§ 01 · THE HONEST PART

Running a business today means running nine apps that can’t testify.

Your answers live in three different places, and none of them agree. The actual record — who did what, when, and why it was allowed — lives in people’s heads, and it leaves when they do. Until then, you’re the glue: the one holding the story together across every tool that was never built to keep one.

CELL 01 · 0xa401
A call comes in
CELL 02 · 0x7e02
Everyone knows their step
CELL 03 · 0xf103
It writes itself down
CELL 04 · 0x9c04
“Prove it” takes one search, not one weekend
steaded.app/home CAPTURED LIVE · JUL 2026
STEADED Ground home surface showing sealed daily record
MY DAY — EVERY COUNT READS FROM THE SEALED RECORD
§ 01.1 · WHAT MARIA SEES NEXT
steaded.app/events CAPTURED LIVE
STEADED Ground events surface showing the sealed event trail
EVENTS — EVERY STEP LEAVES ITS OWN ENTRY

Maria doesn’t open a second app to find out what happened. The trail that built her day’s numbers is the same trail an auditor would pull — same rows, same hashes, same order.

── 0x1a9c…4f · seam closed · § 01 → § 02 ──
§ 02 · THE INSPECTION — LIVE IN YOUR BROWSER

Try to cheat it. Right now.

Five entries, hashed by your own browser — real SHA‑256, computed on this page, right now. Nothing is sent to a server and nothing is faked for the demo. Change the payment below and watch the chain notice.

EVERY AI ANSWER EXPORTS AS A CERTIFICATE THAT VERIFIES THIS WAY — OFFLINE, WITHOUT OUR SERVERS · PATENT PENDING
WHAT THE AUDITOR GETS
  • CERTIFICATE.JSON — full chain, offline-portable
  • VERIFY.SH — re-hashes every entry, no network call
  • ZERO DATA ACCESS — no login, no export of your live system

Built as architecture, not a feature — and the patent applications are on file.


── 0x2f6a…e3 · seam closed · § 02 → § 02.5 ──
§ 02.5 · ONLY HERE

Things only this architecture can do.

Eleven consequences of running everything on one sealed, entitlement-bounded record — each verified against the shipped code.

SAME DOCUMENT, TWO CLEARANCES — REDACTED BEFORE THE PIXELS EXIST
§ 01 · THE ONE BOUNDARY

One boundary. Everywhere. Even in the AI's head.

Set who's cleared to see what once, and it holds through every door out of the system — the live view, the export, the screenshot, the screen-share, even what the AI is allowed to know and what history shows. A field above someone's clearance is redacted into the pixels before they're ever drawn; a live screen-share sends only the page you're on, never the values, so the person following renders it through their own account's clearance. Same document, two people, two truths — and the restricted one never leaves the device it's hidden on.

SCREEN-SHARE A RECORD WITH A CLIENT AND THEY ONLY EVER SEE WHAT THEIR OWN ACCOUNT IS ENTITLED TO — THE RESTRICTED VALUES NEVER LEAVE YOUR DEVICE.
GAP FLAGGED → THE ONE TASK THAT CLOSES IT, ROUTED SAME DAY
§ 02 · REGULATION THAT RUNS

The law changes. Your SOPs already know.

Regulations and procedures share one governed model, so the moment a regulation is recorded as changed, Steaded recomputes exactly which published procedures it touches and where their control coverage now falls short. Every affected procedure gets an attributed review comment naming the precise gap — and the one task that would close it — routed the same day, automatically.

CHANGE ONE REGULATION AND EVERY PROCEDURE IT TOUCHES GETS A ROUTED TO-DO NAMING ITS EXACT GAP — AND THE ONE TASK THAT WOULD CLOSE IT — THE SAME DAY, AUTOMATICALLY.
ISSUED → ACCEPTED → SEALED · 0x7F3A91E2…
§ 03 · THE CUSTODY ARC

When someone leaves, their knowledge doesn't.

Offboarding issues a sealed record transferring a departing person's governed knowledge, proven decisions, and even their open questions — what they provably never got to — to a named inheritor. The inheritor cryptographically counter-signs acceptance, cross-bound to that exact record, and the two-party handoff composes into one portable, offline-verifiable certificate.

A SEALED, TWO-PARTY CUSTODY TRANSFER OF WHAT THEY KNEW AND WHAT THEY NEVER GOT TO — COUNTERSIGNED BY WHOEVER INHERITS IT.
PROCESS CHANGED → POLICY PAUSED, PENDING RE-EARN
§ 04 · DECISION GRADUATION

Every approval you make twice, it learns to make for free.

