Connected and demonstrated locally
Working development milestone: native app → authenticated XPC → service → loopback HTTP → validated fixture verdict. Enrollment, six scenarios, usage, rotation, revocation and deletion are implemented. No backend is deployed and the native demonstration makes no Claude calls.
The default backend factory is isolated from the legacy Anthropic analyzer and database. It returns fixed synthetic recommendations with explicit simulation provenance. A successful enrollment means a temporary mock device credential exists; it does not establish Claude readiness or live protection.
The offline Cloud Demo remains a separate walkthrough using bundled resources and no analysis network requests. Its sample account and reviews do not depend on this server.
Run the local demonstration
# In the repository root
cd backend
python3 -m venv .venv
.venv/bin/pip install -e '.[dev]'
.venv/bin/python -m uvicorn tracerook_backend.app:app_factory --factory --host 127.0.0.1 --port 8787 --no-access-log
# In a second terminal, from the repository root
./scripts/build.sh
open build/TraceRook.app --args --local-api-demo- In Integrations, enable the background service after reviewing its exact configuration preview. Ad-hoc builds use an explicit local LaunchAgent; Developer ID builds retain SMAppService.
- Open Settings → Local API Demo. Confirm this Mac’s loopback endpoint and the synthetic-only consent toggle.
- Select Connect local mock. The service enrolls, authenticates capabilities and loads actual fixture usage.
- Review the exact outgoing sample JSON, select a scenario, then choose Run sample.
- Inspect the fixture rationale, provenance, zero Claude tokens and advisory recommendation. Try Refresh fixture usage, Rotate mock credential and Disconnect.
No API key or .env file is required. Port 8787 must be available. Stop the server with Control-C; disable the service through Integrations when finished. A stopped server produces an unavailable error rather than a fixture success. Build scripts alone do not install hooks or enable the service.
Authenticated native API path
- SwiftUI previews one of six predefined sample contexts and freezes its bytes when Run sample is chosen.
- The explicit action reaches the signed background service over authenticated XPC.
- The service sends JSON to the fixed 127.0.0.1:8787/mock/v1 endpoint, with an in-memory device credential.
- The backend validates the token, principal, schema and exact sample context before returning a fixture or typed error.
- The service checks bounds, request identity, provenance, timestamps and budget before returning a credential-free UI status.
Transport uses an ephemeral URLSession with no cache, cookies, credential store, proxies or redirects. Bodies are bounded to 32 KiB; deadlines and cancellation are bounded. There are no automatic analysis retries. Disconnect cancels in-flight work and prevents late receipts from restoring results.
Six explicit synthetic scenarios
| Scenario | Expected behavior |
|---|---|
| Benign UI work | Low-risk advisory fixture |
| Credential transfer | High-risk advisory fixture; no actual credential or transfer |
| Task drift | Unrelated-task advisory fixture |
| Provider unavailable | 503 simulated provider_unavailable; no verdict |
| Quota exhausted | 429 simulated quota_exhausted; no verdict |
| Deadline exceeded | 504 simulated deadline_exceeded; no verdict |
Arbitrary text, repository data, commands, paths, API keys and host events cannot replace these contexts. Responses require simulation:true, fixture/local_mock/synthetic-v1 provenance and zero input tokens, output tokens and billed units. Critical severity and permission fields are rejected. Mock recommendation allow or review never authorizes a host tool.
Real checks, temporary mock identity
The public development invitation local-demo is an identifier, not a production secret. Enrollment issues a random device token once; the server stores only its digest in memory. Authenticated routes check expiry and principal. Tokens expire after one hour. Rotation invalidates the old credential, Disconnect revokes it, and confirmed Delete mock metadata clears this device’s receipts and revokes access.
Credentials never enter UI replies, preferences, SQLite, logs or Keychain. Both processes discard their ephemeral state on restart. A server restart requires a new enrollment. This is no persistent customer enrollment, billing or hosted quota system.
Successful fixtures are capped at 30 per device per UTC day; errors do not consume evaluations. Same device/request ID and canonical body returns the same receipt for 120 seconds. Changed bodies conflict. Device and receipt cardinality are bounded; concurrent duplicate evaluations are serialized.
Keep the demonstration separate
The server rejects non-loopback peers, unexpected Host headers, browser Origins, queries, unsupported methods, duplicate or unknown JSON keys, invalid UTF-8, nonfinite numbers and oversized bodies. The default factory does not mount the legacy /v1 production API. Responses are no-store JSON and errors do not echo input.
Mock Swift types are separate from the live analysis provider and approval contracts. API commands are available only in explicitly marked developer builds. They cannot create live incidents, approvals, sessions or verified coverage. A real end-to-end check confirms those collections remain unchanged after all scenarios and lifecycle operations.
This limitation is visible in the UI: synthetic, no Claude call, fixture-only analysis and no verified host protection. Native host integration still needs actual callback and benign denial evidence.
Evidence and remaining work
Local validation passes 64 Swift tests, 103 backend tests and 22 native light/dark render cases. Checks cover strict nested fields, binding, secret exclusion, wrong-device rejection, deadlines, cancellation, replay isolation, auth lifecycle, browser/rebinding defenses, idempotency, quota and real socket HTTP. Native smoke testing exercises the app, authenticated service and running server together.
A separate developer diagnostic validated one actual Anthropic claude-haiku-5-5 verdict on October 8, 2026, using 798 input tokens and 178 output tokens in 3,006 ms. That probe sends predefined synthetic content directly to Anthropic. It is opt-in, outside the native mock path, and does not prove a deployed proprietary backend or native live inference.
The backend stays local; publishing this static website deploys no API and provisions no Cloudflare resources. Hosted infrastructure, real-event privacy consent, scoped Keychain credentials, production spend controls, native Claude integration, operational enforcement and release distribution remain separate requirements.
Read the local evidence record, the frozen contract, Claude’s intended role and the protection boundary.