Product scope & evolution

Show the ambition. Never disguise the roadmap as today’s product.

The approved LLD deliberately freezes V1 around a sellable Windows/ransomware investigation slice. Future evidence sources should be driven by pilot feedback and governed by ADR, security, compatibility and licensing review.

SCOPE DISCIPLINE = TRUST
V1 product core

Upload → Process → Normalize → Attack Story → Ask → Proof → Confirm → Report

BASELINE
Build core
Prove workflow
Harden pilot
Then expand
V1 architecture baseline

What belongs in V1

  • Windows/ransomware-oriented investigations.
  • GUI case workspace, customers/tenants, assets, evidence, findings and reports.
  • Resumable evidence upload, server-side hashing, immutable registration and processing status.
  • OpenRelik as first forensic workflow/orchestration adapter.
  • Plaso-compatible timeline parsing and Timesketch search/timeline backend.
  • OCSF-aligned normalization plus forensic provenance envelope.
  • Entity/relation correlation and clickable Attack Story.
  • DFIQ-inspired Investigation Packs and questions.
  • AI via allowlisted tools, deterministic confidence, proof-linked claims and evidence gaps.
  • Proof Ledger, audit log, human validation and report generation.
  • MSSP-friendly organization/customer/case hierarchy.
Not V1

Do not market these as available V1 features

  • Proprietary endpoint agent, disk imager or memory-acquisition agent.
  • Replacement for Magnet, FTK, X-Ways or Velociraptor acquisition capability.
  • Mobile forensics.
  • Full cloud DFIR.
  • Packet-capture analytics.
  • Malware sandboxing.
  • A new SIEM, SOAR or threat-intelligence platform.
  • Mandatory Kubernetes deployment.
  • Dedicated graph or vector database.
  • Autonomous remediation or AI-triggered destructive actions.
How expansion should happen

Pilot feedback first. Developer curiosity second.

The LLD explicitly states that once the 10-minute demo path is stable, feature expansion should stop and customer demos should begin. Pilot feedback determines the next evidence source.

Future consideration

Additional evidence adapters

Each new adapter requires documented source/version assumptions, golden fixtures, raw-field preservation, timezone tests, provenance locators, adversarial security tests, performance benchmark, license/SBOM entry and UI/error mapping.

Requires ADR / review

Cloud, mobile and acquisition integrations

These may be future directions, but the LLD does not promise dates or specific commitments. Architecture, security, license and customer demand must drive any decision.

Governed expansion

AI action capability

Any new write/action capability for AI is an ADR trigger. Autonomous remediation remains explicitly outside the current product baseline.

“Everything else is an adapter or an Investigation Pack.”

Architecture baseline principle after the evidence-to-confirmed-finding vertical slice is proven