Changelog
Hand-curated from git history, grouped by capability. This is not every commit -- internal task names and refactors are left out; what changed for a customer is not.
Public verifier
- Published actaseal-verify v0.1.0, a standalone, dependency-free offline receipt verifier.
- Added a keyless/checkpoint verification mode -- confirms chain and hash-linkage integrity without requiring the verifier to already hold the signer's public key.
- Added RFC 9162 continuity-checkpoint verification (Merkle inclusion and consistency proofs against a signed tree head).
- Hardened packet loading against malformed input (a bare JSON array where an object was expected now fails closed with a named error, instead of crashing).
Licensing
- Added an offline, Ed25519-signed licence file format, with an entitlement gate in front of every regulator-facing export.
- Unlicensed exports remain cryptographically valid and fully functional -- they are watermarked as an unlicensed evaluation copy, never refused or degraded.
- Added a vendor console (customers, licences, issuance history) run as a fully separate application with no access to any customer's ledger or evidence data.
- Automated licence issuance on subscription checkout, renewal, and cancellation.
- Added a revocation list a hosted deployment can poll, or an air-gapped deployment can load from a file, with fail-open-to-last-known-state semantics and visible staleness.
- Added an "unlicensed export" upgrade prompt directly in the console, linking to licensing.
Deployment
- Documented and fixed the fastest self-hosted path (
docker compose up --build), including a real buildx-version prerequisite discovered on a clean-machine install. - Added hosted-deployment provisioning: a per-customer Render blueprint generated from the
product's own
render.yaml. - Added a signed usage-export/import path for hosted customers with zero access to ledger payloads or PII -- counts only.
SDKs and framework integrations
- Shipped a TypeScript SDK (
@actaseal/sdk), mirroring the Python HTTP client field for field, zero runtime dependencies. - Added LangChain, LangGraph, and OpenAI Agents SDK tool adapters -- a blocked action raises a structured tool error, an approval-required action raises (or, on LangGraph, interrupts) with the reason code and receipt reference attached.
- Bound a merchant's terms document into the signed decision receipt itself
(
terms_hash), closing the gap where "what terms were in force" depended on testimony instead of signed evidence. - Published an interoperability binding profile with the Legal Context Protocol, and contributed a real ActaSeal receipt as a conformance evidence item to the agentic-resolution-interop project.
Evidence exports
- Added an FRE 902(13)/(14) self-authenticating certification package.
- Added a preservation-vs-erasure precedence report and an FRCP 37(e) preservation scope report, with notice issued/delivered/acknowledged receipts.
- Added a QC 1000 / ISQM 1 monitoring-and-remediation spine: deficiency aggregation, cadence detection, recurring-deficiency detection, and an internal-vs-regulator delta.
- Added per-control export, route-coverage attestation, and conformance receipt exports, and made every one of them reachable over an authenticated HTTP route -- previously CLI-only, unreachable for a hosted customer with no CLI access.
- Added a signed trust-center bundle: version/build info, an optional SBOM, resilience drill receipts, and a CUEC declaration derived directly from code rather than written prose.
- Added CAIQ-Lite and SIG-Lite security questionnaire exports.
Resilience
- Added three resilience drills with signed receipts: ledger tamper detection, key-compromise classification (every prior receipt marked SUSPECT / CLEAN / ANCHORED_BEFORE_COMPROMISE), and restore-under-corruption (a deliberately corrupted backup must fail closed, not restore quietly wrong).
- Added trust-center staleness tracking: bundle age and per-drill freshness, with an explicit FRESH/STALE/UNKNOWN verdict rather than an implied one.
Console
- Added WebAuthn security-key step-up for approvals.
- Added a persistent composite integrity indicator and one consistent grouped navigation bar across every console page.
- Brought the console to WCAG 2.2 AA (automated axe-core plus a scripted keyboard pass, fixed to zero violations).
- Refreshed the brand mark, wordmark, and favicon set across the console, verifier, and landing surfaces.