Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

The EstateDraftFL app for iPhone and Android: sign in, matters, send a document, notifications, remote revocation

both lanes · Deterministic — no model call

Current availability

Owner-gatedWaiting on the platform owner: the owner's Expo project, the sign-in allow-list entry estatedraftfl://auth/callback, Apple (and, for Android notifications, Firebase) credentials through Expo's build service, the store submissions, then MOBILE_APP_PUBLISHED=1 on the deployment (mobile/README.md).

Where it lives
The app (built from mobile/ by Expo's build service on the owner's account) · /api/mobile/me · /api/mobile/devices · /api/mobile/matters · /api/mobile/sso-join · /api/documents/register · the account's Security page (/dashboard/security → Phones with the EstateDraftFL app)
What unlocks it
anyone with an account: a firm's staff (after the platform's second factor) and the matter's own client

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • Owner-gatedSign in with the email link (it opens the app) or the firm's single sign-on, then the platform's second factor for a firm's staff — a session comes back as a one-time code only that installation can exchange; the app never creates an account.
  • Owner-gatedThe matters the person can open, read as them: the platform's walls and the firm's second factor apply exactly as on the website.
  • Owner-gatedPhotograph a document or choose a file and send it to a matter: it waits in the app's private folder (no signal, a closed app) and goes through the platform's document ingress and quarantine like any upload; refused files keep their reason.
  • Owner-gatedLocal encryption: the session and everything the app keeps are encrypted with a key held in the phone's secure storage, readable only while the phone is unlocked and never copied to a backup or a new phone.
  • Owner-gatedThe screen is covered whenever the app is not the active one, so the app switcher's picture shows nothing of a matter.
  • Owner-gatedRemote revocation: the person (from the website), their firm's administrator or the platform revokes a phone; it is asked each time the app opens, wipes everything and signs out. Another person signing in drops the previous person's queue.
  • Owner-gatedNotifications, when the person turns them on: one fixed line — You have an update — never a matter, a party or a figure.

Limits

  • The app is not yet in the App Store or Google Play: the owner builds and submits it (mobile/README.md); store review is Apple's and Google's.
  • Notifications arrive within about ten minutes of the notice (the outbox drain), and need the owner's push credentials.
  • The app sends documents and reads the matters list; drafting, review and approvals stay on the website.
  • No hardware identifier is used: a reinstalled app is a new device.

What EstateDraftFL refuses

Reason codeHTTPWhat it means
auth_required401The app's request carried no valid session.
invalid400A registration field could not be read.
forbidden403Revoking someone else's phone needs their firm's administrator or the platform.
unavailable503A read could not be answered just now.

Evidence

  • mobile/README.md
  • mobile/src/core/queue.ts
  • mobile/src/core/session.ts
  • mobile/src/secure-storage.ts
  • mobile/src/session.tsx
  • supabase/migrations/20261003230000_phase21_mobile_devices.sql
  • src/lib/mobile/api.ts
  • src/lib/mobile/push.ts
  • src/lib/supabase/bearer.ts
  • src/lib/phase21-mobile-routes.test.ts
  • src/components/MobileDevicesPanel.tsx
  • .github/workflows/mobile.yml
  • docs/security/NATIVE-CLIENT-DESIGN.md

Last reviewed 2026-10-03

← All surfaces