01

Server Summary

SS & Bans
✓ Live
16GB · 56 containers · Audit clean
Prod-Ops
✓ Live
16GB · 204.168.169.58 · 92GB recovered
BTCPay
✓ Live
8GB · 12 containers · 0 restarts
Agency
✓ Live
4GB · Webhook bus 71 entries · Clean
ServerIPRAMOS / ProxySidecarsStatus
SS & Bans65.109.171.3816GBUbuntu · Nginx + Traefik v2.118 (7 Docker + 1 systemd)live
Prod-Ops204.168.169.5816GBUbuntu · Traefik v3 only7 Dockerlive
BTCPay89.167.70.578GBUbuntu · Nginx (BTCPay managed)0live
Agency95.216.141.814GBUbuntu · Traefik v30live · webhook bus 71 entries
SS & Bans architectural rule: Internet → Nginx (80/443, SSL via Certbot) → Traefik (127.0.0.1:8080, internal only) → containers via backend_reup-network. Nginx is the ONLY public entry point. Traefik handles NO TLS. All containers needing external routing must be on backend_reup-network with explicit traefik.docker.network=backend_reup-network labels. All compose files use entrypoints=web only. Any file with entrypoints=websecure or tls.certresolver has NOT been deployed and should be treated as a stale draft.
02

Ops Control Plane — FULLY LIVE

MEF Ops Dashboard (primary) + Discord (notification mirror) + Supabase state layer + sidecar system

MEF Ops Dashboard is the primary operator interface. Discord is the notification mirror only. All new channels go in MEF Ops. Discord channel additions frozen.
ComponentLocationURLStatus
MEF Ops DashboardProd-Ops · /opt/apps/mef-ops/operations.sovereignstack.prolive
Hermes HTTP GatewayProd-Ops · localhost:4200172.19.0.1:4200 (mgmalkz bridge)live · auth pending
Supabase — project_stateswialrjhuixpsnungclfe.supabase.colive · 15 rows
Config ServiceSS&Bans · port 3099config.sovereignstack.prolive
OpsBot (Discord)SS&Bans · discord-bots stacklive
Webhook BusAgency · /opt/apps/webhook-bus/api.sovereignstack.prolive · 71 entries

Supabase Tables — CortexHQ (wialrjhuixpsnungclfe)

TablePurposeRealtimeStatus
project_states15 project rows — sidecar truth sourcelive
project_state_historyFull audit traillive
cortex_memory12-column CortexHQ brainlive
eventsInbound webhook events — powers channel feedslive
leadsRepairRadar + Reddit leadslive
outreach_queueHermes-drafted outreach awaiting approvallive
outreach_repliesWarm replies detected by IMAPlive
project_todosPer-channel todos — Supabase-backedlive
project_notesPer-channel notes — auto-save 1s debouncelive
hermes_messagesPersistent Hermes chat — last 50 per channellive
audit_runsStructured audit runs from /audit commandlive
audit_findingsFindings per run — type: positive/issue/risk/moneylive
project_money_metricsPer-project verdict, revenue_mtd, blockers, next actionlive
session_archiveArchived Hermes chat sessionslive
03

Sidecar System — 15 Projects Tracked

Autonomous state tracking across all active projects on both servers

ContainerProject PathNetworkStatus
kratombans-sidecar/opt/apps/bans/kratombanskratombans-networkrunning
cbdbans-sidecar/opt/apps/bans/cbdbanskratombans-networkrunning
delta8bans-sidecar/opt/apps/bans/delta8banskratombans-networkrunning
mushroombans-sidecar/opt/apps/bans/mushroombanskratombans-networkrunning
sentinel-newsroom-sidecar/opt/apps/sentinel-newsroomkratombans-networkrunning
ship-my-stack-sidecar/opt/apps/ship-my-stackkratombans-networkrunning
scan643-sidecar/opt/apps/scan643scan643-networkrunning
signalforge-sidecar/opt/apps/signalforgebans-networkrunning
sovereignstack-sidecar/var/www/sovereign-stacksystemd (bare metal)running
reup-sidecar/root/workspace/reup-backendreup-backend_reup-networkrunning
sovpay-sidecar/root/workspace/sovpayprod-ops-networkrunning
pluginops-sidecar/root/workspace/pluginopsprod-ops-networkrunning
repairradar-sidecar/root/workspace/repairradarprod-ops-networkrunning
evantage-sidecar/root/workspace/Evantageprod-ops-networkrunning
n8n-sidecar/root/workspace/n8nprod-ops-networkrunning
sovereignstack-sidecar runs as a systemd service (not Docker) because sovereignstack.pro is a bare-metal PM2 process. Config: /etc/systemd/system/sovereignstack-sidecar.service
04

SovPay Merchant Provisioning Bus — ALL GATES CLOSED

7/7 phases proven. All 5 gates confirmed. Ready to sell now.

SovPay is ready for merchant onboarding. Full end-to-end flow confirmed 2026-06-15: store → product → checkout → BTCPay invoice → payment complete → WooCommerce sync. All gates closed. Positioning: public beta / early merchant access. Codex audit score: 8.4/10.
GateDescriptionStatus
Gate 1 — P2POnboarding routing + wallet dashboard flowdone
Gate 2 — StoreNew user provisions store → adds product → customer buys → payment confirmeddone ✓ proven
Gate 3 — WooCommerceBuy product on SovPay → order appears in WooCommerce admin → stock decrementsdone ✓ confirmed by operator
Gate 4 — SafetyTerms and privacy pages live. UI copy clean.done
Gate 5 — Launchgetsovpay.com landing page deployed. $$handle URL routing clean.done ✓ live

Known Polish Items (non-blocking)

ItemOwnerPriority
In-app BTC wallet/copy/QR buttons inactive on payment screenCursorMedium
Malformed JSON returns 500 not 400 on /api/handles/registerCursorMedium
Frontend bundle 1.29MB — code splitting neededCursorLow
Frontend test coverage thin (14 tests)CodexLow
sovpay-postgres-1 on shared prod-ops-network — isolate to sovpay_internalCursorPlanned

Provisioning Endpoints

EndpointPurposeStatus
POST /api/provisioning/merchant/ensureAtomic store + user + API key + webhook. Idempotent. Resumable.live · proven
POST /api/provisioning/merchant/walletConnectConnect watch-only xpub to BTCPay store.live · proven
GET /api/provisioning/merchant/statusPure DB read. Returns full phase state. Safe to poll.live · proven
BTCPay wallet payload quirk: config must be the raw xpub string, not an object. {"enabled": true, "config": "xpub..."} works. Object form fails with "Invalid account derivation".
!
Do NOT rotate SESSION_JWT_SECRET on SovPay — it breaks btcpayMerchantStoreApiKeyEnc encryption. All merchant keys depend on it.
05

SS & Bans — Primary Server

65.109.171.38 · 16GB RAM / 150GB disk · Hetzner Helsinki · Nginx + Traefik v2.11

/opt/apps/ — SS & Bans
/opt/apps/
├── bans/
│   ├── kratombans/           # LIVE · kratombans-api + db + sidecar
│   ├── cbdbans/              # LIVE · cbdbans-api + db + sidecar · explicit traefik.docker.network label added
│   ├── delta8bans/           # LIVE · delta8bans-api + db + sidecar · explicit label added
│   └── mushroombans/         # LIVE · mushroombans-api + db + sidecar
├── discord-bots/             # LIVE · 5 bots: BanWatch, ProcessorPulse, SSAlert, CoOpDN, OpsBot + postgres
├── news-scraper/             # LIVE · feeds kratombans + cbdbans · port 127.0.0.1:4444 (hardened)
├── sentinel-newsroom/        # LIVE · sentinel-newsroom + sentinel-db + sidecar · explicit label added
├── openclaw/                 # LIVE · control-plane (4 containers: app, db, oauth, proxy)
├── ship-my-stack/            # LIVE · shipmystack.com + sidecar · Stripe active
├── scan643/                  # LIVE · scan643-api + database + sidecar
├── mef-compliance-platform-v2/ # LIVE · 6 containers · compliance-network
├── mef-prepscan-dashboard/   # LIVE · prepscan.pro sole owner (conflict resolved 2026-06-15)
├── signalforge/              # LIVE · intel.sovereignstack.pro · 5 containers · internal only
├── reupbot-pwa/              # LIVE · reup-pwa + reup-backend
├── forgesales/               # LIVE · forge.sovereignstack.pro · React+Vite+Express+Claude · Supabase · Phase A+B complete · BasicAuth gated
├── mse/                      # LIVE · engine.merchantfirst.pro · Next.js 14 + Express + Postgres + Redis + Playwright
└── sidecar-config/           # LIVE · config.sovereignstack.pro · port 3099
/var/www/
├── sovereign-stack/          # LIVE · Next.js v14 · PM2 · port 3000 · sidecar via systemd · 46h uptime stable
└── wordpress/                # LIVE · PHP 8.1-FPM · MariaDB · no HTTPS (planned)
sovereignstack.pro PM2 shows 51 historical restarts but has been stable for 46+ hours (0 unstable restarts). BTCPay checkout integration is intentionally disconnected — return to after SovPay B2B sales begin. Missing static page /solutions/commerce/checkout-failure will self-resolve on next full rebuild.
06

