Release Centre / public

What shipped. What can be reviewed.

Release history, technical evidence, the signed runtime manifest, RSS and roadmap remain independently traceable. The roadmap shows direction and acceptance gates—not guaranteed delivery dates.

01CONNECT-2026.09.09-HARDENING2026-09-09
02CONNECT-2026.09.06-PQXDH2026-09-06
03SITE-2026.09.05-PERFORMANCE2026-09-05
RELEASE VERIFICATION

Read the change. Verify its origin. Understand its limits.

Release history, technical claims and the signed runtime record remain separate, directly accessible channels. A signature proves origin and integrity of the published manifest—not that the product is defect-free.

01 / CHANGELOGCONNECT-2026.09.09-HARDENING

Dated, filterable change history with directly linked claim IDs.

Review history
02 / EVIDENCE23 claims

Technical basis and boundary from the dated evidence source.

Control Room
03 / SIGNED RUNTIMEED25519 / MANIFEST

Publicly served Connect runtime manifest, independently verifiable through the documented review path.

Open manifest
04 / OPERATIONSSTATUS / RSS

Current operating state and the machine-readable release feed are deliberately separate.

VENTEX / RELEASE PULSE

Release Centre

Evidenced development from the product foundation to the current review path. Filter by stream and follow technical evidence directly.

evidenced releases
27
workstreams
04
with claim evidence
21
public window
07.17—09.09
  1. CONNECT-2026.09.09-HARDENINGSecurity

    Revocation, local data, realtime and verification paths hardened

    The current source and verification state closes several gaps at the boundaries between device, browser, push, realtime and database layers while expanding the reproducible verification path. This website release did not update the separately signed app runtime. Public material covers effect, review date and boundaries—not internal keys, infrastructure identifiers, test vectors or reproducible attack details.

    Show changes21
    • Current re-run: 308 of 308 conformance rows mapped to a documented counter-test; 19 real-browser runs with 189 checks
    • Realtime messages are limited at output to the explicitly defined contract fields; nested membership or internal records do not travel with them
    • Device revocation, panic mode and the duress path remove related push subscriptions; revoked or expired devices no longer receive incoming-call push events
    • Local removal after revocation covers message history, ratchet state, outbox, private prekeys, device identity and account-scoped browser values; data that cannot be separated from another account remains explicitly bounded
    • Drafts, recently used symbols and local email notices are account-scoped; legacy unowned drafts are removed and device fingerprints are no longer named with a plaintext account identifier
    • The local outbox fallback is read back, remains in the removal path and is not accepted as a silent plaintext path; API responses remain excluded from the service-worker cache
    • New and existing timestamps in the affected communication and key tables are reduced to minute granularity; expiry and view times must not re-expose removed second-level precision
    • PQXDH one-time prekeys have server-side inventory bounds and a tested replenishment path; five series of 60 concurrent requests allocated no key twice
    • Production verification now counts both version 2 and version 3 correctly as Double Ratchet paths and reports an actual fallback to version 1 separately
    • Restart, recovery, multi-device and downgrade paths received broader checks; blocked local deletion now gives a clear user instruction instead of entering a reload loop
    • Browser-storage inventory covers IndexedDB, Cache Storage, Local Storage, Session Storage and cookies; the current service sets exactly one narrowly scoped HttpOnly, Secure and SameSite-Strict authentication cookie
    • Profile images require authentication and are protected at rest, but are not end-to-end encrypted and remain readable to the service; the published boundary now states the current technical reason
    • The reviewed backup path is encrypted; the operational check found no unmanaged plaintext database export outside that boundary
    • Verification scripts, package coverage, schema-to-migration alignment and claim rules were hardened against dead, skipped or self-altering checks
    • Website, verification and product releases remain separately identifiable. Known production carry-over in receipts, audit records, historical time/device references and WebKit key storage remains tracked as open boundaries rather than being treated as resolved by the new source state
    • The following cold-start possession-proof, history-transfer and revocation-cleanup corrections are the current source/test state. They are evaluated as part of the live signed runtime only after a separately authorised app release and migration
    • Pending migrations are checked on the target host in an automatically removed disposable clone of the running data. Before/after row counts and deliberately failing counter-cases prevent silent data loss from being reported as success; user data does not leave the host for this check
    • The revocation cleanup path now covers residual push subscriptions and pending history transfers in addition to sessions. Identity and authorship evidence required for takeover or provenance protection is deliberately retained and is not delivered to revoked devices
    • The encrypted history-transfer client computes its opaque target mark once, binds the intended room inside protected content and skips older unmarked envelopes instead of guessing their destination; six checks with five counter-tests cover the path
    • On cold start, the client reconstructs the opaque identifier directory from encrypted account state before retrying the possession proof. An empty proof set is no longer recorded as complete; four focused checks cover retry, locking and account switching
    • Retention verification discovers newly touched data areas automatically so an added cleanup path cannot remain untested merely because a hand-maintained test list is stale
  2. CONNECT-2026.09.06-PQXDHSecurity

    Hybrid post-quantum session establishment activated under controlled rollout

    Capable devices can now establish new sessions through hybrid PQXDH with X25519 and ML-KEM-1024; the derived secret then feeds the Double Ratchet. Rollout remains device-dependent, versioned and explicitly distinguished from a fully post-quantum ratchet.

    Show changes8
    • Version 3 active in the controlled production path since 6 September 2026
    • Hybrid PQXDH session establishment combining X25519 and ML-KEM-1024
    • Signed and one-time classical and post-quantum prekeys
    • Double Ratchet for ongoing message protection
    • Per-device-pair downgrade guard after version 3 is first used
    • Documented, versioned compatibility path for devices that are not yet capable
    • Signal-inspired, independently implemented architecture without Signal, libsignal or audit-equivalence claims
    • Detailed review material limited to expressly agreed confidential review or audit scopes
  3. SITE-2026.09.05-PERFORMANCEWebsite

    Route-specific styles and mobile accessibility refined

    The website now delivers substantial editorial and product styles only on the routes that use them. An automated size budget and additional accessibility checks keep the leaner delivery verifiable over time.

    Show changes6
    • Split global styles into route- and component-specific packages
    • Deferred layout and paint for deep page sections until they approach the viewport
    • Added an automated CSS budget across representative public routes
    • Removed decorative product controls from the keyboard order
    • Raised the contrast of a technical homepage label
    • Increased the deployment-planner link touch target
  4. SITE-2026.09.04-TRUSTWebsite

    Product security, support boundaries and advisory register published

    The public trust path now explains the Controlled Production Release state, current support lifecycle, vulnerability handling, open CRA gates and the empty machine-readable security-advisory register.

    Show changes6
    • Explicit definition of the Controlled Production Release state
    • Public support and security-update framework without implied SLA or EOL commitment
    • Security-advisory register with a machine-readable JSON endpoint
    • CRA preparation with implemented and open gates
    • Sitemap without fabricated global lastmod dates
    • Founder-led responsibility model separated from employee headcount and departments
  5. SITE-2026.08.30Website

    Product tour, resilience lab and public review rooms

    The public product review experience has been expanded into a connected system spanning a guided tour, failure scenarios, claim-to-control mapping, a procurement workspace and an enhanced Release Centre.

    Show changes6
    • Guided six-stage product tour using synthetic local data
    • Resilience Lab covering five realistic failure and revocation paths
    • Security Control Room derived from the existing dated evidence source
    • Procurement Room with a local checklist plus JSON, print and Markdown export
    • Regrouped desktop, mega and mobile navigation
    • Release Centre with verification and review channels
  6. CONNECT-2026.08.25Security

    Possession proofs extended across listing, file, key and realtime paths

    The service now requests missing membership proofs explicitly and the client supplies them only when required. Authorisation, read state, attachments, key access and membership rooms share the same proof-bound gate; remaining account columns and plaintext identity data stay published as migration boundaries.

    Show changes6
    • Proof supplied on demand instead of extra network rounds on every start
    • Realtime membership rooms derived from proven opaque references
    • Read state, attachments and key access bound to the same possession proof
    • Mentions migrated to conversation-scoped membership references
    • Display names removed from member lists, direct-chat titles, exact-handle search and incoming-call push
    • Remaining conversation_members.userId, users.displayName and legacy-receipt boundaries published
  7. DEMO-2026.08.22Product

    Mission Rooms become a guided operational exercise

    A standalone, entirely local demo guides visitors through briefing, role selection, alert ownership, mission channel, tasks, evidence, closure and debrief without an account or transmission.

