Explore

Product navigation

Judge Route
Canonical reviewer path with product proof, integrations, awards context, and runtime evidence
Start
Guided onboarding and wallet-first flow
Learn
Workflow-first onboarding and product operating guide
Help
Product guide across routes, docs, and proof
Govern
Create, vote, and execute on Solana Testnet
Intelligence
Risk scoring, market context, and signer decision support
Treasury
Treasury health, solvency context, and agent policy routes
Payroll
Private payroll CSV, stablecoin choice, and auditor receipt flow
Gaming
Guilds, tournaments, inventory proposals, and reward operations
Compliance
Scoped compliance packs and bounded viewing-key evidence
Execute
Private payroll, vendor settlement, and treasury actions
Proof
Operation receipts, runtime logs, and verification routes
Developers
API docs, SDK starters, and integration surfaces
RPC Services
Hosted reads, relayer checks, QVAC status, and runtime endpoints
API Status
Backend health, visitor counters, and freshness endpoints
Command Center
Ops dashboard, indexed proposals, and readiness gates
Live State
Proposals, treasury, and action logs
Story
Live product story and fast explanation
Community
Join, updates, pilot interest, and support routing
Benefit
theMiracle wallet-placement benefit and Founding Governor access
Versus
PrivateDAO compared with Realms, Squads, Snapshot, and DAOhaus
Revenue
Self-hosted, managed SLA, and enterprise commercial tiers
Android
Mobile app, APK download, parity plan
Trust
Security, proof, and operating boundaries
Health
Runtime status and verification health
Custody
Multisig, authority transfer, and custody evidence
Analytics
Votes, proposals, actions
API & Pricing
Pilot, API, commercial packs
Engage
Buyer path, pilot motion, mainnet trajectory
Search
Search routes, docs, tracks, and proof
Docs
Curated reviewer and trust docs
Security
Additive hardening
ZK + REFHE + MagicBlock
Security
A security surface that keeps hardening, proof, and production readiness together

The security story stays productized without flattening the truth: additive V3 hardening, integration rails, audit packets, readiness gates, and the cryptographic rails behind the protocol.

Live proofs
2

Baseline proof and dedicated V3 proof packet are both reviewer-facing

ZK anchors
3

On-chain proof anchors exposed in the Testnet evidence path

Wallets
50

Multi-wallet Testnet rehearsal already captured and packaged

Commercial rails
4

Grant, fund, gaming, and enterprise service packs remain part of the UI

Security route brief

Security is where privacy claims, custody discipline, and runtime evidence meet one operating surface

This route is not an audit appendix. It is the operator view for how PrivateDAO protects proposal intent, payout execution, wallet signing, custody posture, and reviewer visibility without flattening the product into a spreadsheet.

Use it to explain the cryptographic stack in plain language before a reviewer opens packets.
Use it to choose the right privacy posture before a treasury or governance action starts.
Use it to show what is proven now on Testnet and what still remains gated for institutional closure.
Encrypted integrations active

REFHE and MagicBlock are now on-chain settlement gates, not posture-only claims

The 2026-05-23 Testnet run configured and settled a REFHE envelope, configured and settled a MagicBlock private payment corridor, consumed settlement evidence, and executed the V3 token payout. The IKA lane remains truthfully scoped to SDK/Sui readiness and Solana pre-alpha approval preparation until a funded dWallet DKG is recorded.

Custody evidence corrected

Squads custody now shows 4/6 gates passed on Testnet

The security route now reflects the actual public evidence: Squads vault authority, 2-of-3 threshold, signer roster, canonical program-upgrade authority transfer, ZK verifier authority transfer, and enforced timelock behavior. DAO and treasury authority transfers remain the two post-unlock gates after the Squads execution window opens.