Prod-Ops — Production

204.168.169.58 · 16GB RAM · Hetzner Helsinki · 100% Docker · Traefik v3

/root/workspace/ — Prod-Ops
/root/workspace/
├── reup-frontend/                # LIVE · thereup.pro
├── reup-backend/                 # LIVE · api.reupbot.com · reup-api + postgres + redis + sidecar
├── sovpay/                       # LIVE · sovpay.me + getsovpay.com · ALL GATES CLOSED · 8.4/10
├── pluginops/                    # LIVE · pluginops.pro + sidecar
├── repairradar/                  # LIVE · radar.pluginops.pro + sidecar · 68 eligible leads queued
├── pain-intelligence-dashboard/  # LIVE · signal.pluginops.pro + sidecar
├── Evantage/                     # LIVE · evantage.pluginops.pro + sidecar
├── n8n/                          # LIVE · brain.pluginops.pro + sidecar
└── mgmalkz/                      # LIVE · MGMX Commerce · $19,284 revenue · 108 orders
/opt/apps/
├── mef-ops/                      # LIVE · operations.sovereignstack.pro · Hermes gateway wired
├── mgmedicalabs/                 # LIVE · mgmedica.payme.mobi · Express+Vite · SendGrid
├── visibility-machine/           # LIVE · visibility.pluginops.pro · seeded · gated
├── sidecar-config/               # LIVE · sidecar.py
├── reddit-watcher/               # STAGED · needs Reddit credentials
├── reup-email-bot/               # STALE · not running · no .env
└── ops/reup-agency-platform/     # STALE · source on disk · .env has live creds — rotate or deploy
/opt/hermes/                      # LIVE · Hermes agent · app + data + memory + workflows
Audit fixes applied 2026-06-15: reup-backend + reup-frontend permissions hardened (777/666 → rw-rw----). 92GB Docker build cache recovered (118GB → 36GB used, 82% → 25%). mgmalkz-traefik-1 confirmed removed. Empty /opt/hermes/docker-compose.yml removed.
Hermes gateway: hermes-http-gateway.js binds to 172.19.0.1:4200 (mgmalkz Docker bridge). Intentional — mgmalkz bots reach Hermes here. No Bearer auth currently. Cursor task: add token validation using MEF_OPS_WEBHOOK_SECRET from /opt/apps/mef-ops/.env.
07

BTCPay — Bitcoin Infrastructure

89.167.70.57 · 8GB RAM · kernel 6.8.0-117 · BTCPay 2.3.9 · Stable since 2026-05-29

ContainerImagePortNotes
btcpayserverbtcpayserver:2.3.949392 (internal)Main BTCPay application
btcpayserver_lnd_bitcoinlnd:v0.19.30.0.0.0:9735 (intentional)Lightning peer port — must be public
btcpayserver_bitcoindbitcoin:29.1internal onlyFull Bitcoin node · 77GB and growing
btcpayserver_litecoindlitecoin:0.21.5.4internal only59GB — verify LTC payment methods active
generated_nbxplorer_1nbxplorer:2.6.7internal onlyHD wallet tracker
generated_lnd_bitcoin_rtl_1rtl:v0.15.43000 (internal only)Ride The Lightning — SSH tunnel access only
generated_postgres_1postgres:18.15432 (internal)BTCPay database
nginxnginx:1.25.380, 443BTCPay managed reverse proxy
Disk: HC Volume 492GB at 29% used. Bitcoin node 77GB and growing ~5-10GB/month. Set a 75% alert. No immediate action needed.
Litecoin node: Running 59GB chain. If no LTC payment methods active in BTCPay Store Settings, disable to recover disk.
BTCPAY_PROVISIONING_API_KEY must be unrestricted for merchant provisioning. Do not scope it. Webhook endpoint: https://api.sovereignstack.pro/webhooks/btcpay · Secret: 4Z9HA6F6SF9JeRZmCdThT9rhngA8
08

Agency — Webhook Bus & API Gateway

95.216.141.81 · 4GB RAM / 38GB disk (25% used) · Traefik v3 · SSL via Let's Encrypt

Webhook bus rebuilt 2026-06-15. 71 entries (35 Discord + 35 MEF Ops + 1 HTTP). All undefined-mef-ops placeholders resolved. mushroombans, ForgeSales, MSE, SignalForge, Visibility Machine added. Container restarted and healthy.
ContainerPurposeStatus
agency-traefikReverse proxy · SSL via Let's Encryptlive
webhook-busFastify webhook receiver + fan-out · 71 destinationslive · 0 restarts
webhook-bus-postgreswebhook_events table via Prismalive · healthy

Webhook Bus Endpoints

EndpointPurposeAuth
POST /webhooks/btcpayBTCPay payment/invoice eventsBTCPay-Sig HMAC
POST /webhooks/woocommerceWooCommerce order eventsX-WC-Webhook-Signature
POST /webhooks/githubGitHub push/PR/release eventsX-Hub-Signature-256
POST /webhooks/repair-radarRepairRadar eligible leadsBearer
POST /webhooks/reddit-leadReddit keyword hitsBearer
GET /healthService status + event countsNone
GET /eventsRecent events with statusBearer or X-API-Key
Staged but not running: sentinel-social (directory exists, secrets missing). reddit-watcher has no directory on Agency — it's on Prod-Ops at /opt/apps/reddit-watcher/.
09

Containers — SS & Bans

Container(s)DomainNetworkStatus
kratombans-api + db + sidecarkratombans.comkratombans-network + backend_reup-networklive
cbdbans-api + db + sidecarcbdbans.comcbdbans-network · explicit label setlive
delta8bans-api + db + sidecardelta8bans.comkratombans-network · explicit label setlive
mushroombans-api + db + sidecarmushroombans.comkratombans-networklive
sentinel-newsroom + db + sidecar(internal)kratombans-network · explicit label setlive
ship-my-stack (4 containers + sidecar)shipmystack.comkratombans-networklive · Stripe active
scan643-api + database + sidecarscan643.proscan643-networklive
openclaw control-plane (4 containers)openclaw.*kratombans-networklive
mef-compliance-platform-v2 (6 containers)(internal)compliance-networklive
mef-prepscan-dashboardprepscan.pro · www.prepscan.pro · dashboard.prepscan.prokratombans-networklive · sole owner of prepscan.pro
signalforge (5 containers + sidecar)intel.sovereignstack.probans-networklive · internal only · 1,383 events collected
forgesales-appforge.sovereignstack.probans-networklive · Phase A+B done · Claude API · Resend · BasicAuth · full outreach cycle
mse-frontend + mse-worker + mse-backend + mse-postgres + mse-redisengine.merchantfirst.probans-networklive · 6 days uptime
discord-bots (5 bots + postgres)(internal)discord-internallive
news-scraper(internal)kratombans-networklive · 127.0.0.1:4444 (hardened)
sidecar-configconfig.sovereignstack.probackend_reup-networklive · port 3099
traefik v2.11backend_reup-networklive · 127.0.0.1:8080

Bare Metal (SS & Bans)

ProcessPathPortStatus
Next.js (sovereignstack.pro)/var/www/sovereign-stack3000live · PM2 · 46h uptime
sovereignstack-sidecar/opt/apps/sidecar-config/sidecar.pylive · systemd
WordPress/var/www/wordpress80live · no HTTPS (planned)
MariaDBhost3306live · bare metal
Nginx/etc/nginx/80/443live · reverse proxy to Traefik
10

Containers — Prod-Ops

Container(s)DomainNetworkStatus
reup-webthereup.proreup-networklive
reup-api + reup-postgres + reup-redis + reup-sidecarapi.reupbot.comreup-backend_reup-internal (isolated DB)live
sovpay-web + sovpay-api + sovpay-postgres + sovpay-sidecarsovpay.me / getsovpay.comprod-ops-network · DB isolation plannedlive · ALL GATES CLOSED
pluginops (web + api + db + sidecar)pluginops.proprod-ops-network · pluginops_internal (DB isolated)live
repairradar + sidecarradar.pluginops.proprod-ops-networklive · 68 eligible leads
pain-intelligence-dashboard + sidecarsignal.pluginops.proprod-ops-networklive
evantage + sidecarevantage.pluginops.proprod-ops-networklive
n8n + sidecarbrain.pluginops.proprod-ops-networklive
mef-opsoperations.sovereignstack.proprod-ops-networklive · primary control plane
visibility-machinevisibility.pluginops.proprod-ops-networklive · seeded · gated · mefworks auth
mgmalkz (web + telegram-bot + discord-bot)mgmalkz.comprod-ops-network + mgmalkz_defaultlive · $19,284 revenue
mgmedica-dashboardmgmedica.payme.mobiprod-ops-networklive
traefik v3prod-ops-networklive · SSL via Let's Encrypt
11

Containers — BTCPay

All official BTCPay-project images. 0 restarts across all containers. Stable since 2026-05-29.

