UpcomingNot shipping yetDesign phase · public architecture

Roadmap onlynot in open core yet. Run the free mesh today.

OPS / Enterprise · roadmap

[INSTITUTIONAL EDGE]

Commercial layer on open-core HOOX: multi-tenant isolation, Workflows, audit, compliance. Design public — code closed and upcoming.

WfP
Upcoming · multi-tenant
Workflows
Upcoming · durable
Logpush
Upcoming · audit
Open core
Available now · free
Open core ↔ Enterprise
Tenancy
Single-tenant / self-hosted
Multi-tenant SaaS or dedicated Ent account
Multi-step durability
Queues + cron + Durable Objects
Workflows (hours/days, step state, human gates)
Audit
Analytics Engine + structured logs
Logpush → R2 / SIEM, Tail Workers, long retention
Security rings
Five-layer model
Layers 0–5+ (Bot Mgmt, API Shield, Access, AI Gateway)
Real-time
REST default; optional WS DO
Hibernatable WS, event-driven risk
AI
Workers AI + basic RAG
AI Gateway, cost control, institutional volume
Support
Community / self-serve
Commercial SLAs, runbooks, higher limits
Capability pillars

Six levers that amplify the open core without reintroducing regional VMs.

01Multi-tenancyUpcoming

Workers for Platforms

True multi-tenant isolation: Dispatch Worker routes by tenant claim / subdomain to isolated User Workers per fund, strategy book, or customer.

  • Namespaces, tags for metering and billing
  • Per-tenant DOs, Queues, D1/R2 paths, secrets
  • Synchronous first deploy — routable when HTTP 200
  • Hosted SaaS or dedicated Enterprise account
Docs ↗
02Durable executionUpcoming

Cloudflare Workflows

Long-running, step-persisted trade and compliance processes — hours to days — with retries, pause-for-external-events, and human approval gates.

  • Full trade lifecycle: validate → risk → execute → reconcile → report
  • Atomic kill-switch + flatten sequences
  • Compliance reports with approval gates
  • Post-trade reconciliation across exchanges and storage
Docs ↗
03ComplianceUpcoming

Logpush · Traces · R2 Audit

Regulator-grade observability: Workers Trace Events, HTTP, WAF, Queues, DOs pushed immutably to R2 or SIEM with long retention.

  • One-click R2 Logpush + custom fields
  • Tail Workers for sample / filter / enrich
  • End-to-end traces across Bindings, DOs, Queues, Workflows
  • Analytics Engine for metrics; Logpush for audit
Docs ↗
04Layers 0–5+Upcoming

Extended Security Stack

Open-core five-layer model plus Enterprise Bot Management, API Shield, Zero Trust Access, mTLS, and AI guardrails.

  • Bot scores, JA3/JA4, verified bots on signal ingress
  • API Shield: schema, JWT, mTLS, sequence mitigation
  • Access SSO, SCIM, device posture for ops surfaces
  • AI Gateway: sanitization, rate limit, cost control
Docs ↗
05Real-timeUpcoming

Hibernatable WebSockets

Persistent exchange connectivity via Durable Object hibernatable WebSockets — live fills, partials, and books without burning CPU while idle.

  • ExchangeConnectionManager DO pattern
  • Event-driven risk beside (or instead of) cron
  • Cheap keep-alive while DO sleeps
  • Pairs with Workflows for durable stream handling
Docs ↗
06Limits · AI · DataUpcoming

Institutional Scale

Higher CPU, memory, subrequests, D1/R2/Queue/Vectorize quotas, AI Gateway at volume, and data residency controls on R2.

  • Custom limit increases via account team
  • AI Gateway logging, caching, multi-provider failover
  • R2 jurisdiction + lifecycle for immutable audit
  • Hyperdrive for hybrid historical data if needed
Docs ↗
Security layers 0–5+
0
Bot Management

Scores, verified bots, JA3/JA4, early drop of toxic signal sources

1
WAF + API Shield

Schema validation, JWT, mTLS, 100+ rate-limit rules

2
Zero Trust Access

SSO, SCIM, device posture on dashboard and mgmt APIs

3
Internal + mTLS

Service Binding auth + per-tenant claims, optional mTLS

4
DO + crypto controls

Idempotency mutex, signed audit records, fail-closed isolation

5
AI Guardrails

Gateway sanitization, rate limits, cost ceilings on LLM paths

Non-negotiable invariants
  1. 01Edge-native composition — Service Bindings, DOs, Smart Placement stay the mesh
  2. 02Evolutionary — open-core workers become templates and system services, not a fork-from-scratch
  3. 03Isolation before convenience — tenant leakage fails closed at dispatch
  4. 04Audit by default — security events are immutable appends
  5. 05Open core stays useful — institutions scale up; individuals are not degraded
Documentation
Next step · today

Ship on open core. Plan for OPS.

Deploy open core now. Enterprise later for multi-tenant SLAs and compliance.