SentriRail

Changelog

0.3.0 2026-09-14

Added

  • Ultimate Plan wave 2: CMS/CMP/GTM discovery, import baselines, /problems, procurement pack, revenue kit, portfolio health, embed scanner, gated partners
  • html_scan and site_discovery worker jobs
  • Portfolio size onboarding, contextual paywalls, Monitoring active card
  • Founder: Stripe MRR entitlements to plan, D7/D30 cohorts
  • Stripe billing: Checkout, portal, webhooks, dunning, 7-day grace

Improved

  • /trust hub: /subprocessors /data-retention /responsible-disclosure
  • Marketing nav Product / Solutions / Tools / Research / Partners
  • --ld-bg / --ld-text tokens on body

Fixed

  • html_scan jobs were not executed by the worker
  • Responsibility matrix: current version = latest insert (rowid), not MAX(created_at) on timestamp collision

Security

  • Rate-limit /e and /api/public/leads

0.2.6 2026-09-14

Added

  • Public scan to account continuity (host already present after verify)
  • /trust hub and /methodology page
  • CSV portfolio import (migration_center flag)
  • Monitoring quality metrics + Playwright canary
  • Founder control (catalogue MRR, funnel) admin-only

Improved

  • Public scan result: trackers, scenarios, findings
  • StatusBadge on command center, client portal, and public scan
  • Docker image: Playwright Chromium

Fixed

  • /verify title: attestation, not generic compliance wording

Security

    0.2.5 2026-09-14

    Added

    • Dashboard EN+FR: remediation, replay, /dashboard/ops, /dashboard/billing

    Improved

      Fixed

        Security

          0.2.4 2026-09-14

          Added

          • Dashboard EN+FR: registry, DSAR, consent log, team, account, policies, fleet, onboarding, feedback, regulatory impact
          • Operational DSAR CSV export
          • Onboarding: privacy scan step as first useful outcome

          Improved

          • Command center, client reports, and attestation use ui-copy.ts

          Fixed

            Security

              0.2.3 2026-09-14

              Added

              • EN/FR copy for remaining site strings (install, pixels, cookie purposes, CMv2, watch, exceptions)

              Improved

                Fixed

                  Security

                    0.2.2 2026-09-14

                    Added

                    • Optional off-VPS backup copy (BACKUP_REMOTE_CMD, tests without remote)
                    • Operational responsibility matrix PDF export
                    • Verify proof chain UI
                    • Remaining lab scenarios (before-consent, withdraw, unknown vendor, late-loading)

                    Improved

                    • Dashboard EN+FR: site, forms, scan, reports, matrix
                    • Hypothetical COGS + indicative resale on /dashboard/ops
                    • Scheduler: targeted scan on regulatory impact action_required
                    • StatusBadge via --ld-healthy/--ld-review/--ld-action/--ld-unknown tokens

                    Fixed

                      Security

                      • ScanButton shows Reference ID on API failure

                      0.2.1 2026-09-14

                      Added

                      • In-app /status page (local components, no client domains)
                      • Ops: recent jobs, failed scans, outbox email, watch
                      • Reference ID on SCAN_FAILED / JOB_FAILED
                      • Dashboard EN/FR shell (ld_lang cookie)
                      • Slack Incoming Webhook payload helper (not a Slack app)

                      Improved

                      • Trust center: policy, DPA, contact, /status link
                      • Getting Started / Monitoring / CI / API docs
                      • Backup: open test + COUNT users/sites

                      Fixed

                      • FindingFeedback no longer imports SQLite on the client (build)

                      Security

                      • Worker errors carry support id without stack

                      0.2.0 2026-09-14

                      Added

                      • Privacy Reliability loop (Playwright monitor, incidents, replay, proofs, fleet, CI, public scanner, demo)
                      • Product / solutions / trackers / CMP / sourced compare / docs / trust center pages
                      • Configurable quotas, hypothetical cost telemetry, scan scheduler, HMAC webhooks, false-positive feedback

                      Improved

                      • Command center Healthy/Review/Action required/Unknown
                      • Public errors { error, message }

                      Fixed

                      • Scan failed no longer closes an incident

                      Security

                      • Security headers, network redaction, LOGGED_IN vault stub, opt-in screenshots with limited retention
                      Changelog | SentriRail