Open work only
What is still on the scale.
Completed early milestones stay in the repository journal. This page shows unfinished or closeout-owed work from the tracked Roadmap.
Public scale
-
Vault layout vNext
Why: fixed capacities and reserved bands for cards and passwords.
What you get: Implemented in tree; destructive HIL / full-flash closeout still owed.
-
Companion-less SD recovery
Why: restore without a working management host.
What you get: Implemented; operator run still owed.
-
Power-loss, object envelopes, applet lifecycle
Why: durable storage and typed composition before CCID products harden.
What you get: Done on the host; HIL evidence still carried.
-
USB CCID: OpenPGP Card 3.4.1
Why: GnuPG, signed commits, and mail without blind signing.
What you get: Done on the LAB card image (2026-09-29): GnuPG signs, encrypts, decrypts and logs in over SSH with the companion closed, each use shown on the glass. Carried: the product image answers GnuPG once csiPass has a registered manufacturer ID.
-
USB CCID: PIV
Why: enterprise PKCS#11 / smart-card identity paths.
What you get: Done (2026-09-29): OpenSC and the Windows inbox driver, browser client certificates, historical decryption, and Windows domain logon over Remote Desktop. Carried: a console logon on a domain-joined PC, and the production attestation CA.
-
Windows sign-in for local accounts
Why: outside a domain or Entra, Windows offers no sign-in with an external key.
What you get: A csiPass tile for local accounts, each press named on the glass, with a backup device and a recovery code.
-
CTAP thirdPartyPayment confirmation
Why: payment ceremonies need an explicit glass gate.
What you get: Trusted-display confirmation for the payment extension.
-
Fingerprint module
Why: fingerprint is a UV method, not a host-trusted authenticator.
What you get: Satellite sensor path, enrolment, and PIN-or-fingerprint UV once hardware exists.
-
On-device Password Vault & Safe-Type
Why: keep master secrets off the PC; optional controlled typing.
What you get: Flash-reserved password vault browsable on glass; Safe-Type keyboard HID when gated.
-
Opt-in anonymous statistics
Why: learn outcomes without sites, accounts, or secrets.
What you get: Consent-gated companion telemetry that cannot change device behavior.
-
Linux companion parity
Why: compiling is not installable across distros without root friction.
What you get: Honest Windows feature set on supported Linux desktops.
-
Linux sign-in
Why: Linux already accepts a FIDO key at login and for disk unlock; it lacks a guided setup.
What you get: Login, sudo and screen unlock through pam_u2f, LUKS unlock at boot, lock on removal, set up from the companion.
-
macOS companion parity
Why: no Mac host and signing identity yet.
What you get: Same companion behavior once transport and notarisation exist, and Mac sign-in with the PIV card paired to a local account.
-
Touch, panels, RTC & SD capabilities
Why: one ESP32-S3R8 firmware class, but Waveshare boards differ by panel, input, and fittings. Owners should not solder GPIO2 just to Confirm.
What you get:
- Touchscreen Confirm and Browse without a separate soldered button
- Other panel shapes/controllers after a concrete board is measured
- Live RTC → TOTP available; dead/missing RTC → honest refuse on glass and in companion
- SD present → Files; no slot/card → Files absent / Storage empty without mystery greys
-
Retail hardware
Why: the lab board is a vehicle, not a sealed product.
What you get: Production PCB/enclosure, provisioning fixtures, and pilot batches — gated on product identity.
-
Product identity & release security
Why: a retail authenticator needs identity before a box.
What you get: Trademark/entity, AAGUID, VID/PID, attestation, Secure Boot, flash encryption, rollback, certification evidence.
Archive PDF of the full markdown roadmap: roadmap.pdf (prefer this live scale for status).