From 461c6d4840137f8369e8fefed82696cb730a95e4 Mon Sep 17 00:00:00 2001 From: Michael Heller <21163552+mdheller@users.noreply.github.com> Date: Mon, 3 Aug 2026 19:25:27 -0400 Subject: [PATCH 1/3] feat(competitive): product-by-product DevSecOps/PaaS/agentic landscape + ranked gap register MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds a competitive-landscape profile to the operations-domain suite (market/execution lane): - schemas/competitive-landscape.schema.json — competitor entry + severity-tagged beats_us_on - source_inputs/competitive-intel/landscape.v0.yaml — 44 products across paas/idp/supply-chain/ gitops/dep-automation/ai-coding-agent clusters, each with maturity, agent integrations, and ONLY the capabilities where they beat us (web-grounded, sourced 2026-08-03) - tools/validate_competitive_landscape.py — schema + invariant validator - tools/generate_competitive_gap_register.py — projection ranking gaps by severity x frequency - docs/competitive/where-we-stand.md — generated "where we're worse" register (one-sided by design) - profiles/competitive-landscape-profile.v0.yaml — the profile binding it together Top critical gaps: agent-native MCP ops surface (8 ahead incl. Qovery/Port), metric-gated progressive delivery + auto-rollback (Argo/Kargo/Flux/Harness), mature autonomous code review (Copilot ~60M reviews, Claude Code, CodeRabbit, Cursor Bugbot). Our differentiators (fail-closed sealed receipts, self-hosted) are narrow and, per the research, increasingly contested. --- MANIFEST.txt | 6 + docs/competitive/where-we-stand.md | 199 ++++++++++++ .../competitive-landscape-profile.v0.yaml | 62 ++++ schemas/competitive-landscape.schema.json | 99 ++++++ .../competitive-intel/landscape.v0.yaml | 302 ++++++++++++++++++ tools/generate_competitive_gap_register.py | 102 ++++++ tools/validate_competitive_landscape.py | 69 ++++ 7 files changed, 839 insertions(+) create mode 100644 docs/competitive/where-we-stand.md create mode 100644 profiles/competitive-landscape-profile.v0.yaml create mode 100644 schemas/competitive-landscape.schema.json create mode 100644 source_inputs/competitive-intel/landscape.v0.yaml create mode 100644 tools/generate_competitive_gap_register.py create mode 100644 tools/validate_competitive_landscape.py diff --git a/MANIFEST.txt b/MANIFEST.txt index 049fc91a..6e1e21f6 100644 --- a/MANIFEST.txt +++ b/MANIFEST.txt @@ -136,3 +136,9 @@ tools/validate_model_fabric_release_readiness.py tools/validate_operational_exhaust_fusion.py tools/validate_resource_contract_telemetry.py tools/validate_service_desk_metrics.py +schemas/competitive-landscape.schema.json +profiles/competitive-landscape-profile.v0.yaml +tools/validate_competitive_landscape.py +tools/generate_competitive_gap_register.py +source_inputs/competitive-intel/landscape.v0.yaml +docs/competitive/where-we-stand.md diff --git a/docs/competitive/where-we-stand.md b/docs/competitive/where-we-stand.md new file mode 100644 index 00000000..7679bd7f --- /dev/null +++ b/docs/competitive/where-we-stand.md @@ -0,0 +1,199 @@ +# Where We Stand — the honest gap register + +> Generated by `tools/generate_competitive_gap_register.py` from `source_inputs/competitive-intel/landscape.v0.yaml`. Do not hand-edit; edit the data and regenerate. +> Benchmark target: **SourceOS/Prophet continuum (sourceos-continuum + prophet-platform)** — stage `experimental`. Researched 2026-08-03. +> +> **This register lists ONLY where competitors are stronger than us.** It is one-sided by design. + +**44 products reviewed · 23 distinct capability gaps · 86 competitor-gap findings.** + +## Ranked gaps — most damaging first + +### 1. `agent-native-mcp-ops-surface` — **critical**, 8 competitors ahead +_ahead of us:_ Backstage (+CNOE), Coolify, Heroku (Salesforce), Kratix, Port, Qovery, Railway, Render + +- **Qovery** (critical): Shipped governed agent surface: RBAC-scoped MCP + PRE-execution policy gating + audit — a more agent-forward version of our own fail-closed/receipt thesis, GA and certified ([src](https://www.qovery.com/interfaces/mcp-server)) +- **Port** (critical): $100M raise specifically for agent governance: MCP gateway + Context Lake + guardrails + audit — directly overlaps + outpaces our governed-agent thesis ([src](https://www.port.io/blog/port-100m-series-c)) +- **Render** (high): GA MCP server + NL ops for its control plane ([src](https://render.com/docs/mcp-server)) +- **Railway** (high): MCP + in-dashboard chat agent + sandboxed coding-agent harnesses, all shipped ([src](https://docs.railway.com/ai/railway-agent)) +- **Coolify** (high): Official MCP server shipped + Ollama one-click 'sovereign local AI' we only claim ([src](https://coolify.io/docs/integrations/mcp)) +- **Heroku (Salesforce)** (high): Remote MCP server + MCP Toolkit exposing app tools to agents ([src](https://heroku.com)) +- **Backstage (+CNOE)** (high): AIContext catalog kind + MCP surface at production 100:1 agent usage ([src](https://roadie.io)) +- **Kratix** (high): SKA + MCP: governed, audited agent discovery/invocation of capability contracts with pre-action guardrails ([src](https://www.syntasso.io/ai-platform-engineering)) + +### 2. `progressive-delivery-auto-rollback` — **critical**, 6 competitors ahead +_ahead of us:_ Argo CD + Rollouts, Flux + Flagger, Harness CD + AI, Kargo (+ managed Argo), Platform Orchestrator + Score, Qovery + +- **Argo CD + Rollouts** (critical): Canary/blue-green with live metric AnalysisRun (Prometheus/Datadog/...) auto-promote/auto-abort mid-deploy, no human; our gate is a static APPROVE ([src](https://argoproj.github.io/rollouts/)) +- **Kargo (+ managed Argo)** (critical): Kargo IS our promotion-gate concept but GA: multi-stage promotion + conditional steps + cross-stage verification gating, sold to regulated enterprise at fleet scale — years ahead of us on our own differentiator ([src](https://akuity.io/blog/kargo-gitops-promotion-layer)) +- **Platform Orchestrator + Score** (high): Drift detection + rollback-to-known-good + progressive rollouts + pre-change impact analysis, shipping ([src](https://humanitec.com/products/platform-orchestrator)) +- **Flux + Flagger** (high): GA canary/blue-green + automated metric analysis + auto-rollback across 5 mesh/ingress backends ([src](https://fluxcd.io/flagger/)) +- **Harness CD + AI** (high): AI Verify ML-analyzes APM metrics mid-canary, auto-rollback before broad impact ([src](https://developer.harness.io/docs/continuous-delivery/verify/)) +- **Qovery** (medium): Deterministic atomic execution + rollback ('no orphans, no half-applied'), marketed ([src](https://www.qovery.com/platform)) + +### 3. `autonomous-code-review-mature` — **critical**, 6 competitors ahead +_ahead of us:_ Claude Code (Code Review), CodeRabbit, Copilot (coding agent + code review), Cursor (+ Bugbot), Devin, Greptile + +- **Copilot (coding agent + code review)** (critical): ~60M autonomous PR reviews, 1-in-5 on GitHub, integrated w/ CodeQL — the most-adopted autonomous reviewer in market; ours is niche and early ([src](https://github.blog/changelog/2025-04-04-copilot-code-review-now-generally-available/)) +- **Claude Code (Code Review)** (critical): Architecturally OUR reviewer but mature: parallel specialized agents + a behavior-verification pass that filters false positives + best-in-class model (Opus 4.5, 80.9% SWE-bench) at scale ($15-25/PR) ([src](https://code.claude.com/docs/en/code-review)) +- **CodeRabbit** (critical): Productized leader in OUR flagship category: 6M repos, 75M defects, 15k customers, every Git host, CI pre-merge checks; independent F1 51.2% ([src](https://coderabbit.ai)) +- **Cursor (+ Bugbot)** (high): Bugbot reviews 100Ks PRs/day, learned-rule self-improvement, 1-click autofix; our reviewer is far earlier ([src](https://cursor.com/bugbot)) +- **Devin** (high): Devin Review is a monetized reviewer that ALSO fixes+re-iterates; ours only emits a verdict, doesn't remediate ([src](https://docs.devin.ai/work-with-devin/devin-review)) +- **Greptile** (high): 82% bug-catch via full-codebase indexing — higher detection than our early reviewer demonstrates ([src](https://greptile.com)) + +### 4. `managed-data-services` — **critical**, 5 competitors ahead +_ahead of us:_ Heroku (Salesforce), Northflank, Porter, Railway, Render + +- **Render** (critical): Managed Postgres (PITR, replicas, pgvector) + Key Value; we have none ([src](https://render.com/docs)) +- **Railway** (critical): HA Postgres on Patroni (quorum/failover) ([src](https://blog.railway.com)) +- **Porter** (critical): Managed Postgres/Redis with auto VPC peering ([src](https://docs.porter.run/addons/datastores)) +- **Northflank** (critical): Managed Postgres/MySQL/Mongo/Redis with PITR + pooling ([src](https://northflank.com/features)) +- **Heroku (Salesforce)** (critical): Mature managed Postgres/Redis/Kafka add-on marketplace ([src](https://heroku.com)) + +### 5. `autonomous-remediation-agents` — **critical**, 5 competitors ahead +_ahead of us:_ Endor Labs (AURI), Harness CD + AI, Mend.io, Prisma/Cortex Cloud (AgentiX), Wiz + +- **Endor Labs (AURI)** (critical): AURI autonomously produces validated fixes (~95% FP eliminated); Magic Patches backport compatible fixes — solves the 'must-update-but-it-breaks' our human gate only pauses on ([src](https://www.endorlabs.com/platform)) +- **Harness CD + AI** (high): GA autonomous worker agents w/ per-agent identity + MCP dispatch surface ([src](https://www.harness.io/press-and-news/harness-launches-autonomous-worker-agents-for-software-delivery)) +- **Wiz** (high): MCP + Issues Agent autonomous root-cause + remediation at Fortune-100 scale ([src](https://www.wiz.io/blog/introducing-mcp-server-for-wiz)) +- **Prisma/Cortex Cloud (AgentiX)** (high): AgentiX autonomous remediation trained on 1.2B incidents w/ governance guardrails — same 'autonomy needs control' thesis, shipped at scale ([src](https://siliconangle.com)) +- **Mend.io** (high): Renovate/Remediate open validated, confidence-scored fix PRs across 90+ ecosystems + malicious-package detection + SBOM/VEX ([src](https://www.mend.io/ai-based-remediation/)) + +### 6. `vuln-db-broad-scanning` — **critical**, 5 competitors ahead +_ahead of us:_ Aqua Platform + Trivy, Artifactory + Xray + AppTrust, Semgrep, Snyk, Wiz + +- **Wiz** (critical): Full CNAPP: SCA/IaC(1000+ rules)/secrets/malware/DSPM + code-to-cloud graph; we have no vuln DB or scanning at all ([src](https://www.wiz.io/platform/wiz-code)) +- **Aqua Platform + Trivy** (critical): Trivy: vuln + IaC + secrets + license + SBOM across all major langs/OS, backed by Aqua Vuln DB ([src](https://appsecsanta.com/trivy)) +- **Snyk** (critical): SCA+SAST+DAST+secrets+container+IaC in one platform w/ a curated DB '3x' public; we scan none of these ([src](https://appsecsanta.com/snyk)) +- **Artifactory + Xray + AppTrust** (high): SCA + SAST + secrets + IaC + container CVE + malicious-package detection + Curation gate-blocking ([src](https://jfrog.com/advanced-security/)) +- **Semgrep** (high): Best-in-class custom-rule SAST (40+ langs) + SCA + secrets w/ dataflow reachability (~98% FP reduction) in <5min PR runs ([src](https://research.contrary.com/company/semgrep)) + +### 7. `attestation-provenance-slsa` — **critical**, 4 competitors ahead +_ahead of us:_ Aqua Platform + Trivy, Chainguard Images/Libraries, Harness CD + AI, Kusari Inspector (GUAC) + +- **Chainguard Images/Libraries** (critical): Sigstore signing + SLSA L2 provenance + build-time SBOM on 2,000+ digest-pinned images — our version-marker check is a hand-rolled slice of this at industrial scale ([src](https://www.chainguard.dev)) +- **Harness CD + AI** (high): GA SLSA L1-3 provenance + SBOM + artifact-promotion policy governance — a mature superset of our signed evidence bundles ([src](https://developer.harness.io/docs/software-supply-chain-assurance/)) +- **Kusari Inspector (GUAC)** (high): GUAC provenance knowledge graph ingesting SBOM+SLSA+in-toto+VEX (production at Guidewire/Yahoo) — a far more general provenance substrate than our bespoke receipts ([src](https://www.kusari.dev/blog/case-study-a-discussion-with-guidewire-on-guac)) +- **Aqua Platform + Trivy** (high): SBOM + Sigstore/Cosign signing + SLSA provenance + artifact-integrity promotion gates + malicious-package detection — our exact loop as a subset, plus much more; Trivy is free/self-hostable/air-gap OSS, undercutting even our sovereign angle ([src](https://www.aquasec.com/products/trivy/)) + +### 8. `composition-provider-ecosystem` — **critical**, 2 competitors ahead +_ahead of us:_ Crossplane, Platform Orchestrator + Score + +- **Crossplane** (critical): XRDs + Composition Functions (versioned, testable, OCI-packaged) over 1,000+ resource types AWS/GCP/Azure/OCI/Terraform — a mature realization of CapD's ambition ([src](https://docs.crossplane.io)) +- **Platform Orchestrator + Score** (medium): Score = open, multi-implementation workload spec vs our single-vendor CapD ([src](https://humanitec.com)) + +### 9. `broad-ecosystem-dep-automation` — **critical**, 2 competitors ahead +_ahead of us:_ Dependabot, Renovate + +- **Renovate** (critical): Update PRs across ~90 managers + Merge Confidence scoring + CI-gated auto-merge; ours is vendored-only, no confidence signal ([src](https://www.mend.io/mend-renovate/)) +- **Dependabot** (high): Zero-setup multi-ecosystem grouped update PRs (GA 2025) + programmable alert auto-triage (GA 2024) at GitHub's install base ([src](https://github.blog/changelog/2025-07-01-single-pull-request-for-dependabot-multi-ecosystem-support/)) + +### 10. `malicious-package-detection` — **critical**, 2 competitors ahead +_ahead of us:_ Semgrep, Socket + +- **Socket** (critical): 70+ behavioral signals catch malware/typosquat PRE-CVE across 10+ ecosystems; Socket Firewall blocks at install; we detect staleness only ([src](https://socket.dev/blog/introducing-socket-firewall)) +- **Semgrep** (medium): GA malicious-dependency detection in Supply Chain ([src](https://semgrep.dev/blog/2025/block-malicious-dependencies-with-semgrep-supply-chain/)) + +### 11. `artifact-registry-maturity` — **critical**, 1 competitors ahead +_ahead of us:_ Artifactory + Xray + AppTrust + +- **Artifactory + Xray + AppTrust** (critical): Artifactory = self-hosted digest-addressed registry with RBAC/replication (our zot equivalent, decade-hardened); AppTrust = our promotion gate productized with signed release bundles + DevGovOps policy ([src](https://jfrog.com/advanced-security/)) + +### 12. `compliance-certifications` — **high**, 7 competitors ahead +_ahead of us:_ Chainguard Images/Libraries, Factory.ai (Droids), Fly.io, Port, Porter, Prisma/Cortex Cloud (AgentiX), Render + +- **Render** (high): SOC2 II + ISO27001 + HIPAA BAA + GDPR DPA live ([src](https://render.com/docs/certifications-compliance)) +- **Fly.io** (high): SOC2 II + ISO27001 + HIPAA + GDPR + documented org RBAC ([src](https://fly.io/compliance/)) +- **Porter** (high): SOC2 Type2 + HIPAA (Nov 2024) ([src](https://www.prnewswire.com)) +- **Port** (high): confirmed SOC2 ([src](https://www.port.io/blog)) +- **Chainguard Images/Libraries** (high): FIPS 140-3 validated + STIG + FedRAMP evidence automation (POA&Ms, KSIs) ([src](https://www.chainguard.dev/solutions/fedramp)) +- **Prisma/Cortex Cloud (AgentiX)** (high): FedRAMP/STIG/FIPS government-grade certs + 100+ compliance frameworks (Checkov) ([src](https://www.paloaltonetworks.com/prisma/cloud/federal)) +- **Factory.ai (Droids)** (high): On-prem/self-host + SOC2 II + ISO 27001/42001 — owns the enterprise-agent lane we target ([src](https://theaiagentindex.com/agents/factory-ai)) + +### 13. `autonomous-feature-development` — **high**, 7 competitors ahead +_ahead of us:_ Amp, Copilot (coding agent + code review), Cursor (+ Bugbot), Devin, Factory.ai (Droids), Jules, Windsurf (Cascade) + +- **Cursor (+ Bugbot)** (high): Full autonomous multi-file feature dev + parallel multi-agent best-of-N + cloud computer-use; ~35% of own PRs agent-made ([src](https://cursor.com/blog/2-0)) +- **Copilot (coding agent + code review)** (high): Platform-native coding agent Issue->draft-PR at the world's largest code host, MCP defaults ([src](https://github.blog/changelog/2025-09-25-copilot-coding-agent-is-now-generally-available/)) +- **Devin** (high): End-to-end async SDLC over 100k+ LOC multi-repo; ~75% task completion; Stacked-PR orchestration we lack ([src](https://devin.ai/blog/introducing-pr-stacks)) +- **Factory.ai (Droids)** (high): Thousands of parallel droids + coordinator decomposition + deepest enterprise workflow (Datadog/Jira/GitHub/Slack incident response) ([src](https://factory.ai/news/terminal-bench)) +- **Amp** (medium): Whole-codebase authoring over 54B-LOC code graph + subagent architecture + own review capability ([src](https://ampcode.com/manual)) +- **Windsurf (Cascade)** (medium): Polished AI IDE + large-scale autonomous multi-file dev + in-house models at enterprise scale ([src](https://www.digitalapplied.com/blog/windsurf-2-deep-dive-cascade-agents-flows-2026)) +- **Jules** (medium): GA unattended async feature/bug work at Google scale (300 tasks/day, 60 concurrent); generalizes 'open a receipted PR autonomously' beyond our narrow re-vendor ([src](https://blog.google/technology/google-labs/jules-now-available/)) + +### 14. `sovereign-airgap-contested` — **high**, 4 competitors ahead +_ahead of us:_ Endor Labs (AURI), Koyeb, Northflank, Qovery + +- **Northflank** (high): Deepest BYOC+BYOK+on-prem/bare-metal/air-gap story, funded + certified ([src](https://northflank.com/enterprise)) +- **Qovery** (high): Air-gapped self-hosted control plane SKU, SOC2 II unqualified + HIPAA/GDPR/DORA/HDS ([src](https://www.qovery.com/pricing)) +- **Endor Labs (AURI)** (high): Endor Outpost delivers the sovereign/air-gapped deployment we position on, GA + Gartner Visionary ([src](https://www.endorlabs.com)) +- **Koyeb** (medium): Mistral-backed EU 'sovereign AI cloud' narrative directly contests our sovereign positioning ([src](https://techcrunch.com/2026/02/17/mistral-ai-buys-koyeb)) + +### 15. `reachability-exploitability` — **high**, 4 competitors ahead +_ahead of us:_ Endor Labs (AURI), Snyk, Socket, Sysdig Secure (Falco/Sage) + +- **Socket** (high): Coana reachability cuts ~50-80% irrelevant CVE alerts ([src](https://socket.dev/blog/series-c)) +- **Endor Labs (AURI)** (high): Function-level reachability 40+ langs, ~92% FP cut ([src](https://www.endorlabs.com/use-cases/reachability-sca)) +- **Sysdig Secure (Falco/Sage)** (high): Falco eBPF runtime in-use reachability: proves a vuln dep is actually executing/exploitable in prod; we only know a tarball is stale ([src](https://www.sysdig.com/why-runtime-insights)) +- **Snyk** (high): function-level reachability + EPSS/CVSS/exploit-maturity prioritization ([src](https://appsecsanta.com/snyk)) + +### 16. `golden-path-scaffolding-marketplace` — **high**, 3 competitors ahead +_ahead of us:_ Backstage (+CNOE), Coolify, Railway + +- **Railway** (high): 2,000+ template marketplace with creator revenue-share ([src](https://railway.com/deploy)) +- **Coolify** (high): 280+ one-click service catalog; we have none ([src](https://coolify.io)) +- **Backstage (+CNOE)** (high): 250+ plugin ecosystem + Software Templates ([src](https://backstage.io)) + +### 17. `web-ui-developer-portal` — **high**, 3 competitors ahead +_ahead of us:_ Backstage (+CNOE), Port, Porter + +- **Porter** (high): Heroku-like GUI + one-click BYOC k8s provisioning; we are CLI/Makefile only ([src](https://porter.run)) +- **Backstage (+CNOE)** (high): Catalog + TechDocs + Scaffolder self-service UX (Expedia 5,000+ services); we are CLI/Makefile ([src](https://backstage.io)) +- **Port** (high): Blueprints + Scorecards/DORA + Interface Designer no-code UX ([src](https://www.port.io/product-main)) + +### 18. `multi-cluster-fleet` — **high**, 3 competitors ahead +_ahead of us:_ Argo CD + Rollouts, Codefresh GitOps Cloud, Octopus Deploy + +- **Argo CD + Rollouts** (high): ApplicationSets + argocd-agent to hundreds of clusters ([src](https://github.com/argoproj-labs/argocd-agent)) +- **Codefresh GitOps Cloud** (high): Connects many Argo instances to one control plane, per-commit-traceable promotion + SLSA, GA ([src](https://octopus.com/news/codefresh-launches-gitops-cloud)) +- **Octopus Deploy** (medium): GA multi-environment promotion + approvals + audit + RBAC + UI across 4,000+ orgs ([src](https://octopus.com)) + +### 19. `ga-scale-and-capital` — **high**, 2 competitors ahead +_ahead of us:_ Coolify, Render + +- **Render** (high): $1.5B valuation, public status/SLA, 4.5M devs ([src](https://render.com/blog/series-c-extension)) +- **Coolify** (medium): 60k stars / 5.2k forks adoption+trust signal vs our experimental status ([src](https://github.com/coollabsio/coolify)) + +### 20. `multi-region-autoscaling` — **high**, 2 competitors ahead +_ahead of us:_ Fly.io, Northflank + +- **Fly.io** (high): Firecracker microVMs, 30+ region edge autoscaling ([src](https://fly.io/docs/launch/)) +- **Northflank** (high): 6+ managed / up to 600 BYOC regions + fractional GPU (A100/H100/B200) ([src](https://northflank.com/pricing)) + +### 21. `gpu-ai-inference-primitive` — **high**, 2 competitors ahead +_ahead of us:_ Fly.io, Koyeb + +- **Koyeb** (high): H100/A100/Tenstorrent serverless GPU, 250ms scale-to-zero, ships models (Phi-4, Qwen2-VL) ([src](https://www.koyeb.com/deploy)) +- **Fly.io** (medium): A10G/L40S GPU machines ([src](https://enterprisedna.co/resources/blog/practitioner-fly-io-ai/)) + +### 22. `vendor-neutral-governance` — **high**, 2 competitors ahead +_ahead of us:_ Backstage (+CNOE), Crossplane + +- **Crossplane** (high): CNCF Graduated: 3rd-party security audits + neutral governance + 450+ orgs ([src](https://www.cncf.io/projects/crossplane/)) +- **Backstage (+CNOE)** (medium): CNCF governance + CBA certification program ([src](https://www.cncf.io/projects/backstage/)) + +### 23. `capability-contract-marketplace` — **high**, 1 competitors ahead +_ahead of us:_ Kratix + +- **Kratix** (high): Promises = API+workflow+deps+policy bundled + 40+ marketplace + authoring SDKs — the closest analog to CapD, already shipped w/ a marketplace ([src](https://docs.kratix.io/marketplace)) + +## Findings by cluster + +- **supply-chain-security**: 12 products, 22 gap findings +- **paas-app-platform**: 9 products, 26 gap findings +- **gitops-progressive-delivery**: 6 products, 9 gap findings +- **ai-coding-agent**: 6 products, 9 gap findings +- **idp-platform-engineering**: 5 products, 13 gap findings +- **autonomous-code-review**: 4 products, 5 gap findings +- **dependency-automation**: 2 products, 2 gap findings + diff --git a/profiles/competitive-landscape-profile.v0.yaml b/profiles/competitive-landscape-profile.v0.yaml new file mode 100644 index 00000000..8403249c --- /dev/null +++ b/profiles/competitive-landscape-profile.v0.yaml @@ -0,0 +1,62 @@ +profile: + id: competitive-landscape + version: 0.1.0 + status: draft + purpose: >- + Product-by-product competitive intelligence for the DevSecOps / PaaS / agentic-delivery + market, scoped to the operations-domain profile's market/execution lane. Each competitor + carries maturity, agent integrations, and a `beats_us_on` list of ONLY the capabilities + where it is stronger than the benchmark target, so a projection can rank where we lose. + +ownership_boundary: + canonical_storage_and_wire: SocioProphet/socioprophet-standards-storage + canonical_ontology: + - SocioProphet/ontogenesis + - SocioProphet/socioprophet-standards-knowledge + operations_domain_projection: SocioProphet/global-devsecops-intelligence + +artifacts: + schema: schemas/competitive-landscape.schema.json + source_input: source_inputs/competitive-intel/landscape.v0.yaml + validator: tools/validate_competitive_landscape.py + gap_register_generator: tools/generate_competitive_gap_register.py + gap_register: docs/competitive/where-we-stand.md + +lanes: + market_execution: + examples: + - competitor.profiled + - capability.gap.detected + - maturity.stage.assessed + - gap.register.generated + +capability_axes: # the dimensions the market is compared on + - managed-data-services + - agent-native-mcp-ops-surface + - compliance-certifications + - ga-scale-and-capital + - web-ui-developer-portal + - golden-path-scaffolding-marketplace + - multi-region-autoscaling + - progressive-delivery-auto-rollback + - multi-cluster-fleet + - gpu-ai-inference-primitive + - vuln-db-broad-scanning + - reachability-exploitability + - malicious-package-detection + - broad-ecosystem-dep-automation + - autonomous-remediation-agents + - attestation-provenance-slsa + - artifact-registry-maturity + - composition-provider-ecosystem + - capability-contract-marketplace + - autonomous-code-review-mature + - autonomous-feature-development + - vendor-neutral-governance + - sovereign-airgap-contested + +maturity_ladder: # aligns with the AI4IT maturity model; used for our_position + each competitor + - experimental # pre-product / scaffold + - beta # usable, not GA + - ga # generally available + - scaled # GA at proven production scale diff --git a/schemas/competitive-landscape.schema.json b/schemas/competitive-landscape.schema.json new file mode 100644 index 00000000..0ba23fd7 --- /dev/null +++ b/schemas/competitive-landscape.schema.json @@ -0,0 +1,99 @@ +{ + "$schema": "http://json-schema.org/draft-07/schema#", + "$id": "https://socioprophet.org/gdsi/schemas/competitive-landscape.schema.json", + "title": "Competitive Landscape (DevSecOps / PaaS / agentic-delivery)", + "description": "Product-by-product competitive intelligence for the operations-domain profile. One entry per competitor product; `beats_us_on` records ONLY where the competitor is stronger than the benchmark target, so a projection (generate_competitive_gap_register.py) can rank where we are worse.", + "type": "object", + "required": ["apiVersion", "kind", "metadata", "spec"], + "additionalProperties": false, + "properties": { + "apiVersion": {"const": "gdsi.socioprophet.org/v0"}, + "kind": {"const": "CompetitiveLandscape"}, + "metadata": { + "type": "object", + "required": ["id", "version", "status", "researched_at", "benchmark_target"], + "additionalProperties": true, + "properties": { + "id": {"type": "string"}, + "version": {"type": "string"}, + "status": {"enum": ["draft", "review", "published"]}, + "researched_at": {"type": "string"}, + "benchmark_target": {"type": "string"} + } + }, + "spec": { + "type": "object", + "required": ["our_position", "competitors"], + "additionalProperties": false, + "properties": { + "our_position": { + "type": "object", + "required": ["maturity_stage", "summary"], + "additionalProperties": true, + "properties": { + "maturity_stage": {"$ref": "#/$defs/maturity_stage"}, + "summary": {"type": "string"}, + "distinctive_claims": {"type": "array", "items": {"type": "string"}, + "description": "Where we plausibly lead. Recorded for balance; DELIBERATELY excluded from the gap register."} + } + }, + "competitors": {"type": "array", "minItems": 1, "items": {"$ref": "#/$defs/competitor"}} + } + } + }, + "$defs": { + "maturity_stage": { + "enum": ["experimental", "beta", "ga", "scaled"], + "description": "experimental=pre-product/scaffold; beta=usable, not GA; ga=generally available; scaled=GA with proven production scale (millions of users / large enterprise install base)." + }, + "severity": { + "enum": ["critical", "high", "medium", "low"], + "description": "How damaging this gap is to us competitively. critical=table-stakes we lack; high=material disadvantage in most deals; medium=noticeable; low=nice-to-have." + }, + "cluster": { + "enum": ["paas-app-platform", "idp-platform-engineering", "supply-chain-security", + "ai-coding-agent", "autonomous-code-review", "gitops-progressive-delivery", + "dependency-automation"] + }, + "competitor": { + "type": "object", + "required": ["vendor", "product", "cluster", "maturity", "beats_us_on"], + "additionalProperties": false, + "properties": { + "vendor": {"type": "string"}, + "product": {"type": "string"}, + "cluster": {"$ref": "#/$defs/cluster"}, + "homepage": {"type": "string"}, + "maturity": { + "type": "object", + "required": ["stage"], + "additionalProperties": false, + "properties": { + "stage": {"$ref": "#/$defs/maturity_stage"}, + "scale": {"type": "string"}, + "funding": {"type": "string"}, + "certs": {"type": "array", "items": {"type": "string"}} + } + }, + "features": {"type": "array", "items": {"type": "string"}}, + "agent_integrations": {"type": "array", "items": {"type": "string"}}, + "beats_us_on": { + "type": "array", + "description": "ONLY capabilities where this product is clearly stronger than the benchmark target.", + "items": { + "type": "object", + "required": ["capability", "severity", "evidence"], + "additionalProperties": false, + "properties": { + "capability": {"type": "string", "description": "Short capability slug (kebab-ish), used to cluster the gap register."}, + "severity": {"$ref": "#/$defs/severity"}, + "evidence": {"type": "string"}, + "source": {"type": "string"} + } + } + }, + "sources": {"type": "array", "items": {"type": "string"}} + } + } + } +} diff --git a/source_inputs/competitive-intel/landscape.v0.yaml b/source_inputs/competitive-intel/landscape.v0.yaml new file mode 100644 index 00000000..462fb3b3 --- /dev/null +++ b/source_inputs/competitive-intel/landscape.v0.yaml @@ -0,0 +1,302 @@ +apiVersion: gdsi.socioprophet.org/v0 +kind: CompetitiveLandscape +metadata: + id: devsecops-paas-agentic-landscape + version: 0.1.0 + status: draft + researched_at: "2026-08-03" + benchmark_target: "SourceOS/Prophet continuum (sourceos-continuum + prophet-platform)" +spec: + our_position: + maturity_stage: experimental + summary: >- + Sovereign, local-first PaaS + autonomous DevSecOps continuum: detect stale vendored deps + -> typed EffectRequest -> fail-closed policy membrane -> digest-pinned re-vendor (own zot + registry, sha256-verified) -> JIT scale-to-zero LLM re-review (sealed APPROVE/REJECT/ + NEEDS_HUMAN) -> fail-closed promotion gate -> hash-sealed receipts on every action. + Self-hosted (Gitea, zot, own runners). Several lifecycle stages are scaffolds. + distinctive_claims: # recorded for balance; EXCLUDED from the gap register by construction + - "Fail-closed gates + hash-sealed per-action receipts as a hard promote-or-it-doesn't invariant" + - "Independent sealed-verdict LLM review as a separate governance authority (not advisory comments)" + - "Version-marker attestation: the packed dist really is the release it claims" + - "Fully self-hosted / no external SaaS (Gitea + zot + own runners)" + - "Receipt-sealed autonomous re-vendor executor with digest verification" + + competitors: + # ───────────────────────── PaaS app-platforms ───────────────────────── + - {vendor: Render, product: Render, cluster: paas-app-platform, homepage: https://render.com, + maturity: {stage: scaled, scale: "4.5M+ devs, +250k/mo", funding: "$258M, $1.5B val (Feb 2026)", certs: [SOC2-TypeII, ISO27001, SOC3, HIPAA-BAA, GDPR-DPA]}, + agent_integrations: ["official Render MCP server", "Coding Agents ops surface", "Render Workflows for agent pipelines"], + beats_us_on: [ + {capability: managed-data-services, severity: critical, evidence: "Managed Postgres (PITR, replicas, pgvector) + Key Value; we have none", source: https://render.com/docs}, + {capability: compliance-certifications, severity: high, evidence: "SOC2 II + ISO27001 + HIPAA BAA + GDPR DPA live", source: https://render.com/docs/certifications-compliance}, + {capability: agent-native-mcp-ops-surface, severity: high, evidence: "GA MCP server + NL ops for its control plane", source: https://render.com/docs/mcp-server}, + {capability: ga-scale-and-capital, severity: high, evidence: "$1.5B valuation, public status/SLA, 4.5M devs", source: https://render.com/blog/series-c-extension}]} + - {vendor: Railway, product: Railway, cluster: paas-app-platform, homepage: https://railway.com, + maturity: {stage: scaled, scale: "3M users, 100k signups/wk", funding: "$120M+ (Series B Jan 2026)", certs: []}, + agent_integrations: ["Railway MCP server (14 tools)", "in-dashboard Railway Agent (fixes deploys, opens PRs)", "Sandboxes prewire Claude Code/Codex + Guardrails"], + beats_us_on: [ + {capability: agent-native-mcp-ops-surface, severity: high, evidence: "MCP + in-dashboard chat agent + sandboxed coding-agent harnesses, all shipped", source: https://docs.railway.com/ai/railway-agent}, + {capability: golden-path-scaffolding-marketplace, severity: high, evidence: "2,000+ template marketplace with creator revenue-share", source: https://railway.com/deploy}, + {capability: managed-data-services, severity: critical, evidence: "HA Postgres on Patroni (quorum/failover)", source: https://blog.railway.com}]} + - {vendor: Fly.io, product: Fly.io, cluster: paas-app-platform, homepage: https://fly.io, + maturity: {stage: ga, scale: "30+ regions", funding: "$115M; $25M Series D (Dell/Intel Capital, Jul 2026)", certs: [SOC2-TypeII, ISO27001, HIPAA-BAA, GDPR-DPA]}, + agent_integrations: ["built-in flyctl mcp-server", "positions as best host for others' MCP servers/agents"], + beats_us_on: [ + {capability: multi-region-autoscaling, severity: high, evidence: "Firecracker microVMs, 30+ region edge autoscaling", source: https://fly.io/docs/launch/}, + {capability: gpu-ai-inference-primitive, severity: medium, evidence: "A10G/L40S GPU machines", source: https://enterprisedna.co/resources/blog/practitioner-fly-io-ai/}, + {capability: compliance-certifications, severity: high, evidence: "SOC2 II + ISO27001 + HIPAA + GDPR + documented org RBAC", source: https://fly.io/compliance/}]} + - {vendor: Koyeb, product: Koyeb, cluster: paas-app-platform, homepage: https://koyeb.com, + maturity: {stage: ga, scale: "acquired by Mistral AI (Feb 2026)", funding: "$8.6M pre-acq; parent $13.8B", certs: []}, + agent_integrations: ["Koyeb MCP server (beta)", "one-click OpenClaw agent platform"], + beats_us_on: [ + {capability: gpu-ai-inference-primitive, severity: high, evidence: "H100/A100/Tenstorrent serverless GPU, 250ms scale-to-zero, ships models (Phi-4, Qwen2-VL)", source: https://www.koyeb.com/deploy}, + {capability: sovereign-airgap-contested, severity: medium, evidence: "Mistral-backed EU 'sovereign AI cloud' narrative directly contests our sovereign positioning", source: https://techcrunch.com/2026/02/17/mistral-ai-buys-koyeb}]} + - {vendor: Porter, product: Porter, cluster: paas-app-platform, homepage: https://porter.run, + maturity: {stage: ga, scale: "hundreds of AI cos, clusters to 100s of machines", funding: "$20M Series A (FirstMark, Jan 2026)", certs: [SOC2-TypeII, HIPAA]}, + agent_integrations: ["none found (no MCP/agent ops surface)"], + beats_us_on: [ + {capability: web-ui-developer-portal, severity: high, evidence: "Heroku-like GUI + one-click BYOC k8s provisioning; we are CLI/Makefile only", source: https://porter.run}, + {capability: managed-data-services, severity: critical, evidence: "Managed Postgres/Redis with auto VPC peering", source: https://docs.porter.run/addons/datastores}, + {capability: compliance-certifications, severity: high, evidence: "SOC2 Type2 + HIPAA (Nov 2024)", source: https://www.prnewswire.com}]} + - {vendor: Northflank, product: Northflank, cluster: paas-app-platform, homepage: https://northflank.com, + maturity: {stage: ga, scale: "100k concurrent sandboxes, 2M+ workloads/mo", funding: "~$25M (Bain/Vertex)", certs: [SOC2-TypeII, HIPAA]}, + agent_integrations: ["microVM sandbox substrate for agent code execution (Kata/Firecracker/gVisor)"], + beats_us_on: [ + {capability: sovereign-airgap-contested, severity: high, evidence: "Deepest BYOC+BYOK+on-prem/bare-metal/air-gap story, funded + certified", source: https://northflank.com/enterprise}, + {capability: multi-region-autoscaling, severity: high, evidence: "6+ managed / up to 600 BYOC regions + fractional GPU (A100/H100/B200)", source: https://northflank.com/pricing}, + {capability: managed-data-services, severity: critical, evidence: "Managed Postgres/MySQL/Mongo/Redis with PITR + pooling", source: https://northflank.com/features}]} + - {vendor: Qovery, product: Qovery, cluster: paas-app-platform, homepage: https://qovery.com, + maturity: {stage: ga, scale: "200+ orgs, 1000+ clusters", funding: "$18M+ (Series A Sep 2025)", certs: [SOC2-TypeII, HIPAA, GDPR, DORA, HDS]}, + agent_integrations: ["MCP server (RBAC-scoped, read-only default)", "Qovery Skill for Claude/Cursor/Codex", "AI Copilot", "policy engine that BLOCKS agent ops PRE-execution"], + beats_us_on: [ + {capability: agent-native-mcp-ops-surface, severity: critical, evidence: "Shipped governed agent surface: RBAC-scoped MCP + PRE-execution policy gating + audit — a more agent-forward version of our own fail-closed/receipt thesis, GA and certified", source: https://www.qovery.com/interfaces/mcp-server}, + {capability: progressive-delivery-auto-rollback, severity: medium, evidence: "Deterministic atomic execution + rollback ('no orphans, no half-applied'), marketed", source: https://www.qovery.com/platform}, + {capability: sovereign-airgap-contested, severity: high, evidence: "Air-gapped self-hosted control plane SKU, SOC2 II unqualified + HIPAA/GDPR/DORA/HDS", source: https://www.qovery.com/pricing}]} + - {vendor: Coolify, product: Coolify, cluster: paas-app-platform, homepage: https://coolify.io, + maturity: {stage: ga, scale: "60k GitHub stars, 575+ contributors", funding: "bootstrapped", certs: []}, + agent_integrations: ["official MCP server (50+ tools, read-only)", "thriving 3rd-party MCP ecosystem", "first-class Ollama (v4.0)"], + beats_us_on: [ + {capability: golden-path-scaffolding-marketplace, severity: high, evidence: "280+ one-click service catalog; we have none", source: https://coolify.io}, + {capability: ga-scale-and-capital, severity: medium, evidence: "60k stars / 5.2k forks adoption+trust signal vs our experimental status", source: https://github.com/coollabsio/coolify}, + {capability: agent-native-mcp-ops-surface, severity: high, evidence: "Official MCP server shipped + Ollama one-click 'sovereign local AI' we only claim", source: https://coolify.io/docs/integrations/mcp}]} + - {vendor: Heroku, product: Heroku (Salesforce), cluster: paas-app-platform, homepage: https://heroku.com, + maturity: {stage: scaled, scale: "millions of apps, decade+", funding: "Salesforce-owned", certs: [SOC2, ISO27001, PCI, FedRAMP-path]}, + agent_integrations: ["Managed Inference + Agents GA", "remote MCP server (OAuth) + MCP Toolkit for Claude/Cursor/Agentforce"], + beats_us_on: [ + {capability: managed-data-services, severity: critical, evidence: "Mature managed Postgres/Redis/Kafka add-on marketplace", source: https://heroku.com}, + {capability: agent-native-mcp-ops-surface, severity: high, evidence: "Remote MCP server + MCP Toolkit exposing app tools to agents", source: https://heroku.com}]} + + # ───────────────────────── IDP / platform-engineering ───────────────────────── + - {vendor: Spotify, product: Backstage (+CNOE), cluster: idp-platform-engineering, homepage: https://backstage.io, + maturity: {stage: scaled, scale: "3.4k adopters, ~89% IDP market share, CNCF Incubating", funding: "CNCF/LF", certs: ["CBA certification program"]}, + agent_integrations: ["Actions Registry + MCP server", "AIContext catalog kind for AI agents", "Roadie AI Assistant; 100:1 agent:human ratio reported"], + beats_us_on: [ + {capability: web-ui-developer-portal, severity: high, evidence: "Catalog + TechDocs + Scaffolder self-service UX (Expedia 5,000+ services); we are CLI/Makefile", source: https://backstage.io}, + {capability: golden-path-scaffolding-marketplace, severity: high, evidence: "250+ plugin ecosystem + Software Templates", source: https://backstage.io}, + {capability: agent-native-mcp-ops-surface, severity: high, evidence: "AIContext catalog kind + MCP surface at production 100:1 agent usage", source: https://roadie.io}, + {capability: vendor-neutral-governance, severity: medium, evidence: "CNCF governance + CBA certification program", source: https://www.cncf.io/projects/backstage/}]} + - {vendor: Port, product: Port, cluster: idp-platform-engineering, homepage: https://port.io, + maturity: {stage: ga, scale: "GitHub/Visa/BT logos, 300% YoY", funding: "$158M, $800M val (Series C Dec 2025)", certs: [SOC2]}, + agent_integrations: ["Port MCP server (governed gateway, RBAC+audit)", "Context Lake + Agent Management + Governance (Agentic Engineering Platform)", "Port AI Assistant (MCP client, permission-scoped, human-approval)"], + beats_us_on: [ + {capability: agent-native-mcp-ops-surface, severity: critical, evidence: "$100M raise specifically for agent governance: MCP gateway + Context Lake + guardrails + audit — directly overlaps + outpaces our governed-agent thesis", source: https://www.port.io/blog/port-100m-series-c}, + {capability: web-ui-developer-portal, severity: high, evidence: "Blueprints + Scorecards/DORA + Interface Designer no-code UX", source: https://www.port.io/product-main}, + {capability: compliance-certifications, severity: high, evidence: "confirmed SOC2", source: https://www.port.io/blog}]} + - {vendor: Humanitec, product: Platform Orchestrator + Score, cluster: idp-platform-engineering, homepage: https://humanitec.com, + maturity: {stage: ga, scale: "~$5.2M rev, PlatCo-owned", funding: "acquired by PlatCo (2024)", certs: []}, + agent_integrations: ["MCP support (~Jan 2026)", "agents as first-class interface"], + beats_us_on: [ + {capability: progressive-delivery-auto-rollback, severity: high, evidence: "Drift detection + rollback-to-known-good + progressive rollouts + pre-change impact analysis, shipping", source: https://humanitec.com/products/platform-orchestrator}, + {capability: composition-provider-ecosystem, severity: medium, evidence: "Score = open, multi-implementation workload spec vs our single-vendor CapD", source: https://humanitec.com}]} + + # ───────────────────────── control-plane composition ───────────────────────── + - {vendor: Upbound, product: Crossplane, cluster: idp-platform-engineering, homepage: https://crossplane.io, + maturity: {stage: scaled, scale: "CNCF GRADUATED (Nov 2025), 3000+ contributors, 450+ orgs (Nike/NASA/SAP)", funding: "Upbound-backed", certs: ["CNCF graduated (3rd-party sec audits)"]}, + agent_integrations: ["v2 'compose any K8s resource'; Upbound AI-native positioning (marketing, no shipped MCP found)"], + beats_us_on: [ + {capability: composition-provider-ecosystem, severity: critical, evidence: "XRDs + Composition Functions (versioned, testable, OCI-packaged) over 1,000+ resource types AWS/GCP/Azure/OCI/Terraform — a mature realization of CapD's ambition", source: https://docs.crossplane.io}, + {capability: vendor-neutral-governance, severity: high, evidence: "CNCF Graduated: 3rd-party security audits + neutral governance + 450+ orgs", source: https://www.cncf.io/projects/crossplane/}]} + - {vendor: Syntasso, product: Kratix, cluster: idp-platform-engineering, homepage: https://kratix.io, + maturity: {stage: beta, scale: "765 stars, small", funding: "Syntasso", certs: []}, + agent_integrations: ["Syntasso Kratix Agentic (SKA): governed MCP agent consumption of Promises, human-in-the-loop, audit trail"], + beats_us_on: [ + {capability: capability-contract-marketplace, severity: high, evidence: "Promises = API+workflow+deps+policy bundled + 40+ marketplace + authoring SDKs — the closest analog to CapD, already shipped w/ a marketplace", source: https://docs.kratix.io/marketplace}, + {capability: agent-native-mcp-ops-surface, severity: high, evidence: "SKA + MCP: governed, audited agent discovery/invocation of capability contracts with pre-action guardrails", source: https://www.syntasso.io/ai-platform-engineering}]} + + # ───────────────────────── GitOps / progressive delivery ───────────────────────── + - {vendor: Argo, product: Argo CD + Rollouts, cluster: gitops-progressive-delivery, homepage: https://argoproj.github.io, + maturity: {stage: scaled, scale: "CNCF Graduated, ~60% of k8s clusters, NPS 79", funding: "CNCF", certs: ["CNCF graduated"]}, + agent_integrations: ["statistical AnalysisTemplates (auditable, not LLM)"], + beats_us_on: [ + {capability: progressive-delivery-auto-rollback, severity: critical, evidence: "Canary/blue-green with live metric AnalysisRun (Prometheus/Datadog/...) auto-promote/auto-abort mid-deploy, no human; our gate is a static APPROVE", source: https://argoproj.github.io/rollouts/}, + {capability: multi-cluster-fleet, severity: high, evidence: "ApplicationSets + argocd-agent to hundreds of clusters", source: https://github.com/argoproj-labs/argocd-agent}]} + - {vendor: Akuity, product: Kargo (+ managed Argo), cluster: gitops-progressive-delivery, homepage: https://akuity.io, + maturity: {stage: ga, scale: "100+ enterprises, tens of millions of releases", funding: "~$25M", certs: []}, + agent_integrations: ["verification hooks (not LLM)"], + beats_us_on: [ + {capability: progressive-delivery-auto-rollback, severity: critical, evidence: "Kargo IS our promotion-gate concept but GA: multi-stage promotion + conditional steps + cross-stage verification gating, sold to regulated enterprise at fleet scale — years ahead of us on our own differentiator", source: https://akuity.io/blog/kargo-gitops-promotion-layer}]} + - {vendor: Flux, product: Flux + Flagger, cluster: gitops-progressive-delivery, homepage: https://fluxcd.io, + maturity: {stage: ga, scale: "CNCF Graduated (Flagger momentum slowed, v1.44 Jul 2024)", funding: "CNCF", certs: ["CNCF graduated"]}, + agent_integrations: ["none native"], + beats_us_on: [ + {capability: progressive-delivery-auto-rollback, severity: high, evidence: "GA canary/blue-green + automated metric analysis + auto-rollback across 5 mesh/ingress backends", source: https://fluxcd.io/flagger/}]} + - {vendor: Harness, product: Harness CD + AI, cluster: gitops-progressive-delivery, homepage: https://harness.io, + maturity: {stage: scaled, scale: "large commercial platform + Traceable", funding: "public-scale", certs: [SOC2, "SLSA L1-L3"]}, + agent_integrations: ["AIDA assistant", "Autonomous Worker Agents GA (Autofix/Code Review, per-agent identity)", "Harness MCP Server"], + beats_us_on: [ + {capability: progressive-delivery-auto-rollback, severity: high, evidence: "AI Verify ML-analyzes APM metrics mid-canary, auto-rollback before broad impact", source: https://developer.harness.io/docs/continuous-delivery/verify/}, + {capability: autonomous-remediation-agents, severity: high, evidence: "GA autonomous worker agents w/ per-agent identity + MCP dispatch surface", source: https://www.harness.io/press-and-news/harness-launches-autonomous-worker-agents-for-software-delivery}, + {capability: attestation-provenance-slsa, severity: high, evidence: "GA SLSA L1-3 provenance + SBOM + artifact-promotion policy governance — a mature superset of our signed evidence bundles", source: https://developer.harness.io/docs/software-supply-chain-assurance/}]} + - {vendor: Octopus, product: Codefresh GitOps Cloud, cluster: gitops-progressive-delivery, homepage: https://codefresh.io, + maturity: {stage: ga, scale: "fleet-of-Argo control plane", funding: "Octopus-owned", certs: ["SLSA"]}, + agent_integrations: [], + beats_us_on: [ + {capability: multi-cluster-fleet, severity: high, evidence: "Connects many Argo instances to one control plane, per-commit-traceable promotion + SLSA, GA", source: https://octopus.com/news/codefresh-launches-gitops-cloud}]} + - {vendor: Octopus, product: Octopus Deploy, cluster: gitops-progressive-delivery, homepage: https://octopus.com, + maturity: {stage: scaled, scale: "4,000+ orgs (Ubisoft/NASA/Disney)", funding: "profitable", certs: []}, + agent_integrations: ["modest"], + beats_us_on: [ + {capability: multi-cluster-fleet, severity: medium, evidence: "GA multi-environment promotion + approvals + audit + RBAC + UI across 4,000+ orgs", source: https://octopus.com}]} + + # ───────────────────────── dependency automation ───────────────────────── + - {vendor: Mend, product: Renovate, cluster: dependency-automation, homepage: https://mend.io, + maturity: {stage: scaled, scale: "de-facto standard, 90+ ecosystems", funding: "Mend", certs: []}, + agent_integrations: ["Merge Confidence (ecosystem-wide data scoring)"], + beats_us_on: [ + {capability: broad-ecosystem-dep-automation, severity: critical, evidence: "Update PRs across ~90 managers + Merge Confidence scoring + CI-gated auto-merge; ours is vendored-only, no confidence signal", source: https://www.mend.io/mend-renovate/}]} + - {vendor: GitHub, product: Dependabot, cluster: dependency-automation, homepage: https://github.com, + maturity: {stage: scaled, scale: "native to GitHub, universal reach", funding: "Microsoft", certs: []}, + agent_integrations: ["rules-based auto-triage"], + beats_us_on: [ + {capability: broad-ecosystem-dep-automation, severity: high, evidence: "Zero-setup multi-ecosystem grouped update PRs (GA 2025) + programmable alert auto-triage (GA 2024) at GitHub's install base", source: https://github.blog/changelog/2025-07-01-single-pull-request-for-dependabot-multi-ecosystem-support/}]} + - {vendor: Socket, product: Socket, cluster: supply-chain-security, homepage: https://socket.dev, + maturity: {stage: ga, scale: "27,000+ orgs, 1.5M repos, 10k attacks blocked/wk", funding: "$125M, $1B val (May 2026)", certs: [SOC2-TypeI]}, + agent_integrations: ["Socket MCP (depscore)", "Claude Code hook blocking low-score installs"], + beats_us_on: [ + {capability: malicious-package-detection, severity: critical, evidence: "70+ behavioral signals catch malware/typosquat PRE-CVE across 10+ ecosystems; Socket Firewall blocks at install; we detect staleness only", source: https://socket.dev/blog/introducing-socket-firewall}, + {capability: reachability-exploitability, severity: high, evidence: "Coana reachability cuts ~50-80% irrelevant CVE alerts", source: https://socket.dev/blog/series-c}]} + - {vendor: Endor Labs, product: Endor Labs (AURI), cluster: supply-chain-security, homepage: https://endorlabs.com, + maturity: {stage: ga, scale: "~$15M ARR +131% YoY, protects 5M+ apps (OpenAI/Atlassian/Cursor)", funding: "$188M (Series B Apr 2025)", certs: [SOC2, ISO42001, "3PAO-endorsed FedRAMP reachability"]}, + agent_integrations: ["AURI agentic AppSec: autonomous validated remediation", "MCP server + Agent Hub + Agent Kit", "AI Security Code Review agent"], + beats_us_on: [ + {capability: autonomous-remediation-agents, severity: critical, evidence: "AURI autonomously produces validated fixes (~95% FP eliminated); Magic Patches backport compatible fixes — solves the 'must-update-but-it-breaks' our human gate only pauses on", source: https://www.endorlabs.com/platform}, + {capability: reachability-exploitability, severity: high, evidence: "Function-level reachability 40+ langs, ~92% FP cut", source: https://www.endorlabs.com/use-cases/reachability-sca}, + {capability: sovereign-airgap-contested, severity: high, evidence: "Endor Outpost delivers the sovereign/air-gapped deployment we position on, GA + Gartner Visionary", source: https://www.endorlabs.com}]} + + # ───────────────────────── supply-chain / provenance ───────────────────────── + - {vendor: Chainguard, product: Chainguard Images/Libraries, cluster: supply-chain-security, homepage: https://chainguard.dev, + maturity: {stage: scaled, scale: "2,000+ near-zero-CVE images, 500M+ manifests, ~$40M