Readiness

Prove the credential-handoff product before selling it as complete.

SecretSeal is usable today as a web-first team vault, Secure Send/Receive workspace, Shared2FA approval queue, and AI-safe MCP/CLI control plane. Paid SaaS launch, native Authenticator parity, and live-agent runtime proof stay explicit gates so the product does not claim completion ahead of evidence.

Public non-secret status
Billing gates1/5 ready
Mobile paritypartial
AI accesspartial
1/5 ready

Paid SaaS

Billing launch gates

Paid plans should stay gated until Stripe configuration, checkout proof, customer portal proof, and webhook reconciliation are verified.

Stripe configuration present
Checkout transaction proof missing
Customer portal proof missing
Webhook reconciliation proof missing
View billing readiness JSON
partial

Mobile

Shared2FA native readiness

Installable web access is available, while Microsoft Authenticator parity remains partial until native device loops are production-proven.

Installable web app: available
Native clients: scaffolded
Authenticator parity: partial
Review mobile readiness
partial

MCP

AI access boundary

Codex, Claude Code, and local automation can use metadata-first tools, including Secure Send / Receive exchange ops plans, without default plaintext access.

13 safe first actions
secretseal_exchange_ops_plan covers Secure Send / Receive attention queues
2 scope presets
Live agent launch proof is needs-configuration.
Plaintext retrieval stays policy-gated
Review MCP and CLI access
captured

Design audit

Screenshot-backed product review

Fresh product-design audit evidence covers public selling, onboarding, management cockpit, MCP, billing, launch proof, and mobile surfaces.

20 screenshots captured in docs/product-design-audit-2026-06-27
Mobile landing and authenticated mobile views recaptured after responsive polish
Evidence limits stay explicit for billing, native apps, live agents, and accessibility
Review completion checklist
Completion audit

Overall status: not-complete.

The current public completion label is not-complete. Run npm run launch:completion-audit after collecting the proof pack with npm run launch:proof-pack before calling the combined 1Password-style vault, Secure Send/Receive, Shared2FA, AI-safe MCP/CLI, SaaS, and native product complete.

Product statusnot-complete

5

Proven

2

Partial

1

Blocked

Next required proof

Run npm run launch:local-proof so aggregate local proof is current; this local proof does not replace external handles.
Run /launch-proof and npm run launch:proof-pack so the aggregate proof pack stays current.
Run the /billing-readiness Stripe proof drill and record real checkout, customer portal, webhook reconciliation, live non-local workspace reconciliation, and STRIPE_VERIFIED_AT proof handles.
Run /mobile-devices Authenticator parity drill attach physical iOS and Android push plus biometric approve/deny and signed code-render receipt proof, signed macOS package, notarization, distribution proof, and SECRETSEAL_NATIVE_VERIFIED_AT.
Attach signed macOS package, notarization, and distribution proof from the native operator sequence.
Run /settings live-agent proof drill, configure public production HTTPS SECRETSEAL_API_URL, secret-managed SECRETSEAL_API_KEY reference, live wrk_... SECRETSEAL_WORKSPACE_ID, and production/live SECRETSEAL_ENVIRONMENT; obtain the opaque receipt issued by the successful real production safe metadata-only run and record the non-secret agent-runtime proof handle before live AI use.

Sell and demo now

5 proven

Starter and the core credential-handoff loop is proven for demo: team vault, Secure Send, Secure Receive, Shared2FA approvals, onboarding, and authenticated management cockpit proof.

Clear public landing and pricing story
1Password-style team vault
Secure Send and Receive
Shared2FA approval workflow
Authenticated management cockpit

Keep positioned as partial

2 partial

AI-safe MCP/CLI agent access and native Authenticator parity stay partial until live runtime, physical-device, packaging, and distribution proof handles exist.

MCP and CLI AI integration
iOS, Android, and macOS Authenticator parity

Keep checkout gated

1 blocked

Paid SaaS billing remains blocked until Stripe checkout, customer portal, webhook reconciliation, workspace reconciliation, and STRIPE_VERIFIED_AT proof are recorded.

