 keyword and native RRF hybrid search from Azure AI Search indexes. Managed identity and API key auth.
MCP server
IntegrationFastMCP server with 6 tools: retrieve, ask (grounded answers), list connectors, list policies, list principals, resolve principal. Works with Claude, Cursor, and any MCP-compatible host.
Grounded Answers
AIPolicy-aware answer synthesis — retrieves only policy-allowed chunks, feeds them to an LLM, returns an answer with citations. Three outcomes: answered, no_access, insufficient_context.
Coming Soon
In active development or on deck. No committed dates.
SOC 2 Type II
ComplianceAudit underway. Target H2 2026. Enterprise customers can request current in-progress artifacts from enterprise@gateco.ai.
Private Data Plane (VPC)
DeploymentRun the Gateco policy engine inside your own VPC. Vector DB credentials never leave your network. Waitlist open now.
BYOK — Bring Your Own Key
SecurityEnterprise customers can provide their own KMS key for encrypting connector credentials and sensitive fields.
HIPAA BAA
ComplianceFormal HIPAA Business Associate Agreement. Gateco's deny-by-default model and audit trails structurally support the minimum necessary standard today. BAA planned after SOC 2 completion.
Webhook notifications
PlatformOutbound webhooks on policy change, high-denial-rate alerts, and IDP sync failures. Configurable per-org with HMAC signing.
EU AI Act audit evidence export
ComplianceOne-click export of Annex III evidence pack: policy version history, retrieval decision log, classification coverage report, and access revocation audit trail.
Exploring
Under consideration — customer signal shapes prioritization.
Self-host (full stack)
DeploymentComplete Gateco stack deployable in your own infrastructure. No Gateco telemetry. Target Q3 2026 waitlist.
Open-source Python SDK
DeveloperOpen-source the gateco-sdk core under a permissive license. Server-side product stays closed; client SDK becomes community-owned.
AuthZEN compliance
InteropImplement the OASIS AuthZEN interoperability standard so Gateco can interoperate with AuthZEN-compatible policy engines.
GitOps policy bundles
PolicyDeclare policies as YAML files in a Git repo. Gateco watches the repo and applies changes on merge. Pairs with existing policy version history.
Cerbos compatibility layer
InteropAllow teams using Cerbos PDP for application authorization to delegate retrieval-layer decisions to Gateco — shared principal context, no double sync.
Multi-region EU data plane (SaaS)
ComplianceHosted EU data plane where policy evaluation, audit logs, and connector credentials all stay in the EU region for GDPR data residency without Private Data Plane deployment.
Shape the roadmap
Roadmap priorities are driven by customer signal. If something on the Exploring column is blocking your adoption, tell us — it moves up the queue.