Product Roadmap

Where we're headed.

Kompflow started with the FTC Safeguards Rule and IRS Publication 4557 because that's what CPA firms need most. Here's what's next for CPA firms, partners, and the adjacent verticals we're heading toward.

About this page.We try to give you honest signals, not hard commitments. Dates below are targets, not promises. If something we ship matters to your renewal, audit, or decision, we'll tell you directly before you count on it.

Shipping soon

Next 90 days

Dated items we're actively building and expect to land in the near term.

Vendor Assessment

May 2026PremiumCPA firms

A dedicated workflow for tracking and assessing your firm's vendors with data-flow context, DPA/contract tracking, and a risk score for each. Replaces the current vendor section inside Data Inventory with a first-class module.

Setup Doc Intake improvements

Ongoing

Continued polish on the intake wizard for faster, more confident firm setup.

On the roadmap

Next 6 months · quarter-level targets

Themes we're investing in next. Quarter targets, not committed ship dates.

For CPA firms

Tabletop Exercise scenario packs

Q3 2026Premium

We give you the scenario pack, the facilitator script, and the follow-up template, scaled to your firm's size and team roles. You run the drill; we document it for your compliance file. No consultant needed.

Light vulnerability scanning

Q3/Q4 2026Premium

A light external scan of your firm's public footprint: DNS records, exposed services, expiring certificates. No agent to install, no network changes. Catches the misconfigurations that kill a cyber insurance renewal.

Framework coverage beyond FTC + IRS

Rolling · H2 2026

Our governance engine is framework-adaptable. We're adding new frameworks as our customers need them, with professional services as our focus. Priority candidates include frameworks commonly asked about during client security reviews.

For partners (MSPs and vCISOs)

Partner portal depth

Ongoing

Continued expansion of reporting, team workflows, and cross-client decision tooling.

White-label enhancements

Target H2 2026

White-label capability for MSPs and vCISOs delivering Kompflow as part of a managed service. On the roadmap, not currently shipping.

Under consideration

Signal-only · no dates

Directions we're listening to and exploring. Not committed, not scheduled. We'll promote items into “On the Roadmap” as the signal strengthens.

Adjacent verticals

Kompflow was built for CPA firms first. Our governance engine adapts cleanly to other professional-services verticals with similar regulatory and insurance pressures. Order of exploration:

  1. 1. Law firms: similar size band, similar cyber insurance dynamics, growing client-security-questionnaire pressure
  2. 2. Wealth advisors / RIAs: SEC regulatory overlay on top of the same core governance needs
  3. 3. Insurance brokers: the firms helping CPAs buy cyber insurance often need governance programs of their own

None of these are shipping commitments. We're listening to early interest; we'll invest where the signal is strongest.

Carrier partnerships

The Insurance Gap Assistant is carrier-agnostic today. We're open to direct relationships with cyber insurance carriers, but only in a way that keeps the product honest: you choose who you work with, and a carrier partnership never narrows your options.

Deeper integrations

Microsoft 365 is our active auto-sync integration today. Additional integrations (other identity providers, common CPA software) are under consideration. We're prioritizing based on where manual data entry hurts most.

Autonomous-agent capabilities

Parts of the product use AI to surface decisions and draft documents today. Over time we expect AI to do more of the proactive monitoring work: watching for changes across your firm's compliance posture and flagging what needs your attention. We'll build this conservatively, with human review in the loop, and we'll tell you exactly what's automated before we automate it.

What's not on the roadmap

Just as useful as knowing what's coming.

We're not becoming a security tool.

Firewalls, EDR, network monitoring. That's what your MSP handles. Kompflow handles governance: the written plans, the documented decisions, the audit trail. Good partnerships with MSPs are how we grow, not by competing with them.

We're not an enterprise GRC platform.

We're built for small and mid-size professional-services firms, 1 to 50 employees as our primary target, with room to serve larger firms that want the same simplicity. If you need a platform designed for Fortune 500 risk teams, we're probably not your fit.

We're not ads-supported, and we don't sell your data.

Ever.

How we update this page

  • Quarterly, around each quarter's end.
  • When we ship something in the “Shipping soon” bucket.
  • When we move something from “Under consideration” to “On the roadmap.”

If a capability you need for a specific deadline is on this page and you want confirmation on timing, reach out. We'd rather tell you the honest answer than have you read tea leaves.

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy