Habitable: keep the repair trail in tenants’ hands
Role: Independent product designer and engineer · 2026 · alpha
I designed and built a working local-first alpha that turns conditions, repair requests, responses, and captured media into a source-aware repair trail and deliberate review copy—without a project-operated tenant-case database. It has only synthetic examples and is not ready for real legal matters.
Evidence boundary
- Built
- A working local-first alpha and deliberate review artifacts controlled by the tenant
- Observed
- Synthetic examples, three review formats, English and Spanish catalog parity, and automated checks
- Not proved
- Truth, admissibility, field safety, legal readiness, or outcomes in a real tenant matter
Selected measures
- project-operated accounts or centralized plaintext case files
- 0
- Reported and Secured keep assertion and technical record distinct
- 2 dates
- review artifacts: axe-tested HTML, print PDF, and signed bundle
- 3
- catalog parity; native-language and human accessibility review remain open
- EN + ES
Habitable (opens in a new tab) is a working reference implementation for a hard product question: how can a tenant preserve a repair trail that others can inspect without first handing a sensitive case file to a vendor? I designed the local app, evidence model, review-copy flow, independent verifier, and adoption materials as an independent open-source project (opens in a new tab) with synthetic examples. One rule governs the design: keep what a person reports, what the software can establish, and what a recipient must decide visibly separate. It is not a government system, client work, legal advice, or a promise that a packet will be admitted in court.
A repair trail starts before a hearing
Housing evidence is a sequence, not a photograph: the condition, repair request, proof of delivery, response, attempted repair, recurrence, and the records that connect them. California's habitability guide (opens in a new tab) and tenant trial guidance (opens in a new tab) tell tenants to retain repair requests, communications, photographs, videos, receipts, notices, and copies for other parties. Habitable addresses the work before that handoff: preserve sequence, source, scope, and visible gaps instead of reconstructing a case from a camera roll and inbox under deadline.
The access problem is also large. The Legal Services Corporation's 2022 Justice Gap study (opens in a new tab) found that 92 percent of substantial civil legal problems reported by low-income Americans received no or insufficient legal help; housing was among the categories with the greatest reported impact. That does not show this alpha improves outcomes. It explains why an organized, reviewable record is worth testing before scarce professional time begins.
A repair trail, not a camera roll
The current Repair Trail brings each condition, repair notice, delivery record, response, recurrence, and capture onto one source-aware chronology. It keeps two dates distinct: Reported is when a person says something happened; Secured is when the entry entered the evidence record. Each step preserves its source, linked material, and proof state, while missing steps stay visibly missing. The current capability ledger (opens in a new tab) is the controlling source for what is shipped, partial, planned, or still externally unvalidated.

What exists today
The alpha includes an English and Spanish local browser app, encrypted capture, offline timestamp queuing, the source-aware Repair Trail, hash-linked custody, whole-unit review-copy export, encrypted paired-device sync and full-case handoff, key rotation and recovery, a repair-letter workflow, and a standalone verifier. Each review copy coordinates axe-tested HTML, a print PDF, and a signed machine-readable bundle. The public site hosts only a static explanation and safe synthetic artifacts; personal cases run locally, not in a hosted case application.
No centralized plaintext case file
Centralizing plaintext tenant cases would concentrate breach, retention, and legal-process risk around photographs, addresses, repair disputes, and household details. Habitable instead runs no project-operated account system or central plaintext case database. Device-controlled encrypted vaults are the default. Its privacy contract (opens in a new tab) documents the remaining exposure. A paired full-case share or sync can deliberately transfer sealed originals to another device. An optional relay can carry authenticated ciphertext between paired devices, but it can still observe timing and traffic volume; encrypted is not invisible.
What the proofs can—and cannot—show
- A SHA-256 hash (opens in a new tab) can show whether the bytes changed. It cannot show whether the image is true.
- An RFC 3161 token (opens in a new tab) is queued while offline and attached when connectivity returns. It can show that content existed no later than its timestamp, once the recipient separately accepts the authority trust. It does not prove the moment of capture or who made it.
- A hash-linked custody log can expose later handling. It does not certify every human assertion in the timeline.
- A verifier can check the package and its selected trust anchor. Technical integrity does not prove authorship, truth, relevance, or admissibility.
Two handoffs, deliberately different
A whole-unit review copy produces policy-processed media, axe-tested HTML, a print PDF, and a signed machine-readable bundle. Shared media removes metadata by default. A paired full-case share or sync is a different flow: it is encrypted to a chosen recipient and may carry sealed originals and their metadata. The sharing trust model (opens in a new tab) keeps those trust boundaries explicit. Omission is not anonymization, and issue- or date-scoped review copies remain blocked where a complete custody proof could leak identifiers for excluded evidence. In that conflict, the product fails closed instead of pretending the scope is private.
Inspect the current synthetic review packet (opens in a new tab) and its signed bundle (opens in a new tab). These are generated product artifacts, not marketing mockups, and the packet states its own scope and legal limits.
Verification belongs to the recipient
A recipient should not have to trust the application that assembled the evidence. Habitable includes a deliberately small standalone verifier (opens in a new tab) that reports structural integrity, timestamp-authority trust, and technical evidence readiness separately. It checks hashes, signatures, timestamp tokens, custody links, and the certificate the verifier chooses to trust. The review walkthrough (opens in a new tab) makes that decision boundary visible. None of those checks establishes real-world producer identity, authorship, depiction, truth, relevance, or admissibility.
The adoption hypothesis: coordination without central custody
The credible first test is organizational distribution, not a mass consumer subscription. A tenant union, legal-aid program, or housing nonprofit could configure the workflow, distribute a signed local app, train members, and define a safe receiving process. Habitable's bilingual quick starts, workshop guide, board risk brief, review routes, threat model, and capability ledger prepare for that test; they are not evidence that a pilot occurred.
- Tenant unions and housing organizers could test a repeatable documentation method and shared review vocabulary without default central custody.
- Legal-aid intake teams could test whether an organized packet reduces time spent sorting unlabeled media and reconstructing chronology.
- Inspectors, mediators, counsel, and other recipients could read ordinary HTML or PDF while technical reviewers inspect the signed bundle and verifier output separately.
- Implementation partners could provide packaging, training, accessibility and security review, support, and narrowly scoped timestamp or ciphertext-relay operations around the open-source core.
That smaller custody footprint is itself operational value. The NIST Privacy Framework (opens in a new tab) treats privacy as risk created across the data-processing lifecycle. A local-first architecture can reduce what an adopting organization collects and retains, which can lower breach exposure, records burden, and the trust demanded at intake. It does not remove the organization's responsibilities for the packets it chooses to receive, devices it manages, or copies its staff create.
That is an adoption hypothesis, not traction. Habitable has no customer deployment, real-case evidence, or measured field outcome. A pilot must test whether tenants can complete the workflow safely, whether organizers spend less time reconstructing chronology, whether recipients understand the packet without overreading its technical claims, and whether local custody creates support or recovery burdens that outweigh its privacy benefit.
What remains unproven
The project has automated accessibility checks, keyboard coverage, and 320-pixel reflow tests (opens in a new tab). It has not had an independent security or legal review, a tenant-union pilot, a recorded human screen-reader pass, native-language review, or validation of real recovery ceremonies. Signed consumer distribution and update operations, and a duress or decoy vault, are not implemented. Until those gaps close, the honest label is alpha, not secure by audit, field-tested, or court-ready.
Explore the public alpha site (opens in a new tab), inspect the capability and claim ledger (opens in a new tab), read the threat model (opens in a new tab), or review the source and verification instructions (opens in a new tab).