Passed
Multisig vault
CALHrBqx6jbzcPn2NVcinqSAHeod65v9LcDuTxsdPqBv
Passed
Threshold
2-of-3 with 48h timelock
Passed
Signer roster
4Mm5... · BBBP... · 2Kp...
Passed
Upgrade authority
Canonical program authority transferred to Squads vault
Pending
DAO authority
Scheduled after Squads proposal index 3 unlocks on 2026-05-27T02:25:39Z
Pending
Treasury authority
Scheduled after proposal index 3 execution and post-transfer readouts
Security remediation

Browser vote salts are no longer persisted

The web commit/reveal lane now redacts persisted governance state, keeps reveal preimages in memory only, removes salt rendering from the DOM, and documents the ZK, API, monitoring, and REFHE/FHE claim boundaries.

Custody hardening

Testnet program upgrades now route through Squads 2-of-3

The current Testnet program-upgrade authority moved from the deployer key to Squads vault authority CALHr...PqBv. Judges can verify the multisig creation, 48-hour timelock, signer roster, and authority-transfer signature directly on Solana Explorer.

Security readiness
Structured custody evidence is partially recorded: 4/6 gates passed.
Partially evidenced

Trust posture, custody summary, and mainnet framing should update in the same surface where hardening and launch discipline are reviewed.

Trust state
Some ceremony evidence is recorded, which improves reviewer confidence and points clearly to the remaining readiness steps.
Evidence completion
4/6
Multisig, threshold, signer roster, transfer signatures, and post-transfer readouts are counted together.
Immediate next move
Reviewer confidence improves once the packet is structured and reproducible, but the launch boundary must remain explicit until every signer, transfer, and readout reference is complete.

Security posture

Partially evidenced
What is live

Private governance, treasury execution, generated proof packets, V3 hardening proofs, and partial custody ceremony evidence now sit together inside one product-facing security surface.

What stays explicit

The signer split and transfer path are becoming inspectable, but missing signatures or post-transfer readouts still keep mainnet custody outside the fully closed claim boundary.

Why it matters

This matters because reviewers and buyers can see security maturity improving in real time without losing the explicit boundary around what is not yet closed.

Authority hardening

Mainnet authority separation should be explicit, reviewable, and multisig-backed

Partially evidenced
Reviewer confidence improves once the packet is structured and reproducible, but the launch boundary must remain explicit until every signer, transfer, and readout reference is complete.
Authority split

Mainnet requires a hard separation between upgrade authority, treasury authority, and admin authority. PrivateDAO should not carry a single-wallet super-admin posture into production.

Upgrade authority must be isolated from treasury execution.
Treasury authority must remain bound to proposal execution and treasury policy.
Admin authority should stay bounded and explicitly reduced before launch.
Production ceremony

Production ceremony evidence is partially recorded (4/6). This is already stronger than a static plan, and the next step is to complete the remaining signatures and readouts.

Create the production multisig and define signer roles.
Transfer upgrade authority with transaction evidence.
Transfer treasury authority and record the evidence path.
Launch boundary

The launch path stays explicit, and it is now supported by partially inspectable custody evidence instead of a purely forward-looking note.

Remove unnecessary single-signer powers.
Keep the next trust steps visible to reviewers and buyers.
Treat authority transfer as a trust event, not an internal note.
Selective disclosure

Selective disclosure turns privacy into an institutional review lane

This is where PrivateDAO explains the narrow window between protected operator intent and reviewer-visible proof. The goal is not full public exposure. The goal is bounded, product-safe disclosure.

Selective disclosure

Give reviewers a narrow window into the operation without turning private work into public exposure

Selective disclosure is the bridge between strong privacy and institutional review. It decides what the operator can keep private, what the reviewer can inspect, and which links are enough to prove the action happened correctly on Testnet.

Auditor review

Use this when an external reviewer needs a bounded proof path for governance or treasury actions without reading the full internal operating log.