    Show changes5
    • Standalone canonical demo host with DE/EN, sitemap and robots
    • Dispatcher, Operator and Observer perspectives
    • Five connected exercise objectives
    • Local attachments, evidence inspection and exportable JSON debrief
    • Hard isolation from the production app, APIs and real operational data
  8. SITE-2026.08.22Website

    Product claims become directly reviewable

    Core statements on product pages now lead into the same dated claim ledger that publishes status, technical basis and system boundary together. A new release pulse makes the evidenced development history visibly filterable.

    Show changes4
    • Direct evidence strips on home and product pages
    • Status, review date, basis and boundary from one source
    • Stable fragment targets for individual claim IDs
    • Filterable release pulse with linked evidence
  9. CONNECT-2026.08.21Security

    Further decoupling of identity from the stored communication graph

    Further direct identifiers have been replaced by secret-derived or conversation-scoped references. The work reduces linkability in a database snapshot without claiming a metadata-free running service.

    Show changes7
    • Direct-chat pair values HMAC-derived with a separate server secret
    • Device ID in key envelopes replaced by an opaque recipient mark
    • Reactions and favourites migrated to conversation-scoped memberRef
    • New read state without new individual message_receipts rows
    • Plaintext display names reduced in sealed memberships and live signals
    • Opaque membership references bound to possession proofs, with the compatibility path for unprovisioned memberships kept explicit
    • Remaining account links and boundaries explicitly documented
  10. CONNECT-2026.08.20Security

    Opaque membership references bound to possession proofs

    Provisioned memberships cryptographically prove authority over their opaque reference. Key change and revocation follow the same membership boundary, while the compatibility path remains visible and measurable.

    Show changes4
    • Possession proof for provisioned memberships
    • Invitations bound to opaque recipient references
    • Key change following membership and device revocation
    • Explicit fallback for memberships not yet provisioned
  11. CONNECT-2026.08.17Security

    Double Ratchet as the default send path

    The former allowlist has been removed. New and existing conversations use pairwise ratchet sessions by default when recipient devices are known; the remaining no-recipient-device fallback is explicitly monitored.

    Show changes4
    • Double Ratchet without a conversation allowlist
    • Automated multi-party and device-join coverage
    • Measurable fallback to the older sender-chain path
    • No claim of an external audit or Signal equivalence
  12. CONNECT-2026.08.14Security

    Reduced plaintext metadata

    M1-D ends plaintext fallbacks for personal conversation preferences. M2 removes the direct sender identifier from stored messages and moves signed author proof into protected content.

    Show changes4
    • Favourites, archive and personal pins from encrypted state
    • messages.senderId removed from the data model
    • Signed author proof inside encrypted message content
    • Communication graph remains a documented boundary
  13. SITE-2026.08.09Website

    Evidence Center, search and public portals

    Product definitions, security boundaries and operating evidence received stable grounding pages. Global search, the deployment planner and dedicated docs and status hosts made the public information architecture durable.

    Show changes4
    • Six grounding pages with claim ledgers
    • Privacy-preserving global search
    • Interactive deployment planner
    • Separate canonical hosts for documentation and status
  14. CONNECT-2026.08.04Security

    Local key state and revocation hardened

    Ratchet state was sealed locally, bound attachments were decoupled from direct uploader references and revocation gained cleanup of local security stores.

    Show changes4
    • Encrypted persistence of ratchet state
    • Uploader reference removed after successful file binding
    • Random sender-chain marks for new messages
    • Local key stores cleared after device revocation
  15. CONNECT-2026.08.03Security

    Device identity and encrypted preferences secured

    Device signatures, key envelopes and encrypted personal conversation state were evidenced across multi-device, realtime and negative paths.

    Show changes4
    • Device-bound signing identity
    • Upgrade path for older key envelopes
    • Encrypted reads for personal conversation preferences
    • Realtime paths checked against plaintext regression
  16. SITE-2026.08.02-BWebsite

    Media, research and measurable website quality

    Approved press assets, an honest research intake, privacy-preserving audience measurement and reproducible SEO, accessibility, performance and header checks expand the product site.