Once a recurring go/no-go decision backtests at 85%+ agreement over six real cases, it graduates into a deterministic $0 policy that stamps the routine ones automatically. But the policy carries the exact shape of the process it learned from — the instant that process changes, it's marked stale and the next matching case climbs straight back to a human, until it re-earns the shortcut.

EVERY APPROVAL YOU MAKE TWICE, STEADED LEARNS TO MAKE FOR FREE — AND THE INSTANT YOU CHANGE THE PROCESS, IT STOPS TRUSTING ITSELF UNTIL IT RE-EARNS THE SHORTCUT.
1 GAP, SEALED & TIMESTAMPED — PROVEN OPEN AT 14:32:06Z
§ 05 · PROVABLE IGNORANCE

Proof it didn't know — sealed the moment it didn't.

Any time the governed AI answers on zero or one grounding fact, it writes a tamper-evidenced, timestamped record proving the organization's AI did not know the answer at that moment — the inverse of a hallucination log. When new facts later close the gap, the record captures exactly what filled it, so "when did we first know?" finally has a provable answer.

THE AI KEEPS A SEALED, TIMESTAMPED RECORD EVERY TIME IT DIDN'T KNOW SOMETHING — SO YOU CAN PROVE EXACTLY WHEN YOU LEARNED IT.
3 DEPENDENTS AT RISK → CROSS-TRAIN NEXT
§ 06 · SCENARIO PLANNER

See what breaks before you commit to it.

Stack a layoff, a move, a leave of absence — any mix of hypothetical changes — against the live org, and the same engine that measures workload re-runs key-person risk with the hypothetical roster. It reports exactly which seats newly go fragile as a side effect of the plan, and ranks the single best person to cross-train next, before anything touches live data.

MODEL THE LAYOFF, THE MOVE, THE LEAVE OF ABSENCE — AND SEE WHICH SINGLE POINTS OF FAILURE IT CREATES BEFORE YOU COMMIT TO IT.
RECORD ERASED AI MEMORY CACHE ANSWERS CERTIFICATE

§ 07 · EPISTEMIC ERASURE

The Row Is Gone. So Is Every Trace It Left.

Erasing a governed fact doesn't stop at the database row. The Epistemic Erasure Certificate names every AI decision that cited it, every model provider live during the exposure window, and declares the response cache stale — then re-queues every contaminated decision. You can verify the closure yourself, offline, without Steaded ever re-exposing the value.

EVIDENCE — src/core/proofs/epistemicErasure.ts:47–260 · contaminated_decision_ids · redecision_ids · provider_ids · cache_evicted_at

VP OPS MGR A MGR B BOX BOX MOVED + GAINS SIGHT R. OKAFOR T. LIN − LOSES SIGHT M. PATEL

§ 08 · REORG STUDIO

Every Move Has A Person On The Other Side.

Reorg Studio doesn't just move a box on a chart. Before you can click Apply, it runs the exact same visibility engine that governs production against the proposed structure — for every active person — and reports precisely who gains sight of new events and accounts, and who loses it. Nothing touches live data until you commit.

EVIDENCE — src/core/people/reorg.ts:88–165 · previewReorg() runs visibleRecords() per person, before vs after

RUNBOOK OPERATOR PROMPT

§ 09 · THE PROCEDURE COMPILER

One Drawing. Two Executors.

Model a process once — in the canvas, with its decision tables, roles, SLAs, and risk tier — and it compiles into two documents. One is the runbook a person follows; the other is the exact versioned system prompt an autonomous agent executes, guardrails and escalation triggers included. Neither can drift from the other, because both come from the same governed model.

EVIDENCE — src/core/ai/procedureToPrompt.ts:61–130 · compileProcedureToPrompt() → versioned CompiledPrompt record

OVERREACH DENIED SEALED 0x7F2A UNDERSTUDY SAME DOOR, SAME SIZE

§ 10 · OVERREACH + THE UNDERSTUDY

Every Boundary Holds — And Proves It.

When an AI agent reaches past its role, the refusal isn't a silent error — it's a permanent, tamper-evident entry naming the exact rule that stopped it, on the same default-deny check a human employee faces. Every employee can also run a personal AI understudy while they're out; its access is mechanically re-synced to their own, so it can never see a door they couldn't open themselves.

EVIDENCE — src/core/ai/agents.ts:41–167 (refusal audit) · src/core/ai/understudy.ts:52–101 (role-synced principal)

NO SERVER NO ACCOUNT NO NETWORK

§ 11 · THE SELF-VERIFYING CERTIFICATE

Proof That Needs No One To Trust.

Every grounded AI answer is bound to a Merkle root over the exact records used to produce it. Export it as one self-contained HTML file, cut the network, open it in any browser — it carries its own from-scratch SHA-256 and Merkle-proof reimplementation and recomputes the entire cryptographic chain itself. Change one byte, and it says so.

