Skip to content
Open Beta Hansestack is completely free during the current phase. 🐙 Submit feedback on GitHub

Roadmap

At Hansestack, you won't find artificially inflated feature lists designed to impress investors. We build what delivers real value in European B2B environments, simplifies GDPR compliance, and secures operations.

Here is the current roadmap for our upcoming development phases.

Open Beta & Core Service

Our full focus is on the stability and delivery of the Hansestack Leak Check.

  • Core API Release: Highly available REST interface for password verification against leak databases.
  • Infrastructure Validation: Testing latency and scalability under real-world load during the Public Beta.
  • Official Company Incorporation: Finalizing the legal framework in Germany prior to the commercial launch.
  • Hansestack Caddy Plugin: Ops over Dev. A native plugin for the Caddy web server to integrate the leak check directly into the reverse proxy at the infrastructure level—without touching application code.
  • Hansestack Kong Plugin: Analogous plugin for Kong Gateway to natively integrate the leak check into enterprise environments using Kong as their central API gateway.
  • Custom Password Lists: Companies can maintain their own password blocklists, which the API checks alongside global breach databases—ideal for internal password policies, credentials compromised in previous incidents, or industry-specific banned lists.

Production & Self-Service

Prior to the commercial launch, the infrastructure will be prepared for SLA-backed operations and our billing model. There deliberately won't be complex analytics dashboards here—the core product is a fast security API, and data sovereignty over login metrics remains within the customers' auth systems anyway.

  • Billing & Subscription Management: Integration of Paddle for straightforward, legally compliant self-service in the European market, including automated overage billing to prevent API blockages during the login flow.
  • Cost Control & Alerting: Automated email notifications upon reaching the included volume quota, ensuring customers retain full control over any overage fees.
  • Production-Ready Launch: Official launch of the regular service with guaranteed Service Level Agreements (SLAs) for enterprise customers.

Evaluation of New Components

New infrastructure components will only be designed once the Leak Check is successfully established in the market. OpenAPI/Swagger specifications will remain the standard for all future endpoints. The following problem areas are currently on the evaluation list:

  • EU-Hosted SSRF Proxy: A secure, isolated proxy service to reliably prevent Server-Side Request Forgery (SSRF) during outgoing webhooks or URL fetches.
  • Privacy-First IP Threat Intel: A fast API for verifying incoming IP addresses (botnets, Tor nodes, proxy lists) without logging risks or data leakage to the US.
  • Webhook Delivery Gateway: A data-sovereign node for the highly available delivery of webhooks, including retries and signature management.

Missing a feature or component?

The best roadmap is driven by real-world needs. If you have a technical challenge in your backend that you'd like to outsource in a data-sovereign way, share your idea with us: