Inventory. Revenue. Vendors. Supply chain. Cash flow. Cross-system failures are hiding across all of it. Sign up — your critical intelligence tabs are waiting.
How DuluthPath is built today, and where the platform is going. Every component is labelled LIVE, ROADMAP, or REFERENCE ARCH.
DuluthPath is an actively developed platform. This page shows what is live today and our 18-month roadmap. We believe enterprise buyers deserve clarity over marketing — so we show both.
Production today — every item is wired and running.
REST APIs (FastAPI)
Every backend route — async, OpenAPI-documented
OAuth 2.0 / Microsoft Entra ID
Authorization-code + client-credentials flows
Fernet-encrypted credentials
OAuth tokens encrypted at rest with symmetric AES
Multi-tenant JWT isolation
Phase B fence enforced — 1,433 docs tenanted, 17 compound indexes
Webhook delivery (signed POST)
HMAC-signed outbound deliveries with retry
MongoDB operational store
Primary data store across every collection
Self-hosted heartbeat agent
Offline JWT license + 5-min heartbeat to control plane
Designed for the next 12–18 months. Performance numbers below are design targets, not yet measured in production.
Apache Kafka event streaming
Design target: 100K+ events/sec, <10ms p99 — not yet measured
Kong / Apigee API gateway
Rate limiting, mTLS, request routing
SAP CPI middleware
RFC / IDoc adapters for SAP-native integration
MuleSoft Anypoint
Salesforce data mapping & orchestration
Debezium CDC
Change-data-capture from source systems into Kafka
Delta Lake / Snowflake
Petabyte-scale analytical warehouse
Redis cache layer
Hot-path KPI caching, session store
GraphQL API
Unified query layer over REST endpoints
Agent framework runtime, request-path data flow, and deployment topology — annotated so your architects can vet the platform without a call.
5 persistent agents poll live tenant data, open hash-chained investigations, propose actions with $-quantified impact, and (with authorization) write back to the connected ERP. Every action lands in the SOC 2 audit chain.
What actually happens when a subscriber asks Canaan a causal question. All ERP payloads stay inside the tenant boundary; only decision summaries cross into the LLM layer.
Kubernetes-hosted API + a standalone Mongo-polling worker for all background pipelines (agent ticks, causal-reasoner passes, SEO snapshots). Both are independently horizontally scalable.
Conceptual data lifecycle. Today, ingestion runs via REST polling into MongoDB; the Kafka/Debezium/Delta Lake path is the target architecture.
REST polling LIVE (Dynamics 365); CDC via Debezium/Kafka roadmap
PARTIALPydantic schema validation on every payload
LIVEPer-route mappers normalize Dynamics → DuluthPath model
LIVEMongoDB LIVE; Delta Lake / Snowflake roadmap
PARTIALREST APIs, pre-computed KPI aggregates
LIVEThese diagrams show how DuluthPath orchestrates data across enterprise systems. Flows marked LIVE are operational today; others show the target architecture as integrations are activated.
These capabilities are on the DuluthPath 18-month roadmap. The audit log, exception alerting, and financial reporting infrastructure are in place as the foundation.
Automated Reconciliation
Bank/GL match engine on roadmap
AI Journal Entries
AI-drafted accrual & adjustment entries
Autonomous Close
Orchestrated close with task gates
Invoice Matching
3-way match with AI suggested resolution
Continuous Audit
Audit log LIVE; automated control testing on roadmap
Exception Workflows
Finance-specific exception routing
DuluthPath Cloud (Managed Kubernetes)
DuluthPath runs on our managed K8s cluster with ingress, supervisor, MongoDB
Self-hosted Docker + docker-compose
On-premise bundle ships at deploy/self-hosted/ — real, downloadable
Offline JWT license system
Signed license issuance, fleet-side validation, expiry tracking
Fleet heartbeat agent
5-min heartbeat back to control plane with health telemetry
Multi-tenant SaaS
JWT-claim enforced row-level isolation across 19 collections
Dedicated single-tenant (manual deploy)
Platinum tier — bespoke deployment, not yet auto-provisioned
Azure AKS deployment
Native Azure cloud target — Bicep / Terraform module
AWS EKS deployment
Native AWS cloud target with CloudFormation
GCP GKE deployment
Native GCP cloud target with Deployment Manager
Automated pod autoscaling
HPA + KEDA event-driven scaling
Petabyte-scale warehouse
Delta Lake / Snowflake target — reference architecture
SSO Integration
SAML 2.0, OpenID Connect, Azure AD/Entra ID, Okta
RBAC + tenant isolation
JWT-claim enforced; field-level via tenant_query() helper
OAuth 2.0 / JWT
Authorization-code + client-credentials flows
MFA
Enforced for all admin access
Encryption at rest
MongoDB native encryption + Fernet-encrypted secrets
Encryption in transit
TLS 1.2/1.3 on every endpoint via ingress
Audit logging
tenant_audit_log — every action, 7-year retention design
PII / PHI masking
Configurable rules engine on roadmap
We list compliance status honestly. No item below is shown as “certified” unless it is.