EVIDENCE — src/core/brain/knowledgeCertificate.ts:46–239 · VERIFIER_SCRIPT reimplements sha256 + Merkle proofs, fully offline

── 0x9d15…7c · seam closed · § 02.5 → § 03 ──
§ 03 · THE ECONOMICS

One bill. It goes down, not up.

Bring your own AI key — billed by the provider at cost. Never metered, never marked up.

HOMESTEAD
$299/MO FLAT · UP TO 15 PEOPLE

Everything a small crew needs, no seat math.

+$15/PERSON FROM 16–35 · GRADUATES TO FOOTING
FOOTING
$40/MO PER OPERATOR
+$15/MO PER GROUND SEAT

Every day-to-day room + the full sealed record.

OPERATOR SEALS · GROUND SEAT WORKS THE RECORD
BEDROCK
$175/MO PER OPERATOR
+$25/MO PER GROUND SEAT

+ governance depth, agents & digital twin, BYOM/BYODB.

FOR ORGANIZATIONS THAT RUN ON THEIR OWN MODELS
OPERATOR = CAN SEAL, APPROVE, CONFIGURE · GROUND = READS, SUBMITS, APPROVES-WITH-PROOF · PORTAL GUESTS FREE
A 20-PERSON SHOP: HOMESTEAD $299 · ZOHO ONE ≈$740 · POINT STACK ≈$440–650 · FIELD-OPS TOOL ALONE $299–599
LIST PRICES JUL 2026 · STEADED MARKET COMPARISON

Steadfast price-lock — your tier keeps its price AND its feature stream. Founding cohort: first 25 organizations, classic pricing locked for life.

MFA · SSO · WEBHOOKS IN EVERY TIER — SECURITY IS NEVER TIER BAIT $2,500 PILOT · 90 DAYS · CREDITED TO YEAR ONE
§ 03.1 · SIZED TO YOU

Build your stack. Watch what one bill gives back.

Pick the tools you pay for today — see what they cost next to one flat bill, which room of GROUND replaces each one, and why it’s better.

100 people team size of which operators · the rest are ground seats

Your stack today

What it costs, both ways

what you pay now · per year
Your stack 6 tools
— tools total $0
— AI, metered $0
total$0
Homestead$299 flat
Footing$40+$15
Foundation$100+$20
Bedrock$175+$25
on STEADED · per year
One platform, all of it $0
AI, your key at cost $0
total$0
$0
kept in year one — and the AI half keeps shrinking as your team teaches its rules

What replaces what

your tools → rooms of one building

The capabilities the enterprise giants charge six- and seven-figure contracts for — process, analytics, work, AI, and governance — on one sealed record. STEADED is $299 flat for a small crew, or $40–$175 per operator + $15–$25 per everyday seat — whether you’re replacing three tools or thirty. The more you pay now, the more fair looks.

Select the tools you pay for above — you’ll see which GROUND room replaces each one.

Every tool you pay for maps to a room GROUND already includes — the more of your stack it covers, the fewer bills, logins, and integrations you keep.

Why the AI half bends down

metered / per-seat AISTEADED — cost-down
yearly AI budget ceiling budget spent — teams pull back routine decisions → $0 day one as your team teaches its rules →
One bill replaces the stack
Mail, work, analytics, docs, e-sign, CRM, support — thirteen rooms of one building on a single sealed record. Nothing to sync, no per-tool renewals.
Cheapest capable first
Every request is served from cache ($0) or on-device ($0) before it pays for a frontier call. Most work never leaves the building.
Bring your own key
Frontier AI runs on your model key, billed by the provider at cost. STEADED never meters it and never adds a markup.

The reflex to blown AI budgets is to retreat. The better move is to consolidate the stack and help the AI along — so every month it costs less to do more, on one bill you can actually prove.

Illustrative model, not a quote. Vendor figures are typical public list prices for illustration only and vary by plan, region, seat tier, and contract — set seats to your own, or add tools with your real rate. Enterprise platforms (process-mining, data-warehouse, and data-virtualization suites) are typically sold as large annual or consumption contracts, not per seat — the figures shown are rough per-seat equivalents for comparison; use your real contract value. The STEADED price shown is the selected tier × team size; AI on the metered path assumes ~$35/user/month for per-seat AI plus metered/agent usage (a common pattern, not any one vendor), and on STEADED your own frontier-model key billed at provider cost, blended down by cache / on-device routing and decision-graduation. STEADED never meters or marks up AI — you pay your model provider directly.

── 0xc71b…2b · seam closed · § 03 → § 04 ──
§ 04 · YOUR MOVE

Stop paying rent on nine tools that can’t testify.