- Invitation and join formats
- Versioned, size-bounded formats reject malformed, expired, unknown, and context-mismatched input before state changes.
- Implemented + tested
- Private invitation proof bound to one device
- A one-shot HPKE check ties the exact signed invitation to one exact MLS KeyPackage, reserves replay values, and records a simulated approval decision.
- Implemented + tested
- Two-device MLS lifecycle
- The in-memory adapter adds a device, exchanges protected messages in both directions, updates the group, removes the device, and tests replay and reordering.
- Implemented + tested
- Local delivery under faults
- Separate deposit, receive, and acknowledgement rights are tested under deterministic loss, duplication, delay, reordering, retry, expiry, and bounds.
- Implemented + tested
- Durable authorization transaction
- The SQLCipher laboratory atomically commits and reloads approval, replay, invitation consumption, MLS state, and the Welcome outbox. Platform key custody, stale-snapshot resistance, secure deletion, and production integration remain open.
- Implemented laboratory
- Production vault and desktop client
- The common macOS, Windows, and Linux baseline needs reviewed key protection, a selected shell, safe deep links, updates, and packaging.
- Required, unimplemented
- Connected FastV1 delivery
- The authenticated Iroh adapter implements experimental connected delivery. Offline delivery, a durable mailbox, anonymity, egress isolation, and production operations remain open.
- Experimental
- GitHub and portable credential admission
- Designed behind the same exact KeyPackage binding, but intentionally kept out of the Phase 1 capability-only laboratory.
- Later roadmap phases