# ParentProof Current Clickable Mockups

Package date: August 23, 2026

This package contains the current ParentProof storefront, parent dashboards, mobile parent-app surfaces, download pages, installers, truthful Windows/macOS secured-desktop experiences, and the Android Device Owner child home. The files are standalone clickable HTML demonstrations. They do not connect to a production backend, process real payments, install software, or transmit family information.

## Quick start

1. Open `ParentProof-Ordered-Demo-Flow.html` for the guided presentation with every surface in sequence.
2. Choose **All surfaces**, **Android tablet**, **Windows desktop**, **Mac desktop**, or **Parent apps and web account** from the presentation header.
3. Use the Back/Next controls or numbered step rail while keeping each embedded mockup fully clickable.
4. Open `parentproof-storefront.html` to start an unframed purchase/signup demo, or `parentproof-complete-clickable-demo.html` to start directly in the web dashboard.
5. Keep all HTML files and the `assets` folder together so the ordered presentation, internal links and installer illustrations continue to work.

### Demo credentials

- Parent email: `sam@family.ca`
- Parent password: `parentproof`
- Dashboard two-step verification code: `482731`
- Storefront email-verification code: `173942`
- No payment information is collected. Stripe Checkout is simulated.

## Included mockups

| File | Surface | What it demonstrates |
|---|---|---|
| `ParentProof-Ordered-Demo-Flow.html` | Guided presentation runner | Loads all current mockups in a deliberate sequence with presenter guidance, progress, credentials, Back/Next navigation and focused Android, Windows, Mac and parent-app paths. |
| `parentproof-storefront.html` | Public website | Three subscription tiers, web-only signup, email verification, simulated Stripe Checkout, and handoff to downloads or the web dashboard. |
| `parentproof-complete-clickable-demo.html` | Web parent dashboard | Complete family controls, profiles, devices, apps, web rules, time, processes, requests, check-ins, quizzes, activity, accounts, billing, privacy, notifications, installers, Light/Dark mode, and a focused 15-step hands-on training system that verifies real dashboard state changes. |
| `parentproof-dashboard-windows.html` | Windows parent dashboard | Windows-branded parent dashboard with login, Light/Dark mode, and the same verified live-control training used by the installer handoff. |
| `parentproof-dashboard-macos.html` | Mac parent dashboard | macOS-branded parent dashboard with login, Light/Dark mode, and the same verified live-control training used by the installer handoff. |
| `parentproof-dashboard-android.html` | Android parent app | Responsive parent-only Android controller with mobile navigation and Light/Dark mode. It has no signup, billing tab, credit purchase, invoice or payment-management UI. |
| `parentproof-dashboard-iphone.html` | iPhone and iPad parent app | Responsive parent-only iOS/iPadOS controller with mobile navigation and Light/Dark mode. It has no signup or billing-management UI. |
| `parentproof-device-downloads.html` | Download selection | Separate choices for securing a tablet or desktop, Windows/Mac installer links, and iOS/Android parent-app links. |
| `ParentProof-Installer-Windows-Updated.html` | Windows installer | Windows-hosted setup for an Android tablet or Windows desktop, parent consent, sign-in, sequential tablet-preparation cards, detailed help, connection repair, installation, dashboard tour, and completion. |
| `parentproof-installer-windows.html` | Windows installer alias | Same current Windows installer under the filename used by existing dashboard/download links. |
| `ParentProof-Installer-macOS-Updated.html` | Mac installer | Mac-hosted setup for an Android tablet or Mac desktop, macOS permissions, tablet preparation, connection checks, installation, dashboard tour, and completion. |
| `parentproof-installer-macos.html` | Mac installer alias | Same current Mac installer under the filename used by existing dashboard/download links. |
| `parentproof-installer-android-tablet.html` | Android tablet setup entry | Android Device Owner / MDM-only installation handoff; no Accessibility, overlay or ordinary-app enforcement alternative. |
| `parentproof-installer-ios.html` | iPhone/iPad download | Parent-only iOS and iPadOS app-download surface. |
| `parentproof-kid-desktop-lockdown.html` | Secured desktop selector | Switch between Windows/macOS and normal/captive modes, inspect the exact shipping boundary, use parent login + 2FA, and choose preset/custom child-home backgrounds. |
| `parentproof-secured-desktop-windows.html` | Windows child desktop | Windows-first version: normal desktop + AppLocker enforcement or optional Assigned Access captive home. |
| `parentproof-secured-desktop-macos.html` | macOS child desktop | Mac-first version: normal desktop + after-launch enforcement or optional guided full-screen home that is not represented as a true OS kiosk. |
| `parentproof-kid-android-home.html` | Android child tablet | Fun managed child home with apps, requests, quiz, check-in, pause state, parent login + 2FA, preset themes and custom background upload. Device Owner / MDM status is always explicit. |
| `assets/parentproof-tablet-prep.png` | Installer artwork | Eight-panel Android tablet preparation illustration used by the installer experience. |

## Main clickable flow

`Storefront → Web signup → Simulated Stripe Checkout → Device downloads → Installer → Parent dashboard tour → Protected child experience`

The installer signs the parent into the dashboard through a simulated authenticated handoff. Its training is not a slideshow: it spotlights the next live control, waits for the parent to perform the actual dashboard action, verifies the resulting state, and only then enables Next. Redo restores the lesson state and requires the real action again. Opening a dashboard normally still presents the complete parent login and two-step verification flow.

## Secured desktop: truthful Windows versus Mac boundary

Difficulty is an engineering estimate for a production-quality implementation:

- **1/5:** straightforward interface or application work
- **2/5:** normal native integration
- **3/5:** several background components or administrator setup
- **4/5:** privileged integration, permissions, and significant edge cases
- **5/5:** conditional on entitlements, device management, OS edition, or strong tamper hardening

| ParentProof capability | Windows | macOS | What the demo now represents |
|---|---:|---:|---|
| Start after the normal OS login | Full · 2/5 | Full · 3/5 | Keep Windows Hello/PIN and macOS password/Touch ID. Install a signed Windows service or notarized LaunchDaemon + LaunchAgent. |
| Normal desktop with rules in the background | Full · 2/5 | Full · 3/5 | Recommended default. Web, app, time, request, screen and monitoring rules remain active without replacing the desktop. |
| Installed/running process inventory | Full · 2/5 | Full · 3/5 | Ordinary process enumeration plus signature/hash/publisher classification. No protected-system-process controls. |
| Prevent a blocked application before launch | Full · 3/5 | **Not shipped** | Current Windows 10/11 can enforce AppLocker policies. A comparable Mac authorization path needs Apple’s restricted Endpoint Security entitlement, so the mockup does not claim it. |
| Detect and close a blocked application after launch | Full · 2/5 | Full · 3/5 | Windows can also close after detection. macOS uses the observable application list and ordinary terminate/force-terminate behavior, with documented system-app limitations. |
| App timeout, schedule and daily limits | Full · 2/5 | Full · 2/5 | A local service/daemon caches rules and schedules so protection continues offline. |
| Domain and subdomain rules | Full · 3/5 | Full · 3/5 | Use a local DNS policy service; no custom Windows filtering driver and no Apple Network Extension entitlement are assumed. |
| Exact URL and URL-fragment rules | Supported browsers · 3/5 | Supported browsers · 3/5 | Browser extensions enforce full URLs. The product does not pretend encrypted full-URL rules are system-wide outside supported browsers. |
| Redirect blocked web access to a request page | Supported browsers · 3/5 | Supported browsers · 3/5 | The extension redirects into ParentProof’s local request page, which auto-sends and always includes “Go back to home.” |
| Parent-requested screenshot / live viewer | Normal desktop · 3/5 | Permissioned · 4/5 | Windows Desktop Duplication covers the ordinary desktop; macOS requires Screen Recording. Protected/secure/DRM surfaces are excluded. |
| Remote mouse and keyboard help | Best effort · 4/5 | Permissioned · 4/5 | Windows input cannot cross integrity/secure-desktop boundaries. macOS requires Accessibility and Remote Management approval. |
| Emergency close, block and pause | Full · 3/5 | Full · 4/5 | Combines app close, web rule, cached pause policy, audit event and the child-safe message. It does not claim control over protected system components. |
| Optional captive/custom child home | Assigned Access · 3/5 | Guided launcher · 2/5 | Windows uses Assigned Access on supported Pro+ editions. Mac uses a full-screen auto-relaunching launcher and clearly says it is not an unbreakable OS kiosk. |
| Replace the OS sign-in or general desktop shell | **Not shipped** | **Not shipped** | No Windows login takeover, Enterprise-only Shell Launcher dependency, Mac login replacement or general shell replacement. |
| Prevent a standard child account from removing protection | Strong · 3/5 | Strong · 4/5 | Parent-authorized privileged components and protected configuration. A local administrator/root user is outside the tamper-proof claim. |
| Custom child-home theme/background | Full · 1/5 | Full · 1/5 | Presets and parent-selected local images apply to the optional captive/guided home; normal OS wallpaper remains OS-managed. |
| Check-ins and bonus-time quizzes | Full · 1–2/5 | Full · 1–2/5 | Product-level feature supported equally on both. |

