Skip to content

Earlier products, kept for the record.

Entries up to August 2026: the finance tools, the gateway releases and the retired console. Routes and prices named here belonged to those products and are not current. The current changelog starts in September 2026.

2026

  1. Launch Two demo films: the gate and the record, and the risks that hide between firms

    Two 2-minute films, both live on the record page and both real end to end. Act one: the gate governs a live agent, every decision signs into a record the operator owns, an edited record is caught in the browser, and a payment cap is proven without revealing a single payment. The film was assembled by an AI agent working behind that same gate; one of its own tool calls was refused on camera. Act two: five parties run a standing covenant where health, silence, and breach are public states while every number stays sealed (the Archegos shape), three desks find their one shared exposure without opening a single book, and clean books earn a co-signed certificate. Every artifact in both films verifies offline with the new standalone CLI (MIT, on npm). Replay everything from your own terminal.

  2. v0.9.6

    Feature protect-mcp 0.9.6: policy you can see and change

    The gate's policy is now inspectable and editable from the CLI: policy list shows permit/forbid/default-deny per tool with allow/deny counts from your own log, policy allow/deny edit it, and commented-out rules are never read as active. Denials teach the fix: a deny names the policy file and gives the exact command to change it. The running gate hot-reloads Cedar edits, fail-closed on a bad edit. Also 0.9.5: npx protect-mcp sample seeds a labeled sample record (8 real signed receipts including a blocked network call, plus a tampered copy) so the demo film replays in an empty folder in 60 seconds. 267 tests.

  3. v0.9.4

    Feature protect-mcp 0.9.4: x402 payment receipts, record checkpoints, pinned-identity anchors

    The agentic-payments layer, shipped the week Cloudflare launched its x402 Monetization Gateway. The gate tags agent payments across the real x402 wire shapes (paymentRequirements, X-PAYMENT, EIP-3009) into signed receipts carrying the amount, the asset, and a hashed recipient. claim --payment-under <cap> proves every agent payment stayed under a cap, position-blind, and an amount the gate could not read counts as over the cap, so the claim cannot lie. anchor-record checkpoints the record's Merkle root into the public log on a heartbeat, so a later claim is provably over the complete record, not a curated subset.

  4. v0.7.1

    Fix protect-mcp 0.7.0/0.7.1: the fail-closed release

    A security release we are candid about. Verification of a community report showed the Cedar gate could fail open on evaluation errors and was not evaluating Cedar correctly against cedar-wasm 4.x. 0.7.0 makes the gate fail closed on any policy error, missing engine, or evaluation failure, and adds a startup self-test: serve --enforce and doctor refuse to arm the gate unless they can prove a known-forbidden action is actually denied. A gate that cannot prove it denies does not start. GitHub security advisory published; per-host hook adapters (Claude, Codex, Gemini, Cursor, Hermes) followed in 0.7.2.

  5. Launch Cold-chain hardware programme: ETCF #197 submitted, CSIRO Kick-Start EOI in process

    Submitted NSW Office of the Chief Scientist & Engineer Emerging Technology Commercialisation Fund application #197 (A$500,000 over 18 months) for the cryptographic cold-chain evidence tag. Three phases: PCB design + embedded Rust firmware (Phase 1), 100 prototype units + NATA-accredited calibration + IP67 enclosure (Phase 2), 50-device NSW field pilot with cold-chain operators (Phase 3). Parallel CSIRO Kick-Start EOI prepared for the engineering de-risking research (A$50K, 6 months): battery-life model with Merkle batch signing, environmental qualification −25 °C to +65 °C, optimal signing cadence. Same receipt format that powers protect-mcp, now embedded in physical sensor hardware. Project page live at scopeblind.com/cold-chain with full spec, two-SKU strategy (disposable evidence tag v1 + reusable+ logger v2), three inspectable demo receipts, comparison vs Sensitech/Emerson/ELPRO/LogTag, FAQ, and one-page PDF brief.

  6. v0.6.0

    Launch protect-mcp 0.6.0 + @veritasacta/verify 0.6.0: commitment-mode receipts shipped

    protect-mcp 0.6.0 wraps any MCP server with opt-in commitment-mode signing: each receipt field is independently committed via SHA-256(salt || JCS({name, salt, value})) and arranged into an RFC 6962-style Merkle tree. The receipt payload carries a single committed_fields_root. Selective disclosure works by revealing specific (name, salt, value, proof) tuples to specific auditors; other fields stay cryptographically hidden. @veritasacta/verify 0.6.0 adds the matching --disclosure-file flag for offline verification. Cross-implementation interop verified: TypeScript signing, JavaScript verification, byte-exact across the same Merkle root. draft-farley-acta-signed-receipts-01 submitted to IETF datatracker. ScopeBlind Founding Plan production support tier launched at scopeblind.com/support: $499/month for first 25 customers, locked for life.