ContainerImagePortStatus
btcpayserverbtcpayserver:2.3.949392 internallive
btcpayserver_lnd_bitcoinlnd:v0.19.39735 public (intentional)live
btcpayserver_bitcoindbitcoin:29.1internallive · 77GB
btcpayserver_litecoindlitecoin:0.21.5.4internallive · 59GB · verify LTC active
generated_nbxplorer_1nbxplorer:2.6.7internallive
generated_lnd_bitcoin_rtl_1rtl:v0.15.43000 internal onlylive · SSH tunnel only
generated_postgres_1postgres:18.15432 internallive
nginxnginx:1.25.380, 443live · BTCPay managed
12

Docker Networks

SS & Bans

NetworkUsed ByNotes
backend_reup-networkTraefik, sidecar-config, kratombans-apiMain Traefik network. All containers needing external routing must join this AND have explicit traefik.docker.network label.
kratombans-networkAll bans apps, sentinel, ship-my-stack, openclaw, news-scraper, sidecarsExternal: true. Primary app network. Known debt: overcrowded — 18+ containers, migration planned.
cbdbans-networkcbdbans-api, cbdbans-db, cbdbans-sidecarcbdbans-app explicit traefik.docker.network label set 2026-06-15.
bans-networkForgeSales, MSE, SignalForge stacksCo-mingles Postgres + Redis instances — DB lateral movement risk. Migration planned.
compliance-networkmef-compliance-platform-v2 stack including mef-merchant-portalIsolated. Correct.
scan643-networkscan643-api, database, sidecarExternal: true. Isolated.
discord-internaldiscord-bots stackBot isolation. Correct.

Prod-Ops

NetworkUsed ByNotes
prod-ops-networkTraefik, most app containersMain shared network. Traefik on this network.
reup-backend_reup-internalreup-api, reup-postgres, reup-redisIsolated DB network. Correct pattern.
reup-backend_reup-networkreup-sidecar onlyIntentional — sidecar only needs reup-api access.
pluginops_internalpluginops-web, pluginops-api, pluginops-dbDB isolated. Correct pattern.
mgmalkz_defaultmgmalkz botsHermes gateway accessible at 172.19.0.1:4200 from this network. Intentional.
13

Domains & SSL

DomainPoints ToSSLStatus
sovereignstack.proSS&Bans · bare metal PM2Certbotlive
config.sovereignstack.proSS&Bans · port 3099Nginx + Certbotlive
intel.sovereignstack.proSS&Bans · SignalForge · Nginx BasicAuthCertbotlive · internal only
forge.sovereignstack.proSS&Bans · ForgeSalesCertbotlive
kratombans.com / cbdbans.com / delta8bans.com / mushroombans.comSS&Bans · TraefikCertbotlive
prepscan.pro / www.prepscan.pro / dashboard.prepscan.proSS&Bans · mef-prepscan-dashboardCertbotlive · conflict resolved 2026-06-15
shipmystack.comSS&Bans · TraefikCertbotlive
engine.merchantfirst.proSS&Bans · MSECertbotlive
btcpay.sovereignstack.proBTCPay serverBTCPay managedlive
sovpay.me / getsovpay.comProd-Ops · TraefikLet's Encryptlive · all gates closed
sovpay.proProd-Ops · TraefikLet's Encryptlive · API only
thereup.proProd-Ops · TraefikLet's Encryptlive
pluginops.pro + subdomainsProd-Ops · TraefikLet's Encryptlive
operations.sovereignstack.proProd-Ops · Traefik · BasicAuthLet's Encryptlive · mefworks auth
visibility.pluginops.proProd-Ops · Traefik · BasicAuthLet's Encryptlive · mefworks auth
api.sovereignstack.proAgency · TraefikLet's Encryptlive · webhook bus
cortexhq.techHostingerEXPIRED — renew or lose
cortexhq.shopHostingerEXPIRED
ss7score.comHostingerEXPIRED
sovereignrails.pro / dataapi.prounassignedplanned
!
ReUp cluster renewal URGENT: thereup.pro, reupbot.com, reuppro.com and related domains renew July–August 2026. Set calendar reminders now. Missing a renewal on thereup.pro while the platform is live kills the product.
14

Port Reference

SS & Bans — Public Ports

PortBindingServiceNotes
80, 4430.0.0.0NginxPublic reverse proxy. Routes to Traefik at 8080.
8080127.0.0.1Traefik v2.11Internal only. Nginx proxies to here.
3099127.0.0.1sidecar-configInternal only. Nginx proxies config.sovereignstack.pro.
4444127.0.0.1news-scraperInternal Docker only. Hardened 2026-06-15 (was 0.0.0.0).

BTCPay — Public Ports

PortServiceNotes
80, 443Nginx (BTCPay managed)Public HTTPS
9735LND LightningIntentionally public — required for Lightning channel opens

Agency — Public Ports

PortBindingServiceNotes
80, 4430.0.0.0Traefik v3Public. SSL via Let's Encrypt.
3000internalwebhook-busInternal only. Traefik routes to it.
5432internalwebhook-bus-postgresInternal only.
15

Security Issues

IssueServerStatusAction
reup-backend + reup-frontend perms 777/666Prod-OpsFIXED 2026-06-15chmod -R o-rwx applied. Now rw-rw----.
news-scraper port 4444 bound to 0.0.0.0SS&BansFIXED 2026-06-15Changed to 127.0.0.1:4444 binding.
ournorthstar/ and signalforge/ world-writable (0777)SS&BansFIXED 2026-06-15chmod 755 applied to signalforge/. ournorthstar/ pending.
SIDECAR_CONFIG_KEY exposed in chatAll serversPENDINGRotate: openssl rand -hex 32. Update all .env files and sovereignstack-sidecar systemd service.
Hermes gateway unauthenticated (172.19.0.1:4200)Prod-OpsCURSOR TASKAdd Bearer token validation to hermes-http-gateway.js using MEF_OPS_WEBHOOK_SECRET.
sovpay-postgres-1 on shared prod-ops-networkProd-OpsPLANNEDCreate sovpay_internal network. Mirror pluginops_internal pattern.
WordPress no HTTPSSS&BansPLANNEDcertbot --nginx -d [wordpress domain]
PM2 running as rootSS&BansKNOWN DEBTArchitecture debt. Not urgent.
SESSION_JWT_SECRET — DO NOT ROTATEProd-Ops SovPayLOCKEDbtcpayMerchantStoreApiKeyEnc depends on this. Rotating breaks all merchant keys.
reup-agency-platform .env with live credentials — not runningProd-OpsREVIEWCheck key names in /opt/apps/ops/reup-agency-platform/.env. Rotate or deploy.
16

Audit Findings — v10.0 (2026-06-15)

Full 4-server read-only scan. 56 containers confirmed healthy.

🔴 Critical — All Resolved

FindingServerResolution
Duplicate Traefik router for prepscan.pro (mef-compliance-dashboard + mef-prepscan-dashboard) — non-deterministic routingSS&BansRESOLVED — mef-compliance-dashboard stopped and removed. mef-prepscan-dashboard is sole owner. Compose file marked SUPERSEDED.
reup-backend + reup-frontend 777/666 permissions — .env world-readableProd-OpsRESOLVED — chmod -R o-rwx applied to both directories.
DESTINATIONS_JSON — 53/114 expected destinations (61 missing)AgencyRESOLVED — Rebuilt to 71 entries (35+35+1). All placeholders resolved. New projects added.