ARR", funding: "$356M, $3.5B val (Series D Apr 2025)", certs: [FIPS-140-3, STIG, FedRAMP]}, + agent_integrations: ["AI/ML tool images ('agentic coding era')"], + beats_us_on: [ + {capability: attestation-provenance-slsa, severity: critical, evidence: "Sigstore signing + SLSA L2 provenance + build-time SBOM on 2,000+ digest-pinned images — our version-marker check is a hand-rolled slice of this at industrial scale", source: https://www.chainguard.dev}, + {capability: compliance-certifications, severity: high, evidence: "FIPS 140-3 validated + STIG + FedRAMP evidence automation (POA&Ms, KSIs)", source: https://www.chainguard.dev/solutions/fedramp}]} + - {vendor: JFrog, product: Artifactory + Xray + AppTrust, cluster: supply-chain-security, homepage: https://jfrog.com, + maturity: {stage: scaled, scale: "public (NASDAQ:FROG), Gartner Visionary 2025 AST", funding: "public", certs: [SOC2, "FedRAMP-oriented"]}, + agent_integrations: ["Agentic Remediation to Copilot via JFrog MCP servers", "AI Catalog + MCP Registry + Agent Skills Registry", "Frogbot fix-PRs"], + beats_us_on: [ + {capability: artifact-registry-maturity, severity: critical, evidence: "Artifactory = self-hosted digest-addressed registry with RBAC/replication (our zot equivalent, decade-hardened); AppTrust = our promotion gate productized with signed release bundles + DevGovOps policy", source: https://jfrog.com/advanced-security/}, + {capability: vuln-db-broad-scanning, severity: high, evidence: "SCA + SAST + secrets + IaC + container CVE + malicious-package detection + Curation gate-blocking", source: https://jfrog.com/advanced-security/}]} + - {vendor: Kusari, product: Kusari Inspector (GUAC), cluster: supply-chain-security, homepage: https://kusari.dev, + maturity: {stage: ga, scale: "smallest peer; GUAC = OpenSSF incubating", funding: "$8M seed (2024)", certs: []}, + agent_integrations: ["AI chat over findings; PR-time go/no-go verdict"], + beats_us_on: [ + {capability: attestation-provenance-slsa, severity: high, evidence: "GUAC provenance knowledge graph ingesting SBOM+SLSA+in-toto+VEX (production at Guidewire/Yahoo) — a far more general provenance substrate than our bespoke receipts", source: https://www.kusari.dev/blog/case-study-a-discussion-with-guidewire-on-guac}]} + + # ───────────────────────── CNAPP ───────────────────────── + - {vendor: Google, product: Wiz, cluster: supply-chain-security, homepage: https://wiz.io, + maturity: {stage: scaled, scale: ">1B ARR, 50%+ Fortune 100, Google-owned ($32B)", funding: "acquired by Google (Mar 2026)", certs: ["widely held (unverified this pass)"]}, + agent_integrations: ["MCP Server for Wiz (Security Graph as agent knowledge layer)", "Issues Agent (autonomous investigate+remediate)", "Dazz genAI remediation"], + beats_us_on: [ + {capability: vuln-db-broad-scanning, severity: critical, evidence: "Full CNAPP: SCA/IaC(1000+ rules)/secrets/malware/DSPM + code-to-cloud graph; we have no vuln DB or scanning at all", source: https://www.wiz.io/platform/wiz-code}, + {capability: autonomous-remediation-agents, severity: high, evidence: "MCP + Issues Agent autonomous root-cause + remediation at Fortune-100 scale", source: https://www.wiz.io/blog/introducing-mcp-server-for-wiz}]} + - {vendor: Palo Alto Networks, product: Prisma/Cortex Cloud (AgentiX), cluster: supply-chain-security, homepage: https://paloaltonetworks.com, + maturity: {stage: scaled, scale: "PANW public co", funding: "public", certs: [SOC2, FedRAMP, FIPS-140-2, STIG]}, + agent_integrations: ["Cortex AgentiX: autonomous agents trained on 1.2B incident responses + no-code builder + guardrails"], + beats_us_on: [ + {capability: compliance-certifications, severity: high, evidence: "FedRAMP/STIG/FIPS government-grade certs + 100+ compliance frameworks (Checkov)", source: https://www.paloaltonetworks.com/prisma/cloud/federal}, + {capability: autonomous-remediation-agents, severity: high, evidence: "AgentiX autonomous remediation trained on 1.2B incidents w/ governance guardrails — same 'autonomy needs control' thesis, shipped at scale", source: https://siliconangle.com}]} + - {vendor: Sysdig, product: Sysdig Secure (Falco/Sage), cluster: supply-chain-security, homepage: https://sysdig.com, + maturity: {stage: scaled, scale: "$283M ARR, ~700 customers, Falco 60% of Fortune 500", funding: "~$2.5B val", certs: ["unverified this pass"]}, + agent_integrations: ["Sysdig Sage 'first agentic cloud security platform' (Aug 2025), >50% customer adoption"], + beats_us_on: [ + {capability: reachability-exploitability, severity: high, evidence: "Falco eBPF runtime in-use reachability: proves a vuln dep is actually executing/exploitable in prod; we only know a tarball is stale", source: https://www.sysdig.com/why-runtime-insights}]} + - {vendor: Aqua, product: Aqua Platform + Trivy, cluster: supply-chain-security, homepage: https://aquasec.com, + maturity: {stage: scaled, scale: "$90M ARR, 500+ enterprises; Trivy 36.5k stars (most-starred OSS scanner)", funding: "$1B+ unicorn", certs: ["unverified this pass"]}, + agent_integrations: ["Agentic Response (runtime intelligence -> automated action)"], + beats_us_on: [ + {capability: attestation-provenance-slsa, severity: high, evidence: "SBOM + Sigstore/Cosign signing + SLSA provenance + artifact-integrity promotion gates + malicious-package detection — our exact loop as a subset, plus much more; Trivy is free/self-hostable/air-gap OSS, undercutting even our sovereign angle", source: https://www.aquasec.com/products/trivy/}, + {capability: vuln-db-broad-scanning, severity: critical, evidence: "Trivy: vuln + IaC + secrets + license + SBOM across all major langs/OS, backed by Aqua Vuln DB", source: https://appsecsanta.com/trivy}]} + - {vendor: Snyk, product: Snyk, cluster: supply-chain-security, homepage: https://snyk.io, + maturity: {stage: scaled, scale: "~$326M ARR, ~4,500 customers, vuln DB '3x public'", funding: "~$7.4B val", certs: [SOC2-TypeII, ISO27001, ISO27017]}, + agent_integrations: ["Snyk MCP (agent-scan)", "AI Security Fabric + Agent Scan/Guard + Evo AI-SPM", "Agent Fix autofix"], + beats_us_on: [ + {capability: vuln-db-broad-scanning, severity: critical, evidence: "SCA+SAST+DAST+secrets+container+IaC in one platform w/ a curated DB '3x' public; we scan none of these", source: https://appsecsanta.com/snyk}, + {capability: reachability-exploitability, severity: high, evidence: "function-level reachability + EPSS/CVSS/exploit-maturity prioritization", source: https://appsecsanta.com/snyk}]} + - {vendor: Mend, product: Mend.io, cluster: supply-chain-security, homepage: https://mend.io, + maturity: {stage: ga, scale: "Microsoft/Google/Siemens logos; owns Renovate", funding: "~$128M", certs: ["unverified this pass"]}, + agent_integrations: ["agentic SAST via MCP (Cursor/Claude/Copilot/Windsurf)", "AI-based remediation (~75% less work)", "Mend AI (AI-BOM, red-teaming)"], + beats_us_on: [ + {capability: autonomous-remediation-agents, severity: high, evidence: "Renovate/Remediate open validated, confidence-scored fix PRs across 90+ ecosystems + malicious-package detection + SBOM/VEX", source: https://www.mend.io/ai-based-remediation/}]} + - {vendor: Semgrep, product: Semgrep, cluster: supply-chain-security, homepage: https://semgrep.dev, + maturity: {stage: ga, scale: "~2M OSS users, 100M+ scans/yr, 150+ enterprises", funding: "~$193M (Series D)", certs: [SOC2-TypeII]}, + agent_integrations: ["Semgrep Assistant (auto-triage + auto-fix + guided upgrades)", "Semgrep MCP server"], + beats_us_on: [ + {capability: vuln-db-broad-scanning, severity: high, evidence: "Best-in-class custom-rule SAST (40+ langs) + SCA + secrets w/ dataflow reachability (~98% FP reduction) in <5min PR runs", source: https://research.contrary.com/company/semgrep}, + {capability: malicious-package-detection, severity: medium, evidence: "GA malicious-dependency detection in Supply Chain", source: https://semgrep.dev/blog/2025/block-malicious-dependencies-with-semgrep-supply-chain/}]} + + # ───────────────────────── AI coding agents / autonomous review ───────────────────────── + - {vendor: Anysphere, product: Cursor (+ Bugbot), cluster: ai-coding-agent, homepage: https://cursor.com, + maturity: {stage: scaled, scale: "$500M+ ARR, $29.3B val (Nov 2025); acquired Graphite", funding: "$29.3B val", certs: [SOC2-TypeII]}, + agent_integrations: ["Composer frontier model", "Background/Cloud Agents (own VM+browser) open PRs", "Bugbot autonomous review (8-pass, majority-vote, autofix, self-improving)", "mature MCP (OAuth, 3 transports)"], + beats_us_on: [ + {capability: autonomous-feature-development, severity: high, evidence: "Full autonomous multi-file feature dev + parallel multi-agent best-of-N + cloud computer-use; ~35% of own PRs agent-made", source: https://cursor.com/blog/2-0}, + {capability: autonomous-code-review-mature, severity: high, evidence: "Bugbot reviews 100Ks PRs/day, learned-rule self-improvement, 1-click autofix; our reviewer is far earlier", source: https://cursor.com/bugbot}]} + - {vendor: GitHub, product: Copilot (coding agent + code review), cluster: autonomous-code-review, homepage: https://github.com, + maturity: {stage: scaled, scale: "~20M users, 4.7M paid, 90% Fortune 100", funding: "Microsoft", certs: ["MS/Azure envelope"]}, + agent_integrations: ["Copilot coding agent (Issue->PR, GA Sep 2025)", "Copilot code review (~60M reviews, '1 in 5 on GitHub')", "GitHub + Playwright MCP default"], + beats_us_on: [ + {capability: autonomous-code-review-mature, severity: critical, evidence: "~60M autonomous PR reviews, 1-in-5 on GitHub, integrated w/ CodeQL — the most-adopted autonomous reviewer in market; ours is niche and early", source: https://github.blog/changelog/2025-04-04-copilot-code-review-now-generally-available/}, + {capability: autonomous-feature-development, severity: high, evidence: "Platform-native coding agent Issue->draft-PR at the world's largest code host, MCP defaults", source: https://github.blog/changelog/2025-09-25-copilot-coding-agent-is-now-generally-available/}]} + - {vendor: Cognition, product: Devin, cluster: ai-coding-agent, homepage: https://devin.ai, + maturity: {stage: scaled, scale: "$492M run-rate, ~$25B val; Goldman Sachs", funding: "$1B+ raised", certs: [SSO/SAML]}, + agent_integrations: ["async cloud