Skip to content

Phony Cloud Platform - Roadmap ​


Overview ​

This roadmap is gate-driven, not date-driven. Each phase ends at a validation gate; the next phase's spend (time and money) is only unlocked when the gate is passed. Three phases build on each other:

┌─────────────────────────────────────────────────────────────────────────┐
│                    PHONY IMPLEMENTATION STRATEGY                         │
├─────────────────────────────────────────────────────────────────────────┤
│                                                                          │
│  PHASE 1: OSS WEDGE (NOW)                                                │
│  ═══════════════════════                                                 │
│  Goal: Become the best Faker alternative for PHP/Laravel                 │
│  Engine + CLI + package manager: DONE. Remaining: PHP port,              │
│  conformance suite, bundled models, Laravel integration, launch.         │
│  Revenue: $0 (community building)                                        │
│                                                                          │
│         │  GATE 1: 500 GitHub stars                                      │
│         ▼                                                                │
│                                                                          │
│  PHASE 2: CLOUD CONTROL PLANE + LOCAL-FIRST SYNC (NEXT)                  │
│  ══════════════════════════════════════════════════════                  │
│  Goal: Monetize orchestration — hosted control plane (metadata           │
│  only) + DB Sync MVP running in customer infra. KVKK/Turkey              │
│  wedge for first sync revenue.                                           │
│                                                                          │
│         │  GATE 2: $30K ARR, 5+ paying sync customers                    │
│         ▼                                                                │
│                                                                          │
│  PHASE 3: SCALE & ECOSYSTEM (LATER)                                      │
│  ══════════════════════════════════                                      │
│  Goal: Enterprise (self-hosted control plane), deferred sync             │
│  depth (CDC, PITR), ARR-triggered privacy features, more                 │
│  runtimes (signal-driven).                                               │
│  Revenue: $150K → $600K+ ARR → Exit                                      │
│                                                                          │
└─────────────────────────────────────────────────────────────────────────┘

Status: What Is Already Built ​

The foundation phase is largely complete. Marking it explicitly so the rest of the roadmap reads as remaining work:

AreaStatusNotes
Rust generation engineDONEFive core generator types (Logic, List, Model, Statistical, Event Sequence) plus composition, in the Rust workspace
PGDL (JSON) + PELDONEphony-pgdl crate — canonical schema format is JSON, expression language implemented
.ngram model format + trainingDONEphony train produces .ngram model files; phony generate consumes PGDL JSON
CLI train + generateDONEOffline, no auth required
Git-based package managerDONEphony.json manifest, MVS resolution, content-addressed store, phony.lock, remote release assets, install/add/remove/update/list — see Package Manager
Hosted package registryKILLEDSuperseded by the git-based design. No registry, no publish, no hosted search — ever, unless a gate proves otherwise

Phase 1: OSS Wedge (NOW) ​

Goal: Ship the Faker replacement for PHP/Laravel and reach Gate 1. Gate 1: 500+ GitHub stars, 200+ weekly Packagist downloads, featured in Laravel News or similar.

Architecture Decision: One Core, One Port, Bindings ​

There is exactly one implementation of Phony's semantics: the Rust core. Training, full PGDL/PEL, and the package manager live only there.

  • PHP gets a hand-written pure-PHP port — the single exception, because Laravel is the flagship market and composer require must work with no extension, no FFI, no binary. The port is generation-only: an .ngram model reader, a PEL evaluator, and the generators. No training, no package resolution logic (it consumes the closure the CLI resolves).
  • Every other language gets bindings to the Rust core, not a reimplementation: Python via a PyO3 wheel, JavaScript/TypeScript via WASM (which also enables a browser playground). Ruby is deferred.
  • The contract between runtimes is a cross-runtime conformance vector suite: versioned test vectors (seed + PGDL input → expected output) generated from the Rust core and run in CI against every runtime. Same seed, same output, everywhere.
  • Fallback posture: if byte-for-byte parity between Rust and PHP proves too costly to maintain, we retreat to portable format + per-runtime determinism (same seed is deterministic within a runtime, models portable across runtimes) — but parity is the target.
┌─────────────────────────────────────────────────────────────────────────┐
│  WHY THIS ARCHITECTURE                                                   │
├─────────────────────────────────────────────────────────────────────────┤
│                                                                          │
│  • One source of semantics → no version drift across languages           │
│  • PHP port is small (reader + PEL + generators), not a second engine    │
│  • Conformance vectors make "same data everywhere" a tested claim        │
│  • Bindings (PyO3/WASM) reuse the core → new runtimes are cheap          │
│  • WASM binding doubles as a zero-install browser playground             │
│                                                                          │
└─────────────────────────────────────────────────────────────────────────┘

