August 11, 2026 — Release and recovery integrity
Standalone installers now verify Sigstore identity and provenance, release publication fails closed on incomplete evidence, and disaster-recovery tooling reconciles encrypted object inventory without decrypting customer files.
August 11, 2026 — Browser transport hardening
Production Content Security Policy now upgrades insecure subresource requests while retaining the existing narrow connection allowlist, browser isolation headers, and WebAssembly requirement for client-side encryption.
Verification boundary
This changelog describes implemented product controls and regression coverage. It is not an independent audit, certification, or guarantee that every deployment has completed its external CDN, storage, backup, and restore evidence checks.