The honest state of the platform: what's live in the private beta, the limitations we know about, and what's on the roadmap. We keep this page current as things ship — if something here would surprise you, we'd rather you read it now than find it in production.
The engine is built and running — an append-only ledger, a governed rules DSL, GraphQL reporting, and GDPR-by-design privacy, exercised by 1,100+ automated tests and currently tagged v0.9.0-beta.2. The platform rebuilds from scratch on Azure and seeds its demo tenant through its own import APIs — the same path your historical data takes. What's still maturing is the adoption surface: self-serve provisioning is rolling out via the waitlist, and onboarding is operator-guided while the design-partner cohort is small. That's the trade we're offering early teams: direct founder access and roadmap influence, in exchange for patience with the rough edges below.
Append-only entries, atomic transaction grouping, snapshot balances. Cancels and refunds post as first-class reversals.
Sandboxed evaluator, 50ms timeout, complexity budget, dry-run simulation, deterministic A/B splits, campaign multipliers, tier auto-qualification.
DataLoader, cursor pagination, real-time WebSocket subscriptions, dataAsOf staleness metadata.
Per-customer envelope encryption, cryptographic erasure, a PII-free event bus verified by negative tests in CI, and an append-only audit log with per-tenant configurable retention.
Points-to-credit conversion, typed credit with expiry and FEFO consumption, redemption with reversal windows, finance analytics.
Shopify, Salesforce OMS, and SFCC inbound; Segment, Klaviyo, Iterable, and Salesforce Marketing Cloud outbound with consent-gated egress. Caveats below.
Bring your order history and opening balances through an auditable import API with declared-vs-actual reconciliation reporting.
CloudEvents envelopes, HMAC-signed delivery (live-validated end-to-end), SSRF protection, retry with dead-lettering, secret rotation with show-once reveal — plus a delivery dashboard covering every webhook and connector delivery, with dead-letter replay.
Per-tenant machine agents over the Model Context Protocol — read-scoped, tenant-bound (cross-tenant access fails closed, proven live), with provision / rotate / revoke credential lifecycle in the portal and every action audited.
Open-source member widgets on npm (mock-first today), a docs portal, an API explorer, and an in-app AI assistant.
Per-tenant OIDC federation (Entra ID, Okta, Google Workspace, Auth0, Ping) with JIT provisioning — live-validated end-to-end against Microsoft Entra ID. Tenant portals are served on per-tenant custom domains (private beta).
None of these affect ledger balance integrity — points and credit balances are transactionally maintained and idempotent. They are behavioural limits you should design around, and each is on the backlog with a stated direction.
These appear on our feature and pricing pages clearly labelled as roadmap. Listing them here too, so there's one honest answer everywhere.
Native feeds to Snowflake, BigQuery, Synapse/Fabric, Redshift. Today, historical data moves via the import API.
Rules run on the sandboxed IR evaluator today; a hardware-isolated tier is planned for Scale/Enterprise.
GraphQL server-side allow-listing and a published query-cost budget are coming; pagination caps apply today.
Provisioning is rolling out via the waitlist; today a sandbox is set up for you.
Service-mesh mTLS, event schema registry, multi-region DR, FIDO2 + four-eyes super-admin.
Inbound connectors (Shopify, Salesforce OMS, SFCC) are feature-flagged per tenant and validated against your store during onboarding. Iterable and Salesforce Marketing Cloud outbound adapters are built and tested but await live vendor-sandbox validation. The SFCC cartridge is a reference implementation; certification is in progress. Widget live-backend wiring is the final GA step (mock mode works today).
Beta support is founder-direct and best-effort, with target — not contractual — response times; formal SLAs arrive at GA. SOC 2 Type I is in progress (a pre-certification evidence pack is available to prospects under review; a third-party pen test is scheduled). Data protection is by architecture: DPA with SCCs, per-customer envelope encryption, and cryptographic-erasure offboarding with a defined export grace period — see the Trust Center.
Design partners get direct founder access and a real say in what ships next — and a fuller, versioned copy of this disclosure with their agreement. Last updated 15 July 2026.