🟠 High — All Resolved

FindingServerResolution
Disk at 82% (118GB used of 150GB)Prod-OpsRESOLVED — 92GB recovered via docker system prune. Now 25% (36GB used).
news-scraper port 4444 bound to 0.0.0.0SS&BansRESOLVED — Changed to 127.0.0.1:4444.
kratombans-sidecar generic Traefik router name "api" — collision riskSS&BansDOCUMENTED — Rename to kratombans-sidecar-api on next deploy.
sovereign-stack PM2 51 restartsSS&BansCLEARED — Historical accumulation. 46h uptime, 0 unstable restarts. Not an active problem.

🟡 Medium — Documented / Deferred

FindingServerStatus
Traefik network labels implicit — cbdbans, delta8bans, sentinel-newsroom missing explicit traefik.docker.networkSS&BansFIXED — Labels added. Compose files updated.
Stale .production.yml files causing schema confusionSS&BansFIXED — Renamed to .STALE across bans stack and signalforge.
kratombans-network overcrowding — 18+ unrelated containersSS&BansDEBT — Planned migration. Not urgent.
bans-network co-mingles ForgeSales/MSE/SignalForge Postgres + RedisSS&BansDEBT — Planned migration.
Dead nginx vhosts td.sovereignstack.pro + tdalt.sovereignstack.proSS&BansPENDING — Remove from nginx sites-enabled.
sovpay-postgres-1 on shared prod-ops-networkProd-OpsDEBT — Create sovpay_internal. Pattern: pluginops_internal.
mgmalkz-traefik-1 in Created state — port conflict landmineProd-OpsRESOLVED — Container removed by prune. Compose file was already clean.
Hermes gateway unauthenticated at 172.19.0.1:4200Prod-OpsCURSOR TASK — Add Bearer auth.
Visibility Machine BasicAuth hash confusion ($$ vs $)Prod-OpsRESOLVED — Hash hardcoded in compose label. $$ format correct everywhere.
BTCPay Litecoin node 59GB — verify activeBTCPayCHECK — BTCPay Store Settings → Payment Methods → LTC.

🟢 Low / Informational

FindingServerStatus
3 orphaned Docker networksSS&Banscleanup
4 leftover .tar.gz archivesSS&Bans + Prod-Opscleared on Prod-Ops
2 zombie node processesSS&Bans + Prod-Opsself-clearing on restart
Node.js 18 deprecated by @supabase/supabase-jsSS&Bans + Prod-Opsplanned upgrade to Node 20
BTCPay disk — 29% used, Bitcoin 77GB growingBTCPayset 75% alert
RTL (Ride The Lightning) port 3000 internalBTCPayintentional · SSH tunnel only
17

Stale / Inactive

ItemLocationNotes
/home/mef/sovereign-stack/SS&BansOld copy. 709MB. Safe to delete — live version is /var/www/sovereign-stack.
reup-email-botProd-Ops /opt/apps/reup-email-bot/Not running. No .env. Move to Agency when ready.
reup-agency-platformProd-Ops /opt/apps/ops/Source on disk, not running. Has .env with live credentials — review and rotate or deploy.
reddit-watcherProd-Ops /opt/apps/reddit-watcher/Single Python file, not running. Needs Reddit credentials to activate.
sentinel-socialAgency /opt/apps/sentinel-social/Directory exists, no containers running. Needs 16 .env secrets (Twitter/Reddit/FB/IG).
Duplicate BTCPay test storesBTCPay serverOld stores from failed provisioning attempts. Archive via BTCPay admin.
.production.yml filesSS&Bans variousRenamed to .STALE — never deployed. entrypoints=websecure conflicts with Nginx-first architecture.
mef-compliance-dashboard/SS&Bans /opt/apps/Superseded by mef-prepscan-dashboard. Compose file marked SUPERSEDED. Directory safe to delete.
18

Discord Ops Control Room — Notification Mirror

Discord is the notification mirror. MEF Ops Dashboard is the primary operator interface. Discord channel additions frozen.

Discord serves as Hermes's autonomous workspace. MEF Ops is where the operator works. Hermes operates in Discord, pushes summaries and escalations to MEF Ops.
📁 COMMAND
├── # directives          # Active work orders. Current focus lives here.
├── # agent-log           # All agent activity. Automated reports.
├── # deployments         # Deployment events across all servers.
├── # priorities          # Weekly focus list.
└── # changelog           # Version history and release notes.
📁 SS & BANS SERVER
├── # sovereignstack       # sovereignstack.pro Next.js marketing site.
├── # kratombans           # kratombans.com legislative tracking.
├── # cbdbans              # CBD legislative tracking.
├── # delta8bans           # Delta-8 THC legislative tracking.
├── # mushroombans         # Psilocybin/mushroom legislative tracking.
├── # sentinel-newsroom    # Automated news pipeline.
├── # mef-compliance       # MEF compliance engine.
├── # scan643              # Automated website scanning.
├── # ship-my-stack        # shipmystack.com B2B deployment SaaS.
├── # openclaw             # OpenClaw platform.
├── # forgesales           # LIVE · forge.sovereignstack.pro · ForgeSales
├── # mse                  # LIVE · engine.merchantfirst.pro · Merchant Survival Engine
└── # signalforge          # LIVE · intel.sovereignstack.pro · Intelligence terminal
📁 PROD-OPS SERVER
├── # reup                 # thereup.pro multi-tenant payment orchestration.
├── # sovpay               # sovpay.me non-custodial Bitcoin PWA. ALL GATES CLOSED.
├── # pluginops            # pluginops.pro internal plugin processing.
├── # repairradar          # radar.pluginops.pro lead gen SaaS. 68 leads queued.
├── # evantage             # evantage.pluginops.pro
├── # pain-intel           # signal.pluginops.pro pain intelligence dashboard.
├── # n8n-brain            # brain.pluginops.pro n8n automation hub.
└── # visibility-machine   # LIVE · visibility.pluginops.pro · build-in-public command deck
📁 BTCPAY SERVER
├── # btcpay               # btcpay.sovereignstack.pro self-hosted BTCPay.
├── # payment-kernel       # payment-kernel self-hostable payment OS.
├── # sovereign-kernel     # Sovereign payment kernel.
└── # lightning            # Lightning Network operations.
📁 AGENCY SERVER
├── # webhook-bus          # Webhook bus. 71 entries live.
└── # api-gateway          # api.sovereignstack.pro central endpoint bus.
📁 AGENTS
├── # hermes-chat          # Hermes autonomous agent. Live operations.
└── # general              # Cross-project ops discussion.
📁 INTEL
├── # ban-alerts           # BanWatch bot. Real-time legislative alerts.
├── # processor-pulse      # ProcessorPulse bot. Payment processor monitoring.
├── # ss-status            # SSAlert bot. Infrastructure uptime.
└── # notifications        # General system notifications.
📁 REVENUE
├── # leads-incoming       # RepairRadar + Reddit keyword hits.
├── # outreach-queue       # Hermes outreach drafts awaiting SEND approval.
├── # outreach-sent        # Log of dispatched emails.
└── # replies-detected     # Warm reply detected. Hermes generates 1-3-1 response.
19

Webhook Bus — Fan-out Architecture

api.sovereignstack.pro · Agency server · 71 entries · Rebuilt 2026-06-15

External service (BTCPay / WooCommerce / GitHub / RepairRadar / etc.)
    │
    ▼ POST to Agency webhook bus
api.sovereignstack.pro/webhooks/[source]
    │
    ├── kind: "discord"  →  Discord webhook URL  →  Discord channel
    │
    └── kind: "mef-ops"  →  Bearer POST to operations.sovereignstack.pro
                              /api/inbound/[channelId]
                                    │
                                    ▼
                              INSERT into Supabase events table
                                    │
                                    ▼
                              Supabase Realtime pushes to dashboard

Fan-out Summary (71 entries total)

KindCountNotes
discord35All channels named. Consistent new-style schema.
mef-ops35All undefined-mef-ops placeholders resolved.
http1engine.merchantfirst.pro ban signal webhook. mushroombans added to sources.
New channels added 2026-06-15: mushroombans, forgesales, mse, signalforge, visibility-machine — all wired to Discord + MEF Ops fan-out.
mushroombans MEF Ops entries route to /api/inbound/notifications (no dedicated channel). Update when dedicated MEF Ops channel is created.
20