Repository Structure ​

┌─────────────────────────────────────────────────────────────────────────┐
│  PUBLIC REPOSITORIES (MIT Licensed)                                      │
├─────────────────────────────────────────────────────────────────────────┤
│                                                                          │
│  Rust workspace                 Engine, PGDL/PEL (phony-pgdl), CLI       │
│  ├── engine + generators       Training + generation (DONE)             │
│  ├── pkg module                Git package manager (DONE)               │
│  └── conformance/              Versioned cross-runtime test vectors      │
│                                                                          │
│  phony-php                      Hand-written pure-PHP port (Packagist)   │
│  ├── .ngram reader             Generation-only                          │
│  ├── PEL evaluator             Validated against conformance vectors    │
│  └── generators                                                         │
│                                                                          │
│  phony-laravel                  Laravel integration (Packagist)          │
│                                                                          │
│  Content packages (git, one repo each — no registry)                     │
│  ├── @phony/base               Generic generators/assets                │
│  ├── @phony/tr_TR              Turkish models (release-artifact .ngram) │
│  └── @phony/en_US              English models (release-artifact .ngram) │
│                                                                          │
├─────────────────────────────────────────────────────────────────────────┤
│  PRIVATE REPOSITORY (Proprietary)                                        │
├─────────────────────────────────────────────────────────────────────────┤
│                                                                          │
│  phonycloud/cloud               Control plane (Phase 2)                   │
│                                                                          │
└─────────────────────────────────────────────────────────────────────────┘

Remaining Work ​

1.1 Conformance Vector Suite ​

DeliverableDescription
Vector generatorRust binary emits versioned vectors: seed + PGDL JSON → expected output
Coverage matrixEvery generator type, PEL function, and model sampling path
Rust CI harnessVectors run against the core on every commit
Published artifactVectors versioned + downloadable so any runtime can self-certify

1.2 phony-php Port ​

DeliverableDescription
.ngram readerLoad binary model files, pure PHP, no extensions
PEL evaluatorEvaluate expressions identically to the Rust core
GeneratorsLogic, List, Model, Statistical, Event Sequence + composition
Conformance CIPHP port runs the full vector suite; parity is the release criterion

1.3 Bundled Models ​

DeliverableDescription
@phony/tr_TRTurkish names, addresses, companies — plus TCKN and other TR-format generators
@phony/en_USEnglish equivalents
@phony/baseLocale-independent generators and assets
Release assetsLarge .ngram models shipped as release artifacts, not git blobs

1.4 Laravel Integration ​

DeliverableDescription
Service provider + facadeAuto-discovery, Phony:: facade
Factory integrationDrop into Eloquent factories
Deterministic seedingPer-test seeds → reproducible factories in CI
Configconfig/phony.php

1.5 Faker API Compatibility + Agent-Readable Migration ​

The primary "user" performing a Faker→Phony migration is increasingly a coding agent, not a human. Both deliverables are designed for that reader:

DeliverableDescription
Faker compat layerDrop-in fake()-compatible API surface on top of the Phony engine — one line in CLAUDE.md/AGENTS.md should be enough to redirect an agent's fake() reflex to Phony
Migration guideMechanical, rule-based, example-mapping format (Faker call → Phony call) so an agent can apply it without judgment calls
AGENTS.md snippetCanonical copy-paste block for consumer repos

1.6 Agent Surface (never paywalled) ​

DeliverableDescription
AGENTS.mdIn phony-php and phony-laravel repo roots
Editor skills / snippetsClaude Code, Cursor et al. instructions
Messaging"Agent-written tests stay reproducible — no flaky fake data"

1.7 Docs + OSS Release + Launch ​

DeliverableDescription
Docs siteGetting started, CLI reference, PHP API, tutorials
Packagist + crates.io + install scriptcomposer require, cargo install, curl | sh
LaunchLaravel News, Show HN, Product Hunt, r/php + r/laravel

Phase 1 Success Criteria (Gate 1):

  • [x] Rust engine, PGDL/PEL, CLI train + generate shipped
  • [x] Git-based package manager shipped
  • [ ] Conformance vector suite passing on Rust and PHP
  • [ ] phony-php + phony-laravel on Packagist
  • [ ] @phony/tr_TR, @phony/en_US, @phony/base published (git packages)
  • [ ] Faker compat layer + agent-readable migration guide
  • [ ] 500+ GitHub stars, 200+ weekly Packagist downloads
  • [ ] Featured in Laravel News or similar

Phase 2: Cloud Control Plane + Local-First Sync (NEXT) ​

Precondition: Gate 1 passed. Goal: First revenue from DB Sync, with a local-first architecture. Gate 2: $30K+ ARR, 5+ paying customers, <5% monthly churn.

