Skip to content

Roadmap

Nothing here is marked finished. That is not modesty.

A phase closes only when its definition of done passes and the result is recorded as a measurement. By that rule, every phase of this project is still open — and saying so is more useful to you than a row of green ticks would be.

The three states

Most roadmaps have two states. The third is the one that matters.

Built and proven

The code exists and its behaviour has been measured, or is deterministic enough to be tested exhaustively.

Built and unproven

The code exists, it is tested in isolation, and its real-world effectiveness has never been measured. This is where most of the agent lives today.

Not built

Described in the plan, absent from the product.

The second category is the honest one, and it is the one that disappears from every competitor's marketing.

Built and proven

What works today.

  • A complete browser shell: tabs and groups, bookmarks, history, downloads with quarantine, uploads, find-in-page, profiles, a deterministic address bar
  • The agent end to end: command palette, live console, runtime, tool plane, browser tools — with four cloud providers and fully offline local inference
  • The security kernel: policy classification, risk tiers, plan-scoped grants, human-in-the-loop, credential vault and broker, egress firewall, prompt-injection screening, event journal
  • Network privacy with real tunnels: userspace WireGuard and Tor, chained Tor over VPN, per-tab and per-group binding, a fail-closed kill switch verified end to end against the built application
  • Nine first-party extensions, and an MCP client
  • English and Turkish at full parity, with a dedicated Turkish keyboard pipeline
  • tepegoz-verify, a standalone proof-of-run verifier

Built, not proven

The entire agent competence programme.

Thirteen phases, all with capability code landed, all still owing a measurement.

The benchmark protocol is written and pre-registered — including a withdrawal clause stating the claim dies the moment it stops reproducing — and the runs have not been paid for.

Three capabilities ship deliberately switched off, and one phase records a measured refutation of its own original design rather than quietly redesigning around the failure.

Also here: proof-of-run notarisation, transaction mandates, verifiable policy bundles, governed agent endpoints, the recipe compiler, the Turkish public-service classifier and the supply-chain gate — each a decision layer that is landed, reviewed, documented, and not yet wired to a live call.

Not built

Described in the plan, absent from the product.

Planned

  • Parallel multi-tab execution
  • Durable checkpoint, resume and hand-off between agents
  • Long-term task memory
  • Official-API integration adapters
  • Google Safe Browsing
  • An MCP server surface

Planned

  • Fingerprinting resistance
  • Chrome MV3 extension support
  • The optional managed cloud tier and encrypted sync
  • macOS and Linux as first-class targets

Blockers

Named by kind, not lumped into "we need funding".

What each blocked item actually needs
BlockerWhat it actually needs
The agent benchmark baselineAPI spend — roughly $550–780 for the full sweep
The head-to-head comparisonRival subscriptions, about $60/month — not API credit
The local-model phaseDownloaded model weights, not tokens
The independent security auditAn outside reviewer, and the budget for one
Phase 0 closingA watched CI run, and the suite executing on macOS at least once

Why publish this

Because the alternative is a number nobody can reproduce.

And this category already has several.

An agentic browser makes an unusually large promise: that it can act for you on pages that matter. The only responsible way to make that promise is to be explicit about which parts are demonstrated, which are merely built, and which are still a sentence in a plan.

All of it is maintained in the repository, per phase, with the evidence or the absence of it: phase index · known issues · changelog