Features
Product Feature Inventory
This inventory is the documentation checklist for the product catalog in lib/substrate-product-categories.ts. Each product area below lists the capabilities currently declared in the website product model.
AI
Inference
- llama.cpp and vLLM runtimes
- Model download and integrity verification
- Node enrollment, health, drain, and updates
- Private and public capacity planes
- Model and runtime attestation
- Distributed KV cache sharing
- Prefill/decode and distributed-runtime foundations
Distributed KV caching
- Cross-worker KV cache sharing
- Prefix-aware cache placement
- Cache-affinity routing
- Shared cache lifecycle
- Tenant and model isolation
- Cache hit and reuse evidence
Marketplace
- Model and artifact discovery
- Private capacity pools
- Public surplus-capacity offers
- Skill search, import, and updates
- Signed usage records
- Tenant, project, model, and cache isolation
Agent fleet
- Single and multi-agent execution
- Validated task plans and concurrent waves
- Agent identities, keys, sessions, and connections
- Cohorts and fleet-level operations
- Human approval and secure forms
- Operational memory and verification loops
AI gateway
- OpenAI-compatible Chat and Responses APIs
- Cost, latency, throughput, and balanced routing
- Provider and model fallback
- Exact response cache and cache affinity
- PII, injection, exfiltration, and tool controls
- Durable usage, request history, and traces
RAG
- Schema and entity discovery
- Lexical and vector retrieval
- Relationship and lineage signals
- Permission-aware context
- Sensitive-data redaction
- Agent and AI gateway integration
Semantic layer
- Schema and entity discovery
- Relationship and lineage graphs
- Entity resolution
- Weighted retrieval and embeddings
- Curated context briefs
- Schema-search tools and prompt augmentation
Training
- Dataset registration and lineage
- Training-job orchestration
- LoRA and adapter lifecycle
- Checkpoint and artifact management
- Model evaluation and approval gates
- Deployment into governed model routes
Storage
Key-value
- High-throughput reads and writes
- Low-latency key access
- Workload-aware caching
- Policy-aware gateway paths
- Migration and replay readiness
- Self-hosted deployment
Relational
- SQL and relational access
- Schema-aware operations
- Transactions and composition
- Workload intelligence
- Live migration paths
- Self-hosted deployment
Object storage
- Durable object storage
- Bucket and object policy
- Placement-aware access
- Artifact lifecycle
- Migration and replication paths
- Self-hosted deployment
Document
- Document-native access
- Schema discovery
- Collection and field policy
- Query and workload evidence
- Live migration paths
- Self-hosted deployment
Streaming
- High-throughput event streams
- Topic and consumer controls
- Replayable event history
- Gateway and storage integration
- Operational telemetry
- Self-hosted deployment
Data in Motion
Multi-gateway
- Endpoint registration and metadata
- PostgreSQL, MongoDB, Redis, SQL, NoSQL, cache, vector, warehouse, and API paths
- Connection pooling and backend lanes
- Command, query, and endpoint policy
- Traffic routing, mirroring, and failover
- Scoped credentials and access evidence
Auto caching
- Repeat-read detection
- Policy-aware cache placement
- Freshness and invalidation controls
- Hot-path optimization
- Cache hit and miss evidence
- Per-tenant and per-endpoint isolation
Traffic replication
- Multi-endpoint traffic copies
- Source-authoritative execution
- Response and error comparison
- Target health and latency evidence
- Cohort and route controls
- Migration and cutover preparation
APIs & integrations
- Published API lifecycle
- Endpoint and template bindings
- Function endpoints
- REST and GraphQL integrations
- SaaS and developer-tool endpoints
- Migration-aware execution
Workflows
- Workflow definitions and versions
- Workflow planning and runs
- Workflow lifecycle controls
- Triggers and event sources
- Reusable templates
- Operational status and evidence
Transactions & composition
- Cross-database ACID transactions
- Typed template inputs
- Conditions and iteration
- JSON mapping utilities
- Template access controls
- Versioned execution
Modernization