Paid SaaS selling and billing management

Current missing proof keys

Public readiness uses the same metadata-only proof snapshot as the launch proof cockpit and CLI proof pack. Missing keys are proof handles and configuration names for the credential handoff product, not secret values.

paid-saas-billing

1/5 ready

Run a real production Stripe checkout, then record a non-secret cs_live_... checkout session handle.

STRIPE_VERIFIED_CHECKOUT_SESSION_IDSTRIPE_VERIFIED_PORTAL_SESSION_IDSTRIPE_VERIFIED_WEBHOOK_EVENT_IDSTRIPE_VERIFIED_RECONCILED_WORKSPACE_IDSTRIPE_VERIFIED_AT

native-authenticator-parity

0/4 ready

Run physical iOS push notification approve and deny loops, then record ios-device: and approve/deny audit: handles.

SECRETSEAL_IOS_PUSH_RECEIPT_PROOFSECRETSEAL_IOS_BIOMETRIC_APPROVAL_PROOFSECRETSEAL_IOS_BIOMETRIC_DENY_PROOFSECRETSEAL_ANDROID_PUSH_RECEIPT_PROOFSECRETSEAL_ANDROID_BIOMETRIC_APPROVAL_PROOFSECRETSEAL_ANDROID_BIOMETRIC_DENY_PROOFSECRETSEAL_MACOS_SIGNED_PACKAGE_PROOFSECRETSEAL_MACOS_NOTARIZATION_PROOFSECRETSEAL_NATIVE_DISTRIBUTION_PROOFSECRETSEAL_NATIVE_VERIFIED_AT

live-mcp-cli-agent-access

3/5 ready

Set a public production HTTPS API URL, secret-managed API key proof, live wrk_... workspace id, and SECRETSEAL_ENVIRONMENT=production before using live agent access.

SECRETSEAL_API_URLSECRETSEAL_API_KEYSECRETSEAL_WORKSPACE_IDSECRETSEAL_ENVIRONMENTSECRETSEAL_AGENT_RUNTIME_PROOF
Management map

Protected cockpit surfaces ready to inspect after sign-in.

Authenticated management supports the 1Password-style vault, Secure Send / Receive, Shared2FA approvals, mobile approval readiness, audit, billing, and workspace administration story. This public page lists metadata only; it does not expose secrets or generated codes.

Protected

Vault management

Manage encrypted credentials, API keys, secure notes, recovery codes, and Shared2FA records from the workspace vault.

Collections and rotation context
Device-bound unlock support
Workspace-scoped records
Sign in to manage
Protected

Secure send

Create and monitor expiring outbound secret handoffs without leaving material in email or chat.

One-time send lifecycle
Viewed, expired, revoked states
Client-side encryption model
Sign in to manage
Protected

Receive requests

Collect inbound client secrets through controlled request links instead of unmanaged intake threads.

Inbound request tracking
Workspace audit trail
Safe handoff vault records
Sign in to manage
Protected

Shared2FA management

Manage shared authenticator accounts, reviews, rotation due dates, and approval-gated reveals.

No seed leakage in public surfaces
Approval queue model
Authenticator-grade continuity target
Sign in to manage
Protected

Mobile devices

Review registered devices, notification readiness, and native approval state for mobile workflows.

Device registration route
Push approval readiness
Biometric approval gates
Sign in to manage
Protected

Audit and workspace admin

Inspect workspace activity, membership, settings, and billing readiness before expanding paid rollout.

Workspace audit route
Member settings routes
Billing readiness cockpit
Sign in to manage

Completion checklist

Prove each product promise before calling SecretSeal complete.

Current proof is 5/8 ready, 2 partial, and 1 blocked. Each track lists the command or external evidence needed for the 1Password-style vault, secure exchange, Shared2FA approvals, AI-safe MCP/CLI controls, SaaS billing, and native app promise.