Agent Setup

Agent Division of Labor

AgentRolePrimary StrengthDoes NOT
Claude DesktopStrategist / ArchitectPlans, analyzes, briefs, produces /ops/ files, architecture decisionsTouch production, deploy, send outreach
Hermes DesktopRevenue OperatorRuns money loop, drafts outreach, monitors replies, daily reportInvent products, refactor code, start side quests
CursorImplementation EngineerWires missing endpoints, fixes bugs, implements CLI commandsRedesign business, create new products
CodexBulk Execution WorkerScans repos, builds large modules, long audits, generates testsHandle outreach, make business decisions

Hermes Configuration

SettingValueNotes
Location/opt/hermes/ · Prod-Opsapp + data + memory + workflows + repos dirs
Config/root/.hermes/config.yamlPrimary config. Env vars in /opt/hermes/.env override.
approvals.modeauto ✓Routine actions execute without prompts.
browser.allow_private_urlstrue ✓Hermes can reach internal services.
agent.max_turns150 ✓Increased for longer autonomous SDR sessions.
SOUL file (SDR)/opt/hermes/soul-sdr.mdDefines SDR behavior, email tone, approval gate logic. Create before activating outreach.
AgentMailNOT CONFIGUREDRequired for autonomous email dispatch. Tell Hermes in #hermes-chat to set up.
Discord channelsAll channels whitelistedfree_response_channels: all channels.
Bitwarden Secrets Manager still pending. Required before handing Hermes live email credentials. Separate project from personal vault — machine access token scoped to ops secrets only.
21

MEF Ops Dashboard — Primary Control Plane

operations.sovereignstack.pro · Prod-Ops · Next.js · Supabase Realtime · Hermes Gateway

MEF Ops is the declared primary operator interface. Discord is the notification mirror. All operator workflow routes through MEF Ops. Discord channel expansion frozen.

Auth

Traefik BasicAuth middleware. User: mefworks. Hash hardcoded in docker-compose.yml label with $$ escaping. Pattern: "traefik.http.middlewares.mef-auth.basicauth.users=mefworks:$$apr1$$..."

Persistence Layer (Supabase)

project_todos, project_notes, hermes_messages all Supabase-backed with Realtime. audit_runs and audit_findings populated by /audit command. project_money_metrics updated by audit — verdict, revenue_mtd, blockers, next_money_action.

22

Revenue Engine — SDR Pipeline

RepairRadar discovery + Reddit social listening + Hermes SDR + Sentinel Social

Revenue Targets — Priority Order

PriorityTargetBlockerOwnerCommand
1RepairRadar 68 eligible leadsSOUL file + AgentMail + webhook bus 4-URL (NOW DONE)Hermesmef outreach draft <leadId>
2SovPay B2B merchant onboardingNone — all gates closedHermes outreachmef pay merchant provision <handle>
3ShipMyStack outreachNo SDR targeting activeHermesmef outreach draft <leadId> --product shipmystack
4ForgeSales outreachNo inbound yetHermesStandard outreach flow
5MSE outreachNo SDR targetingHermesStandard outreach flow
6SovereignStack.pro checkout offersNo traffic yetSentinel Social + contentVisibility Machine post factory
7Bans network / Mit45 acquisitionWaiting on Mit45 responseClaude + humanFollow up on offer sent

SDR Pipeline Activation Checklist

ActionServerStatus
Create Hermes SOUL file (/opt/hermes/soul-sdr.md)Prod-OpsPENDING
Tell Hermes to set up AgentMail inbox#hermes-chatPENDING
Add 4 REVENUE webhook URLs to bus DESTINATIONS_JSONAgencyDONE — in 71-entry rebuild
Add /webhooks/repair-radar route to webhook busAgencyCURSOR TASK
Wire RepairRadar eligible-lead POST to busProd-OpsCURSOR TASK
Create Reddit bot account + app credentialsreddit.comPENDING
Fill Sentinel Social .env and start containerAgency16 secrets needed

Proven Revenue

SourceAmountOrdersMethod
MGMX Commerce (mgmalkz)$19,284108BTCPay checkout
StoutAlkz (ReUp P2P)$1,406,8428,498Zero processor — Zelle/CashApp/Chime/BTC
duckdose (ReUp P2P)$1,406,0426,498Zero processor
Stout Alks + stoutalkz.org (Apr–Jun 2026)~$371KAltPay P2P
stoutallz.org (NMI processor)activeNMI card checkout via Pledged Plugins
Shippo labels (12 months)$85,397 net5,911 labelsFedEx + USPS — corroborates P2P volume
23

AI Operations Pipeline

Designed 2026-06-15. Ready to implement. All /ops/ files produced.

Daily Operating Workflow

06:00  Hermes Desktop wakes up
       → mef money (revenue snapshot)
       → mef money leads --limit 10
       → mef money blockers
       → drafts top 3 outreach emails
       → posts to #outreach-queue

06:30  HUMAN reviews queue
       → approves or edits
       → replies SEND in MEF Ops

Async  Hermes watches #replies-detected
       → warm reply → drafts 1-3-1 response
       → posts to #outreach-queue for approval

17:00  Hermes generates DAILY_MONEY_REPORT.md

Rules of Engagement

#Rule
1No new build unless it unlocks a revenue action within 24 hours.
2No AI is allowed to create new product ideas unless explicitly asked.
3Every task must map to: lead / sale / follow-up / deployment / invoice / blocker removal.
4Every day starts with mef money.
5Every day ends with DAILY_MONEY_REPORT.md.
6If a system is not connected to money, it is ignored for 7 days.
7Human approves outbound sales messages until trust is established.
8Claude plans. Hermes operates. Cursor implements. Codex bulk-executes.

/ops/ Files Produced

FilePurpose
AI_OPERATIONS_BLUEPRINT.mdMaster execution document — 15 sections
ACTIVE_ROLES.mdOne-page role reference
TODAY_EXECUTION_QUEUE.mdDaily task queue
DAILY_MONEY_REPORT_TEMPLATE.mdHermes fills nightly
HERMES_REVENUE_SOUL.mdDeploy to /opt/hermes/soul-sdr.md
CURSOR_EXECUTION_RULES.mdCursor constraints and priority queue
CODEX_EXECUTION_RULES.mdCodex task format
CLAUDE_STRATEGY_RULES.mdWhen and how to use Claude
NO_NEW_PROJECTS.mdScope freeze for 30 days
24

MEF CLI — mef

Designed 2026-06-15. TypeScript. Routes into existing services. Ready to implement.

The mef CLI is a personal operating system for running the entire MEF ecosystem from one command surface. It routes into existing services — never reimplements them. Config lives at ~/.mef/config.yaml.

Command Hierarchy

Primary commands
mef money                          # Revenue snapshot — runs daily
mef money leads --limit 10         # Top eligible leads
mef money blockers                 # What's blocking revenue
mef money opportunities            # Products ready to sell
mef money followups                # Threads needing next action

mef pay invoice create --amount 250 --currency USD
mef pay merchant provision <handle>
mef pay merchant status <handle>
mef pay health

mef comply scan <url>
mef comply wp audit <url>
mef comply bans status kratom

mef intel leads list --status eligible
mef intel processor status
mef intel collect

mef outreach draft <leadId>
mef outreach queue
mef outreach send <outreachId>
mef outreach replies

mef monitor status
mef monitor logs <project> --tail 50
mef monitor ssl <domain>

mef webhook health
mef webhook watch --channel leads-incoming
mef webhook replay <eventId>

mef agent status
mef agent run hermes <task>
mef agent soul show
mef agent soul edit

mef deploy project <name>
mef deploy sovereignstack

mef server health --server all
mef server ps --server prod-ops
mef server ports --server prod-ops

mef audit <project>
mef project list
mef project blockers

Architecture

AdapterUsed ForTarget
SSH AdapterServer ops, deploy, logs, port checksHetzner servers via node-ssh
HTTP AdapterBTCPay Greenfield, SovPay provisioning, webhook busAPI endpoints with auth headers
Supabase Adapterproject_states, leads, outreach, money_metricsIPv4 pooler + SSL CA + SNI (known quirk)
Shell AdapterLocal commandschild_process

Phase Documents Produced

FileContent
INVENTORY_REPORT.mdAll projects classified: ACTIVE / REVENUE READY / NEAR REVENUE / INTERNAL / ARCHIVE / DEAD
CAPABILITY_MAP.md14 capability domains organized by function, not project
CLI_SPEC.mdFull command hierarchy, global flags, config file structure
MONEY_COMMANDS.mdmef money subcommands — reads from Supabase project_money_metrics
ROUTING_ARCHITECTURE.mdPlugin-based module system, YAML routing table, auto-discovery
CONSOLIDATION_REPORT.md21 KEEP, 3 MERGE, 2 REPLACE, 4 DELETE, 7 ACTIVATE, 7 DEFER
25

