What a licence covers today. And what is still on the roadmap.

Other vendors sell the sensor and then sell the platform that makes the sensor useful - SIEM licence, log retention tier, correlation add-on, managed detection subscription, analyst dashboard, executive reporting module, each a separate line item with its own contract. The honest answer to that is not to claim we have already shipped the platform. Detection and decontamination run on each protected machine, and that is where the findings stay: structured JSON scan and quarantine reports under /var/echoron, plus the service logs and the systemd journal, read on the device with your own log tooling. Nothing is reported off the machine to Echoron today. The dashboard carries your installers, device and licence registration, certification orders, sealed report downloads and billing.

So, plainly: there is no fleet reporting into the dashboard today, no immutable audit retention, no cross-device correlation, no continuous fleet observation by Echoron, no SIEM export and no executive or board reporting pipeline. All of that is on the roadmap, with no date committed, and none of it is priced into the tiers. The tiles below keep the two apart. Content inspection applies to unencrypted traffic. No product that sits on the network can read inside an encrypted session - ours included.

INCLUDED TODAY
Per-Machine Findings on the Device
Sentinel writes what it finds where it finds it. Scan and quarantine results land on the protected machine as structured JSON reports, alongside the service logs and the systemd journal. Your own collectors can read them; Echoron does not.
INCLUDED TODAY
Service Logs and Local Retention
The Echoron services log to the journal like any other system service, so retention, rotation and shipping follow your existing host and log policy. There is no Echoron-side retention tier to buy, because there is no Echoron-side retention.
INCLUDED TODAY
Installers and Order Management
The dashboard is where you get installers, register devices and licences, order Convergence Certifications, download sealed reports and manage billing. That is what it does today; it is not a SOC console yet.
INCLUDED TODAY
Sealed Certification Reports
Each Convergence Certification returns a cryptographically sealed, independently verifiable report naming every pattern detected and what the rewrite removed. A report with no findings means nothing was detected by those methods, which is not proof the device is clean.
ON THE ROADMAP
Fleet Reporting to the Dashboard
Protected machines do not send findings to Echoron today. Reporting per-device findings up into the dashboard for a fleet-wide view is on the roadmap. No date is committed, and no tier is priced on it.
ON THE ROADMAP
Immutable Audit Retention
Append-only, tamper-evident retention of security events for HIPAA, PCI-DSS, SOC 2 or SOX evidence is on the roadmap. Today the audit trail is the local reports and service logs on each machine, retained under your own policy.
ON THE ROADMAP
Cross-Device Correlation
Correlating a coordinated attack across many machines requires findings from many machines in one place, which is exactly what does not exist yet. Detection today is per-machine. Correlation is on the roadmap.
ON THE ROADMAP
Continuous Fleet Observation
The services run continuously on each machine they are installed on. What does not exist is continuous observation of your fleet by Echoron, or a live fleet view for your SOC. That is on the roadmap.
ON THE ROADMAP
SIEM Export
There is no SIEM export today. Structured export into the SIEM you already run is on the roadmap. Until then, the local JSON reports and journal entries are what your own collector can pick up.
ON THE ROADMAP
Executive and Board Reporting
There is no pipeline that generates a quarterly posture, incident or risk summary for you today. Executive and board reporting is on the roadmap. The sealed certification reports you already receive are yours to use in the meantime.