What a licence covers today. And what is still on the roadmap.
Other vendors sell the sensor and then sell the platform that makes the sensor useful - SIEM licence, log retention tier, correlation add-on, managed detection subscription, analyst dashboard, executive reporting module, each a separate line item with its own contract. The honest answer to that is not to claim we have already shipped the platform. Detection and decontamination run on each protected machine, and that is where the findings stay: structured JSON scan and quarantine reports under /var/echoron, plus the service logs and the systemd journal, read on the device with your own log tooling. Nothing is reported off the machine to Echoron today. The dashboard carries your installers, device and licence registration, certification orders, sealed report downloads and billing.
So, plainly: there is no fleet reporting into the dashboard today, no immutable audit retention, no cross-device correlation, no continuous fleet observation by Echoron, no SIEM export and no executive or board reporting pipeline. All of that is on the roadmap, with no date committed, and none of it is priced into the tiers. The tiles below keep the two apart. Content inspection applies to unencrypted traffic. No product that sits on the network can read inside an encrypted session - ours included.