Architecture: Local-First Cloud ​

  • The data plane (sync, anonymization, snapshots) runs in customer infrastructure — the customer's data never transits our servers.
  • The hosted control plane sees metadata only: schemas, PII findings, job status, audit events. It sells orchestration, visibility, and compliance reporting.
  • The mock API is the hosted exception — it serves synthetic data only, so hosting it creates no PII exposure.
  • Free tier has no hosted COGS (engine + CLI are local; no hosted workloads to subsidize).
  • Enterprise = self-hosted control plane (Phase 3).
  • Value metric for billing: connected data sources — generation volume, users, and agents are never metered.

Implementation Order ​

OrderFeatureRationale
2.1Control-plane foundationEverything depends on this
2.2DB Sync MVP (local-first)The revenue feature
2.3KVKK / Turkey wedgeFirst paying sync customers
2.4Mock API (read-only, hosted)Synthetic-only, unique feature
2.5Snapshots (local-first)Ephemeral envs; agent story
2.6Language bindings (post-Gate 1, demand-driven)PyO3 wheel, WASM + playground

2.1 Control-Plane Foundation ​

DeliverableDescription
Auth + orgs + projectsRegistration, OAuth, teams, roles, API keys
BillingStripe; plans gated by connected data sources
Agent enrollmentCustomer-infra agent registers with control plane; outbound-only connection
CLI cloud commandsphony login, phony whoami, agent bootstrap
MCP serverControl-plane MCP surface for coding agents (free tier included — agent surface is a distribution channel, never paywalled)

2.2 Database Sync MVP (Local-First) ​

Deliberately narrow: MySQL → staging, full sync, heuristic PII detection, manual + daily scheduled runs. Depth comes later.

DeliverableDescription
MySQL connectorRuns in the customer-infra agent; credentials never leave customer infra
Schema analysisIntrospection, FK detection — schema metadata reported to control plane
Heuristic PII detectionColumn-name + pattern heuristics; findings surfaced in dashboard
Full sync + anonymizeComplete table copy with transforms, in customer infra
Manual + daily runsTrigger from dashboard/CLI; simple daily schedule
Sync dashboardConnection wizard, transform rules, run history — metadata only

Explicitly deferred out of the MVP: PostgreSQL, incremental sync, CDC, PITR, cross-database subsetting (see Phase 3).

2.3 KVKK / Turkey Wedge ​

The first paying sync customers are most likely Turkish mid-market teams: KVKK creates the compliance pressure, Tonic has no meaningful Turkish presence, and Phony already has the local assets.

DeliverableDescription
TCKN + TR formatsValid-checksum TCKN, TR phone/IBAN/plate generators (ships in Phase 1 packages; surfaced as sync transforms here)
tr_TR model qualityProduction-grade Turkish names/addresses/companies
KVKK report packAnonymization evidence report per sync run, in Turkish, mapped to KVKK terminology
TR go-to-marketTurkish content, local case study, Laravel TR community

2.4 Mock API (Read-Only, Hosted Exception) ​

DeliverableDescription
PGDL → REST endpointsDeterministic, seed-based responses; synthetic data only
HostingSubdomain routing, CORS, per-tier rate limits
PaginationDeterministic cursor + offset paging

Stateful mock (POST/PUT/DELETE, webhooks, latency/error simulation) is deferred to Phase 3 — read-only must prove valuable first.

2.5 Snapshots (Local-First) ​

DeliverableDescription
Snapshot create/restoreAnonymized DB captures, stored in customer storage (S3-compatible)
Scheduling + retentionControl-plane orchestrated
Ephemeral environmentsSpin up a prod-like, PII-free DB per branch/test run — "give your coding agent a prod-like DB it can't leak PII from"

Incremental snapshots and point-in-time restore are deferred to Phase 3.