    Show changes5
    • Press and media kit with machine-readable facts
    • Open university and research process without invented partnerships
    • Cookie-free daily aggregates without visitor identifiers
    • Individual social cards and structured data
    • Request-nonce CSP and automated quality audit
  17. SITE-2026.08.02Website

    Public product transparency

    Comparison, roadmap, responsible disclosure and a protected contact path expand the public product website.

    Show changes4
    • Fair comparison matrix backed by primary sources
    • Public change history and directional roadmap
    • Disclosure policy and standards-based security.txt
    • Contact form with validation, rate limiting and SMTP delivery
  18. SITE-2026.08.01Website

    Evaluation, documentation and status

    The product site added a local Mission Room demo, long-form technical documentation and honest status monitoring.

    Show changes4
    • Guided Mission Room simulator without production data
    • Six technical documentation chapters
    • Status API and RSS feed with explicit not-monitored state
    • German and English architecture whitepapers
  19. CONNECT-2026.07.31Security

    Encrypted conversation preferences

    Supported clients read selected conversation preferences from encrypted state for the first time. At this release, the plaintext fallback remained until the separately approved M1-D step.

    Show changes4
    • M1-B completed in substance
    • Realtime summaries moved to encrypted reads
    • Coverage made measurable per device
    • M1-D explicitly not approved yet
  20. CONNECT-2026.07.30Operations

    Reproducible release evidence

    Signature verification, independent rebuild and DNS-bound key checks connect source state to the bytes actually delivered.

    Show changes4
    • Manifest and Ed25519 signature outside the server
    • Byte comparison of the published build
    • Expected public key through an authoritative DNS channel
    • Service worker refuses unknown release files
  21. CONNECT-2026.07.29Security

    Reduced time, file and read metadata

    File names were sealed, server-side drafts removed and several precise timestamps replaced by coarser or sequence-based state.

    Show changes4
    • Sealed file names for new attachments
    • Server-side drafts removed
    • Reduced precise presence and activity timestamps
    • Read progress prepared for position-based state
  22. CONNECT-2026.07.27Security

    Conversation titles protected on the client

    Current conversation titles moved from open server state into sealed client payloads with a controlled transition for older rooms.

    Show changes4
    • Encrypted titles for direct chats, groups and Mission Rooms
    • Version-bound title payloads
    • Multi-device reads from the same protected state
    • Transition boundaries for older conversations documented
  23. CONNECT-2026.07.26Product

    Calls, reactions and secure device transfer

    The messenger gained call events, reactions, pinned conversations and controlled history transfer between devices. A duress password extends the emergency path.

    Show changes4
    • Audio/video call events in the message model
    • Encrypted reaction content
    • Device-bound history transfer
    • Duress password and local forgetting in the emergency path
  24. CONNECT-2026.07.25Security

    Passkeys, invitations and ephemeral messages

    FIDO2/WebAuthn, controlled invitations, self-destructing messages and private presence rules extended identity and access protection.

    Show changes4
    • FIDO2/WebAuthn registration and authentication
    • Invitation codes with bounded lifecycle
    • Self-destructing messages with server enforcement
    • Presence privacy and prepared sender chains/ratchets
  25. CONNECT-2026.07.23Product

    Administration and security console

    Owners and administrators received a dedicated surface for users, roles, devices, sessions and security-relevant events.

    Show changes4
    • User overview and role-based administration
    • Targeted device and session revocation
    • Login history and security events
    • Account suspension and global session revocation
  26. CONNECT-2026.07.22Product

    Messenger experience and Mission Room foundations

    Direct chats, groups, search, replies, forwarding, files and the dedicated Mission Room type were joined into one coherent workspace.

    Show changes4
    • Direct and group chats with realtime synchronisation
    • Replies, editing, deletion, forwarding and search
    • Files, pins, favourites and drafts
    • Mission Rooms as a dedicated conversation type
  27. CONNECT-2026.07.17Operations

    Product foundation, realtime and installable PWA

    The first coherent product foundation connected Next.js, Node.js, PostgreSQL, realtime, private file storage and an installable Progressive Web App.

    Show changes4
    • Modular web, API and database layers
    • Realtime communication and multi-device sessions
    • Private object storage for files
    • PWA installation and Web Push foundation
POLICY / CHANGE CONTROL

Release communication without theatre.

An entry means the change is visible in the repository and its associated evidence. It does not automatically mean every instance has already been updated.