Project Registry — New in v10.0

ProjectURLServerStackStatus
SignalForgeintel.sovereignstack.proSS&BansReact + FastAPI + Postgres + RedisLIVE · internal only · 1,383 events
ForgeSalesforge.sovereignstack.proSS&BansReact+Vite+Express+Claude API+Supabase+ResendLIVE · Phase A+B complete · full outreach cycle · BasicAuth gated
MSEengine.merchantfirst.proSS&BansNext.js 14 + Express + Postgres + Redis + PlaywrightLIVE · 6 days uptime
Visibility Machinevisibility.pluginops.proProd-OpsNode.js + Gemini AILIVE · seeded · 7 posts scheduled
ReUp Minireupmini.comVercelNext.js 15 + api.reupmini.comLIVE · production-safe frontend deployed
MEF Story Engine(local)Local dev (H:\)Cursor project · 15,944 imagesACTIVE LOCAL · proof documentation

Visibility Machine Capabilities

Build Log · Proof Vault · Clip Builder · Post Factory (Gemini — 7 platforms) · Angle Finder · Dispatch Calendar · Launch Pad · Money Board · Growth Tracker · Reuse Library

Active: ReUp Proof Series — P2P at $1.4M campaign (50% complete). 7 posts scheduled June 16–25. Auth: Traefik BasicAuth, mefworks. Repo: MEF-works/visibility-machine. Deploy key: C:\Users\MeF\.ssh\mgmalkz.pem

ReUp Mini

Passwordless merchant onboarding. Direct shop link + embed code. In-page checkout modal. Cash App / Venmo / Zelle / PayPal / BTC / ETH. Zero custody. Starter free / Pro $29/mo (coming soon).

Repo: MEF-works/reup-mini-new · Commit: dfac727 · Env: NEXT_PUBLIC_MOCK_MODE=false on Vercel

26

WordPress Sites — Hostinger

DomainPurposeStatus
mefworks.comPrimary brand / dev/engineer public site + client PWAlive
sovereignstack.proSovereignStack marketing + checkout (Next.js on Hetzner — not Hostinger WP)live · bare metal
stoutalkz.comClient commerce — $1.4M ReUp P2P volumelive
thereup.proMulti-merchant/customer Expo full commerce dual-sided applive
reuppro.comModern Next.js multi-merchant platformlive
reupmini.comReUp Mini — live P2P mini shop platformlive · Vercel
getsovpay.comSovPay marketing landing pagelive
kratombans.comKratom legislative tracking (also on Hetzner)live
kratombans.blogKratomBans blog contentlive
mgmalkz.comMGMX Commerce — $19,284 revenuelive
merchantfirst.proMSE marketing domainlive
shipmystack.comShipMyStack B2B deployment SaaSlive · Stripe active
scan643.proScan643 compliance scanninglive
elitegaragedoorohio.comPersonal — garage door business if reactivatedlive
eliteplugs.comProductslive
engineeredresults.proAgency/serviceslive
flowstateops.proOps brandlive
freewayrails.proFreeway Rails payment productlive
getreup.proReUp marketinglive
groundedobservations.comContent/bloglive
highriskpayments.newsHigh-risk payments content/intellive
highriskthis.comBrandlive
levyai.techLevy agent brandlive
licenses.mefworks.comLicense managementlive
mef.moneyInternal filing cabinet / WooCommerce test env / WooDock / MEF~DOCSinternal only
mefdup.comDev/engineer public facing + client progress PWA (built, not active)built · inactive
payme.mobiSovPay P2P adjacentlive
reparchitect.youaskedchatgptwhat.comContentlive
reupbot.storeReUp storelive
samnmef.comPersonal/brandlive
scan643.comScan643 marketinglive
sovereignrails.proPayment kernel brand (domain only)planned
stoutalkzz.comClient commerce variantlive
sweepersedge.comAffiliate social casino — 53+ pages unique content, first commercial buildlive
up247time.proUptime monitoring productlive
youaskedchatgptwhat.comContentlive
cortexhq.techCortexHQ brandEXPIRED
ss7score.comSS7 productEXPIRED
27

Domain Inventory — 73 Total (Hostinger)

!
ReUp cluster renewal URGENT — July/August 2026: thereup.pro, thereup.store, thereup.site, thereup.cloud, reupbot.com, reupbot.store, reuppro.com, reupmini.com, getreup.pro, stayup.pro. Set calendar reminders now.
Expired domains: cortexhq.tech (in use as brand), cortexhq.shop, ss7score.com. Check grace period and renew or let go.

ReUp Cluster (RENEW Jul–Aug 2026)

thereup.pro · thereup.store · thereup.site · thereup.cloud · reupbot.com · reupbot.store · reuppro.com · reupmini.com · getreup.pro · stayup.pro

SovPay Cluster

sovpay.me · sovpay.pro · getsovpay.com · payme.mobi

Bans Network

kratombans.com · kratombans.blog · kratombans.site · cbdbans.com · delta8bans.com · mushroombans.com · psilocybinbans.com · mef-bans.network · mefbans.com

SovereignStack / Infrastructure

sovereignstack.pro · sovereignrails.pro · freewayrails.pro · altpayrails.com · dataapi.pro · shipmystack.com · pluginops.pro · repairradar.pro · engineeredresults.pro · up247time.pro

Scan / Compliance

scan643.com · scan643.pro · prepscan.pro · readystate.pro · highriskpayments.pro · highriskpayments.news · highriskpayments.online · highriskpayments.cc · highriskthis.com

CortexHQ

cortexhq.pro · cortexhq.tech (EXPIRED) · cortexhq.blog · cortexhq.shop (EXPIRED)

MEF Brand

mefworks.com · mefdup.com · menterprisefirminc.com · licenses.mefworks.com · mef.money · mef-bans.network · mefbans.com

Agent / AI Brands

levyai.tech · neuragoal.pro · realitygrid.pro · ournorthstar.space

Commerce / Clients

stoutalkz.com · stoutalkzz.com · mgmalkz.com · mgmx.pro · mgmtracker.pro · eliteplugs.com · elitegaragedoorohio.com · sweepersedge.com

Products / Tools / Misc

merchantfirst.pro · merchantscout.pro · forgesales.pro · flowstateops.pro · groundedobservations.com · youaskedchatgptwhat.com · reparchitect.youaskedchatgptwhat.com · githubxray.pro · accountableinteractions.com · safemoney.pro · safeguarded.pro · papermaker.pro · householdheros.pro · samnmef.com · ss7score.com (EXPIRED) · altpayrails.com · reupmini.com · ournorthstar.space · mgmx.pro

28

Next Actions

Tonight (Critical Path)

PriorityActionServerOwner
1Build signal-filter.py — keyword filter on SignalForge output → intel_signals → intel_eventsSS&BansCursor
2Build merchant-event-matcher.py — links intel_events to merchant_profilesSS&BansCursor
3Tune RepairRadar scan targeting — real high-risk merchant domains not test/docs sitesProd-OpsCursor + RepairRadar UI
4Schedule repairradar_sync.py cron on Prod-Ops (after targeting tuned)Prod-OpsHuman
5Deploy Hermes SOUL file → /opt/hermes/soul-sdr.mdProd-OpsHuman + SSH
6Tell Hermes in #hermes-chat to set up AgentMail inbox#hermes-chatHuman
7Clean up test merchant rows (test-merchant*.com) from SupabaseSupabaseHuman

Cursor Task Queue (Ordered)

PriorityTaskServer
1signal-filter.py — SignalForge → intel_signals → intel_events (keyword rules defined in ops session)SS&Bans
2merchant-event-matcher.py — daily job matching new intel_events to merchant_profilesSS&Bans
3RepairRadar targeting tuning — focus scan criteria on kratom/CBD/delta8/mushroom/firearms/adult verticalsProd-Ops
4ForgeSales Phase C — daily run endpoint + n8n cron at 05:00SS&Bans
5Wire RepairRadar eligible-lead POST → api.sovereignstack.pro/webhooks/repair-radar (webhook bus)Prod-Ops
6Add Bearer token auth to hermes-http-gateway.js on Prod-OpsProd-Ops
7Fix sovereign-stack Next.js bound on *:3000 → 127.0.0.1:3000SS&Bans
8Create sovpay_internal Docker network — isolate sovpay-postgresProd-Ops
9Remove dead nginx vhosts td.sovereignstack.pro + tdalt.sovereignstack.proSS&Bans

Completed This Session (2026-06-17)