How the handoff works
Choose the privacy posture before the wallet signs.
Run the governance or treasury action on Testnet.
Open the proof and custody routes that match that action.
Disclose only the hashes, logs, and reviewer packet needed for that review window.
Private until the right boundary
vote intent before reveal
sensitive payout reasoning and internal operator notes
committee-only context that does not need public distribution
Visible for review and verification
transaction signatures and explorer-visible hashes
runtime logs, proof packets, and reviewer summaries
custody and authority state when that proof is required
Strict custody ingestion

Record ceremony evidence in the exact shape needed by the canonical custody proof

4/6 gates
This surface no longer collects free-form notes only. It builds a strict, reviewer-safe JSON packet that maps directly into docs/multisig-setup-intake.json. Only public keys, public transaction signatures, and readout references belong here.
Define signer set
Repo-ready
Freeze the real 3-signer roster and backup procedures before any authority movement.
Record multisig package
Strict ingestion live
Collect the implementation, address, creation signature, rehearsal signature, and timelock references in one structured packet.
Capture authority transfer evidence
External execution next
Record the destination authority, transfer signature, and post-transfer readout reference for each operational surface.
Apply and rebuild canonical proof
Repo automation ready
Save the JSON packet into `docs/custody-evidence-intake.json` and run the apply command to update canonical proof artifacts.
Multisig package
Implementation, address, creation signature, and rehearsal signature
Next step
Need implementation, multisig address, creation signature, and rehearsal signature.
Threshold and timelock
Capture the final threshold and 48+ hour configuration evidence
Valid
Threshold and timelock evidence are fully recorded.
Signer roster
Record each signer slot with a real public key and backup confirmation
Valid
Slot 1 · founder-operator
Valid
Public key and backup discipline recorded.
Slot 2 · independent-security-or-ops-signer
Valid
Public key and backup discipline recorded.
Slot 3 · recovery-or-governance-signer
Valid
Public key and backup discipline recorded.
Authority transfer surfaces
Each surface needs destination authority, transfer signature, and post-transfer readout reference
program-upgrade-authority
EP9xE8MJZ6FfyEwLqns6HDdUZBknEa7WGYs1Jzsecuva
Valid
Destination, signature, and readout reference are all recorded.
dao-authority
EP9xE8MJZ6FfyEwLqns6HDdUZBknEa7WGYs1Jzsecuva
Next step
Need destination authority, transfer signature, readout text, and a reference link.
treasury-operator-authority
EP9xE8MJZ6FfyEwLqns6HDdUZBknEa7WGYs1Jzsecuva
Next step
Need destination authority, transfer signature, readout text, and a reference link.
Authority split

Mainnet requires a hard separation between upgrade authority, treasury authority, and admin authority. PrivateDAO should not carry a single-wallet super-admin posture into production.

Upgrade authority must be isolated from treasury execution.
Treasury authority must remain bound to proposal execution and treasury policy.
Admin authority should stay bounded and explicitly reduced before launch.
Production ceremony

Authority transfer has to be observable and reviewable. The credible path is a documented multisig ceremony with signer inventory, role assignment, and transaction-backed handoff evidence.

Create the production multisig and define signer roles.
Transfer upgrade authority with transaction evidence.
Transfer treasury authority and record the evidence path.
Launch boundary

Until the ceremony is complete, authority hardening remains part of the explicit production-gate surface. This is a strength when shown clearly rather than implied away.

Remove unnecessary single-signer powers.
Keep the next trust steps visible to reviewers and buyers.
Treat authority transfer as a trust event, not an internal note.

Strict intake packet

How to close this fast
When the real ceremony values arrive, download the JSON packet below, save it as docs/custody-evidence-intake.json, then run npm run apply:custody-evidence-intake. That command updates the canonical intake and rebuilds canonical custody proof, reviewer packet, and launch trust packet artifacts together.
Ingestion readiness
4/6 structured gates passed
ready-for-transfer
This local packet remains reviewer-safe. It accepts only public keys, public transaction signatures, and docs or explorer references.
Current packet preview
Multisig implementation: Squads Protocol v4
Multisig address: CALHrBqx6jbzcPn2NVcinqSAHeod65v9LcDuTxsdPqBv
Timelock configured hours: 48
Signer keys populated: 3/3
Authority transfers with signatures: 1/3
Never include secrets
No seed phrases, private keys, unencrypted keypair exports, or screenshots containing secret material belong in this packet.
Release readiness registerProduction custody ceremonyAuthority hardening briefOpen multisig setup intakeOpen canonical custody proofOpen reviewer packetOpen launch trust packetOpen authority transfer runbook
2026 operating reality

Security posture now has to survive real-world signer attacks, not only audit checklists

The Drift exploit and STRIDE response changed what serious judges expect. PrivateDAO keeps signer discipline, readiness gates, runtime visibility, and migration-safe hardening in the product surface instead of hiding them in ops notes.

