Paid SaaS
Billing launch gates
Paid plans should stay gated until Stripe configuration, checkout proof, customer portal proof, and webhook reconciliation are verified.
Readiness
SecretSeal is usable today as a web-first team vault, Secure Send/Receive workspace, Shared2FA approval queue, and AI-safe MCP/CLI control plane. Paid SaaS launch, native Authenticator parity, and live-agent runtime proof stay explicit gates so the product does not claim completion ahead of evidence.
Paid SaaS
Paid plans should stay gated until Stripe configuration, checkout proof, customer portal proof, and webhook reconciliation are verified.
Mobile
Installable web access is available, while Microsoft Authenticator parity remains partial until native device loops are production-proven.
MCP
Codex, Claude Code, and local automation can use metadata-first tools, including Secure Send / Receive exchange ops plans, without default plaintext access.
Design audit
Fresh product-design audit evidence covers public selling, onboarding, management cockpit, MCP, billing, launch proof, and mobile surfaces.
The current public completion label is not-complete. Run npm run launch:completion-audit after collecting the proof pack with npm run launch:proof-pack before calling the combined 1Password-style vault, Secure Send/Receive, Shared2FA, AI-safe MCP/CLI, SaaS, and native product complete.
5
Proven
2
Partial
1
Blocked
Starter and the core credential-handoff loop is proven for demo: team vault, Secure Send, Secure Receive, Shared2FA approvals, onboarding, and authenticated management cockpit proof.
AI-safe MCP/CLI agent access and native Authenticator parity stay partial until live runtime, physical-device, packaging, and distribution proof handles exist.
Paid SaaS billing remains blocked until Stripe checkout, customer portal, webhook reconciliation, workspace reconciliation, and STRIPE_VERIFIED_AT proof are recorded.
Public readiness uses the same metadata-only proof snapshot as the launch proof cockpit and CLI proof pack. Missing keys are proof handles and configuration names for the credential handoff product, not secret values.
paid-saas-billing
1/5 readyRun a real production Stripe checkout, then record a non-secret cs_live_... checkout session handle.
native-authenticator-parity
0/4 readyRun physical iOS push notification approve and deny loops, then record ios-device: and approve/deny audit: handles.
live-mcp-cli-agent-access
3/5 readySet a public production HTTPS API URL, secret-managed API key proof, live wrk_... workspace id, and SECRETSEAL_ENVIRONMENT=production before using live agent access.
Authenticated management supports the 1Password-style vault, Secure Send / Receive, Shared2FA approvals, mobile approval readiness, audit, billing, and workspace administration story. This public page lists metadata only; it does not expose secrets or generated codes.
Manage encrypted credentials, API keys, secure notes, recovery codes, and Shared2FA records from the workspace vault.
Create and monitor expiring outbound secret handoffs without leaving material in email or chat.
Collect inbound client secrets through controlled request links instead of unmanaged intake threads.
Manage shared authenticator accounts, reviews, rotation due dates, and approval-gated reveals.
Review registered devices, notification readiness, and native approval state for mobile workflows.
Inspect workspace activity, membership, settings, and billing readiness before expanding paid rollout.
Completion checklist
Current proof is 5/8 ready, 2 partial, and 1 blocked. Each track lists the command or external evidence needed for the 1Password-style vault, secure exchange, Shared2FA approvals, AI-safe MCP/CLI controls, SaaS billing, and native app promise.
Keep public copy aligned with shipped proof before paid launch.
Add browser proof for first vault item, first send, first Shared2FA record, and first MCP key after demo signup.
Run full send/receive browser flow after authenticated demo env is configured.
Prove authenticated vault and approval UI with demo management browser smoke.
Configure the public production API URL, secret-managed API key proof, workspace id, and production environment, then record the receipt issued by a successful real production safe metadata-only run before selling live AI-agent access.
Configure Stripe env, verify a real checkout transaction, open a real customer portal session, and verify webhook workspace reconciliation.
Prove real-device push receipt, biometric approve/deny, signed packaging, and store/notarization paths.
Keep browser proof current as vault, Shared2FA, billing, native mobile, and audit cockpit surfaces evolve.
Use the product today for web-first vault, secure exchange, Shared2FA, and MCP/CLI workflows. Keep paid SaaS and native Authenticator claims gated until non-secret proof handles exist.
Keep paid Team and Business checkout gated until Stripe env, a real checkout session, and webhook workspace reconciliation have non-secret proof handles.
Non-secret proof handles
Next actions
Keep iOS, Android, and macOS claims partial until physical-device push, biometric approve/deny, signing, notarization, and distribution handles exist.
Non-secret proof handles
Next actions
Keep AI-agent claims partial until the live API URL, live wrk_... workspace id, and secret-managed API key are configured without printing secret values.
Non-secret proof handles
Next actions
Public readiness is also available at /api/v1/billing/readiness, /api/mobile/readiness, and /api/v1/mcp/readiness.