ItemStatus
ForgeSales Phase A — Gemini removed, Claude integrated, auth, persistence, outreach cycle✓ DONE
ForgeSales Phase B — Market Scout, Sales Doctrine, Script Forge, CRM Tracker wired to Supabase✓ DONE
Supabase schema v1 — 39 tables, all RLS enabled, all policies correct✓ DONE
MEF CLI Phases 0–4 — config, project, monitor, money, webhook, pay, comply, server, deploy✓ DONE
Full outreach loop confirmed — propose → approve → Resend send → email received✓ DONE
Inbound webhook with Claude classifier + Svix signature verification✓ DONE
Merchant memory writing on every action (scan, outreach, reply, strategy)✓ DONE
RepairRadar sync script built and deployed to Prod-Ops✓ DONE
BasicAuth password gates on ForgeSales + MEF Ops + Visibility Machine✓ DONE
SS&Bans kernel upgrade + reboot — all 54 containers and PM2 processes came back clean✓ DONE
Architecture philosophy locked — Supabase is Shared Truth, decision engine not intel landfill✓ LOCKED

Infrastructure Planned

ActionNotes
Set up Bitwarden Secrets ManagerBefore handing Hermes live email credentials. Machine access token, separate from personal vault.
Add SSL to WordPressSS&Bans: certbot --nginx -d [wordpress domain]
BTCPay disk alert at 75%Bitcoin node growing ~5-10GB/month on 492GB volume.
Node.js 18 → 20 upgradeSS&Bans bare metal + Prod-Ops. Required by @supabase/supabase-js.
Prod-Ops kernel rebootKernel update pending on Prod-Ops — same as SS&Bans. pm2 save first then reboot.
ReUp domain renewalsURGENT — July/August 2026. Set reminders now.
Rotate SIDECAR_CONFIG_KEYWas exposed in session. openssl rand -hex 32. Update all .env files and sovereignstack-sidecar systemd service.
29

ForgeSales — Merchant Intelligence Platform

forge.sovereignstack.pro · SS&Bans · Phase A + B complete 2026-06-17

Phase A + Phase B complete. Full outreach cycle live: scout → compose → approve → send → receive → classify → store. Gemini removed. Claude API (claude-sonnet-4-6) integrated. Resend email sending live. Inbound webhook with Claude classifier live. Merchant memory writing on every action. BasicAuth password gate via Traefik.

Architecture

ForgeSales is the Human+AI workspace. It does NOT own merchant data — Supabase owns all intelligence. ForgeSales surfaces merchant history, risks, opportunities, outreach, and memory. Every action writes back to Supabase.

Dual DB Pattern

ClientUsed ForAuth
pg pool via DATABASE_URLCore ForgeSales tables: leads, email_templates, campaigns, campaign_runs, collaboration_actions, internal_comms, handoff_requestsPostgres password
@supabase/supabase-js via server/services/supabase.jsMerchant schema: merchant_profiles, merchant_scans, merchant_findings, merchant_outreach, merchant_memory_events, merchant_event_matches, intel_events, contacts, organizations, scan_decisionsSUPABASE_SERVICE_ROLE_KEY

Phase A — Completed 2026-06-17

TaskStatusNotes
Strip Gemini, install Claude SDKdoneclaude-sonnet-4-6 · callClaude() + callClaudeJSON() in server/services/claude.js
API key auth on /api/collab + /api/agentdoneFORGESALES_API_KEY header · VITE_FORGESALES_API_KEY baked into frontend build
Persist data to PostgresdoneTemplates, campaigns, notes, handoffs, proposals survive container restart
CollabNotifications wired into App.tsxdonePending proposals + flagged notes visible in UI header
POST /api/agent/outreach/proposedoneWrites to collaboration_actions + outreach_queue + merchant_outreach
Approval auto-triggers Resend senddonePOST /api/collab/action/respond {approved:true} → Resend fires → memory event written
Inbound email webhook rebuilt (Claude classifier)doneSvix signature verification · Claude classifies reply intent · updates merchant stage + memory
Extend /api/ingest to write merchant schemadoneUpserts merchant_profiles + merchant_scans + contacts + merchant_memory_events
Email templates updateddoneInforming not selling tone · Early Access footer · sovereignstack.pro signature
Webhook bus fan-outdoneFires on propose, send, reply, ingest → MEF Ops channels
Rotate credentialsdoneNew INGEST_API_KEY + FORGESALES_API_KEY · .env gitignored
Traefik BasicAuth password gatedonemefworks / same password as MEF Ops + Visibility Machine

Phase B — Completed 2026-06-17

ScreenWasNow
Market Scout / Find LeadsEmpty Gemini-powered prospect searchLive merchant browser from merchant_profiles. Cards show domain, vertical, geo, stage, score, findings count, intel matches, outreach count. Detail drawer: 6 tabs (Overview, Scans, Findings, Intel, Outreach, Memory). Quick Scan + Full Scan buttons trigger engine.prepscan.pro.
Sales Doctrine / Strategy PlaybookGeneric sales playbook generator (Gemini)Per-merchant strategy engine. Select merchant → Claude reads full context from Supabase (scans, findings, intel matches, memory) → generates approach, lead_with, supporting_points, intel_hooks, avoid, confidence, urgency. Output feeds Script Forge.
Script Forge / Message LabFree-form message generator (Gemini)Receives pre-populated context from Sales Doctrine. Claude generates email with ai_claims[] (every claim has evidence + source + confidence). Queue for Approval → proposal enters outreach cycle.
CRM Tracker / Merchant CRMStatic pipeline tableMerchant list on left, color-coded memory timeline on right. Every scan, email, reply, intel match, mitigation displayed chronologically from merchant_memory_events.

New Backend Endpoints (Phase B)

EndpointPurpose
GET /api/merchantsList merchant_profiles with filters (stage, vertical, geo, search) + scan/finding/intel counts
GET /api/merchants/:idFull merchant profile — scans, findings, outreach, intel matches, memory, contacts
GET /api/merchants/:id/memoryPaginated merchant memory timeline
POST /api/merchants/:id/scanTrigger PrepScan at engine.prepscan.pro — writes memory event on trigger
POST /api/merchants/:id/strategyClaude strategy brief from full merchant context — writes opportunity_surfaced memory event
POST /api/agent/outreach/composeClaude email draft with ai_claims[], Early Access footer, sovereignstack.pro signature
POST /api/scan-decisionsRecord scan decision (outreach/monitor/skip/disqualify) with outcome tracking
GET /api/scan-decisionsList scan decisions with filters
Known: NODE_TLS_REJECT_UNAUTHORIZED=0 set in container — workaround for Supabase SSL cert on Node 20. prod-ca-2021.crt is bundled in image. Should be replaced with proper SSL_CERT_FILE env pointing to the cert. Non-urgent.
30

Merchant Schema — Supabase v1

Deployed 2026-06-17 · 39 tables total · All RLS enabled · All service_role protected

mef_schema_v1.sql ran successfully. All 39 tables have RLS enabled and service_role_all policy. Anon read-only policies on MEF Ops display tables (project_states, events, hermes_messages, project_todos, project_notes, audit tables, project_money_metrics). All bad anon full-access policies removed.

Core Philosophy

Supabase is Shared Truth. Every system writes facts to Supabase. Every AI reads from Supabase. No AI owns truth. No frontend owns truth. Facts are permanent. Reasoning is temporary. Only store information that changes: merchant risk, merchant opportunity, outreach, operations, revenue, or mitigation. Discard everything else.

