# CapchaCloud — product direction

High-level direction for customers and partners. The same text is available as [Roadmap](https://capchacloud.com/roadmap.html) and [roadmap.md](https://capchacloud.com/roadmap.md). Detailed engineering and certification sequencing are maintained separately and are **not** published on this page.

Timelines are indicative and change with demand and capacity. For security and compliance posture, use the [Trust Center](https://capchacloud.com/trust-center.html) and [Compliance hub](https://capchacloud.com/compliance.html). Nothing here is a certification claim or a legal commitment.

---

## Generally available

- Hosted OAuth sign-in, consent capture with integrity-oriented exports, and Cloudflare Turnstile, delivered on Cloudflare’s network.
- Operator console, embeddable widget, per-tenant API keys, outbound webhooks, and subscription tiers (**Free**, **Starter**, **Pro**, **Business**) billed in **auth credits** (authenticated sessions), as on the [Pricing](https://capchacloud.com/pricing.html) page.

---

## Near term (themes)

- **Teams and access** — multiple users per organization with clearer roles and audit-friendly patterns.
- **More identity providers** — additional enterprise and developer IdPs where enrollment and policy allow.
- **Developer experience** — clearer HTTP APIs, examples, and more robust webhook delivery and visibility.
- **Email-based authentication** — flows such as magic links where they fit the product, gated so abuse and deliverability stay controlled.

---

## Mid term (themes)

- **Trust and assurance** — structured work toward SOC 2–style controls and evidence for buyers who need it; scope follows engagement and funding.
- **Optional product extensions** — capabilities that need extra care (for example optional media or assisted review), shipped only with strict defaults and retention controls.
- **Enterprise workflows** — procurement-friendly paperwork, security questionnaires, and contracting patterns.

---

## Longer horizon

- Deeper integrations, broader regulated-industry fit, and additional compliance programs **only** with clear customer pull and resources to execute—without premature marketing claims.

---

## RFPs and procurement

Rely on published policies, the Trust Center, Compliance hub, and [Support](https://capchacloud.com/support.html). If a capability or attestation is not published or contractually agreed, treat it as **not** committed.