Clear SaaS positioning

ready
npm run launch:local-proof
Landing page explains 1Password-style vault, secure send/receive, Shared2FA, and AI-safe MCP/CLI.
Local launch proof covers public pages, buyer onboarding, MCP, mobile, billing readiness, native scaffold, management surfaces, and Shared2FA demo proof.
Stripe billing launch proof stays separate until real checkout, customer portal, and webhook handles exist.

Keep public copy aligned with shipped proof before paid launch.

Buyer onboarding path

ready
npm run buyer:onboarding:smoke
Starter signup lands new buyers in product setup instead of a dead-end form.
Onboarding guides workspace, vault, secure send/receive, Shared2FA, mobile devices, MCP/CLI keys, billing readiness, and audit proof.
Onboarding uses live workspace readiness data when a workspace is selected.

Add browser proof for first vault item, first send, first Shared2FA record, and first MCP key after demo signup.

Secure send and receive

ready
npm test -- --runTestsByPath src/__tests__/integration/sends.test.ts
Secure send and receive routes are part of the protected management map.
Public handoff routes skip global auth session fetching.

Run full send/receive browser flow after authenticated demo env is configured.

Team vault and Shared2FA

ready
npm run shared2fa:demo:smoke
Vault-backed Shared2FA records, approval workflow, and metadata-only native contract are modeled.
Shared2FA seed/code fields stay out of readiness payloads.

Prove authenticated vault and approval UI with demo management browser smoke.

MCP and CLI agent access

partial
npm run agent:readiness:smoke && npm run agent:launch-proof
13 safe first MCP actions are exposed.
Live agent launch proof is needs-configuration.
Vault reveal, export, and generated TOTP code tools remain unavailable to CLI/MCP.

Configure the public production API URL, secret-managed API key proof, workspace id, and production environment, then record the receipt issued by a successful real production safe metadata-only run before selling live AI-agent access.

Paid SaaS billing

blocked
npm run billing:route-contract:smoke && npm run billing:readiness:smoke && npm run billing:launch-proof
Stripe billing configuration is present.
Checkout transaction proof handle is missing.
Customer portal proof handle is missing.
Webhook reconciliation proof is missing.

Configure Stripe env, verify a real checkout transaction, open a real customer portal session, and verify webhook workspace reconciliation.

iOS, Android, and macOS Authenticator parity

partial
npm run native:proof:smoke
Installable web app: available.
Native clients: scaffolded.
Authenticator parity: partial.
Native launch proof is blocked.

Prove real-device push receipt, biometric approve/deny, signed packaging, and store/notarization paths.

Authenticated management cockpit proof

ready
npm run demo:management:prepare && npm run db:seed && npm run shared2fa:demo:smoke && npm run demo:management:surface-smoke && npm run demo:management:browser-smoke && npm run buyer:onboarding:browser-smoke
Management cockpit, vault, Shared2FA, billing, mobile device, and audit routes are protected.
Seeded demo admin can open authenticated Shared2FA approval inbox and mobile device management proof.
Seeded demo admin can open buyer onboarding and first-use destinations in browser proof.
Settings exposes scoped API-key presets and MCP setup commands without secret-shaped values.
Local proof keeps Shared2FA payloads, generated codes, raw push tokens, and secrets out of smoke output.

Keep browser proof current as vault, Shared2FA, billing, native mobile, and audit cockpit surfaces evolve.

Launch proof

Proof handles required before complete.

Use the product today for web-first vault, secure exchange, Shared2FA, and MCP/CLI workflows. Keep paid SaaS and native Authenticator claims gated until non-secret proof handles exist.

