overview
9
Status meetings held since Jan 2026
~72%
Estimated build progress
Q2 '26
Target go-live (end of quarter)
3% → 100%
Certificate coverage uplift at full production
feature build progress
Core rule-based flagging engine100%
Okta SSO access (staging + production)100%
VWB link integration & image scanning100%
AI feedback loop & false-positive retention90%
Validation check coverage (OV/EV/VMC/S-MIME)85%
Cert-level analytics dashboard drill-down60%
Automated image processing20%
Daily API pull from engineering15%
quarterly breakdown (Q1 = Feb–Apr · Q2 = May–Jul · Q3 = Aug–Oct · Q4 = Nov–Jan)
Q1 FY27
Feb – Apr 2026
- Introductory meeting; hybrid automation strategy agreed
- Tool named TOAST; basic UI and flag interface built
- AI deep check added alongside rule-based engine
- Image access from VWB obtained; Cloud Vision scanning live
- Dashboard tracking error trends by BR version implemented
- VWB link on all orders; PEM parser created
- Okta tile set up; staging environment accessible via VPN
- Certificate checks expanded from 8 to 11
- API batch import set up; OEM page link replacing PEM display
- Phone, address, and request-authenticity flags in progress
- “Request certificates” button — pending engineering
Q2 FY27
May – Jul 2026 · current quarter
- AI false-positive feedback retention fixed and confirmed
- Fetch issued certificates feature repaired (Databricks)
- “Audit failure” flag type removed; 3 types finalised: Critical / Remediation / Bookkeeping
- Grouped flagged orders view introduced (bulk review)
- Org-level CSV export with audit status and product type
- Document source URL backend retrieval implemented
- AI training expanded: OV → EV → MARC → S/MIME in progress
- Cert-level analytics dashboard — with Danny, in progress
- Flag breakdown by validation step — design done, build pending
- Downloadable confirmed-error report (serial numbers, steps, notes)
- High-risk agent review feature — ticket created, not in sprint
- Automated image processing — waiting on engineering
Q3 FY27
Aug – Oct 2026 · planned
- Hybrid parallel run: TOAST + 3% manual audit side-by-side
- Daily API integration with validation backend goes live
- Automated image processing (once engineering delivers)
- Full EV / OV / VMC / Code Signing / S-MIME coverage
- BDO sign-off on automation approach (before Q3 audit)
- Bedrock Guardrails integration for managed PII redaction
- Expanded RAG over full VAL Confluence space
- Per-analyst quality dashboards
Q4 FY27 +
Nov 2026 onwards · future state
- 100% coverage replaces 3% random sample as primary audit method
- Old manual process formally phased out
- Automated remediation report to CAS management (replaces manual Excel)
- Qualified certificates onboarded (excluded initially due to complexity)
- Slack or email integration for CAS remediation notifications
- TOAST-generated evidence replaces manual sample reports for external auditors
Complete
In progress
Planned / pending
meetings timeline
26 Jan 2026
Introductory meeting — hybrid strategy agreed; phased build starting with OV
11 Feb 2026 · Q1 start
SR1 — basic UI live; flags with descriptions, references and confidence; 100% audit plan confirmed
25 Feb 2026
SR2 — tool named TOAST; AI deep check added; bookkeeping vs. remediation logic correct; KB outline begun
1 Apr 2026
SR3 — functional interface accessible via VPN; dashboard tracking errors by BR version; Okta SSO in progress; document notes gap identified
8 Apr 2026
SR4 — stage env live; image scanning via Cloud Vision; checks 8→11; go-live target end of Q2; Q3 hybrid parallel run planned
15 Apr 2026
SR5 — Okta access granted to Elle, Blake and Kim; AI learning confirmed; image coverage tracking live; PEM setup complete
22 Apr 2026 · Q1/Q2 boundary
SR6 — API batch imports ready; EV/OV/VMC/Code Signing/S-MIME scope confirmed; 100% audit intent restated; Databricks fetch error resolved
6 May 2026
SR7 — AI feedback loop built; URL verification logic updated; Bugzilla integration descoped; grouped flag view designed; high-risk agent feature scoped
13 May 2026
SR8 — cert count export live; 3% hybrid sampling strategy agreed; auditor evidence gap flagged; ~230 snapshots/month baseline confirmed
27 May 2026 · most recent
SR9 — false-positive fix confirmed; grouped view live; MARC and S-MIME AI training underway; analytics dashboard handed to Danny; standard practice for notes on all flag reviews agreed
flag severity framework
Critical
Breaks a CABF Baseline Requirement. Missing OV/EV evidence, expired validation docs at issuance, cert validity exceeding BR limits, blocklisted domains, missing dual-agent sign-off.
Remediation
Fixable issues that do not invalidate the cert. Incomplete org info, stale JOI data, contact method gaps, undocumented verification calls, format inconsistencies.
Bookkeeping
Process and documentation hygiene. Missing audit notes, incomplete tile documentation, process deviations that do not affect cert validity.
projected impact vs current 3% manual process
Audit coverage
3% → 100%
Every certificate reviewed daily (~1,000–1,200 snapshots/day) vs quarterly random sample
AI analysis cost
~$20–$25 / day
~$0.018–$0.022/order (Claude Sonnet 4.6 on Bedrock: $3/1M input + $15/1M output tokens) · pay-per-token, no idle GPU spend
Error detection speed
Same-day
vs weeks/months lag in quarterly spot-check model
Monthly audit baseline (SR8)
~230 snapshots
~40 errors/month · ~29 unique org-level issues · mix: OV 10%, EV 43%, OV CS 17%, EV CS 11%, S-MIME 18%
Compliance risk
Substantially lower
CABF Forum/WebTrust incidents avoided by catching remediation and critical issues before external audit
Auditor evidence
Automated reports
Replaces manual Excel. TOAST provides issued vs. need-to-audit vs. audited counts for BDO review
time and cost impact calculator
Adjust assumptions to your actuals
manual audit hours — current 3% baseline
Time by product type — manual (monthly)
Detailed breakdown — manual (monthly)
| Product | Count | Min/cert (clean/error) | Hours |
|---|
with TOAST — scenarios
Monthly auditor hours — scenario comparison