Operators
Run client access without inbox archaeology.
Store durable credentials, collect inbound secrets, and prove who touched what from one workspace.
Team vault, Secure Send / Receive, Shared2FA, AI-safe MCP/CLI
SecretSeal brings a 1Password-style team vault, Secure Send / Receive, Microsoft Authenticator-style Shared2FA approvals, and MCP/CLI controls into one workspace so operators can store, exchange, approve, and automate credential access without exposing secrets in email, chat, or AI sessions.
Current completion audit
Status: not-complete. Sell the proven operating loop now; keep paid billing, native distribution, and live agent runtime proof visible until external handles exist.
5
Proven
2
Partial
1
Blocked
Proof gates still required
Stripe handles
Native handles
AI runtime handles
Vault
1Password-style team records
Web proof green
Send / Receive
Expiring client handoffs
Browser proof green
Shared2FA
Web approvals green; native proof pending
Partial native parity
AI access
MCP/CLI metadata and exchange ops
Handoff ready; live proof pending
Store
Workspace vault records for passwords, API keys, recovery codes, secure notes, and Shared2FA seeds.
Exchange
Secure Send / Receive handoffs keep client secrets out of email, chat, tickets, and unmanaged forms.
Approve
Shared2FA approvals keep authenticator access auditable while native proof gates stay visible.
Automate
MCP and CLI expose metadata, readiness, rotation, import, and Secure Send / Receive attention queues without plaintext by default.
Authenticator records
Fast team access with review and rotation context.
NetSuite Production
ops@client.example
Approval pending
Owner unlock required
Stripe Admin
finance@company.example
Reviewed
Rotation in 30 days
SolBox
theo@solbox.it
Metadata only
Code hidden by policy
$ secretseal exchange ops-plan --workspace ops
activeSends: 4, openReceives: 2
$ secretseal totp ops-plan --workspace ops
rotationDue: 3, reviewDue: 5
$ secretseal vault request-reveal netsuite
approval_required: owner
Device unlock
WebAuthn protected
MCP policy
Scoped metadata first
Exchange ops
Handoff queues
Operators
Store durable credentials, collect inbound secrets, and prove who touched what from one workspace.
Security leads
Use approval queues, review dates, and native approval gates while seeds stay sealed.
AI-enabled teams
Expose metadata, readiness, rotation plans, and Secure Send / Receive attention queues through MCP/CLI while reveal stays policy-gated.
Choose your path
SecretSeal can be sold from a clear SaaS path: demo the proven workspace loop now, keep paid checkout behind Stripe proof, and use readiness before broader launch claims.
Starter
Available nowCreate a free workspace, add vault records, send and receive secrets, set up Shared2FA, and review audit evidence without Stripe checkout.
Team
Stripe proof requiredReview Team pricing and run the Stripe proof drill before selling paid checkout, customer portal, and webhook reconciliation as complete.
Launch
Proof-ledUse readiness to separate proven vault, Secure Send / Receive, Shared2FA, management, MCP/CLI, native, and billing gates before buyer claims.
SaaS positioning
SecretSeal sells as a practical operating workspace: vault storage, secure exchange, shared authenticator continuity, and AI-safe controls that share one permission and audit model.
Review launch readinessSecretSeal is built for operators who need durable secrets, one-time exchanges, shared authenticator continuity, and controlled automation under the same policy model.
Permanent encrypted records for passwords, API keys, recovery codes, secure notes, and client system credentials.
One-time sends and receive requests move sensitive material without leaving it in email or chat.
Team-controlled authenticator records for client systems that should not depend on one person's phone.
Scoped metadata-first access for Codex, Claude Code, and trusted automation, including Secure Send / Receive attention queues without default plaintext dumping.
First workspace path
SecretSeal should feel simple before it feels powerful. A new operator can validate the full product in one workspace without waiting for paid checkout or native push release gates.
Start free, pick the team workspace, and keep personal, client, and operator access separated from day one.
Store a password, API key, recovery code, secure note, or Shared2FA seed as an encrypted workspace record.
Create a one-time outbound handoff for credentials that should not live in email, chat, or ticket comments.
Send a receive request so clients can submit inbound credentials without pasting secrets into unmanaged forms.
Scan or paste an authenticator setup link, keep the seed encrypted, and require owner approval before generated codes appear.
Give agents metadata, Secure Send / Receive ops plans, launch proof handoff, readiness, import planning, and approval workflows without handing them plaintext by default.
