Skip to content

Product status

This page is the source of truth for what you can use now.

Status terms

  • Available — A user can use the capability now in its stated scope.
  • Built — The capability is implemented and tested. It is not available in a supported production path unless this page says that it is deployed.
  • Planned — The capability has an accepted design but is not built.
  • Not implemented — The capability does not exist.

Some rows use production proof. This means that GaugeWright has operated and verified the capability in production for a named proof. It does not mean that the capability is generally available or that all users can configure it without GaugeWright support.

Important data-flow fact

GaugeDesk does not run the model on your device. A run sends the prompt and the admitted context to the configured model provider. The provider sees that data in plaintext.

For a local run, you select and authorize the provider. For a public deployment, the deployment uses the exact hosted credential that its owner selected. GaugeWright does not provide confidential inference today.

Read Where your data goes before you use sensitive data.

Capability table

Capability Status Current scope
Local desktop workbench: build, run, and review Available Runs on the user's computer. Model inference is remote.
Self-federation across devices Available Verified with the product protocol and test environments.
Cross-party federation Built The protocol and relay path are tested. General cross-party service availability is not established.
Append-only audit log and export Available The application event log is append-only. Audit export is implemented.
Central production security-event monitoring Available Azure Monitor and Log Analytics collect metadata-only production events. Alert delivery was exercised on 2026-07-29.
Linux and macOS method isolation Available Uses the supported operating-system sandbox.
Windows method isolation Planned Windows does not have the same kernel isolation.
Local encryption at rest Available Uses AES-256-GCM envelope encryption.
KMS-backed encryption Built The Key Vault adapter and recovery path are tested. Availability depends on the managed deployment.
Package and release lifecycle Built The immutable package and release controls are implemented.
Output review and release Built Review and approved transfer are implemented and tested.
Enterprise OIDC, SAML, SCIM, and RBAC Built The code and vendor conformance paths are tested. Customer rollout is not generally available.
GaugeDesk Administration Built The shared, capability-gated management environment is implemented.
Public Embeddable Panels runtime Production proof The Theory A deployment runs on the production edge. General self-service availability is not established.
Publish, preview, update, and monitor controls Built Production infrastructure exists. The complete no-founder-intervention path is still being proved.
Public-session collection Built and deployed Release-declared collections can be sealed and deposited. The complete author-to-visitor-to-review journey is not yet accepted as self-service.
Attested confidential-VM compute Built The verifier and key-release seams are tested. No generally available attested service exists.
Confidential inference Planned The model provider remains in the trust boundary.
Native iOS and Android clients Built Signed CI and hosted-device journeys pass. Store distribution, carrier push, and physical-device proof remain.
GaugeDesk Plus Built The USD 12 per-seat monthly plan is defined. General commercial availability is not stated here.
SBOM and build provenance Available Release workflows generate SPDX SBOMs and OIDC provenance attestations.
Dependency, secret, and static scanning Available Scheduled and change-triggered checks run in active repositories.
Privacy notice, DPA, and subprocessor list Available GaugeWright publishes these documents and operates a privacy request path.
Independent penetration test Planned No independent penetration test is complete.
SOC 2 or ISO 27001 certification Planned GaugeWright does not claim either certification.
Contractual uptime SLA Not implemented The hosted control plane is single-node. Tested recovery is not high availability.

Public Embeddable Panels

GaugeWright operates one production proof for Theory A. The public data plane uses edge routing, one deployment record, and one runtime for each visitor session.

Publication creates a signed, immutable release. A session stays pinned to the release that it opened. A later update activates a new release for new sessions. The author's computer, GaugeDesk process, and project Home are not in the public serving path.

The current production proof includes:

  • exact website-origin checks;
  • session-owned durable execution;
  • one WebSocket event stream for browser panels;
  • direct model-provider streaming from the privileged runtime boundary;
  • exact credential-reference and credential-class checks;
  • session, spend, and use limits;
  • immutable release pinning;
  • retention bounds;
  • release-declared, sealed collection deposits; and
  • owner-authorized collection drain into local quarantine.

The following work is not yet accepted as a general self-service capability:

  • completion of the full publish-to-collection journey without founder action;
  • broad customer onboarding and support;
  • a published general-availability commitment; and
  • an uptime SLA.

See Embedding an agent.

Security and operational limits

  • The model provider receives prompts and admitted context in plaintext.
  • Windows does not have the Linux/macOS method-isolation sandbox.
  • The hosted control plane is concentrated on one Azure virtual machine.
  • GaugeWright has tested backup restore and uses internal recovery targets of a 24-hour recovery point and an 8-hour recovery time. These targets are not a customer SLA.
  • GaugeWright is founder-operated. Independent approval and separation of duties are not available.
  • GaugeWright has no completed independent penetration test, SOC 2 report, or ISO 27001 certification.

See Known limitations and Security and trust.