Where FormaOS is
headed next
22 items across 7 categories: what has shipped, what is being built now, and what is still being evaluated. Last reviewed August 2026.
Roadmap at a glance
Where the product stands today. Reviewed August 2026.
Everything on the roadmap
22 items across compliance, security, integrations, platform, reporting, automation, and collaboration.
Shipped
Live in production and available to all users.
AI-Assisted Control Mapping
ShippedHigh impactMachine learning model suggesting control mappings across frameworks based on semantic similarity.
Compliance Q&A Assistant (general-purpose)
ShippedStateless AI Q&A for compliance vocabulary and policy drafting. Org-grounded retrieval is on the roadmap, not in this release.
GRC API (Public)
ShippedHigh impactRESTful API with full CRUD operations, webhooks, and SDK support for custom integrations.
Real-Time Compliance Dashboard
ShippedLive dashboard with WebSocket-powered updates, customizable widgets, and TV mode.
GitHub & GitLab Integration
ShippedPull request compliance checks, code review evidence collection, and SDLC compliance tracking.
Bulk Import & Migration Tools
ShippedCSV/XLSX import wizards for controls, evidence, and organizational data with field mapping.
Audit Readiness Score
ShippedHigh impactAggregated audit readiness metric with actionable recommendations and timeline estimates.
Notification Rules Engine
ShippedConditional notification routing with escalation chains, digest batching, and quiet hours.
In Progress
Actively under development with a target release date.
Multi-Region Data Residency
In ProgressHigh impactDeploy compliance data to US, EU, and APAC regions with full jurisdictional isolation.
Mobile Companion App
In ProgressHigh impactiOS and Android app for evidence capture, task management, and compliance alerts on the go.
HRIS Integration Hub
In ProgressConnect BambooHR, Workday, and Rippling for automated personnel compliance tracking.
Planned
Scoped and scheduled for an upcoming development cycle.
Advanced Reporting Engine
PlannedHigh impactCustom report builder with drag-and-drop widgets, scheduled delivery, and multi-format export.
SAML 2.0 + OIDC Hybrid SSO
PlannedSupport both SAML 2.0 and OpenID Connect for maximum identity provider compatibility.
Continuous Control Monitoring
PlannedHigh impactReal-time monitoring of technical controls with automated drift detection and alerting.
Custom Framework Builder
PlannedCreate bespoke compliance frameworks with custom controls, evidence mappings, and scoring weights.
AWS Config Integration
PlannedHigh impactAutomated compliance monitoring for AWS infrastructure using Config rules and conformance packs.
Exploring
Under evaluation based on customer demand and feasibility.
Evidence Auto-Collection via Cloud APIs
ExploringHigh impactScheduled API pulls from cloud providers and security scanners to automatically collect and update compliance evidence.
Multi-Tenant Audit Portal
ExploringRead-only portal for external auditors with time-limited access and scoped visibility.
Vendor Risk Management
ExploringHigh impactAssess, monitor, and track third-party vendor compliance posture with questionnaires and evidence collection.
SOC 2 Type II Automation
ExploringHigh impactAutomated evidence collection for SOC 2 Type II continuous monitoring requirements.
Privacy Impact Assessments
ExploringStructured DPIA and PIA workflows with template library and stakeholder review chains.
Compliance Training Module
ExploringBuilt-in training management with assignment, tracking, and certification evidence collection.
Where we're investing
Where the work sits across categories, and how much of each has already shipped.
Built with transparency
How the product is planned, built, and released, and what you can expect when something changes.
The roadmap is public
This page is the roadmap. Items that stall stay visible with their status changed rather than disappearing.
Priorities you can question
What gets built next is driven by regulatory change and by what evaluators and users ask for. If something here is in the wrong order for you, say so.
Every change is written down
The changelog records what shipped and why, including the things that were quietly broken before they were fixed.
Security work comes first
Security fixes take priority over feature work, and every release runs automated security and accessibility checks before it goes out.
Semantic Versioning
We follow SemVer strictly. Breaking changes only in major versions with migration guides and extended support.
Notice before things change
Breaking changes and deprecations are announced in the changelog and by email before they land, not after.
Have a feature request?
If something on this list is in the wrong order for your compliance program, or missing entirely, tell us. Requests from regulated operators carry the most weight.