Product impact matters more than narrative stacking

The single most important operating truth is that product impact, startup quality, and believable user value matter more than stacking narratives around one build.

Lead every product walkthrough from the live product shell, not from protocol internals.

Drift proved ops failures can beat good code

The largest Solana DeFi exploit in history came through signer hygiene, durable nonce exposure, weak admin thresholding, and missing timelocks rather than a contract bug.

Keep signer posture, timelock discipline, release gates, and runtime clarity visible in the product.

STRIDE and SIRN raised the security bar

Operational security, threat monitoring, incident readiness, and governance posture now matter alongside audits.

Present PrivateDAO as a protocol plus operating system, not as audited code alone.

Anchor v1 rewards disciplined upgrade posture

Teams now have stronger migration, testing, and runtime safety defaults available through Anchor 1.0.

Keep the roadmap aligned with migration-safe schemas, hooks, and stricter runtime validation.

Bootcamp 2026 and Engineering Solana raised judge literacy

Judges and builders are seeing more production-readiness, indexing, security, and systems-engineering content than before.

Make our proof, diagnostics, indexing, and readiness surfaces concrete and easy to inspect.
ZK Matrix

A PrivateDAO-specific matrix for what ZK proves now and what it does not claim

This matrix turns the ZK story into a reviewer-friendly surface: live proofs, proposal-bound anchors, attestation, and zk_enforced posture on one side, with explicit non-claims on the other.

PrivateDAO ZK matrix

Vote validity
Live off-chain

Verifier path: prove + verify commands

Boundary: Additive to current protocol

Delegation authorization
Live off-chain

Verifier path: prove + verify commands

Boundary: Additive to current protocol

Tally integrity
Live off-chain

Verifier path: bounded tally proof

Boundary: Not a full hidden tally replacement

Proposal-bound proof anchors
Live and anchored

Verifier path: Core integrations + live proof V3

Boundary: Reviewer-facing on-chain anchoring

zk_enforced path
Live but bounded

Verifier path: verifier strategy + V3 proof packet

Boundary: Not yet the dominant production recommendation

On-chain verifier CPI
Future protocol phase

Verifier path: Not claimed

Boundary: Future protocol phase

Why this matrix matters

It separates live ZK capability from future work. That makes the reviewer story stronger and keeps the buyer/operator story honest.
Open curated ZK capability matrix

Layer-by-layer truth-aligned matrix for proofs, anchors, attestation, `zk_enforced`, and verifier boundaries.

This does not claim full on-chain verifier CPI, anonymous treasury execution, or a hidden tally replacement. It keeps those boundaries explicit.
Confidence Engine

A deterministic scoring engine for ZK, REFHE, MagicBlock, and Fast RPC

This surface does not claim magical security. It explains, with explicit weights, why one proposal pattern has stronger privacy depth, enforcement depth, execution integrity, or reviewer confidence than another.

