Roadmap

Burn down existential risk before building expensive community systems.

The delivery order should prove the direct-platform business model quickly while keeping legal, payment, privacy, moderation, and operational risk ahead of feature expansion.

Sequence principle

Build the beautiful private catalog first. Add controlled participation. Earn the right to add live community later.

Delivery sequence

Risk-burn-down roadmap

PhaseOutcomeExit criteria
Phase 0 — Planning lockHTML docs finalized enough to guide MVP implementation.Product, privacy architecture, trust/safety, compliance risks, roadmap, and implementation track reviewed and accepted.
Phase 1 — Foundation skeletonRust + Axum app, server-rendered templates, Postgres, Redis, Docker, local dev flow, basic CSP/security headers, local owner diagnostics, and backup posture visibility.Health route, base layout, migrations, test harness, container startup, local smoke/HTTP smoke/seed helpers, and local doctor checks verified.
Phase 2 — Account, sessions, and access gatesPseudonymous member accounts, one-time owner invite codes, self-custody recovery with explicit saved-key confirmation and current-key-proven rotation, opaque sessions, CSRF protection, age self-attestation, preview entitlements, and gated placeholder media routes for private test.User can create an invite-gated account, save and confirm recovery phrase custody, log in/out, rotate recovery keys, revoke sessions, and recover with the current secret; owner can create/list/revoke invite codes without storing raw codes or identity bindings.
Phase 3 — Media catalog MVPPrivate media metadata, gated catalog, image/video viewing, authenticated media delivery, selective downloads, no DRM.Unauthenticated users cannot access media; authenticated active members can view protected image/video files through disk-backed byte-range streams; selected assets expose attachment downloads by policy; media routes apply privacy-preserving per-session limits; owner can import private files and promote/draft/archive catalog items locally before production proxy/object-storage hardening.
Phase 4 — Payment proof, checkout lifecycle, matrix, and webhook replayProcessor-neutral payment proof, reversal ledger, checkout sessions, stale-session expiry cleanup, webhook replay inbox, and source-backed provider decision matrix exist first; processor selected and integrated for subscription and/or 30-day pass in test mode only after vendor approval.Local checkout pages can create pending provider-neutral sessions and mark browser success/cancel returns without granting access; local payment record/list/refund/chargeback/void plus payment-checkout list/expire/complete and payment-webhook record/list/replay commands can create paid proof, expire stale sessions, grant entitlements, reject duplicate/expired provider-reference completion, and revoke linked paid access without customer identity or raw payloads; the provider matrix blocks live hosted checkout, endpoint signature verification, cancellation/retry states, and provider adapter work until adult/AI-adult approval is confirmed.
Phase 5 — Controlled participationSignals, polls, private request queue, aggregate reactions, aggregate unlock goals, and basic admin review UI.Local MVP primitives now exist for owner-granted Signals, owner-created polls/options, authenticated member browser voting, browser catalog/media reactions, Hermes-screened private requests, owner review states, aggregate reaction summaries, aggregate unlock-goal progress, and a minimal gated owner dashboard for request/reaction/goal review without public posting, profiles, leaderboards, or activity feeds; reward/contest fulfillment remains open before wider testing.
Phase 6 — Trust/safety hardeningHermes policy taxonomy, moderation states, takedown intake, enforcement events, evidence handling, and operator workflow.Initial deterministic request screening routes allow/reject/quarantine/lock-review cases with reasons; public /report intake can open external cases without login/uploads/identity fields and now has non-identifying abuse controls for body size, honeypot, dwell time, token expiry, and active queue cap; local report/takedown cases can quarantine media or archive catalog/request targets; a minimal gated browser owner workflow exists; the private-VPS escalation runbook defines SLA tiers, quarantine-first triage, external escalation triggers, and evidence minimization; jurisdiction/provider-specific escalation validation, production owner auth, and calibration remain open.
Phase 7 — Private external testVPS deployment, HTTPS, production-edge profile, configured/external backup posture, observability, expanded health/doctor remediation, restricted access, sample synthetic media, payment sandbox or limited live test.Owner can access externally; no public launch; basic abuse/security tests pass; production-edge doctor mode fails closed for missing HTTPS origin, secure cookies, owner gate, or local-only backup posture; vps-bootstrap-plan checks private env/template/compose posture before service startup; deployment-rehearsal-plan prints the secret-free evidence/backup/readiness rehearsal sequence; production-preflight blocks placeholder domains, long owner sessions, and before-exposure posture failures; Caddy/nginx reverse-proxy templates define first-pass body limits, header stance, and access-log minimization, with memory-only nginx sensitive-POST throttles and an explicit stock-Caddy trusted-edge boundary; scripts/external-edge-smoke.sh verifies the final public origin for shallow health, headers, diagnostics non-exposure, private-media gates, and body caps; smoke-member-provision creates recovery-confirmed disposable credentials through an operator recovery-key file, scripts/external-member-smoke.sh verifies disposable-member login, account, library, media ranges, downloads, checkout return non-authority, owner gate posture, and logout through the same final origin, and smoke-member-cleanup revokes active smoke access afterward; deployment-evidence-record/list/check captures sanitized proof plus artifact hashes, backup-manifest-record/list/check tracks sealed backup dump/media hashes, backup-custody-record/list/check tracks encrypted/offsite custody retention metadata, restore-drill-plan prints the isolated backup-restore checklist and backup_restore_drill evidence command without restoring anything, and private-vps-readiness blocks wider private testing until preflight, evidence, origin consistency, backup posture, sealed backup manifest completeness, and encrypted/offsite custody retention pass; diagnostics point to common local/server misconfigurations without exposing internals over HTTP; local smoke/HTTP smoke/reset-seed passes, and at least one isolated restore drill succeeds before broader exposure.
Phase 8 — Public launch readinessLegal/payment/tax/privacy validation, final terms, privacy notice, processor approval, retention windows, launch content set.No known critical blocker in compliance register; public launch checklist complete.
Phase 9 — Paid MVP launchPublic acquisition funnel, paid membership, controlled participation, recurring drop cadence.Direct-platform conversion and retention measured without adding live chat.
Phase 10 — Community expansion decisionEvaluate optional Discord satellite or native lounge.Only proceed if revenue/retention justifies moderation burden and safeguards are mature.
MVP

Paid MVP scope

Included

  • Premium landing page and gated catalog.
  • Pseudonymous account and self-custody recovery.
  • Age self-attestation with future verifier abstraction.
  • Payment entitlement for monthly subscription and/or 30-day pass.
  • Image/video media access with no public URLs.
  • Signals, owner-created polls, private request queue, aggregate reactions, aggregate unlock goals, and drop seasons.
  • Basic public takedown/report intake with non-identifying abuse guardrails, local case list/review, gated owner dashboard review, and target quarantine.

Deferred

  • Native live chat.
  • Discord member automation.
  • DMs, attachments, user-uploaded media.
  • Regional pricing.
  • Crypto payments.
  • Complex tier ladder or annual subscriptions.
  • Advanced personalization and behavioral analytics.
Validation

What the MVP must prove

Later decision gate

Native lounge decision test

Do not add chat because it feels attractive. Add it only if at least one of these becomes clearly true: