Current implementation status
| Milestone | Status | Evidence / next gate |
|---|---|---|
| MVP1 · Native UI / Cloud Demo | Implemented; local checks passed | Native demo, sample review, 20 light/dark renders; manual accessibility and notification checks remain |
| MVP2.0 · Baseline and contracts | Passed locally | 43 tests; debug/release builds; strict v2 codec; native launch; v1 compatibility retained |
| MVP2.1 · Service and durable state | Pending | Authenticated signed-family XPC, private hook socket, SQLite migrations, service-owned approvals and real UI state |
| MVP2.2 · Claude Code integration | Pending | Safe configuration changes, shared emergency rules and actual Bash plus Write/Edit pre-execution deny proof |
| MVP2.3 · Codex integration | Pending | Explicit native trust and actual Bash/apply_patch denial proof |
| MVP2.4 · Policy and native review | Pending | Executable rule corpus, exact-invocation CAS, notification actions, expiry and replay tests |
| MVP2.5 · Anthropic Claude BYOK | Pending | Keychain, consent, privacy preflight, real direct API call, validated verdict and incident |
| MVP2.6 · Signed beta hardening | Pending | Developer ID, notarization, macOS 26/27, performance, accessibility and clean install/uninstall |
There is no released live-protection beta or signed download. Contract tests and native renders are useful development evidence; they do not prove that a real tool body was blocked.
Next: authenticated service and storage
MVP2.1 connects the persistent service, signed UI control plane, bounded private hook transport and SQLite single writer. The native app will read sanitized service state while retaining the isolated Cloud Demo. A disconnected service must produce an honest unavailable or degraded state.
Unsigned and wrong-family clients must fail approval mutations. The hook socket must reject approval writes. Database migration, restart, retention and sanitized export checks are required. This phase can demonstrate simulated service ingestion, clearly labeled, before installing live hooks.
The PR2 implementation plan lists exact source changes and authentication tests.
Before protection is claimed
MVP2.2 and MVP2.3 need actual callbacks and benign denial tests on both hosts. A denied operation that would create a canary file must leave that file absent. Evidence is keyed to exact host version, adapter version, tool class, schema hash, binary signature and test time.
MVP2.4 completes deterministic critical rules and service-owned high-risk review. Block denies; Allow Once clears only TraceRook review for the original waiting invocation, with native host permissions intact. Expiry, changed arguments, changed nonces, duplicate clicks and old notifications cannot authorize another action.
MVP2.5 adds real Anthropic Claude analysis only after consent, Keychain, redaction and a second remote preflight. Model recommendations remain advisory and cannot override concrete critical evidence.
Beta release gates
- Both hosts prove shell and supported file-edit pre-execution denial.
- Signed app, service and CLI; authenticated IPC; no alternate approval channel.
- Exact service-owned approval, bounded expiry, replay resistance and live/demo isolation.
- Shared catastrophic rules work without Anthropic when the hook actually runs.
- Real direct Anthropic BYOK request yields a validated, sanitized incident.
- No raw commands, transcripts, keys or provider responses in persistent history or logs.
- Coverage limits and host upgrades are reflected truthfully.
- Clean signed/notarized install on macOS 26/27, measured latency, VoiceOver and notification checks.
The phase acceptance matrix keeps every release blocker explicit.
Actual platform and source observations
Local validation used an Apple Silicon macOS 27 host, Swift 6.4 and Command Line Tools. Full Xcode and Developer ID identities are absent. Production signed-family rejection, archive, notarization and macOS 26 validation remain open gates. The passing native SwiftPM backend emits a deprecation warning; full build-tool migration must preserve security checks.
The existing rule module contains evidence contracts rather than an executable rule engine. The foundation Codex decoder assumes object input, so live integration needs tool-specific handling. Review DTOs reuse Core’s existing ApprovalBinding rather than duplicating it in Contracts. These gaps are documented, not treated as implemented features.
Read the implementation record and compatibility audit for the underlying evidence.
Beyond the current beta scope
OpenCode, hosted TraceRook Cloud accounts and billing, team policy, SIEM, broad sandboxing, vulnerability scanning and system-wide monitoring are deferred. No dates or model pricing are promised.
MVP2 keeps the native macOS experience and focuses on privacy, safe configuration changes and truthful protection for supported local Claude Code and Codex sessions.