Implemented research slice
- HTTP health, capabilities, policy resolution, key creation, sign and verify;
- pinned policy and explicit failure categories;
- opaque tenant-bound key references;
- in-memory software provider and non-secret evidence;
- OpenAPI, JSON Schema, examples and contract tests; and
- native personal-site research documentation.
Next operation coverage
- encryption and decryption;
- MAC generation and verification;
- key agreement;
- encapsulation and decapsulation;
- key derivation;
- symmetric-key lifecycle;
- rotation, transformation and migration; and
- richer discovery.
Algorithm priorities
The v2 examples center RSA-PSS, ECDSA P-256, ML-DSA-65 and the ECC-to-ML-DSA transition. Runtime work must add provider-specific execution, test vectors, negative tests and explicit profiles before any algorithm is labeled implemented.
Provider backends
Planned adapters include PKCS#11, OpenSSL, KMIP/KMS, JCA and cloud key services. Each adapter publishes capabilities and limitations without changing CALI semantics.
Platform work
- richer policy templates and security properties;
- gRPC and REST/HTTP gateway bindings;
- persistent storage encrypted at rest;
- hierarchical policy with regulatory profiles;
- local, remote and hybrid deployment modes;
- declarative key-evolution policy;
- Docker and Kubernetes packaging; and
- a black-box conformance runner and versioned test vectors.
Release rule
A roadmap item moves to implemented only when code, schemas, OpenAPI, examples, negative tests, documentation and security limitations agree.