Cryptographic confidence engine

PrivateDAO now exposes a deterministic scoring model for proposal patterns that use ZK, REFHE, MagicBlock, and Fast RPC together. It does not pretend to be a formal proof of security. It is a truth-aligned explanation layer for why one governance path is stronger, more private, or more reviewer-complete than another.
Privacy depth
Weight 28%
Commit-reveal voting
ZK review overlay
REFHE confidential envelope
Proposal-bound proof anchors
Enforcement depth
Weight 28%
Governance Hardening V3
Settlement Hardening V3
Proposal-bound proof anchors
MagicBlock settlement evidence
REFHE execution boundary
Execution integrity
Weight 24%
Fast RPC indexed runtime
MagicBlock corridor evidence
REFHE envelope readiness
Baseline live proof
Dedicated V3 proof
Reviewer confidence
Weight 20%
Baseline live proof
Dedicated V3 proof
Audit packet
Launch boundary remains explicit
Principles
The score is additive and reviewer-facing, not a claim of impossible-to-break security.
ZK, REFHE, MagicBlock, and Fast RPC contribute differently depending on the proposal pattern.
Launch blockers and external custody gates are intentionally left outside the score so the app does not hide ceremony-gated work.
Interactive policy composer
Toggle ZK, REFHE, MagicBlock, Fast RPC, and hardening rails
73 · Strong
Preset: High-sensitivity capital allocation with deeper review rails
Strongest signals: Commit-reveal voting, ZK review overlay, Proposal-bound proof anchors, Governance Hardening V3
Recommendations: Keep settlement simpler unless corridor evidence or encrypted payout semantics are actually required.

Scenario scorecards

Confidential payroll
REFHE + Governance V3 + Fast RPC
90
Advanced

Payroll flows benefit from private signal collection, versioned governance snapshots, REFHE-bound manifests, and runtime evidence that stays visible to reviewers.

Privacy depth100
Enforcement depth88
Execution integrity74
Reviewer confidence100
Strongest signals: Commit-reveal voting, ZK review overlay, REFHE confidential envelope, Proposal-bound proof anchors
Still missing: MagicBlock settlement evidence, MagicBlock corridor evidence
Private grant committee
ZK + Governance V3 + reviewer-safe proof
66
Strong

Grant committees need private signal collection and strong reviewer context more than confidential payout corridors. ZK and proof anchors do most of the heavy lifting here.

Privacy depth72
Enforcement depth48
Execution integrity50
Reviewer confidence100
Strongest signals: Commit-reveal voting, ZK review overlay, Proposal-bound proof anchors, Governance Hardening V3
Still missing: REFHE confidential envelope, Settlement Hardening V3, MagicBlock settlement evidence
Gaming rewards corridor
MagicBlock + Settlement V3 + Fast RPC
47
Foundational

Token reward programs rely more on settlement evidence and corridor controls than on encrypted payroll-style envelopes. The score reflects that difference instead of pretending every pack has the same cryptographic posture.

Privacy depth26
Enforcement depth40
Execution integrity62
Reviewer confidence70
Strongest signals: Commit-reveal voting, Settlement Hardening V3, MagicBlock settlement evidence, Fast RPC indexed runtime
Still missing: ZK review overlay, REFHE confidential envelope, Proposal-bound proof anchors
Open the canonical engine spec

Formula, weights, factor-by-factor meaning, and explicit non-claims for the PrivateDAO cryptographic confidence engine.

Confidential payout corridor

Private payout is now packaged as a reviewer-safe service lane

What it proves
PrivateDAO can already connect private governance to confidential payout rehearsal, grant releases, and payroll-style treasury motions on Testnet.
Why judges care
Umbra and Encrypt reviewers need a practical payout workflow, not generic privacy language. This packet ties treasury motions to governance, trust, and payout review.
Boundary
This is Testnet and evidence-backed. It is not a real-funds mainnet claim until audit, custody, and settlement-receipt blockers are closed.
Encrypted operations lane

