Skip to content

Roadmap

Kairo edited this page May 25, 2026 · 1 revision

Roadmap

Kairo follows a phased release plan. Each phase builds on the last without breaking the developer experience established in the previous one.


v1.0 — Foundation

The complete security substrate. Everything required for a production API with full protection.

Layers shipped:

  • Request Membrane (entropy scoring, ghost routes, signed envelopes, behavioral fingerprinting)
  • Runtime Sentinel (taint tracking, canary frames, memory pressure alarms)
  • Trust Lattice (relationship-graph authorization, temporal tokens, step-up auth)
  • Data Shield (field encryption, contextual redaction, poison pills, query injection analysis)
  • Developer Experience Layer (inline coaching, audit mode, override recording)

CLI: kairo new, kairo generate, kairo audit

Database adapters: Prisma, Drizzle, raw pg / mysql2

MCP: @kairo/mcp with kairo_surface, kairo_audit, kairo_explain tools


v1.1 — Intelligence

The Intent Engine and behavioral contract validation. The layer that catches supply chain compromises and insider threats.

New capabilities:

  • Intent Engine — intent declarations as runtime contracts, behavioral drift detection
  • Intent Graph — zero-trust service mesh, automatic graph construction during development
  • Semantic route guards — natural language authorization requirements resolved by the Lattice
  • Behavioral biometrics — browser client SDK, session anomaly detection
  • kairo dashboard — live security budget UI
  • Hot-patch bus v1 — signed patch channel, autoApply support

v1.2 — Hardening

The adaptive defense layer. Everything that activates when the application is under attack.

New capabilities:

  • Hardening Mode — elastic rate limiting, shadow execution, stealth deflection
  • Circuit breaker mesh — behavioral circuit breakers on service-to-service calls
  • Differential privacy on aggregate queries
  • kairo fuzz CLI command — built-in fuzzer
  • kairo surface CLI command — attack surface map in terminal

v2.0 — Ecosystem

Integration, compliance, and edge runtime support.

New capabilities:

  • Mutation drift detection — behavioral comparison between deploys
  • Zero-knowledge proof authentication (optional, tree-shaken when unused)
  • Full @kairo/mcp tool suite — all eight tools
  • OpenTelemetry native integration
  • Security policy export for compliance mapping (SOC 2, ISO 27001)
  • Edge runtime support — Cloudflare Workers, Deno Deploy

What is not on the roadmap

A few things that will not be added regardless of demand, because they would violate the core principle:

Mandatory security patterns. Kairo will never require developers to write code in a specific way to get protection. Security forms around code; code does not form around security.

Silent behavior changes in patches. Hot patches modify framework behavior, not application behavior. A patch will never change what a handler returns or how a model is stored.

Telemetry to Kairo infrastructure. Security event data stays in the application. No events, entropy scores, or behavioral data are transmitted to Kairo's servers.


← MCP Integration · Glossary →

Clone this wiki locally