Roadmap
Preview capabilities Protecto is building next: context-based access control, governed RAG over MCP, and dynamic runtime authorization.
What's coming
The capabilities below are in active development. They are not yet generally available, and their interfaces may change before release. Use this page to understand what's coming and how it fits into the rest of the Protecto platform.
CBAC (Context-Based Access Control)
Turn a plain-English sensitivity policy into an enforceable control that reads any document and splits it into a clean copy and a sensitive extract, based on context rather than regex.
GPTGuard MCP
Secure RAG server exposed over the standard MCP surface. Ingests and protects a document repository, then serves governed, policy-filtered retrieval to any MCP-compatible agent.
Dynamic Auth
Runtime, context-aware authorization in place of static permissions. Scoped, time-bound auths replace standing credentials for agentic workflows.
These features are in preview. Functionality, endpoints, and interfaces described here are subject to change before general availability.