  7. Launch Integrations hub + cedar-agent-schemas community repo

    Launched /integrations, the canonical map of every framework, runtime, and marketplace where ScopeBlind and Veritas Acta plug in. Shipped VeritasActa/cedar-agent-schemas v0.1.0: canonical Cedar schema library for agent action verbs (exec, open, connect, request_tool), with TypeScript bindings, three reference policies, and OWASP Agentic Top 10 mapping. Created in response to cedar-for-agents#76 per Cedar RFC #58/#69 community-venue pattern.

  8. Launch AWS Cedar-for-agents PR #73 merged

    Second PR merged into AWS cedar-policy/cedar-for-agents. RequestGenerator WASM bindings complete the JS/TS Cedar toolchain: any agent host can now adopt Cedar policy-as-code with three function calls, no Rust toolchain required. Paired with the already-merged #64 (schema generation), the full build-time + runtime Cedar pipeline is available in any JS environment.

  9. Launch 3 AGT PRs merged: Tutorial 33, sb-runtime integration, governance skill

    Three PRs merged into Microsoft Agent Governance Toolkit: #1201 (Signet added to cross-implementation table), #1202 (sb-runtime integration guide), #1203 (sb-runtime governance skill provider shim with nono-composable sandbox backend). Positions Veritas Acta receipts as the composition layer for governance frameworks, with nono recommended as the Linux/macOS sandbox primitive.

  10. v0.5.0

    Feature @veritasacta/verify v0.5.0 (Bold Arrow) shipped

    Unified reference verifier: Ed25519 signed receipts, full Schnorr DLEQ verification for VOPRF anonymous credentials, Knowledge Unit bundles, and selective-disclosure receipts all in one CLI. BRASS wire-compatible with api.scopeblind.com. 12 new round-trip tests against production issuer + client logic. Sigil fingerprint over 25 source files.

  11. Feature VS Code Extension Published + Trace Walkthrough

    ScopeBlind Trace extension published to VS Code Marketplace. Animated walkthrough GIF of the Trace demo. Compare page (ScopeBlind vs Vectimus vs logs). Dark/light mode toggle. Improved 404 page. Dashboard: Trace integration + Underwriter Export button.

  12. Feature "Break My Agent" CTF + MCP Server Directory

    Launched the Break My Agent CTF challenge. MCP Server Directory (/hub) with verification badges. Trace V2 with hover tooltips, Verify All button, Insights tab, and shareable URLs. Trust Center with DPA, SLA, SLSA, and CSA CAIQ. Enterprise Self-Hosted pricing tier.

  13. Feature 6 new packages + GitHub Action + webhooks

    Published @scopeblind/otel-exporter, create-scopeblind-agent (npm), acta-sql (PyPI), VS Code extension scaffold, autoresearch and HyperAgents integrations. GitHub Action for SLSA provenance. Slack/PagerDuty webhook integration.

  14. Launch IETF Internet-Draft published

    Published draft-farley-acta-signed-receipts-00. Referenced as informative reference in draft-serra-mcp-discovery-uri-04.

  15. Feature Blog launched across all properties

    Blog launched on scopeblind.com, blindllm.com, and veritasacta.com. First post: "How BlindLLM Uses Signed Receipts to Prove AI Comparisons."

  16. Feature Cedar policies + CVE packs + compliance pages

    Cedar policy engine support via --cedar flag. 5 CVE-anchored policy packs shipped. OWASP Agentic Top 10 mapping. SOC 2 and EU AI Act compliance pages.

  17. v0.3.3

    Feature protect-mcp v0.3.3, HTTP/SSE + notifications

    protect-mcp v0.3.3 published with HTTP/SSE transport, notification system (SMS/webhook/email), and HuggingFace export pipeline.

  18. Improvement Homepage redesigned with interactive demos

    New homepage with interactive demos: DAG visualization, Selective Disclosure, and Human Approval flow. MIT license adopted across all packages.

  19. v1.0.0

    Feature MCP Plugin for AI IDEs

    New scopeblind-mcp package (npx scopeblind-mcp) lets AI coding assistants in Cursor, Claude Desktop, and Windsurf scan endpoints, provision tenants, get abuse reports, and generate integration code, 4 tools, zero config.

