Quantum Shield Delivery Roadmap
Delivered pilot
- White marketing website with the approved logo and animations.
- Company workspace and ChatGPT sign-in through private Sites access.
- Server-side owner, admin, analyst and viewer roles.
- Email-bound, expiring invitations with private token acceptance.
- Ethereum and Base account snapshots with stored evidence and limitations.
- Assessment history, JSON downloads and printable reports.
- Watchlist creation, pause/resume, manual checks and in-app change alerts.
- Scoped API keys with hash storage, revocation and a server-side JavaScript SDK.
- Database migrations, local SQLite development, security tests and operator documentation.
- A scheduler entrypoint, but no automatic schedule claimed until configured and verified.
Next release gates
1. Validate three company use cases and define the minimum useful report. Founder and security advisor; one to two weeks of interviews, not a guaranteed schedule.
2. Replace shared public RPC with an agreed provider plan and fallback. Backend owner; measure quotas, costs, timeout behavior and chain coverage.
3. Provision and observe monitoring jobs. Operations owner; prove restart recovery, acceptable lag and idempotent alert delivery before enabling the UI status.
4. Add verified-domain transactional email and an outbox/retry mechanism. Require delivery tracking and recipient controls before customer alerts.
5. Add public commercial identity or document platform sign-in requirements. Test authorization independently from the identity provider and private Site sharing boundary.
6. Add pagination, retention, export/deletion workflows and a tested backup/restore process. Establish a support and incident contact.
7. Obtain independent application security review and remediate material findings. No paid protection guarantees before specialist review.
8. Integrate payments only after founder approval. Confirm country, legal entity, tax handling, refund terms and provider availability. Validate signed, idempotent webhooks and server-side entitlements.
Product expansion
Ethereum and Base are the only supported networks in the pilot. BNB Chain, Arbitrum and Polygon need adapter validation, representative test fixtures and provider coverage checks. Solana and Bitcoin need separate account and cryptographic models; they are not enabled by changing an RPC URL.
Full transaction history, public-key exposure evidence, approvals, proxy/admin policy analysis and verified multisig configuration are separate data capabilities. They must show coverage and confidence and must not infer safety from an empty response. Do not label generic activity as a quantum attack.
Quantum Vault remains a research program. Scope a threat model, account recovery, cryptographic agility, signature verification costs, testnet implementation, independent audits and a controlled adoption plan before discussing mainnet custody or automatic migrations.
Commercial milestones
Start with companies and a free individual scanner. Interview 10 to 15 potential buyers. Recruit three design partners. Offer a scoped readiness engagement if qualified specialists can deliver it. Test Team and Growth subscription proposals against measured support and provider costs. Seek renewals and recurring product use before expanding marketing spend.
Example acceptance measures: every live report has evidence and coverage limits; cross-workspace reads/writes are denied; provider failure never produces a fabricated completed report; scheduled checks recover after restarts; alerts are traceable; SDK keys revoke promptly; billing remains disabled until specifically integrated.
Open founder decisions
Business country and legal entity; development/operations budget; security reviewer; target company segment; service and incident-response hours; data retention period; provider accounts; public sign-in strategy; payment integration date. These decisions change commercial readiness, not the ability to test the private pilot.