Roadmap

What we're shipping, what's next, and what we're thinking about. No committed dates — we'd rather ship right than ship on time.

Something missing? Tell us what you need →

In Beta

Shipped and available — may have rough edges. Feedback welcome.

ReBAC (Relationship-based Access Control)

Policy

Define resource ownership, team membership, and project access via 1-hop relationship policies. Evaluated at retrieval time with a 60s result cache.

API Keys

Auth

Create and revoke named API keys from the dashboard. Keys are bcrypt-hashed at rest; plaintext shown exactly once on creation.

Vertex AI Search connector

Connector

Hybrid + keyword + vector retrieval from Google Discovery Engine data stores. Supports global and regional locations.

Azure AI Search connector

Connector

Ranked BM25 keyword and native RRF hybrid search from Azure AI Search indexes. Managed identity and API key auth.

MCP server

Integration

FastMCP server with 6 tools: retrieve, ask (grounded answers), list connectors, list policies, list principals, resolve principal. Works with Claude, Cursor, and any MCP-compatible host.

Grounded Answers

AI

Policy-aware answer synthesis — retrieves only policy-allowed chunks, feeds them to an LLM, returns an answer with citations. Three outcomes: answered, no_access, insufficient_context.

Coming Soon

In active development or on deck. No committed dates.

SOC 2 Type II

Compliance

Audit underway. Target H2 2026. Enterprise customers can request current in-progress artifacts from enterprise@gateco.ai.

Private Data Plane (VPC)

Deployment

Run the Gateco policy engine inside your own VPC. Vector DB credentials never leave your network. Waitlist open now.

BYOK — Bring Your Own Key

Security

Enterprise customers can provide their own KMS key for encrypting connector credentials and sensitive fields.

HIPAA BAA

Compliance

Formal HIPAA Business Associate Agreement. Gateco's deny-by-default model and audit trails structurally support the minimum necessary standard today. BAA planned after SOC 2 completion.

Webhook notifications

Platform

Outbound webhooks on policy change, high-denial-rate alerts, and IDP sync failures. Configurable per-org with HMAC signing.

EU AI Act audit evidence export

Compliance

One-click export of Annex III evidence pack: policy version history, retrieval decision log, classification coverage report, and access revocation audit trail.

Exploring

Under consideration — customer signal shapes prioritization.

Self-host (full stack)

Deployment

Complete Gateco stack deployable in your own infrastructure. No Gateco telemetry. Target Q3 2026 waitlist.

Open-source Python SDK

Developer

Open-source the gateco-sdk core under a permissive license. Server-side product stays closed; client SDK becomes community-owned.

AuthZEN compliance

Interop

Implement the OASIS AuthZEN interoperability standard so Gateco can interoperate with AuthZEN-compatible policy engines.

GitOps policy bundles

Policy

Declare policies as YAML files in a Git repo. Gateco watches the repo and applies changes on merge. Pairs with existing policy version history.

Cerbos compatibility layer

Interop

Allow teams using Cerbos PDP for application authorization to delegate retrieval-layer decisions to Gateco — shared principal context, no double sync.

Multi-region EU data plane (SaaS)

Compliance

Hosted EU data plane where policy evaluation, audit logs, and connector credentials all stay in the EU region for GDPR data residency without Private Data Plane deployment.

Shape the roadmap

Roadmap priorities are driven by customer signal. If something on the Exploring column is blocking your adoption, tell us — it moves up the queue.