Roadmap

What we shipped, what's in flight, what's next

Updated as we ship. No vapor — items move into "Shipped" only when they're running in production for paying customers. Want something specific? Tell us.

Shipped

In production today.

17
  • Verified savings receipts (d7 / d14 / d30)

    FinOps

    Every executed action is rechecked against the bill at three checkpoints; receipts mark verified, inconclusive or regressed.

  • Conflict guard before execution

    FinOps

    IaC ownership, freeze windows, policy protection, and ticket requirements run before any cloud API call.

  • Multi-cloud inventory

    FinOps

    AWS, Azure, GCP — compute, storage, network, database, Kubernetes, serverless and containers.

  • Commitment optimizer

    FinOps

    AWS RI + Savings Plan + Azure Reserved + GCP CUD recommendations with confidence intervals.

  • Per-feature AI cost attribution (BYOAI)

    AI

    OpenAI / Anthropic / Gemini usage tracked per feature, per end-user, per model — without proxying customer traffic.

  • Cost anomaly detection (FIN-ANO-001)

    AI

    24-hour burn-rate anomaly detection with dashboard surfacing.

  • Approval-gated remediation

    Security

    Manual approval default; per-action approval chains, freeze windows, per-role permissions, audit trail.

  • AES-256-GCM credential encryption + HSM-optional

    Security

    HKDF-derived keyring, per-row keyVersion audit column, optional AWS KMS / Azure Key Vault / GCP Cloud KMS.

  • Tenant isolation: RLS on 49 tables

    Security

    Postgres row-level security on every tenant-scoped table; automated quarterly drift audit.

  • SAML SSO + SCIM provisioning

    Security

    Enterprise identity with per-token rate limiting, rotation and soft-revoke endpoints.

  • AuditLog monthly partitioning + retention cron

    Platform

    Partitioned table with rolling partition-maintenance cron; plan-based retention.

  • Per-organisation rate limiting

    Platform

    Redis-backed throttling keyed by organisationId; per-IP fallback for pre-auth routes.

  • BullMQ correlation propagation

    Platform

    HTTP correlation ID flows into job context so worker logs join back to the originating request.

  • Dead-letter queue visibility

    Platform

    Threshold-flagged DLQ metric in Prometheus, admin digest endpoint with recent failure reasons.

  • Audit evidence export

    Enterprise

    CSV / JSON exports for audit logs, findings, resources, evidence artifacts.

  • Jira + ServiceNow + Slack / Teams integrations

    Enterprise

    Ticket creation, webhook dispatch, configuration UI with permissions guide.

  • Stripe billing + plan entitlements

    Enterprise

    Plan catalog, checkout, portal handoff, idempotent webhook handling.

In progress

Active engineering work.

4
  • SOC 2 Type II readiness

    Enterprise

    Trust Services Criteria mapping done; auditor engagement scheduled.

  • External penetration test

    Enterprise

    Vendor selection underway; summary report will be made available to enterprise customers under NDA.

  • First disaster-recovery restore drill

    Platform

    Quarterly cadence starting Q3 2026.

  • OpenAPI auto-publish + Postman collection

    Platform

    Swagger generation already in place; export to /api/openapi.json and a curated Postman collection.

Next

Committed for the upcoming quarter.

6
  • US data residency option

    Enterprise

    Second Supabase project + Render region for customers with US-only data requirements.

  • Slack-first daily digest

    FinOps

    Per-org daily summary of top recoverable spend, top findings, top pending actions — directly into Slack.

  • Per-customer cost attribution (unit economics) refinements

    FinOps

    Better ingestion of customer mapping data and clearer cost-per-customer chart in the executive view.

  • AI model rightsizing recommendations

    AI

    Highlight features where a smaller model would meet observed quality thresholds at a fraction of the cost.

  • Distributed cron locking

    Platform

    ShedLock-style lock so multiple worker instances can run safely behind a load balancer.

  • Quarterly access review automation

    Security

    Auto-generated report of PlatformAdmin and per-org-admin members for SOC 2 evidence.

What you do notsee here is intentional. We do not publish speculative ideas; the roadmap is a commitment, not a wish list. If something you care about isn't listed, talk to us— customer asks move items into "Next".

Last updated continuously. See the changelog for shipped-and-deployed history.

Get started

Find recoverable spend before the next invoice lands.

Connect one AWS, Azure or GCP scope, approve the safest savings actions, and give finance a receipt when the savings verify.

Read-only scan first. Approval gates before remediation.