Every phase is tested against a single rule: the vendor must never gain the ability to read, recover, or be compelled to disclose content. Features that would cross that line don't get built — that discipline is the product.
The foundation, working end to end today: invitation-only identity with per-device credentials, decision rooms, MLS-encrypted messaging, encrypted document sharing, client-side retention, multi-device support — and the test that matters most, proving a removed member cryptographically loses access to everything sent after removal.
What turns a working system into one a compliance officer signs: an administration console for membership and device governance, device revocation, out-of-band device verification, server-side retention enforcement, and an independent external audit of the cryptographic core.
Mobile clients built from the same Rust core — one implementation, every platform — plus content-free push notifications and an installable app experience.
Encrypted conferencing keyed from the same MLS groups, and structured decision artifacts — motions, approvals, signatures. The goal is to be the system of record for decisions, not messages.
White-label, single-tenant deployments sold per institution — on their infrastructure, in their jurisdiction, running our audited crypto. The server ships as a single static binary because this phase was the plan from day one.
What a product refuses to build is as load-bearing as what it ships. These are permanent.