Plan a sponsor-grade confidential operation inside the product

This workbench turns the confidential payout story into an actual operating plan. It helps the same product read better for Privacy, Umbra, and Encrypt by making the encrypted operation, settlement posture, and reviewer path explicit.
Confidential operation plan
This plan can be carried into reviewer packets, treasury review, and sponsor-facing submission work without rewriting the product story.
Reviewer-safe confidential operation
Recommended amount
1,000 USDC
Recipient count hint
8
Prepare a governed salary or grant disbursement where the manifest stays off-chain and the settlement path remains reviewable. Use the existing private governance discipline and keep recipient detail in an encrypted off-chain manifest. Use the current settlement evidence posture with explicit reviewer-safe continuity.
Raises PrivacyRaises UmbraRaises Encrypt
{
  "requestId": "ENCRYPTED:CONFIDENTIAL-PAYROLL:MANIFEST-HASH-AND-COMMIT-REVEAL:ATTESTED-EVIDENCE",
  "operationProfile": "Confidential payroll",
  "privacyMode": "Manifest hash + commit-reveal",
  "settlementMode": "Attested evidence",
  "operatorVisibility": "Hybrid",
  "sponsorLift": [
    "Privacy",
    "Umbra",
    "Encrypt"
  ],
  "recommendedAmount": "1,000 USDC",
  "recipientCountHint": "8",
  "posture": "Reviewer-safe confidential operation",
  "rationale": "Prepare a governed salary or grant disbursement where the manifest stays off-chain and the settlement path remains reviewable. Use the existing private governance discipline and keep recipient detail in an encrypted off-chain manifest. Use the current settlement evidence posture with explicit reviewer-safe continuity.",
  "reviewerPath": "/security",
  "servicePath": "/services",
  "settlementPath": "/documents/settlement-receipt-closure",
  "proofPath": "/documents/confidential-payout-evidence-packet",
  "nextOperatorAction": "Keep the manifest boundary explicit and carry the same operation plan into treasury review and governed execution."
}
Review checklist
  • Confirm the operation profile is confidential payroll and the recipient count posture still matches the intended treasury motion.
  • Confirm Manifest hash + commit-reveal is the right privacy mode for the sponsor and reviewer expectations.
  • Confirm Attested evidence keeps the trust boundary readable enough for this submission and release stage.
  • Confirm Hybrid keeps the operation understandable to the target reviewer without weakening the privacy story.
Continue the same lane
Use the security route for the privacy story, the services route for the treasury motion, and the settlement packet for reviewer continuity.
Settlement receipt surface

How payout proof, receipts, and blockers connect in one route

Privacy and payout reviewers should not have to guess where settlement confidence comes from. This surface connects the governed payout lane to evidence, trust, and the exact remaining receipt gap.
Governed payout lane
Treasury motion, payout selection, and commercial service routes are presented as governed execution, not ad-hoc transfers.
Proof-linked payout evidence
Confidential payout evidence, launch trust, and custody proof stay near the route so reviewers can inspect one corridor instead of three disconnected pages.
Receipt publication gap is explicit
The product now shows where settlement evidence exists and where source-verifiable receipt closure still remains before honest mainnet claims.
Fundable next step
This is exactly the sort of corridor that grants can accelerate: better receipts, better runtime coverage, and tighter treasury proof publication.
Runtime operations readiness

The last operational gap between live Testnet proof and a credible mainnet release path

Funders and reviewers need one route that explains why wallet runtime coverage and monitoring closure matter, what already exists, and what still remains explicitly open.
Real-device wallet matrix
Supported wallet environments are defined and reviewable, but completion still depends on captured runs across browser wallets and Android/mobile runtime.
Monitoring rules exist
RPC, governance, proof, treasury, and authority alerts are already defined in-repo. What remains is live delivery, ownership, and tested transcripts.
Mainnet confidence gap
These two areas are operational blockers, not product-concept blockers. Closing them shortens the path to an honest mainnet release candidate.
Fundable next action
This is exactly the kind of bounded execution work grants and accelerators should fund: measurable, visible, and directly tied to release credibility.
Wallet matrix and monitoring

The two operating systems that turn a strong Testnet product into a confident mainnet candidate

This surface uses generated runtime and alert artifacts directly. It shows how wallet coverage and monitoring discipline are being pushed into the same product story a reviewer can inspect after a real Testnet session.
Real-device wallet matrix
Wallet coverage
1/5 complete
Signed wallet captures are tracked through a dedicated intake program and attached to proof packets as they are verified.
Submission proof
1 captured
Real-device submission evidence remains the most visible runtime lift before stronger production-release claims.
Diagnostics captures
1 recorded
Diagnostics evidence must stay linked to real wallets, not browser-only expectations.
Target environments: desktop-browser, android-or-mobile
Monitoring and alerting
Defined alerts
8 rules
The alert set already covers RPC, governance, proof, treasury, and authority activity.
High-pressure rules
2 critical / 5 high
The rulebook is already defined. Delivery ownership and tested transcripts are the next operating lift.
Environment claim
solana-testnet-production-candidate
Testnet backend probes are live and verified; external alert routing and incident transcripts remain pending delivery setup
Current operating boundary: Testnet backend probes are live and verified; external alert routing and incident transcripts remain pending delivery setup
Why this matters to funders
These are not abstract roadmap promises. They are the practical operating layers that let funders and judges see a real product gaining the coverage and discipline needed for production release.
Real-device closure program

