The July 2026 platform release: Ontology, Apps, and CVE intelligence
Shipped as a single release across July 2026. This is the release in which the platform stopped only answering questions about the external estate and began acting on them.
Ontology: the model arrives built
A pre-built, continuously refreshed connected model of the organisation's external digital ecosystem: 26 object types across four provenance rings (Observed, Enriched, Derived, Asserted), 20 relationship types, and explicit provenance on every element. Populated from day 1 by the platform's own external observation; there is no modelling engagement.
Apps: no-code automation with Slack and Jira built in
A drag-and-drop App Composer with 8 building-block types, 6 trigger types and 12+ ready-made templates. AI can draft an App from a plain-language description. Apps notify and act across five channels: intelligence feed, in-app, email, Slack and Jira, both built in. Every action is recorded in the App actions ledger with timestamp, App, action, target and outcome.
MCP for AI assistants, alongside A2A
Eight read-only MCP tools with an OAuth sign-in flow, so an AI assistant such as Claude can answer questions grounded in the organisation's live estate. Nine published A2A agent skills on the open Linux Foundation standard cover the same ground for deterministic automation, plus a conversational analyst skill. Both are consumption interfaces only: read-only, per-organisation, off by default. Neither can modify data in the platform. Acting on what the platform finds is the job of Apps, which run inside the platform under the same isolation and record every action in the App actions ledger.
Framework-agnostic compliance reporting
The compliance engine is framework-agnostic. Controls can be evaluated against any framework, including a customer's own internal policy, rather than a fixed supported list. NIST CSF, ISO 27001, SOC 2, CIS Controls, HIPAA and GDPR remain recognised examples, not a ceiling.
