Changelog
What's new
A running record of product and platform changes. Security and infrastructure updates appear here alongside customer-facing features.
April 2026
Security & compliance hardening- Full-site security audit across 17 phases — 30+ defects closed.
- Content Security Policy rolled out in report-only mode; HSTS preload enabled.
- GDPR right to data portability: clients can now download a JSON bundle of their account, purchases, invitations, and session data from account settings.
- GDPR right to erasure: "Close Account" flow added to settings.
- Candidate PII retention: auto-scrub weekly job deletes test-taker personal details older than 24 months while retaining aggregate scores.
- Stripe refund handling: partial and full refund events now correctly reverse credit-pack, co-branding, and certificate purchases.
- New rate limits on login, register, password reset, and invitation endpoints to prevent credential stuffing and email spam.
- HIBP "Have I Been Pwned" password checks during registration and password reset.
- AI & Automated Scoring notice published at /ai-notice (Colorado AI Act & NYC AEDT compliance).
- Trust Center launched at /trust.
- Sitemap expanded — comparison pages, whitepapers, test demos, and trust-cluster pages now included.
- AI training crawlers (GPTBot, ClaudeBot, CCBot, Google-Extended, Perplexity) blocked in robots.txt.
- Post-password-reset security notification email.
- Credits-low warning email — active clients now get a heads-up when their balance drops to 3 or fewer credits.
- Accessibility: skip-to-main-content link and universal keyboard focus outlines added across all public pages.
March 2026
PlatformEntries for prior months will populate as we backfill historic release notes.
Want to be notified?
Significant updates are included in our monthly client digest. You're subscribed automatically when you sign up.
Create a free account