The real-device capture board that expands Testnet proof into release-grade confidence

Completion
1/5 targets closed
This is a live capture program, not a speculative roadmap. Every row below maps to a wallet/client where recorded proof strengthens the release story and makes the product easier to trust.
Active targets
4
Phantom, Solflare, Backpack, Glow, and Android/mobile are all being pulled into the same reviewer-visible intake path so visitors can see the product growing across real wallet conditions.
Submission standard
connect + sign + submit
A capture counts when it shows diagnostics visibility and a signed Testnet outcome or an explicit wallet-side error boundary. That keeps the evidence honest while still moving the product toward broader production confidence.
desktop-browser
Phantom
pending-capture
Capture connect, diagnostics, and one signed Testnet submission from Phantom on desktop.
connect: pending
signing: pending
submission: pending
tx/error: pending
Required evidence
wallet version visible in extension or popup
connect result and diagnostics visibility
signed Testnet transaction signature or explicit wallet error
screenshot or short recording reference
desktop-browser
Solflare
pending-capture
Capture the full governance submit path from Solflare, including the signature prompt and explorer-visible outcome.
connect: pending
signing: pending
submission: pending
tx/error: pending
Required evidence
wallet version and browser
proposal or DAO submission result
explorer URL or transaction signature
evidence refs for the success or failure boundary
desktop-browser
Backpack
pending-capture
Capture Backpack desktop connect and one governed wallet action on Testnet.
connect: pending
signing: pending
submission: pending
tx/error: pending
Required evidence
connect result
signing result
submission result
diagnostics snapshot or error transcript
desktop-browser
Glow
pending-capture
Capture Glow desktop compatibility for the same minimum Testnet flow used elsewhere.
connect: pending
signing: pending
submission: pending
tx/error: pending
Required evidence
wallet and browser identification
connect and signing result
submission signature or explicit failure
evidence refs
android-or-mobile
Android Native / Mobile
captured
Capture Android-native or mobile browser wallet flow with diagnostics and one signed Testnet transaction.
connect: success
signing: success
submission: success
tx: 5ZQfvJxU7QvKakZvS1JkDNJLBZVzTesQk7g1NhzAXGBzKYYsPcSzUbiNiDa9Xc2wq5K7yfeJm3uT2qY5aWW9cMV2
Required evidence
device and OS build
wallet client name
connect/signing/submission result
screenshot or log evidence
Mainnet execution scorecard

How much of the mainnet path is already structured vs what still depends on external closure

Repo-defined path
7/11
Documented, defined, or Testnet-proven launch steps already exist in the repo and can be reviewed now.
External closure
7
External actions still define the remaining path: audit, multisig, monitoring delivery, and release ceremony.
Runtime capture gap
2
Real-device wallet evidence remains one of the clearest readiness accelerators because it is bounded and measurable.
Readiness profile
2 critical / 4 high
The remaining critical and high-severity items are explicit, countable, and therefore more credible to a serious grant reviewer.
Readiness boundary
Production mainnet claim allowed: false. This surface exists to raise confidence through explicit execution structure and measurable closure, not through inflated readiness language.
Mainnet timeline

Four-week company launch path after the hackathon

The current Testnet product is deliberately staged for production: custody, audit, wallet coverage, monitoring, mainnet deployment, and wallet-placement launch are sequenced as one operating plan.