Live migrations
- Historical copy
- Live write capture
- Log-and-replay
- Progress and throughput metrics
- Pause and resume
- Completion and cancellation controls
Modernization
- PostgreSQL, MongoDB, and MySQL selected routes
- Schema and field mappings
- Request mappings
- Compatibility reports
- Vector and search migration previews
- Route-specific maturity controls
Migration readiness
- Source and target preflight
- Compatibility analysis
- Historical workload analysis
- Readiness recommendations
- Route and mapping plan
- Approval-ready evidence
Traffic replay & live testing
- Traffic mirroring
- Captured request replay
- Controlled live traffic
- Canary and cohort targeting
- Source-target verification
- Performance thresholds and fail-closed controls
Backup & recovery
- Backup lifecycle
- Snapshot lifecycle
- Artifact download
- Status and statistics
- Recovery primitives
- Migration-linked evidence
Operations
Live operations
- Operational overview
- Live event streams
- Endpoint and fleet status
- Migration and agent activity
- Notifications and triggers
- Cross-system evidence
Workload intelligence
- Hot and cold analysis paths
- Query and command fingerprints
- Anomaly state transitions
- Adaptive metadata polling
- Discovery and burst windows
- Pattern, sequence, and aggregate analysis
Recommendations & optimization
- Hot keys and oversized values
- TTL and pipeline opportunities
- Expensive query and fanout detection
- Error, stale, and unusual-pattern findings
- Cost and route optimization
- Semantic annotations and agent triggers
Incidents & investigations
- Anomaly timelines
- Investigation runs
- Agent trigger rules
- Evidence capture
- Approval and verification
- Operational memory
Fleet & runtime health
- Endpoint and node health
- Connection and session state
- Model and cache availability
- Placement and route evidence
- Load balancing and failover
- Drain, update, and recovery state
Costs & usage
- Request and token usage
- Model and provider cost
- Agent and key attribution
- Migration throughput
- Capacity settlements
- Budgets and rate limits
Logs, metrics & traces
- OTLP logs and traces
- Prometheus metrics
- ClickHouse analytics
- Request and route traces
- Streaming AI telemetry
- Core, IAM, endpoint, gateway, migration, and fleet metrics
Customer infrastructure
- Customer infrastructure provisioning
- Data and runtime placement
- Fleet and node enrollment
- Upgrade and drain
- Provider adapters
- Status, entitlement, and recovery workflow
Security
AI & agent security
- Prompt-injection and exfiltration detection
- Tool allowlists and approval
- Model and route policy
- Agent access boundaries
- Token budgets and rate limits
- Run evidence and verification
Data access security
- Server-side credential injection
- Encrypted secret storage
- Endpoint-level security
- Per-user backend credentials
- Command policy
- Data masking and fail-closed execution
Universal masking
- Developer-safe data views
- Agent context masking
- Field and attribute policies
- Role and purpose-aware rules
- Consistent gateway enforcement
- Masking evidence and audit
PII & data loss prevention
- Request and response detection
- Organization PII dictionaries
- Template-derived sensitive terms
- Redaction and blocking
- Endpoint masking
- DLP scan and audit metadata
Identity & access
- Human and agent authentication
- OIDC identity providers
- Control-plane and data-plane RBAC
- Auth groups
- Scoped API and gateway keys
- Session history and revocation
Policy & governance
- Content policy profiles
- Policy bindings
- Access boundaries
- Trusted-principal rules
- Policy simulation
- Governance snapshot hydration
Approvals & audit
- Approval requests and delegation
- Tool and agent evidence
- Audit activity
- Evidence-pack templates
- Lineage and feature records
- Governance exports and replay jobs
Event log
- Per-command audit events
- Governance feature history
- Agent run events
- Decision and approval records
- Trace and resource correlation
- Retention, filtering, and export
VPN & NAT gateway
- VPN networks and peers
- NAT gateway egress
- Private routes
- Configuration rendering
- Endpoint-node placement
- TLS and mTLS
- Fail-closed transport and credential behavior