  20. Feature Agent discovery header + /verify-agent page

    Agent SDK now sends X-Device-Identity header linking to /verify-agent, a dual-content landing page with human-friendly copy and hidden machine-readable section for LLMs/crawlers. Every protected agent request leaves a breadcrumb.

  21. v1.0.2

    Feature Agent SDK v1.0.2 with DPoP

    scopeblind-agent now includes X-Device-Identity header and DPoP proof-of-possession (RFC 9449) for AI agents, CLIs, and MCP tool servers. Zero dependencies, uses node:crypto.

  22. Improvement License consolidation to MIT

    All packages now MIT licensed, gateway, verifier, SDKs, and protocol libraries. No restrictions on self-hosting, modification, or commercial use.

  23. Fix Pre-launch consistency fixes

    Unified pricing across homepage ($79/mo Pro, $199/mo Growth), docs, and llms.txt. Updated agent auditing instructions and proactive scanning prompts in llms.txt. Added MCP plugin to docs overview and links.

  24. Improvement Homepage copy overhaul + launch polish

    New pain-led headline, inline cost calculator in hero, comparison table replacing card grid, streamlined 3-step How It Works, verifiable credibility strip replacing placeholder testimonials. Privacy policy updated with VOPRF/JWT/edge-processing specifics. Plausible analytics, PWA manifest, and apple-touch-icon added.

  25. Improvement Teal brand rebrand

    Complete rebrand from purple/orange to teal/cyan across the full design system. 50+ color references updated. Favicon tinted. New color identity: unclaimed territory in the security × dev-tools space with strong semantic fit for 'cryptographic.'

  26. Improvement Micro-interactions + delight pass

    20 new animations: nav link underlines, copy button success, pricing card hover lift, input focus glow, code block language badges, accordion auto-scroll, mobile nav backdrop, button loading states, testimonial card hover, and full prefers-reduced-motion accessibility.

  27. Feature Stripe checkout + billing management

    Added checkout success/cancel pages, billing portal link for Pro users on the dashboard, and Growth tier contact form replacing mailto links.

  28. Feature Agent API keys + fast-lane

    AI agents can now authenticate with dedicated API keys and skip VOPRF challenges entirely. Manage keys from your dashboard with create, list, and revoke. JWT tokens include an agent: true claim.

  29. Fix Security hardening pass

    Stripe webhook signature verification is now mandatory. Admin API key comparisons use constant-time checks. Webhook test endpoint blocks internal/private IPs (SSRF protection). OG image endpoint escapes user input to prevent SVG injection.

  30. Improvement Dashboard UX improvements

    Refresh button no longer gets stuck spinning on error. Quick Start section auto-collapses once you have traffic. Auth state badge shows whether you're authenticated or read-only. Toast notifications on all write failures.

  31. Fix Docs code examples fixed

    Fixed Express import syntax (import * as jose), Python key selection (filters for OKP key type), and Django/FastAPI line continuation bugs. Added CDN cache propagation note for JWKS verification.

  32. Feature Guided deploy wizard + live dashboard demo

    After scanning your API, a 3-step wizard walks you through deployment and verification. Plus /t/demo now shows a live demo dashboard with sample data so you can see the product before deploying.

  33. Feature Custom cost-per-abuser input

    Set your actual API/compute cost per user in the dashboard ROI card. See real dollar impact instead of a generic estimate.

  34. Improvement 62% smaller initial page load

    Code splitting with React.lazy, the homepage now loads 62% less JavaScript. Dashboard, docs, and other pages load on-demand.

  35. Feature Enforce pre-flight checklist

    Switching to enforce mode now shows a data-driven checklist with your abuse rate, estimated blocked count, and safety assurances before you confirm.

  36. Feature Report page social cards

    Sharing a /report/:slug link on Twitter, LinkedIn, or Slack now shows a rich preview card with your abuse rate and grade.

  37. Feature Smart email lifecycle

    New automated emails: welcome on provision, no-deployment troubleshooter at 48h, first-data milestone at 100 pings, and quota warnings at 75% and 100%.

  38. Feature 7-day traffic chart + empty-state preview

    Dashboard now shows a 7-day area chart of visitors vs. unique devices. New tenants see a preview of what their dashboard will look like once data flows in.

  39. Improvement Synthetic test ping on provision

    New endpoints get a synthetic ping immediately on creation, so the dashboard shows data right away instead of a blank state.

  40. v1.0.0

    Launch v1.0.0, Public launch

    ScopeBlind gateway released as open source (MIT). Edge-native progressive enforcement for APIs with VOPRF proofs, EdDSA JWT pass tokens, and a real-time dashboard.