2 min read Updated July 23, 2026

Known Production Gaps

Tamandua is not product-ready and is not authorized for broad external capability claims. The following gaps control stronger language.

LaneCurrent stateRemaining evidence
Core EDRAvailable code / Advanced alphaClosure, preflight and dispatch gates; platform release evidence; tenant isolation; repeatable response and rollback validation
AutoXDRPilotComplete correlation, approval, audit, timeout, dry-run and rollback paths; no autonomous-response claim
AI Runtime SecurityExperimentalDurable evidence/receipt path, trusted replay, PostgreSQL/RLS, KMS and shared AutoXDR storyline/investigation proof
App GuardPlanned / Design partnerG1 signed physical ingestion/anti-replay; G2 hostile+clean efficacy; G3 iOS XCFramework; G4 release packet; G5 classification of 100% of scenario/platform pairs as detected, degraded, unsupported or bypassed, with no omitted failures and no vendor-parity inference

App Guard specifics

Local source, emulator, unsigned APK, static or synthetic evidence does not prove production runtime protection. The site must not imply an operational uploader, no-code shielding, binary rewriting, protected-build delivery, GA or vendor parity.

Licensing and offer gaps

  • Open source applies to identified components only.
  • Managed App Guard is closed commercial scope.
  • Limited Free and Pro are planned; quotas, eligibility, pricing and service levels are TBD.
  • Enterprise is negotiated and remains subject to the technical maturity of the selected lane.
  • No free-forever promise is made.

Other known gaps

macOS release signing/notarization, mobile credentials and physical evidence, production ML training/holdout quality, packet-level NDR, autonomous response, CSPM and marketplace/governance surfaces remain separate validation tracks. A local smoke or roadmap mapping is not production truth.