Open work only

What is still on the scale.

Completed early milestones stay in the repository journal. This page shows unfinished or closeout-owed work from the tracked Roadmap.

Public scale

  1. M9 Closeout owed

    Vault layout vNext

    Why: fixed capacities and reserved bands for cards and passwords.

    What you get: Implemented in tree; destructive HIL / full-flash closeout still owed.

  2. M10 Closeout owed

    Companion-less SD recovery

    Why: restore without a working management host.

    What you get: Implemented; operator run still owed.

  3. M12–M14 HIL carried

    Power-loss, object envelopes, applet lifecycle

    Why: durable storage and typed composition before CCID products harden.

    What you get: Done on the host; HIL evidence still carried.

  4. M15 Done, carried

    USB CCID: OpenPGP Card 3.4.1

    Why: GnuPG, signed commits, and mail without blind signing.

    What you get: Done on the LAB card image (2026-09-29): GnuPG signs, encrypts, decrypts and logs in over SSH with the companion closed, each use shown on the glass. Carried: the product image answers GnuPG once csiPass has a registered manufacturer ID.

  5. M16 Done, carried

    USB CCID: PIV

    Why: enterprise PKCS#11 / smart-card identity paths.

    What you get: Done (2026-09-29): OpenSC and the Windows inbox driver, browser client certificates, historical decryption, and Windows domain logon over Remote Desktop. Carried: a console logon on a domain-joined PC, and the production attestation CA.

  6. M16.5 Open

    Windows sign-in for local accounts

    Why: outside a domain or Entra, Windows offers no sign-in with an external key.

    What you get: A csiPass tile for local accounts, each press named on the glass, with a backup device and a recovery code.

  7. M17 Open

    CTAP thirdPartyPayment confirmation

    Why: payment ceremonies need an explicit glass gate.

    What you get: Trusted-display confirmation for the payment extension.

  8. M18 Hardware-gated

    Fingerprint module

    Why: fingerprint is a UV method, not a host-trusted authenticator.

    What you get: Satellite sensor path, enrolment, and PIN-or-fingerprint UV once hardware exists.

  9. M19 Open

    On-device Password Vault & Safe-Type

    Why: keep master secrets off the PC; optional controlled typing.

    What you get: Flash-reserved password vault browsable on glass; Safe-Type keyboard HID when gated.

  10. M20 Design open

    Opt-in anonymous statistics

    Why: learn outcomes without sites, accounts, or secrets.

    What you get: Consent-gated companion telemetry that cannot change device behavior.

  11. M21 Open

    Linux companion parity

    Why: compiling is not installable across distros without root friction.

    What you get: Honest Windows feature set on supported Linux desktops.

  12. M21.5 Open

    Linux sign-in

    Why: Linux already accepts a FIDO key at login and for disk unlock; it lacks a guided setup.

    What you get: Login, sudo and screen unlock through pam_u2f, LUKS unlock at boot, lock on removal, set up from the companion.

  13. M22 Deferred

    macOS companion parity

    Why: no Mac host and signing identity yet.

    What you get: Same companion behavior once transport and notarisation exist, and Mac sign-in with the PIV card paired to a local account.

  14. Board family Open / parallel

    Touch, panels, RTC & SD capabilities

    Why: one ESP32-S3R8 firmware class, but Waveshare boards differ by panel, input, and fittings. Owners should not solder GPIO2 just to Confirm.

    What you get:

    • Touchscreen Confirm and Browse without a separate soldered button
    • Other panel shapes/controllers after a concrete board is measured
    • Live RTC → TOTP available; dead/missing RTC → honest refuse on glass and in companion
    • SD present → Files; no slot/card → Files absent / Storage empty without mystery greys
  15. M23 Open

    Retail hardware

    Why: the lab board is a vehicle, not a sealed product.

    What you get: Production PCB/enclosure, provisioning fixtures, and pilot batches — gated on product identity.

  16. GATE Parallel

    Product identity & release security

    Why: a retail authenticator needs identity before a box.

    What you get: Trademark/entity, AAGUID, VID/PID, attestation, Secure Boot, flash encryption, rollback, certification evidence.

Archive PDF of the full markdown roadmap: roadmap.pdf (prefer this live scale for status).