AI Language Model
Claude Sonnet (Anthropic) powers Canaan AI advisory, document generation, and scenario analysis
Multi-model routing per task type
Different prompts and model temperatures per document type and analysis depth
Document analysis pipeline
15 enterprise document types — business case, board prep, vendor SLA, etc.
Scenario modeling & what-if sim
Live scenario simulators for O2C, P2P, finance close, SCM
Anomaly alerting (rule-based)
Threshold + tier-1/2/3 SLA escalation; ML anomaly on roadmap
Fernet-encrypted AI credentials
OAuth tokens for LLM provider and connector adapters encrypted at rest
Custom LSTM / Prophet forecasting
Time-series models for revenue, cash, demand forecasting
Isolation Forest anomaly detection
Unsupervised anomaly detection on transaction streams
RLHF feedback loop
User-feedback signal back into model selection & prompt tuning
Differential privacy
Privacy-preserving training data techniques — design principle
All AI-generated recommendations are logged with full audit trail. Critical financial decisions require human approval. Model versioning + prompt-template change tracking are in place.
Honest status per connector. Microsoft Dynamics 365 is the flagship live integration today; other connectors are at varying readiness stages.
SAP S/4HANA
Primary ERP · OData / RFC / IDoc
OData sync active — POs, PO items, inventory, goods receipts, suppliers
SAP ECC
Legacy ERP · RFC / BAPI / IDoc
Roadmap · Q3 2026
Oracle ERP Cloud
Cloud ERP · REST / SOAP
Auth wired, data stub · Q3 2026
Oracle E-Business Suite
On-Premise ERP · REST / JDBC
Roadmap · Q4 2026
Salesforce
Cloud CRM · REST / Bulk API
Account read live (25-row sample); full sync · Q3 2026
Microsoft Dynamics 365
Cloud ERP/CRM · OData / REST
Read sync active (SCM, Finance, Sales)
SAP CX
Experience Mgmt · OData / Events
Roadmap · Q4 2026
Blue Yonder
Supply Chain Planning · REST / EDI
Roadmap · Q3 2026
Kinaxis
Concurrent Planning · REST API
Roadmap · Q4 2026
E2OPEN
Supply Network · REST / AS2 / EDI
Roadmap · Q3 2026
Oracle SCM Cloud
Cloud SCM · REST / SOAP
Roadmap · Q4 2026
Power BI
BI / Dashboards · DirectQuery / REST
Marketing page live; live data sync · Q3 2026
Azure Machine Learning
ML / Inference · REST
Roadmap · Q3 2026
Tableau
BI / Storytelling · Hyper / Live
Roadmap · Q4 2026
API response time
<500ms p99 — measured
Alert delivery time
<30s end-to-end (event → alert console)
Sync cycle (Dynamics 365)
4-6 hours full refresh; on-demand re-sync available
Event throughput
100K+ events/sec — Kafka design target, not yet measured
Cache latency
<10ms p99 — Redis design target, not yet measured
Uptime target
99.9% — operational target, no public SLA backing yet
Independent performance audit available on request for Enterprise / Platinum tier customers.
Marketing landing pages are live for each platform; live data sync is on the roadmap.