Use readiness and launch proof pack to confirm vault, Secure Send / Receive, Shared2FA, billing, native, and live-agent gates before paid rollout claims.
Operator workflow
Teams do not just store passwords. They ask clients for secrets, hand credentials to colleagues, approve 2FA requests, rotate old access, and need evidence after the fact.
Keep client, team, and personal secrets split by workspace, role, collection, and audit history.
Use the vault for durable credentials, secure send for one-time handoff, or receive requests for inbound material.
AI tools can list metadata, plan rotations, create encrypted records, and request access without bypassing policy.
Sensitive actions stay deliberate, auditable, and ready for mobile approval as native apps mature.
AI and automation
MCP and CLI flows are designed around metadata-first access. Agents can bootstrap, list safe context, prepare encrypted imports, inspect audits, and plan rotations, while reveal and export stay policy-gated.
Review MCP access$ secretseal agent bootstrap --client codex
safeFirstActions: status, scopes, vault_list
$ secretseal launch proof-handoff
proofTracks: billing, native parity, live MCP agent
$ secretseal vault ops-plan --before 2026-07-01T00:00:00.000Z
destructiveActionsExecuted: false
$ secretseal totp code --id netsuite
blocked: approval_required
Launch proof
Public readiness contracts show what is available, what is partial, and what still needs production configuration before a buyer relies on it.
Paid SaaS
Needs Stripe env proofCheckout, portal, and webhook routes exist, while production Stripe configuration remains visible as a readiness gate.
Agent access
Needs live agent proofAgents can inspect scopes, bootstrap config, list metadata, and plan Secure Send / Receive attention queues without receiving plaintext by default; live access still needs agent launch proof.
Mobile approval
PartialiOS, Android, and macOS share one metadata-only approval model, with real-device push and packaging still tracked honestly.
Buyer proof path 01
Use the public readiness page to show buyers exactly which credential-handoff promises are proven, partial, or blocked: vault, Secure Send / Receive, Shared2FA, billing, native, and MCP/CLI.
Buyer proof path 02
Run the authenticated cockpit for workspace onboarding, API keys, billing readiness, mobile devices, audit, vault, sends, receives, and Shared2FA management.
Buyer proof path 03
Attach real Stripe checkout, customer portal, webhook, iOS, Android, macOS, and live agent proof handles before calling the SaaS/native/AI launch complete.
Buyer launch checklist
Vault, Send / Receive, Shared2FA web approvals, management cockpit
Demo the proven operating loop: create a workspace, store a vault record, send and receive secrets, review Shared2FA approvals, and inspect audit history.
MCP/CLI metadata access and native approval contract
Show metadata-first AI access, Secure Send / Receive ops plans, and mobile approval flows, but keep live agent runtime and physical-device proof marked partial until external handles exist.
Paid SaaS billing, native distribution, live agent runtime
Wait for real Stripe checkout, customer portal, webhook reconciliation, live non-local workspace reconciliation, physical iOS and Android biometric proof, signed macOS package, notarization, distribution, and non-secret agent-runtime proof handle before claiming launch complete.
Demoable commercial promise
A buyer can see the full operating loop today: workspace vault, Secure Send / Receive, Shared2FA approval workflow, audit trail, onboarding, and settings cockpit.
Completion proof promise
Run npm run launch:local-proof first; local proof does not replace external handles. Then run npm run launch:proof-pack, attach the missing Stripe, native-device, macOS distribution, and live-agent handles, then rerun npm run launch:completion-audit before claiming SecretSeal is complete.
Security model
TOTP seeds, generated codes, recovery codes, plaintext credentials, raw push tokens, and encrypted payloads are kept out of notifications, logs, readiness responses, and default agent output.
Replace shared spreadsheets and chat threads with workspace-scoped secret records.
Move one-time secrets and inbound client submissions through Secure Send / Receive instead of email or ticket comments.
Keep authenticator continuity for operational systems without exposing TOTP seeds in logs, notifications, or agent output.
Give AI agents useful metadata, rotation, import, and Secure Send / Receive attention queues while reveal and export paths stay policy-gated.
Show prospects the exact readiness state for billing, mobile, and MCP instead of relying on vague launch claims.
Demo the web workspace today: vault records, Secure Send / Receive, Shared2FA approvals, audit, and MCP/CLI metadata controls. Keep paid checkout, native app release, and live MCP/CLI runtime gated until Stripe, device QA, and agent-runtime handles are captured.