Roadmap
Nothing here is marked finished. That is not modesty.
A phase closes only when its definition of done passes and the result is recorded as a measurement. By that rule, every phase of this project is still open — and saying so is more useful to you than a row of green ticks would be.
The three states
Most roadmaps have two states. The third is the one that matters.
Built and proven
The code exists and its behaviour has been measured, or is deterministic enough to be tested exhaustively.
Built and unproven
The code exists, it is tested in isolation, and its real-world effectiveness has never been measured. This is where most of the agent lives today.
Not built
Described in the plan, absent from the product.
The second category is the honest one, and it is the one that disappears from every competitor's marketing.
Built and proven
What works today.
- A complete browser shell: tabs and groups, bookmarks, history, downloads with quarantine, uploads, find-in-page, profiles, a deterministic address bar
- The agent end to end: command palette, live console, runtime, tool plane, browser tools — with four cloud providers and fully offline local inference
- The security kernel: policy classification, risk tiers, plan-scoped grants, human-in-the-loop, credential vault and broker, egress firewall, prompt-injection screening, event journal
- Network privacy with real tunnels: userspace WireGuard and Tor, chained Tor over VPN, per-tab and per-group binding, a fail-closed kill switch verified end to end against the built application
- Nine first-party extensions, and an MCP client
- English and Turkish at full parity, with a dedicated Turkish keyboard pipeline
tepegoz-verify, a standalone proof-of-run verifier
Built, not proven
The entire agent competence programme.
Thirteen phases, all with capability code landed, all still owing a measurement.
The benchmark protocol is written and pre-registered — including a withdrawal clause stating the claim dies the moment it stops reproducing — and the runs have not been paid for.
Three capabilities ship deliberately switched off, and one phase records a measured refutation of its own original design rather than quietly redesigning around the failure.
Also here: proof-of-run notarisation, transaction mandates, verifiable policy bundles, governed agent endpoints, the recipe compiler, the Turkish public-service classifier and the supply-chain gate — each a decision layer that is landed, reviewed, documented, and not yet wired to a live call.
Not built
Described in the plan, absent from the product.
- Parallel multi-tab execution
- Durable checkpoint, resume and hand-off between agents
- Long-term task memory
- Official-API integration adapters
- Google Safe Browsing
- An MCP server surface
- Fingerprinting resistance
- Chrome MV3 extension support
- The optional managed cloud tier and encrypted sync
- macOS and Linux as first-class targets
Blockers
Named by kind, not lumped into "we need funding".
| Blocker | What it actually needs |
|---|---|
| The agent benchmark baseline | API spend — roughly $550–780 for the full sweep |
| The head-to-head comparison | Rival subscriptions, about $60/month — not API credit |
| The local-model phase | Downloaded model weights, not tokens |
| The independent security audit | An outside reviewer, and the budget for one |
| Phase 0 closing | A watched CI run, and the suite executing on macOS at least once |
Why publish this
Because the alternative is a number nobody can reproduce.
And this category already has several.
An agentic browser makes an unusually large promise: that it can act for you on pages that matter. The only responsible way to make that promise is to be explicit about which parts are demonstrated, which are merely built, and which are still a sentence in a plan.
All of it is maintained in the repository, per phase, with the evidence or the absence of it: phase index · known issues · changelog