What a licence covers today. And what is still on the roadmap.

Detection and decontamination run on the protected machine, and that is where the findings stay. Every scan, every quarantine action and every certification is written on the device itself - structured JSON reports under /var/echoron plus the service logs and the systemd journal - and you read them there, with your own log tooling. Nothing is reported off the machine to Echoron today. The dashboard gives you your installers, device and licence registration, certification orders and billing.

We are not going to describe a fleet intelligence platform we have not shipped. There is no fleet reporting into the dashboard today, no immutable audit retention, no cross-device correlation, no continuous fleet observation, no SIEM export and no executive or board reporting pipeline. Those are on the roadmap, with no date committed. The tiles below separate the two honestly. Content inspection applies to unencrypted traffic. No product that sits on the network can read inside an encrypted session - ours included.

INCLUDED TODAY
Per-Machine Findings on the Device
Sentinel writes what it finds where it finds it. Scan and quarantine results land on the protected machine as structured JSON reports, alongside the service logs and the systemd journal. You read them on the device, or pull them with whatever log tooling you already run.
INCLUDED TODAY
Service Logs and Local Retention
The Echoron services log to the journal like any other system service, so retention, rotation and shipping follow your own host policy. There is no Echoron-side retention tier to buy, because there is no Echoron-side retention.
INCLUDED TODAY
Installers and Order Management
The dashboard is where you get your installers, register devices and licences, order Convergence Certifications, download sealed reports and manage billing. That is what it does today; it is not a fleet console yet.
INCLUDED TODAY
Sealed Certification Reports
Each Convergence Certification returns a cryptographically sealed, independently verifiable report naming every pattern detected and what the rewrite removed. A report with no findings means nothing was detected by those methods, which is not proof the device is clean.
ON THE ROADMAP
Fleet Reporting to the Dashboard
Protected machines do not send findings to Echoron today. Reporting per-device findings up into the dashboard for a fleet-wide view is on the roadmap. No date is committed, and nothing here is priced on it.
ON THE ROADMAP
Immutable Audit Retention
Append-only, tamper-evident retention of security events for HIPAA, PCI-DSS or SOC 2 evidence is on the roadmap. Today the only audit trail is the local reports and service logs on each machine, retained under your own policy.
ON THE ROADMAP
Cross-Device Correlation
Correlating a coordinated attack across several machines requires findings from several machines in one place, which is exactly what we do not do yet. Detection today is per-machine. Correlation is on the roadmap.
ON THE ROADMAP
Continuous Fleet Observation
The services run continuously on each machine they are installed on. What does not exist is continuous observation of your fleet by Echoron, or a live fleet view for you. That is on the roadmap.
ON THE ROADMAP
SIEM Export
There is no SIEM export today. Structured export into whatever SIEM you or your MSP already run is on the roadmap. Until then, the local JSON reports and journal entries are what your own collector can read.
ON THE ROADMAP
Executive and Board Reporting
There is no reporting pipeline that produces a quarterly posture, incident or risk summary for you today. Executive and board reporting is on the roadmap. The sealed certification reports you already receive are yours to use in the meantime.