Skip to content
Trellis

Roadmap

What is next, and what we will not build

No dates, because we would miss them and you would remember. The order is real and it changes when customers tell us it should.

How this gets decided

Every founder call ends with the same question: what did you have to do by hand this week. The answers move things up this page, and they have twice already.

Shipping now

Evidence pack export

One archive with every piece of evidence, named the way an auditor's request list names it, with the control it satisfies on the cover sheet.

Security questionnaire answers

Paste the questionnaire a customer sent. Trellis answers from evidence you already have and flags every answer it could not ground.

Next

ISO 27001 Annex A

Mapped so evidence collected for SOC 2 counts once and applies to both. Growth plan.

Read-only auditor view

A link your auditor opens to see the evidence pack without an account and without edit rights.

Connectors for identity and code hosting

Read-only pulls from the identity provider and the code host, so access and change evidence refresh themselves.

Later

Continuous drift checks

Tell you when a control that used to pass stopped passing, before the auditor samples it.

Self-hosted model option

For teams who cannot send policy text to a third party. The open model candidate in our routing table exists for this.

HIPAA and GDPR Article 32

Two more mappings over the same evidence.

Not doing

Three things we have decided against

A roadmap without this section is a wish list.

Becoming your auditor. It is a conflict of interest and it is a licensed activity.

Selling a badge for your website that we made up.

Agent access that changes your production settings for you. Trellis reads and drafts. You decide and act.

Something missing that would change your mind

Tell us. It is how the top of this page gets decided.