What's shipped, what's next, and what we're not building.
Most roadmaps are marketing. This one includes the kill criteria — what we'll drop if it doesn't work, and the trade-offs behind the dates. Every item is dated by the quarter we commit to, not a vague "coming soon."
Shipped (live today)
These are in the product right now. If you're signed in, you're using them.
Dynamic destination URLs
Edit where a printed QR points without reprinting. Source of truth is a shortcode, not the URL on the paper. Live.
Privacy-first analytics
Day-bucketed scan counts by country and device class. No IP storage, no raw user agents, no cross-site tracking. Live.
Static backup QR
Every Pro code ships with a static-QR backup of the destination URL. Prints next to your dynamic code; keeps working even if Abundera disappears. Live.
90-day cancellation grace
Cancel, and your codes keep resolving for 90 days. No overnight deadlinks. Printed material outlives the subscription long enough to react. Live.
Keep-Alive tier
$4/mo, $36/yr, or $240 Keep-Alive Decade (10-year prepay). Preservation-only: codes keep resolving with a 30-day destination edit cooldown; no new codes, no team seats, no API. Live (Apr 2026).
Multi-seat teams
Team and Agency tiers. Owner / admin / member roles. Codes scoped to the team, not individual users. 10 seats (Team), 25 seats (Agency). Live.
Hourly analytics granularity
Team and Agency tiers get hour-by-hour breakdowns on top of daily buckets. Useful for campaign-launch visibility. Live.
REST API + rate limits
Bearer-token auth, per-day rate limits (1K / 10K / 50K requests/day by tier), documented at pro.qr.abundera.ai/docs/. Live.
One-click data export
Download a ZIP with codes.csv + scans.csv + README. No lock-in, no "contact us for export." Live.
30-day GDPR hard delete
Request deletion; after a 30-day hold, everything is purged from D1, KV, and backups. Honored on the same 30-day timeline regardless of jurisdiction (subject to applicable retention laws — Stripe records, EU VAT). Live.
Q3 2026 — next up
Committed for Q3. Each has a spec, a kill criterion, and a real engineering estimate. If a dependency slips (cert approvals, partner onboarding), the date slips publicly, not silently.
Wallet passes
Apple .pkpass and Google Wallet passes for every Pro code. Add-to-wallet link on each code's edit page. Blocked on Apple Developer Program Pass Type ID cert and Google Wallet Issuer approval — both in motion.
Kill criterion: if <5% of paid Pro users add at least one code to a wallet in the first 3 months, sunset.
Short-domain (aqr.net)
Shorter printed-code URLs (aqr.net/x/abc123) served by the same redirect worker. Delivery pending domain registrar transfer (ETA 2026-04-20 to 2026-05-05). Main qr.abundera.ai domain stays for SEO and free-tier; aqr.net is print-only.
Kill criterion: if <15% of new Pro codes opt into the short domain within 90 days of launch, hold at beta and reassess.
Signed-QR protocol + verifier library
Anti-quishing: cryptographic signature embedded in the redirect payload, verifiable without a proprietary scanner. Ships as an open protocol spec + an npm verifier package. Consumer mobile scanners come later (see Q4).
Kill criterion: if no production integration (internal or partner) is running after 6 months, pause further investment.
Agency channel program
Formal partner agreement for print shops, marketing agencies, and design studios reselling Pro. Reseller discount, co-branded account pages, consolidated billing. Policy and contract work — no new code required.
Kill criterion: if zero signed partners after 90 days, the positioning isn't hitting — rework or drop.
Public status page
Externally hosted uptime + sweeper-heartbeat mirror. Current state: heartbeats write to internal healthchecks; no public reflection. Q3 item.
SOC 2 scoping → Type I kickoff
Formal engagement with an auditor, gap assessment, policy work. Type II is a 6-9 month observation window after Type I. We'll share the scoping date publicly when the engagement letter is signed.
Q4 2026 — under construction
Committed for Q4, dependent on Q3 landing. Specs exist; dates firm up as Q3 lands.
Abundera Authenticator (mobile)
iOS + Android native apps. Anchors both the Signed-QR verifier (Q3 protocol) and the BYO-server rekey flow. This is a 3-4 month native build; hence Q4, not Q3.
FIDO-bound dynamic QR
Hardware-attested identity bound to code ownership via a FIDO2 authenticator or passkey. Depends on the Authenticator app landing.
Integrations marketplace
Five opinionated integrations (Slack, Discord, Zapier, Make, Webhooks generic). Not a full app store — we'd rather build 5 integrations well than 50 poorly.
Kill criterion: any integration with <10 customer installs after 90 days is removed.
SOC 2 Type II observation
Assumes Q3 Type I ran. Observation window begins in Q4; report available 6-9 months later.
Deliberately not building
Requests we hear frequently and are saying "no" to, with our reasoning. This is not a "roadmap TBD" list — these are explicit passes.
Google Analytics / Meta Pixel integration
Integrating third-party trackers would break the privacy guarantee we sell. Export your own scan CSV and correlate it yourself if you need that data — we won't pipe it out.
Self-hosted / on-prem version
The redirect worker is Cloudflare-native (KV hot path + D1 aggregates). Running this on customer infrastructure would mean re-engineering against every hyperscaler, which isn't tenable at our size.
QR beautification marketplace
Custom logos, colors, and frames are already in the free generator. We're not adding a "QR-as-art" skins store — it's a commodity feature other vendors compete on.
AI-generated destination content
Out of scope. We redirect; we don't generate landing pages. This keeps the product simple and the privacy model clean.
Geofenced or time-locked redirects
Tempting, but they'd require storing scanner geolocation, which conflicts with our "country bucket only, no IP" privacy model. Building it would mean rewriting the scan-analytics foundation. Not now.
Contact-sales-only enterprise tier
Agency at $349/mo is our enterprise tier. We'd rather show the real price than hide it behind a sales call. If you genuinely need more than 50,000 codes or a signed MSA, we'll coordinate — but the starting point is public.
How this page is maintained
A few ground rules so this doesn't become the usual "coming soon" wasteland.
Only dates we'll defend
Every Q3/Q4 commitment above is something we're willing to miss publicly. If a date slips, this page is updated with the slip and the reason — not deleted.
Kill criteria, not just dreams
Every new feature has a kill criterion (stated inline). If a feature doesn't hit it, it's retired — we don't carry zombie features. This page shows what survived.
Not the same as marketing copy
Features listed as "live" are verified against the codebase. We will not advertise a feature that isn't shipped. If you see something on the landing page, you can use it today.
Have a feature you'd pay for? Email us. Every request gets logged and reviewed monthly.