Roadmap stages
The public roadmap progresses from the working transaction-protection foundation toward a governed trust layer.
Roadmap items describe direction, not a commitment to availability or timing. Provider access, partner scope, security testing, legal review, and audit outcomes determine delivery.
Status map
Controlled-demo acceptance path
The published controlled demonstration shows three deterministic scenarios:- Clean incoming funds produce
ALLOW. - Unclear or degraded provenance produces
REVIEWwith an explainable matched rule. - High-confidence illicit exposure produces
BLOCKwith source and freshness.
Delivery gates
- Approve provider licensing, credentials, retention, and attribution before enabling external data.
- Review intelligence before policy, and policy before SafeReceive integration.
- Preserve API compatibility or version the contract deliberately.
- Link implementation pull requests to the canonical roadmap issue.
- Require qualified ownership, tests, testnet verification, and independent security review before material Escrow upgrades or deployment.
- Confirm production authentication, tenant isolation, retention, pricing, billing, and treasury controls before onboarding real business customers.
- Verify the published support mailbox and connect an approved ticket intake before promising case tracking or response targets.
- Validate every named institution or exposure claim against an authorised source and preserve its reference and freshness.
Review product status
See the confirmed status of each Cardinal capability.