Week 1 post-hackathon
1
Week 2
2
Week 3
3
Week 4
4
Monitoring delivery closure

The exact operating path between defined alert rules and believable live delivery

Defined rulebook
8 rules
2 critical and 5 high-severity rules already exist in-repo.
Delivery status
pending-external
Owner: operations. This remains a readiness gate before honest mainnet real-funds language.
Exact next action
Configure live monitoring and alert delivery for proposal lifecycle, failed proof or settlement checks, RPC degradation, and treasury execution anomalies.
Delivery requirements
Alert destination ownership
partial · operations owner assigned; external alert destination delivery transcript remains the closure item
Primary and fallback RPC probes
closed · same-domain /healthz and /api/v1/readiness pass on https://api.privatedao.org with QuickNode Testnet RPC redacted in public payloads
Proposal lifecycle monitor
partial · Solana Testnet chain watcher endpoint returns latest indexed transactions; routed alert transcript still required
Treasury balance monitor
partial · Token and treasury evidence remains indexed in reviewer packets; balance anomaly delivery transcript still required
Proof and settlement monitor
closed · QuickNode stream stats, freshness endpoint, QVAC runtime proof, Umbra relayer health, and backend provider readiness packet all return HTTP 200
Authority activity monitor
partial · Squads custody evidence and timelock proof are recorded; external authority-activity alert transcript still required
Owner assignments
operations-lead
assigned · alert destination ownership and response windows
rpc-operator
assigned · primary and fallback RPC probe routing
release-manager
assigned · incident acknowledgment transcript retention
Evidence path
docs/launch-ops-checklist.json
docs/launch-ops-checklist.md
docs/monitoring-alert-rules.json
docs/monitoring-alert-rules.md
docs/monitoring-alerts.md
docs/production-operations.md
docs/incident-response.md
Transcript requirements
trigger source and timestamp
alert destination and delivery result
acknowledging operator
response window
linked runbook and incident note
Readiness boundary
Testnet backend probes are live and verified; external alert routing and incident transcripts remain pending delivery setup
Monitoring delivery evidence

Defined monitoring rules and the live delivery route

Rule coverage
8 rules
RPC, governance, proof, treasury, and authority activity are already represented in the alert rule set.
Highest-severity alerts
2 critical / 5 high
The monitoring posture already knows which failures are treasury- or custody-critical. The operator route now focuses on live routing and tested acknowledgment.
Delivery gap
external delivery lane
The blocker is not rule design. It is primary/fallback RPC selection, alert destination ownership, response windows, and tested transcripts.
Funder relevance
execution unlock
This is exactly the kind of bounded operations work a serious funder can accelerate without asking whether the product itself already exists.
Current boundary
Testnet backend probes are live and verified; external alert routing and incident transcripts remain pending delivery setup
Security + Intelligence

Proposal, treasury, voting, RPC, and gaming analysis belong inside the security story

PrivateDAO should help users detect abnormal treasury motions, summarize governance discussion, and interpret runtime health before signatures happen. This is where AI-style assistance becomes operational instead of cosmetic.

Security + Intelligence layer

This is where AI belongs in PrivateDAO: proposal review, treasury execution review, voting compression, RPC interpretation, and gaming-governance assistance. It is decision support, not a shallow chatbot.

Operational intelligence
User-facing analysis
Hugging Face free-ready path

How to use this route

Open it before signing when you want a plain-language explanation of proposal or treasury risk.
Use the RPC analyzer when the product feels slow and you want the data path explained without digging through logs first.
Use the gaming path when governance and reward decisions need to stay fair, fast, and understandable to non-experts.

Proposal Review AI

Proposal execution review

Execution notes attached
Intelligence output

This proposal should keep explanation, trust context, and destination rationale visible before signatures are collected.

The point of this output is not to replace human judgment. It is to compress hard governance, treasury, RPC, and gaming context into something a signer can actually understand before acting.
Transfer size is meaningful enough to justify an explicit treasury review note.
Recipient has no prior usage history in this governance context yet.
Timelock is compact, so timing context should stay explicit before execution.
Hugging Face free posture

This layer is built to help users now with browser-side intelligence and clear governance heuristics. If you later want a free open-model path, the same UX can be connected to a Hugging Face-hosted summarization or classification adapter without changing the product surface.