2.6 Language Bindings (Post-Gate 1, Demand-Driven) ​

No reimplementations — bindings to the Rust core, certified by the same conformance vectors:

DeliverableDescription
Python wheelPyO3 binding, pip install phony; pytest fixtures
JS/TS WASMnpm package; Node + browser
Browser playgroundWASM-powered try-it-now on phony.cloud — zero install

Phase 2 Success Criteria (Gate 2):

  • [ ] Internal production use (dogfooding)
  • [ ] 10+ beta customers using sync
  • [ ] 5+ paying customers (first ones likely via the KVKK wedge)
  • [ ] $30K+ ARR
  • [ ] <5% monthly churn
  • [ ] Zero customer data touching hosted infrastructure (mock API synthetic-only excepted)

Phase 3: Scale & Ecosystem (LATER) ​

Precondition: Gate 2 passed. Goal: Enterprise readiness, sync depth, exit preparation.

3.1 Enterprise Features ​

CategoryFeatures
DeploymentSelf-hosted control plane (the enterprise product), VPC peering, air-gapped
AuthSSO (SAML, OIDC), SCIM provisioning, RBAC, IP allowlisting
ComplianceSOC2 Type II, GDPR docs, KVKK docs, HIPAA BAA, data residency
Support99.9%+ SLA, dedicated success manager

3.2 Sync Depth (Deferred from Phase 2) ​

FeatureNotes
PostgreSQL supportSecond connector, type mapping, COPY bulk load
Incremental syncTimestamp/checksum-based
CDCLog-based change capture — deliberately deferred; heavy for a solo founder, only justified by paying demand
PITRPoint-in-time restore on snapshots — same posture
Stateful mock APIMutations, webhooks, latency/error simulation

3.3 Additional Runtimes (Signal-Driven) ​

Decision signals: GitHub issues, paying customers asking, market gap.

RuntimePriorityApproach
RubyDeferredBinding (magnus/FFI) if Rails demand materializes — not a port
GoFutureBinding (cgo)
More localesOngoingNew @phony/<locale> git packages — community-contributable

There is no hosted package registry on any horizon: packages stay git-based (decision record). Registry analytics, badges, private-package hosting are all dead with it — private packages are just private git repos.

3.4 Advanced Privacy Features (ARR-Triggered, Cloud Platform) ​

These are cloud-platform features — data-plane capabilities orchestrated by the control plane, not OSS engine features. Each unlocks only at its ARR trigger:

ARR TriggerFeatures
$150K+Differential Privacy: Mathematical privacy guarantees (ε-differential privacy), Laplace/Gaussian mechanisms, GDPR/HIPAA compliance certification
$200K+Geo-Aware Generation: Lat/long fuzzing with k-anonymity, HIPAA Safe Harbor address generation, population-aware postal code truncation
$250K+Structured Data Masks: JSON path masking, XML XPath masking, regex capture group transformation, HTML content redaction
$300K+Format-Preserving Transformation: Character scramble (email, phone), credit card masking (Luhn-valid), SSN/ID format preservation
$400K+Database subsetting, NER-based PII detection, automated data discovery
$600K+Unstructured de-identification, document redaction, image/PDF anonymization
$1M+Guided redaction workflows, expert determination support, compliance audit reports

3.5 Statistical & ML Features (ARR-Triggered, Cloud Platform) ​

ARR TriggerFeatures
$300K+Distribution Learning: Auto-detect distributions from source data, histogram matching, percentile preservation
$400K+Correlation Preservation: Learn and preserve multi-column correlations, covariance matrix replication
$600K+AI Synthesizer: VAE-based deep learning for high-fidelity data synthesis, automatic relationship detection

Phase 3 Success Criteria:

  • [ ] $600K-1M+ ARR
  • [ ] 300+ paying customers
  • [ ] SOC2 Type II certified
  • [ ] At least 2 enterprise customers ($5K+/mo) on self-hosted control plane
  • [ ] At least 1 binding runtime shipped (if demand)
  • [ ] Exit-ready metrics

Dependency Graph ​

PHASE 1: OSS WEDGE
══════════════════════════════════════════════════════════════════════════

  Rust core (engine + phony-pgdl + CLI + pkg)          [DONE]
  │   ├── train / generate
  │   ├── git package manager (phony.json, phony.lock)
  │   └── .ngram model format
  │
  ├──▶ conformance/ vector suite  ──────────────┐
  │                                             │ certifies
  ├──▶ phony-php (pure-PHP port) ◀──────────────┘
  │        │
  │        └──▶ phony-laravel (facade, factories)
  │
  ├──▶ @phony/base, @phony/tr_TR, @phony/en_US (git content packages)
  │
  └──▶ Faker compat + agent migration guide + AGENTS.md
           │
           ▼
       OSS LAUNCH ──▶ GATE 1: 500 stars