Blocked

Paid SaaS billing proof

Keep paid Team and Business checkout gated until Stripe env, a real checkout session, and webhook workspace reconciliation have non-secret proof handles.

npm run billing:launch-proof

Non-secret proof handles

STRIPE_VERIFIED_CHECKOUT_SESSION_ID=cs_live_...
STRIPE_VERIFIED_PORTAL_SESSION_ID=bps_...
STRIPE_VERIFIED_WEBHOOK_EVENT_ID=evt_...
STRIPE_VERIFIED_RECONCILED_WORKSPACE_ID=wrk_<live_workspace_id>
STRIPE_VERIFIED_AT=2026-06-26T00:00:00.000Z

Next actions

Configure Stripe secret, webhook secret, Team price, and Business price in the deployment environment.
Run a real production Stripe checkout and record a cs_live_... checkout session handle.
Verify webhook delivery updates the live workspace, then record evt_..., wrk_..., and the final verification timestamp.
Run billing proof drill
Partial

Native Authenticator parity proof

Keep iOS, Android, and macOS claims partial until physical-device push, biometric approve/deny, signing, notarization, and distribution handles exist.

npm run native:launch-proof

Non-secret proof handles

SECRETSEAL_IOS_PUSH_RECEIPT_PROOF=ios-device:<model>:<build>:<screenshot_or_runbook>
SECRETSEAL_IOS_BIOMETRIC_APPROVAL_PROOF=audit:<ios_approval_event_or_runbook>
SECRETSEAL_IOS_BIOMETRIC_DENY_PROOF=audit:<ios_deny_event_or_runbook>
SECRETSEAL_ANDROID_PUSH_RECEIPT_PROOF=android-device:<model>:<build>:<screenshot_or_runbook>
SECRETSEAL_ANDROID_BIOMETRIC_APPROVAL_PROOF=audit:<android_approval_event_or_runbook>
SECRETSEAL_ANDROID_BIOMETRIC_DENY_PROOF=audit:<android_deny_event_or_runbook>
SECRETSEAL_MACOS_SIGNED_PACKAGE_PROOF=macos-package:<path_or_build_id>
SECRETSEAL_MACOS_NOTARIZATION_PROOF=notary:<request_or_ticket_id>
SECRETSEAL_NATIVE_DISTRIBUTION_PROOF=distribution:<testflight_play_console_mdm_or_release_handle>
SECRETSEAL_NATIVE_VERIFIED_AT=2026-06-26T00:00:00.000Z

Next actions

Run physical iOS and Android Shared2FA approval loops and record ios-device:, android-device:, and audit: handles.
Sign and notarize the macOS companion, then record macos-package: and notary: handles.
Record distribution: proof from TestFlight, Play Console, MDM, release, or equivalent distribution review.
Run mobile proof drill
Partial

Live MCP/CLI agent proof

Keep AI-agent claims partial until the live API URL, live wrk_... workspace id, and secret-managed API key are configured without printing secret values.

npm run agent:launch-proof

Non-secret proof handles

SECRETSEAL_API_URL=https://secretseal.io
SECRETSEAL_API_KEY=<load-from-secret-manager-or-keychain>
# Record SECRETSEAL_API_KEY_PROOF_SOURCE as keychain:<name>, secret-manager:<name>, ci-secret:<name>, or mcp-secret:<name>. Never record the raw API key.
SECRETSEAL_API_KEY_PROOF_SOURCE=keychain:<non-secret-reference>
SECRETSEAL_WORKSPACE_ID=wrk_<workspace_id>
SECRETSEAL_ENVIRONMENT=production
SECRETSEAL_AGENT_RUNTIME_PROOF=agent-runtime:secretseal.io:workspace-<hash>:run-<opaque-receipt-issued-by-production-run>
agent-runtime:<host>:workspace-<hash>:run-<opaque-production-receipt>

Next actions

Store SECRETSEAL_API_KEY in MCP client secret manager, OS keychain, or equivalent protected runtime.
Configure SECRETSEAL_API_URL and SECRETSEAL_WORKSPACE_ID for the live wrk_... workspace.
Complete a successful production safe metadata-only run, obtain its opaque receipt, then record only the non-secret agent-runtime:<host>:workspace-<hash>:run-<opaque-production-receipt> handle and run npm run agent:launch-proof. The report never generates the receipt.
Keep result free of API keys, plaintext payloads, TOTP seeds, generated codes.
Run live-agent proof drill
Machine-checkable endpoints

Public readiness is also available at /api/v1/billing/readiness, /api/mobile/readiness, and /api/v1/mcp/readiness.

Open mobile JSON