Engineering reference MVP1 / v1.0

MVP1 status & roadmap

Completed development milestones and the acceptance gates still required for a live beta.

Development previewLive hooks, enforcement, and Anthropic BYOK are pending. This guide distinguishes current behavior from the MVP1 design.

Current implementation status

PhaseStatusEvidence / next gate
0 · FoundationPassed locallyNative executables, contracts, fixtures, tests
1 · Native UI / Cloud DemoImplemented; local checks passedNative render and launch checks; manual accessibility/notification acceptance pending
2 · Live ingestionPendingSigned helper, authenticated XPC, private socket, safe installer, SQLite
3 · EnforcementPendingBoth hosts prove pre-execution block, review, and allow-once
4 · Claude BYOK / driftPendingKeychain, direct API, consent, privacy preflight, budgets
5 · Hardening / betaPendingDeveloper ID, notarization, macOS 26/27 tests, performance, release checklist

There is no released live-protection beta or signed download in this milestone. No phase is waived by the website.

The next live milestone

Phase 2 connects real callbacks and durable local state. Authenticated signed-family XPC must precede privileged UI mutations. The CLI gets a private, UID-checked, bounded event socket; the service becomes the sole SQLite writer.

Installation needs concrete previews, reversible backups, atomic writes, source-hash conflict detection, and actual version/trust verification. Real events alone do not complete Phase 3’s enforcement gate.

Before protection is claimed

Phase 3 adds shared deterministic critical rules, service and CLI fallback, exact-call approvals, and a real host-format return path. Both agents must pass harmless deny, review, allow-once, expiry, and failure tests.

Phase 4 connects Anthropic Claude with Keychain, consent, redaction, constrained output, deadlines, cost limits, and task drift. It must demonstrate real analysis while keeping fixtures isolated and local rules useful during provider outages.

Beta release gates

  • Native menu bar, dashboard, onboarding, incident evidence, and approval UX.
  • Verified live pre-tool interception on supported local Claude Code and Codex releases.
  • Signed nonprivileged helper and bridge with authenticated transport boundaries.
  • Reversible, user-consented configuration changes and separate Codex trust.
  • Exact nonreplayable approval, correct timeout denial, and truthful coverage.
  • Real direct Anthropic BYOK with minimal redacted data and Keychain storage.
  • Retention, migration, deletion, sanitized diagnostics, and no raw secrets.
  • macOS 26/27 checks, release corpus, performance, accessibility, Developer ID, and notarization.

Actual platform observations

Local development used an Apple Silicon macOS 27 host with Swift 6.4 and Command Line Tools; full Xcode was absent. SwiftPM’s default SwiftBuild path failed to initialize there, so local validation uses the native build backend. The testing script supplies missing framework search paths.

An SDK 27 State macro plugin was absent in that environment. The UI uses a compatibility alias to the standard SwiftUI.State property wrapper. These changes preserve native SwiftUI and Swift 6 concurrency; full Xcode archive validation remains required.

The repository implementation record documents observations and pending gates. Future changes require evidence from actual platform or host behavior.

After MVP1

OpenCode, real TraceRook Cloud accounts and billing, team policy, SIEM, broad sandboxing, code vulnerability scanning, and system-wide monitoring are deferred. No dates or model pricing are promised here.

MVP1’s scope remains an understandable, privacy-conscious review layer for one developer’s supported local coding agents.

Based on the MVP1 architecture specification, version 1.0 · October 8, 2026.