New Tables Added 2026-06-17

TablePurposeKey Columns
organizationsHolding companies, agency clientsname, type, industry[]
merchant_profilesOne row per store. Domain unique but NOT permanent ID. References organizations.domain, vertical[], geo_states[], stage, last_scan_at, last_outreach_at, last_reply_at, source, forgesales_id
contactsHumans at a merchant. Separated from domain.merchant_id, organization_id, email, name, role, verified
merchant_scansEvery scan from every scanner. Evidence lives here permanently.merchant_id, scanner, score, risk_level, violation_count, findings jsonb, report_snapshot jsonb, evidence jsonb, sources jsonb
merchant_findingsIndividual actionable findings. Resolved or unresolved.merchant_id, scan_id, finding_type, severity, title, evidence jsonb, confidence, resolved_at
intel_eventsONE row per real-world event. Never duplicated. Source of truth for all regulatory/market intel.title, category, severity, affected_verticals[], affected_states[], evidence jsonb, decision_impact, confidence, is_active
merchant_event_matchesLinks merchants to intel events. One event → N matches. UNIQUE(merchant_id, event_id).merchant_id, event_id, match_reason, priority, status
merchant_outreachEvery outreach attempt permanently. Full draft + send + reply history.merchant_id, contact_id, subject, body, status, ai_claims jsonb, intel_event_ids[], scan_ids[], sent_at, replied_at
merchant_memory_eventsCrown jewel. Append-only history of everything. Never update, only insert.merchant_id, event_type, title, summary, evidence jsonb, sources jsonb, outcome, related_id, recorded_by
intel_signalsSignalForge filtered output. Only decision-relevant events.source, category, title, score, relevance_tags[], product_verticals[], geo_scope, raw_payload jsonb, promoted_to_event
scan_decisionsTrack every scan decision with outcome. History dataset.merchant_id, scan_id, domain, decision, reason, decided_by, outcome, decided_at

merchant_memory_events — Event Types

scan_completed · outreach_sent · reply_received · finding_detected · finding_resolved · intel_matched · processor_issue · mitigation_applied · client_onboarded · subscription_started · subscription_ended · opportunity_surfaced · outcome_recorded · discord_joined · discord_question

RLS Policy Summary

Policy PatternTablesAccess
service_role_all onlyAll merchant/intelligence tables, ForgeSales collab tables, leads, outreach_queue, session_archiveBackend only via service role key. No anonymous access.
service_role_all + anon_readproject_states, project_state_history, events, hermes_messages, project_todos, project_notes, audit_findings, audit_runs, project_money_metricsMEF Ops frontend reads via anon key. Backend writes via service role.
31

Outreach Cycle — Full Loop Live

Scout → Compose → Approve → Send → Receive → Classify → Store

End-to-end outreach loop confirmed working 2026-06-17. Proposal created, approved, email sent via Resend, email received. Inbound webhook with Claude classifier and Svix signature verification deployed.

Full Cycle Flow

RepairRadar / PrepScan / Manual scan
  ↓
POST /api/ingest (x-api-key: INGEST_API_KEY)
  → upserts leads table (pg)
  → upserts merchant_profiles (Supabase)
  → inserts merchant_scans (Supabase)
  → upserts contacts (Supabase)
  → inserts merchant_memory_events: scan_completed
  → fan-out to #leads-incoming via webhook bus
  ↓
Market Scout — merchant card appears with score + findings
  ↓
Sales Doctrine — select merchant → Generate Strategy
  → Claude reads: scans + findings + intel_matches + memory
  → Returns: approach, lead_with, supporting_points, intel_hooks, avoid
  → Writes merchant_memory_events: opportunity_surfaced
  ↓
Script Forge — Forge Payload (pre-populated context)
  → POST /api/agent/outreach/compose
  → Claude generates email with ai_claims[] (every claim cited)
  → Early Access footer + sovereignstack.pro signature
  ↓
Queue for Approval → POST /api/agent/outreach/propose
  → collaboration_actions (status: pending_approval)
  → outreach_queue (status: pending)
  → merchant_outreach (status: draft, ai_claims jsonb)
  → fan-out to MEF Ops #outreach-queue + CollabNotifications
  ↓
HUMAN REVIEWS — approves in ForgeSales UI or MEF Ops
  ↓
POST /api/collab/action/respond {approved: true}
  → Resend sends email from outreach@sovereignstack.pro
  → collaboration_actions → executed
  → outreach_queue → sent
  → merchant_outreach → sent
  → leads → contacted
  → merchant_profiles stage → contacted, last_outreach_at updated
  → merchant_memory_events: outreach_sent
  → fan-out to #outreach-sent
  ↓
Reply arrives → Resend inbound → POST /api/webhooks/inbound-email
  → Svix signature verified (RESEND_WEBHOOK_SIGNING_SECRET)
  → Lookup lead/contact by from email
  → Claude classifies: intent, sentiment, summary, urgency, key_points
  → merchant_outreach: replied_at + reply_summary
  → leads: status → replied
  → merchant_profiles: stage → replied, last_reply_at updated
  → merchant_memory_events: reply_received
  → internal_comms: flagged note (visible in Leads·Outreach·CRM)
  → fan-out to #replies-detected

AI Zero-Trust Rules

Every email draft includes internal ai_claims jsonb — never shown to merchant, stored permanently in merchant_outreach. Each claim must include:

FieldRequiredNotes
claimExact claim made in email
evidenceSource of this claim — scan result, finding ID, intel event
sourceWhich scanner/event this came from and when
confidence0-100. If AI cannot explain itself, it does not make the claim.
verifiabletrue/false — can the merchant verify this independently

Early Access Email Footer (locked — use verbatim)

All outreach emails must include this footer
You are receiving these findings as part of our Early Access
Merchant Survival Engine program.

For a limited time, we are sharing intelligence reports,
compliance findings, and industry alerts with a small group
of merchants at no cost.

The purpose of this program is simple: to prove the value
of the intelligence before asking anyone to pay for it.

Over the coming weeks, we will continue sharing relevant
findings that may affect your business. If these reports
prove valuable to you, there will be an option to continue
receiving them as part of the Merchant Survival Network
after the pilot period ends.

No obligation. No pressure. Just useful information designed
to help merchants stay ahead of changing risks and opportunities.

Email Configuration

SettingValue
ProviderResend
From addressoutreach@sovereignstack.pro
Inbound webhookPOST /api/webhooks/inbound-email on forge.sovereignstack.pro
Signature verificationSvix · RESEND_WEBHOOK_SIGNING_SECRET in .env
MX recordAlready configured in Hostinger DNS for sovereignstack.pro
32

Intelligence Pipeline — Architecture Locked

Scripts filter → Supabase stores → AI reasons → ForgeSales surfaces

Data Flow

Reality
  ↓
PrepScan · Scan643 · RepairRadar · SignalForge
  ↓
Filter Engine (scripts — fast, cheap, deterministic — NOT AI)
  ↓
Supabase (Shared Truth)
  intel_signals → intel_events → merchant_event_matches
  merchant_profiles → merchant_scans → merchant_findings
  merchant_outreach → merchant_memory_events
  ↓
ForgeSales · Discord Bots · Hermes · Visibility Machine
  ↓
Human Decisions
  ↓
Outcomes → stored back into Supabase (merchant_memory_events)

Intelligence Systems Status

SystemRoleOutput TableStatus
PrepScanPlaywright scanner · 200+ rulesets · compliance findingsmerchant_scans via /api/ingestlive · engine.prepscan.pro
Scan643Checkout/payment script intel · processor dependencies · third-party scriptsmerchant_scans via /api/ingestlive · scan643.pro
RepairRadarDeep domain scans · AI reasoning · outreach eligibility scoringleads + merchant_profiles via repairradar_sync.pylive · targeting needs tuning
SignalForgeRegulatory/tech/commerce/cybersecurity intel collection · 9,018 collected · 2,439 promotedintel_signals (filter script pending)live · signal-filter.py NOT YET BUILT

RepairRadar Sync Script

ItemDetail
Location/root/scripts/repairradar_sync.py on Prod-Ops
Source DBSQLite at /root/workspace/repairradar/prisma/dev.db
TargetPOST to ForgeSales /api/ingest → merchant_profiles + merchant_scans + leads
RunINGEST_API_KEY=xxx python3 /root/scripts/repairradar_sync.py
Dry runAdd --dry-run flag — shows what would be synced without POSTing
Cron0 4 * * * — not yet scheduled (pending RepairRadar targeting tuning)
StatusBuilt and tested · 4 eligible leads found (3 real merchants + 1 noise) · targeting needs tuning before cron

Pending Intelligence Scripts

ScriptPurposeServerStatus
signal-filter.pyReads SignalForge API · keyword/score filter · writes decision-relevant events to intel_signals · promotes to intel_eventsSS&BansNOT BUILT
merchant-event-matcher.pyFor each new intel_event · queries merchant_profiles by vertical[] + geo_states[] · creates merchant_event_matches rows · deduplicates via UNIQUE constraintSS&Bans or Prod-OpsNOT BUILT

MSE Subscription Model (planned)

TierWhat's Included
Free / Early AccessWeekly intel email personalized to their domain + vertical. No Discord. No obligation. Pilot period.
Merchant Survival Network ($X/mo)Everything above + MSE Discord access + monthly compliance rescan + processor alert monitoring via ProcessorPulse + direct human response path + historical report access (full merchant memory)
Discord bots must cite sources on every answer — zero-trust principle applies to Discord too. "Here's the answer, here's the source, here's when it was last updated." No confident wrong answers.