agent plan->code->test->PR", "Stacked PRs w/ auto-rebase", "Devin Review (self-review + auto-fix + iterate)", "publishes MCP server + is MCP client"], + beats_us_on: [ + {capability: autonomous-feature-development, severity: high, evidence: "End-to-end async SDLC over 100k+ LOC multi-repo; ~75% task completion; Stacked-PR orchestration we lack", source: https://devin.ai/blog/introducing-pr-stacks}, + {capability: autonomous-code-review-mature, severity: high, evidence: "Devin Review is a monetized reviewer that ALSO fixes+re-iterates; ours only emits a verdict, doesn't remediate", source: https://docs.devin.ai/work-with-devin/devin-review}]} + - {vendor: Anthropic, product: Claude Code (Code Review), cluster: autonomous-code-review, homepage: https://claude.com, + maturity: {stage: scaled, scale: "~$2.5B run-rate, parent >$30B, 1000+ >$1M enterprises", funding: "Anthropic", certs: ["Bedrock/GCP/Foundry, ZDR option"]}, + agent_integrations: ["multi-agent parallel Code Review + behavior-verification pass filtering FPs", "severity-tagged inline comments + machine-readable check run", "first-party MCP + background subagents"], + beats_us_on: [ + {capability: autonomous-code-review-mature, severity: critical, evidence: "Architecturally OUR reviewer but mature: parallel specialized agents + a behavior-verification pass that filters false positives + best-in-class model (Opus 4.5, 80.9% SWE-bench) at scale ($15-25/PR)", source: https://code.claude.com/docs/en/code-review}]} + - {vendor: Factory, product: Factory.ai (Droids), cluster: ai-coding-agent, homepage: https://factory.ai, + maturity: {stage: ga, scale: "rev doubling 6mo, #1 Terminal-Bench", funding: "~$220M, ~$1.5B val (Series C Apr 2026)", certs: [SOC2-TypeII, ISO27001, ISO42001]}, + agent_integrations: ["massively-parallel droid swarm + coordinator", "Review Droid in the swarm", "on-prem deploy + full compliance"], + beats_us_on: [ + {capability: autonomous-feature-development, severity: high, evidence: "Thousands of parallel droids + coordinator decomposition + deepest enterprise workflow (Datadog/Jira/GitHub/Slack incident response)", source: https://factory.ai/news/terminal-bench}, + {capability: compliance-certifications, severity: high, evidence: "On-prem/self-host + SOC2 II + ISO 27001/42001 — owns the enterprise-agent lane we target", source: https://theaiagentindex.com/agents/factory-ai}]} + - {vendor: Sourcegraph, product: Amp, cluster: ai-coding-agent, homepage: https://ampcode.com, + maturity: {stage: ga, scale: "Sourcegraph 54B LOC indexed, spun out Dec 2025", funding: "$223M (parent)", certs: []}, + agent_integrations: ["subagents (Oracle/Librarian) + per-check review subagents", "background Runners + remote Orbs", "MCP local+remote"], + beats_us_on: [ + {capability: autonomous-feature-development, severity: medium, evidence: "Whole-codebase authoring over 54B-LOC code graph + subagent architecture + own review capability", source: https://ampcode.com/manual}]} + - {vendor: Cognition, product: Windsurf (Cascade), cluster: ai-coding-agent, homepage: https://windsurf.com, + maturity: {stage: ga, scale: "$82M ARR, 350+ enterprises, hundreds-k DAU", funding: "$240M+ raised; Cognition-owned", certs: []}, + agent_integrations: ["Cascade agent (MCP/shell/web) w/ diff-staging + review workflow", "in-house SWE-1.5 models"], + beats_us_on: [ + {capability: autonomous-feature-development, severity: medium, evidence: "Polished AI IDE + large-scale autonomous multi-file dev + in-house models at enterprise scale", source: https://www.digitalapplied.com/blog/windsurf-2-deep-dive-cascade-agents-flows-2026}]} + - {vendor: Google, product: Jules, cluster: ai-coding-agent, homepage: https://jules.google, + maturity: {stage: ga, scale: "GA Aug 2025, 140k+ public improvements, Gemini 3 Pro", funding: "Google", certs: ["Google envelope"]}, + agent_integrations: ["fully async cloud agent clone->plan->edit->test->PR", "60 concurrent tasks (Ultra)"], + beats_us_on: [ + {capability: autonomous-feature-development, severity: medium, evidence: "GA unattended async feature/bug work at Google scale (300 tasks/day, 60 concurrent); generalizes 'open a receipted PR autonomously' beyond our narrow re-vendor", source: https://blog.google/technology/google-labs/jules-now-available/}]} + - {vendor: CodeRabbit, product: CodeRabbit, cluster: autonomous-code-review, homepage: https://coderabbit.ai, + maturity: {stage: scaled, scale: "6M repos, 75M defects found, 15,000+ customers", funding: "well-funded", certs: [SOC2]}, + agent_integrations: ["autonomous PR review every Git host", "Codegraph cross-file context", "'Fix with AI' 1-click commits + MCP + Jira/Linear + CI pre-merge checks"], + beats_us_on: [ + {capability: autonomous-code-review-mature, severity: critical, evidence: "Productized leader in OUR flagship category: 6M repos, 75M defects, 15k customers, every Git host, CI pre-merge checks; independent F1 51.2%", source: https://coderabbit.ai}]} + - {vendor: Greptile, product: Greptile, cluster: autonomous-code-review, homepage: https://greptile.com, + maturity: {stage: ga, scale: "82% bug-catch (100% critical subset)", funding: "funded", certs: []}, + agent_integrations: ["full-codebase-indexed autonomous PR review"], + beats_us_on: [ + {capability: autonomous-code-review-mature, severity: high, evidence: "82% bug-catch via full-codebase indexing — higher detection than our early reviewer demonstrates", source: https://greptile.com}]} diff --git a/tools/generate_competitive_gap_register.py b/tools/generate_competitive_gap_register.py new file mode 100644 index 00000000..db41c5ee --- /dev/null +++ b/tools/generate_competitive_gap_register.py @@ -0,0 +1,102 @@ +#!/usr/bin/env python3 +"""Project the competitive-landscape data into a ranked "where we are worse" register. + +Reads the CompetitiveLandscape source input, collects every `beats_us_on` finding (each a +place a competitor is stronger than the benchmark target), clusters findings by their +`capability` slug, and ranks the clusters by worst severity then by how many distinct +competitors share the gap. Emits a markdown register that states ONLY where we are behind — +by construction `our_position.distinctive_claims` never appear. This is the deliberately +one-sided view: it exists to find where we lose, not where we win. + +Usage: python3 tools/generate_competitive_gap_register.py [--check] + --check exit non-zero if the committed register is stale vs. the data (CI gate). +""" +from __future__ import annotations + +import collections +import sys +from pathlib import Path + +try: + import yaml +except Exception as exc: # pragma: no cover + raise SystemExit("pyyaml is required: `python -m pip install pyyaml`") from exc + +ROOT = Path(__file__).resolve().parents[1] +DATA = ROOT / "source_inputs" / "competitive-intel" / "landscape.v0.yaml" +OUT = ROOT / "docs" / "competitive" / "where-we-stand.md" +SEV_WEIGHT = {"critical": 4, "high": 3, "medium": 2, "low": 1} + + +def render(doc: dict) -> str: + comps = doc["spec"]["competitors"] + by_cap: dict[str, list[dict]] = collections.defaultdict(list) + by_cluster: collections.Counter = collections.Counter() + for c in comps: + by_cluster[c["cluster"]] += 1 + for g in c.get("beats_us_on", []): + by_cap[g["capability"]].append( + {"severity": g["severity"], "who": c["product"], "cluster": c["cluster"], + "evidence": g["evidence"], "source": g.get("source", "")}) + + def rank_key(item): + _, entries = item + return (max(SEV_WEIGHT[e["severity"]] for e in entries), len(entries)) + + ranked = sorted(by_cap.items(), key=rank_key, reverse=True) + total_findings = sum(len(v) for v in by_cap.values()) + + L = [ + "# Where We Stand — the honest gap register", + "", + f"> Generated by `tools/generate_competitive_gap_register.py` from " + f"`{DATA.relative_to(ROOT).as_posix()}`. Do not hand-edit; edit the data and regenerate.", + f"> Benchmark target: **{doc['metadata']['benchmark_target']}** — stage " + f"`{doc['spec']['our_position']['maturity_stage']}`. Researched {doc['metadata']['researched_at']}.", + ">", + "> **This register lists ONLY where competitors are stronger than us.** It is one-sided by design.", + "", + f"**{len(comps)} products reviewed · {len(by_cap)} distinct capability gaps · " + f"{total_findings} competitor-gap findings.**", + "", + "## Ranked gaps — most damaging first", + "", + ] + for i, (cap, entries) in enumerate(ranked, 1): + worst = max(entries, key=lambda e: SEV_WEIGHT[e["severity"]])["severity"] + who = sorted({e["who"] for e in entries}) + L.append(f"### {i}. `{cap}` — **{worst}**, {len(entries)} competitors ahead") + L.append(f"_ahead of us:_ {', '.join(who)}") + L.append("") + for e in sorted(entries, key=lambda e: -SEV_WEIGHT[e["severity"]]): + src = f" ([src]({e['source']}))" if e["source"] else "" + L.append(f"- **{e['who']}** ({e['severity']}): {e['evidence']}{src}") + L.append("") + + L += ["## Findings by cluster", ""] + for cluster, n in by_cluster.most_common(): + gaps = sum(len(g.get("beats_us_on", [])) for g in comps if g["cluster"] == cluster) + L.append(f"- **{cluster}**: {n} products, {gaps} gap findings") + L.append("") + return "\n".join(L) + "\n" + + +def main(argv: list[str] | None = None) -> int: + argv = sys.argv[1:] if argv is None else argv + doc = yaml.safe_load(DATA.read_text()) + rendered = render(doc) + if "--check" in argv: + current = OUT.read_text() if OUT.exists() else "" + if current != rendered: + print("STALE: where-we-stand.md is out of date — run generate_competitive_gap_register.py", file=sys.stderr) + return 1 + print("ok: gap register is current") + return 0 + OUT.parent.mkdir(parents=True, exist_ok=True) + OUT.write_text(rendered) + print(f"wrote {OUT.relative_to(ROOT).as_posix()}") + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/tools/validate_competitive_landscape.py b/tools/validate_competitive_landscape.py new file mode 100644 index 00000000..4ba4b676 --- /dev/null +++ b/tools/validate_competitive_landscape.py @@ -0,0 +1,69 @@ +#!