Skip to main content
TruStacks

Product facts

What TruStacks does, and does not do, today.

This page is the canonical list of TruStacks capabilities. Shipped and roadmap items are separated rather than blended, and every entry carries the date it was last checked against the product repository. It exists so anyone evaluating us, human or agent, can ground on one source instead of inferring from marketing pages.

16 shipped5 roadmapOldest entry verified 2026-08-10

Why this page exists. Our own security page once described a shipped capability as roadmap for three months, and published a verification command that could not work, because nothing on the page carried a date or a source. This one does. If you find an entry that is wrong or stale, tell us and we will fix it.

The agent crew

  • The conversational agent an engineer talks to. Reads the repository, the environment profile, and the policy bundle, and routes work to specialists. Never writes code itself.

    Verified 2026-08-10 · SITE_BRIEF.md, refreshed 2026-08-10

  • Emits CI workflow YAML, Dockerfiles, Helm charts, and Argo Application manifests. Reads the platform repository first so customer customizations are preserved rather than overwritten.

    Verified 2026-08-10 · SITE_BRIEF.md, refreshed 2026-08-10

  • Reviews application-repository changes and detects framework and runtime version.

    Verified 2026-08-10 · SITE_BRIEF.md, refreshed 2026-08-10

  • Consults on image scanning, SAST and SCA, secret scanning, and SBOM signing. Returns findings with severity and tool candidates that fit the declared stack. Free at every tier.

    Verified 2026-08-10 · SITE_BRIEF.md, refreshed 2026-08-10

  • Auditor-relevant findings across CC1 to CC9 control families, with evidence hints grounded in the customer's own stack. Paid add-on, Enterprise and above.

    Verified 2026-08-10 · Shipped 2026-05-02 per SITE_BRIEF.md

  • HIPAA, FedRAMP, PCI, ITIL, SRE Specialists

    Roadmap

    Queued. Each ships as a paid Specialist Pack plus a Specialist agent. Not available today.

    Verified 2026-08-10 · SITE_BRIEF.md roadmap section

Languages and frameworks

  • The Code Reviewer detects framework and runtime version across these four. New frameworks ship via community packs rather than a release.

    Verified 2026-08-10 · SITE_BRIEF.md. Confirmation requested from mvp — see MVP_HANDOFF.md request 5.

Policy

  • A signed Rego policy bundle authored by TruStacks. Free at every tier, non-waivable, and the foundation every proposal is checked against.

    Verified 2026-08-10 · SITE_BRIEF.md

  • Customers author their own rules with the trustacks rule new / test / lint / sign CLI and a Coordinator-assisted Rules UI. Overlay rules can only ratchet stricter than the constitution; a linter proves this at compile time.

    Verified 2026-08-10 · SITE_BRIEF.md

  • Agents propose changes as pull requests. A named human merges. There is no configuration flag that creates an autonomous merge path.

    Verified 2026-08-10 · Core product constraint. SITE_BRIEF.md voice rules.

  • Standalone Specialist Packs

    Roadmap

    Paid subscribable Rego bundles for regulatory and specialty domains, purchasable independently of the matching agent. Not available today.

    Verified 2026-08-10 · SITE_BRIEF.md roadmap section, Phase 5.4

Security and supply chain

  • Every published image and the constitution policy bundle are signed via Sigstore keyless OIDC against the release workflow's identity. There is no long-lived signing key, because there is no key. Each release also lands in the Rekor public transparency log.

    Verified 2026-08-10 · Verified live against the registry 2026-08-10: runner image signed at v0.2.12, policy/constitution at v0.2.11, certificate verified against trusted CA certificates.

  • A Software Bill of Materials is attached to each image manifest at build time and enumerates every vendored dependency. Inspectable without asking us for anything.

    Verified 2026-08-10 · Verified live 2026-08-10: docker buildx imagetools inspect returns SPDX for linux/amd64, syft-v1.42.3.

  • An in-toto SLSA build-provenance attestation is attached per platform, carrying the source revision, build type, and build parameters, covered by the same signature as the image.

    Verified 2026-08-10 · Verified live 2026-08-10 against runner:latest. A published SLSA *level* is pending mvp confirmation — see MVP_HANDOFF.md request 1.

  • Agents open pull requests against a separate platform repository. The customer's ArgoCD or Flux deploys what their people merged. Credentials never leave the customer environment.

    Verified 2026-08-10 · SITE_BRIEF.md

  • TruStacks SOC2 (our own)

    Roadmap

    TruStacks does not hold its own SOC2 report yet. The SOC2 Specialist agent helps customers with theirs; that is a different thing and we will not blur the two.

    Verified 2026-08-10 · GTM_PLAN_10M.md gating dependency 1

Where it runs

  • TruStacks emits configuration; the customer runs it on their Kubernetes, their ArgoCD or Flux, their CI, their registry. Source code does not leave the customer environment.

    Verified 2026-08-10 · SITE_BRIEF.md

  • A k3d sandbox with the full agent crew and sample applications, runnable on a laptop. No signup, no credit card.

    Verified 2026-08-10 · Live at /quickstart

  • Cluster Operator with CRDs

    Roadmap

    Phase 5, post-Beta. Not available today.

    Verified 2026-08-10 · SITE_BRIEF.md roadmap section

Commercial

  • Five tiers. Only the Developer price is public today; the rest are quoted. Pricing is a working hypothesis and may change before GA.

    Verified 2026-08-10 · content/pricing.ts, the same source the pricing page renders

  • TruStacks Insights (DORA and SPACE telemetry)

    Roadmap

    Paid add-on, Phase 6, post-GA. Not available today.

    Verified 2026-08-10 · SITE_BRIEF.md roadmap section

Checking rather than reading?

Everything on this page is verifiable. Our images and the constitution bundle are signed and carry build provenance and an SBOM; the commands are on the security page. Agents and crawlers can start from /llms.txt.