══════════════════════════════════════════════════════════════════════════

PHASE 2: CONTROL PLANE + LOCAL-FIRST SYNC
══════════════════════════════════════════════════════════════════════════

  Control plane (hosted, metadata only)
  │   ├── auth / orgs / billing (connected data sources)
  │   ├── MCP server (agent surface, free)
  │   └── dashboards (schema, PII findings, run history)
  │
  ├──▶ Customer-infra agent (data plane)
  │        ├── DB Sync MVP (MySQL, full, heuristic PII, daily)
  │        └── Snapshots (customer storage)
  │
  ├──▶ KVKK wedge (TCKN transforms + KVKK report pack)
  │
  ├──▶ Mock API (hosted exception, synthetic-only, read-only)
  │
  └──▶ Bindings: PyO3 wheel, WASM + browser playground (post-Gate 1)
           │
           ▼
       GATE 2: $30K ARR, 5+ paying

══════════════════════════════════════════════════════════════════════════

PHASE 3: SCALE (signal- and ARR-driven)
══════════════════════════════════════════════════════════════════════════

  Self-hosted control plane (Enterprise)
  Sync depth: PostgreSQL → incremental → CDC → PITR
  Stateful mock API
  ARR-triggered privacy + statistical ladders
  Additional runtimes (Ruby et al. — bindings only)

CLI Command Reference ​

The phony CLI is a unified tool for both offline (free) and cloud (paid) operations.

┌─────────────────────────────────────────────────────────────────────────┐
│                    UNIFIED CLI (Single Binary: phony)                    │
├─────────────────────────────────────────────────────────────────────────┤
│                                                                          │
│  OFFLINE COMMANDS (Free, MIT Licensed, No Auth Required)                 │
│  ═══════════════════════════════════════════════════════                 │
│                                                                          │
│  $ phony train input.txt -o model.ngram        # Train a model           │
│  $ phony train data.csv --column name          # Train from CSV column   │
│  $ phony generate schema.pgdl.json             # Generate from PGDL JSON │
│  $ phony info model.ngram                      # Show model metadata     │
│  $ phony validate model.ngram                  # Validate model format   │
│  $ phony stats model.ngram                     # N-gram statistics       │
│                                                                          │
│  PACKAGES (git-based — no registry, no publish)                          │
│  ══════════════════════════════════════════════                          │
│                                                                          │
│  $ phony install                               # Resolve + fetch closure │
│  $ phony add github.com/acme/geo-tr@v1         # Add a dependency        │
│  $ phony remove @acme/geo-tr                   # Remove a dependency     │
│  $ phony update                                # Update within constraints│
│  $ phony list                                  # List resolved packages  │
│                                                                          │
│  CLOUD COMMANDS (Requires: phony login)                                  │
│  ════════════════════════════════════════                                │
│                                                                          │
│  $ phony login / logout / whoami               # Auth + identity         │
│  $ phony sync                                  # Trigger sync (runs in   │
│  $ phony sync --status                         #  customer infra)        │
│  $ phony snapshot create --name "v1.2"         # Anonymized snapshot     │
│  $ phony snapshot restore v1.2                 # Restore (ephemeral env) │
│  $ phony mock deploy                           # Hosted mock API         │
│                                                                          │
├─────────────────────────────────────────────────────────────────────────┤
│                                                                          │
│  SIMILAR TO:  gh (GitHub CLI)    → gh auth login / gh repo create        │
│               vercel             → vercel login / vercel deploy          │
│                                                                          │
│  BENEFIT:     Single tool for entire workflow                            │
│               Offline-first (train/generate/install never need auth)     │
│               Progressive disclosure (cloud unlocks with login)          │
│                                                                          │
└─────────────────────────────────────────────────────────────────────────┘

Timeline Summary ​

Gates, not dates:

PhaseTrigger to StartExit Gate
Phase 1Now (engine already built)500+ GitHub stars, 200+ weekly Packagist downloads
Phase 2Gate 1 passed$30K+ ARR, 5+ paying, <5% churn
Phase 3Gate 2 passed$600K-1M ARR, enterprise-ready, exit-ready

Milestone Checkpoints ​

CheckpointDeliverable
P1.aConformance vector suite green on Rust
P1.bphony-php passes conformance suite
P1.c@phony/tr_TR + @phony/en_US + @phony/base published
P1.dLaravel integration + Faker compat + migration guide
P1.eOSS launch → Gate 1
P2.aControl plane live (auth, billing, agent enrollment, MCP)
P2.bDB Sync MVP: MySQL full sync in customer infra
P2.cKVKK report pack; first Turkish paying customer
P2.dMock API read-only + snapshots
P2.eGate 2 ($30K ARR)

Phony Cloud — Documentation & Specification