/usr/bin/env python3 +"""Validate the competitive-landscape source input against its schema and invariants.""" +from __future__ import annotations + +import json +import sys +from pathlib import Path + +try: + import yaml +except Exception as exc: # pragma: no cover + raise SystemExit("pyyaml is required: `python -m pip install pyyaml`") from exc + +ROOT = Path(__file__).resolve().parents[1] +DATA = ROOT / "source_inputs" / "competitive-intel" / "landscape.v0.yaml" +SCHEMA = ROOT / "schemas" / "competitive-landscape.schema.json" +SEVERITIES = {"critical", "high", "medium", "low"} +STAGES = {"experimental", "beta", "ga", "scaled"} + +errors: list[str] = [] +doc = yaml.safe_load(DATA.read_text()) + +if doc.get("apiVersion") != "gdsi.socioprophet.org/v0": + errors.append("apiVersion must be gdsi.socioprophet.org/v0") +if doc.get("kind") != "CompetitiveLandscape": + errors.append("kind must be CompetitiveLandscape") + +competitors = (doc.get("spec") or {}).get("competitors") or [] +if not competitors: + errors.append("spec.competitors is empty") + +seen: set = set() +for c in competitors: + key = f"{c.get('vendor')}/{c.get('product')}" + if key in seen: + errors.append(f"duplicate competitor: {key}") + seen.add(key) + for field in ("vendor", "product", "cluster", "maturity", "beats_us_on"): + if field not in c: + errors.append(f"{key}: missing {field}") + if (c.get("maturity") or {}).get("stage") not in STAGES: + errors.append(f"{key}: maturity.stage not in {sorted(STAGES)}") + if not c.get("beats_us_on"): + errors.append(f"{key}: beats_us_on is empty (an entry with no gap should be dropped)") + for g in c.get("beats_us_on", []): + for field in ("capability", "severity", "evidence"): + if field not in g: + errors.append(f"{key}: gap missing {field}") + if g.get("severity") not in SEVERITIES: + errors.append(f"{key}: gap severity {g.get('severity')!r} not in {sorted(SEVERITIES)}") + +# Optional strict schema validation when jsonschema is installed. +try: + import jsonschema # type: ignore + try: + jsonschema.validate(doc, json.loads(SCHEMA.read_text())) + except jsonschema.ValidationError as exc: # pragma: no cover + errors.append(f"schema: {exc.message}") +except ImportError: + pass + +if errors: + print("VALIDATION FAILED:") + for e in errors: + print(f" - {e}") + sys.exit(1) + +gaps = sum(len(c.get("beats_us_on", [])) for c in competitors) +print(f"ok: competitive-landscape valid — {len(competitors)} competitors, {gaps} gap findings") From fb8fd1b9cf48cdaadfe59bc272cfa76a6e346558 Mon Sep 17 00:00:00 2001 From: Michael Heller <21163552+mdheller@users.noreply.github.com> Date: Mon, 3 Aug 2026 19:29:53 -0400 Subject: [PATCH 2/3] =?UTF-8?q?docs(competitive):=20the=20superiority=20ma?= =?UTF-8?q?rch=20=E2=80=94=20close=20every=20gap=20faster/secure/ergonomic?= =?UTF-8?q?/open?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/competitive/superiority-march.md | 43 +++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 docs/competitive/superiority-march.md diff --git a/docs/competitive/superiority-march.md b/docs/competitive/superiority-march.md new file mode 100644 index 00000000..84cf7318 --- /dev/null +++ b/docs/competitive/superiority-march.md @@ -0,0 +1,43 @@ +# The Superiority March + +> The plan to answer [`where-we-stand.md`](where-we-stand.md): close **every** capability gap, but +> do each one **faster, more secure, more ergonomic, and fully open** than the incumbent — so a gap +> becomes a differentiated win, not parity. Generated register is the scoreboard; this is the march. + +## Doctrine (how "we win, and open" is different from "we catch up") + +Every incumbent capability we're behind on is either (a) SaaS/closed, (b) advisory not enforced, or +(c) audit-logged but not cryptographically verifiable. Our answer to each is the same shape: + +- **Faster** — scale-to-zero, event-driven, deterministic-first (the model is a thin edge, not the gate). +- **More secure** — fail-closed by default; every action pre-gated by policy AND sealed into evidence. +- **More ergonomic** — agent-native (MCP) + one-command golden paths; the platform is drivable by an agent. +- **Fully open** — MIT, self-hosted, our own Gitea/zot/runners; no external SaaS, no lock-in, and + **standards-based** provenance (cosign/SLSA/in-toto) so trust is externally verifiable, not self-issued. + +## The sequenced moves (dependency order; each closes ranked gaps) + +| # | Move | Closes (gap register) | Our open edge over the leader | Status | +|---|------|----------------------|-------------------------------|--------| +| 1 | **Governed MCP ops surface** on the control plane | `agent-native-mcp-ops-surface` (#1, 8 ahead) | Qovery/Port gate pre-exec + audit-log (SaaS). We add **fail-closed + hash-sealed receipts on every tool call**, fully open, scale-to-zero. | **executing** | +| 2 | **Wire observability** (Prometheus/Grafana/Loki/Tempo behind the OTel collector) | keystone for #2/chaos/autoscale | Open OTel stack, self-hosted; unblocks metric-gated everything. | next | +| 3 | **Metric-gated progressive delivery** (canary/blue-green + auto-rollback + our sealed promotion gate) | `progressive-delivery-auto-rollback` (#2, 6 ahead) | Argo Rollouts analysis, but **gated by our sealed APPROVE verdict** and evidenced — auto-rollback *and* provenance. | sequenced | +| 4 | **Standards-based attestation** (emit cosign/SLSA/in-toto via our `zot`) alongside receipts | `attestation-provenance-slsa`, and repairs the "self-issued receipts" weakness | **Externally verifiable** provenance (public-log-compatible) + our governed enforcement wrapper on top. | sequenced | +| 5 | **Service mesh** (Istio mTLS + gateway; MeshSpace-style header routing) | mesh net-new (diagrams) | Open Istio, sovereign; enables canary traffic-shifting. | sequenced | +| 6 | **Autonomous fix-and-verify remediation** (re-vendor executor + reviewer → propose+validate fix) | `autonomous-remediation-agents`, `malicious-package-detection` | Endor/Harness fix (SaaS). Ours: sealed, fail-closed, open; add reachability + malicious-package signal to the loop. | sequenced | +| 7 | **Broad-ecosystem dependency intelligence** (reachability + confidence + malicious-package) | `vuln-db-broad-scanning`, `reachability-exploitability`, `broad-ecosystem-dep-automation` | Consume OSS advisory data (OSV) + reachability; keep it sovereign + receipted. | sequenced | +| 8 | **Developer portal + inner-loop dev-environments** (Nocalhost-style DevSpace + web console) | `web-ui-developer-portal`, dev-env diagrams | Open catalog + golden paths over CapD; agent-driven via move #1. | sequenced | +| 9 | **Compliance evidence automation** (map sealed receipts + attestations → SOC2/FedRAMP controls) | `compliance-certifications` | Turn our provenance into audit evidence; open control mappings. | sequenced | + +## Meet-or-beat on the reference diagrams + +- **Nocalhost DevSpace/MeshSpace, Istio mesh** → moves #5, #8 (we're behind; open Istio + DevSpace). +- **Sovereign Agentic Cloud-Shell, Agent Governance Architecture** → move #1 realizes these; they are *our* design — the march makes them real and shipped. +- **Karpathy wiki pipeline** → already realized: this intelligence suite *is* structured-knowledge + generated projections. +- **prophet-platform readiness (Have/Partial/Net-new)** → observability keystone = move #2; mesh/canary/chaos = moves #3/#5. + +## Non-skimp clause + +Each move ships the nice-to-haves that make it ergonomic, not just the minimum: MCP tool schemas + +elicitation, one-command golden paths, sealed receipts on every action, and standards-based +attestation — because "more ergonomic and fully open" is the whole point of the march. From 3e2f2509add4d6abb4c28a7faeeae3b5fd8e29c1 Mon Sep 17 00:00:00 2001 From: Michael Heller <21163552+mdheller@users.noreply.github.com> Date: Tue, 4 Aug 2026 20:01:32 -0400 Subject: [PATCH 3/3] =?UTF-8?q?chore:=20regenerate=20MANIFEST.txt=20?= =?UTF-8?q?=E2=80=94=20add=20docs/competitive/superiority-march.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- MANIFEST.txt | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/MANIFEST.txt b/MANIFEST.txt index 6e1e21f6..c3b51d42 100644 --- a/MANIFEST.txt +++ b/MANIFEST.txt @@ -54,6 +54,8 @@ docs/architecture/ops-ingestion-and-measurement-plane.md docs/architecture/runtime-control-plane-telemetry-alignment.md docs/architecture/support-and-premium-support-ai4it-loop.md docs/architecture/telemetry-surface-profile.md +docs/competitive/superiority-march.md +docs/competitive/where-we-stand.md docs/devops/ci-validation-gate.md docs/devops/client-runtime-dump-exposure.md docs/devops/devops-process-open.md @@ -97,12 +99,15 @@ open-ai4it-spec/modules/story_services/README.md open-ai4it-spec/modules/story_services/incident_similarity/scorer.py profiles/browser-telemetry-risk-profile.v0.yaml profiles/client-runtime-dump-exposure-profile.v0.yaml +profiles/competitive-landscape-profile.v0.yaml profiles/github-footprint-itops-expansion.yaml profiles/operational-exhaust-fusion-profile.v0.yaml requirements.txt +schemas/competitive-landscape.schema.json schemas/github-footprint-itops-generated.schema.json serve.py source_inputs/README.md +source_inputs/competitive-intel/landscape.v0.yaml source_inputs/institutional-account/account-hierarchy.v0.json source_inputs/integration-planes/ops-integration-map.v0.json source_inputs/ontogenesis/module-map.v0.json @@ -113,6 +118,7 @@ third_party/ibm-itops/GLO_V1-profile-excerpt.ttl third_party/ibm-itops/IMPORT-MANIFEST.v2.json third_party/ibm-itops/LICENSE.Apache-2.0 third_party/ibm-itops/UPSTREAM.md +tools/generate_competitive_gap_register.py tools/generate_github_footprint_itops_projection.py tools/mesh_consume.py tools/tests/fixtures/client-runtime-dump-exposure/allowed-synthetic.txt @@ -128,6 +134,7 @@ tools/tests/test_resource_contract_verdict.py tools/tests/test_serve.py tools/tests/test_service_desk_metrics.py tools/validate_client_runtime_dump_exposure.py +tools/validate_competitive_landscape.py tools/validate_github_footprint_itops.py tools/validate_incident_similarity.py tools/validate_manifest.py @@ -136,9 +143,3 @@ tools/validate_model_fabric_release_readiness.py tools/validate_operational_exhaust_fusion.py tools/validate_resource_contract_telemetry.py tools/validate_service_desk_metrics.py -schemas/competitive-landscape.schema.json -profiles/competitive-landscape-profile.v0.yaml -tools/validate_competitive_landscape.py -tools/generate_competitive_gap_register.py -source_inputs/competitive-intel/landscape.v0.yaml -docs/competitive/where-we-stand.md