### Platform references

- [Microsoft: AppLocker requirements](https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/applocker/requirements-to-use-applocker)
- [Microsoft: Assigned Access](https://learn.microsoft.com/en-us/windows/configuration/assigned-access/)
- [Microsoft: Desktop Duplication API](https://learn.microsoft.com/en-us/windows-hardware/drivers/display/desktop-duplication-api)
- [Microsoft: SendInput integrity boundary](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-sendinput)
- [Apple: Notarizing macOS software](https://developer.apple.com/documentation/security/notarizing-macos-software-before-distribution)
- [Apple: Service Management](https://developer.apple.com/documentation/servicemanagement/)
- [Apple: NSWorkspace running applications](https://developer.apple.com/documentation/appkit/nsworkspace/runningapplications)
- [Apple: NSRunningApplication terminate](https://developer.apple.com/documentation/appkit/nsrunningapplication/terminate%28%29)
- [Apple: ScreenCaptureKit](https://developer.apple.com/documentation/screencapturekit/capturing-screen-content-in-macos)
- [Apple: Distributing Safari web extensions](https://developer.apple.com/documentation/safariservices/distributing-your-safari-web-extension)
- [Android: DevicePolicyManager](https://developer.android.com/reference/android/app/admin/DevicePolicyManager)
- [Android: Lock task mode for dedicated devices](https://developer.android.com/work/dpc/dedicated-devices/lock-task-mode)
- [Android: Dedicated-device restrictions cookbook](https://developer.android.com/work/dpc/dedicated-devices/cookbook)

## Android child-enforcement boundary

- ParentProof supports **Android Device Owner / fully managed MDM enrollment only** for child Android devices.
- Enrollment happens on a clean/factory-reset device during initial setup, using the signed Windows or notarized Mac installer over a USB data cable.
- The managed ParentProof DPC applies the app allowlist, custom launcher, lock-task policy, web policy, user restrictions, schedules, protected settings and authenticated removal path.
- ParentProof does **not** support an Accessibility-only, overlay-only, ordinary device-admin, sideload-only or “just install the app” child-enforcement mode.
- The Android parent app is a separate controller surface. It is not Device Owner on the parent’s phone and does not restrict the parent device.

## Account and billing surface boundary

- Account creation and purchase happen only on `parentproof-storefront.html`.
- Subscription management, plan changes, credit top-ups, invoices, payment methods and cancellation happen only in the web dashboard/Stripe flow.
- The iPhone/iPad and Android parent demos require sign-in, but contain no signup screen, billing tab, top-up button, invoice UI or payment-management action.
- Windows and Mac parent dashboards may show subscription status and hand off to the secure web account; they do not collect payment information.

## Production boundaries represented by the demos

- ParentProof does not replace Windows PIN, Windows Hello, macOS password, Touch ID, FileVault, or the OS sign-in screen.
- Billing, signup, subscription changes, credit purchases, invoices, and account purchasing happen only on the web through Stripe.
- Parent mobile apps do not expose signup or billing-management flows.
- Every child can have a maximum of three devices attached to their profile.
- Android child protection always means Device Owner / MDM; there is no weaker fallback enforcement product.
- Remote viewing and control require explicit installation permissions, visible disclosure, encrypted transport, audit history, and emergency termination.
- The HTML files are interface prototypes. Production enforcement requires signed native Windows/macOS agents, an Android DPC/MDM implementation, browser integrations and a secure backend.
