Changelog
We ship server updates continuously and firmware over-the-air every few weeks. Each entry below captures what changed and when it reached platforms in the field.
v2026.08.01Server
Added
- Two-factor authentication: TOTP enrolment with a scannable QR code, verification and single-use backup codes.
- Account settings reachable from the dashboard.
- News posts in four languages, starting with the operator's statement.
Changed
- The platform page carries both products behind one switcher; the separate Stand Base address now redirects there.
- Getting Started documents the real power-on sequence: charge, press, hold, release.
Fixed
- Checkout refuses to complete when a shipping quote cannot be produced, instead of quietly charging nothing for carriage.
- The cart no longer loses per-segment colour configuration when it is viewed.
v2026.07.30Server + firmware
Added
- Sleep-aware presence: a platform announces its own next-contact deadline, so a sleeping platform reads as sleeping rather than offline.
- Founders' Circle: invite lifecycle, per-hour claim flow and permanently frozen point names.
Fixed
- Firmware shows a missing signal and a missing location honestly instead of drawing a placeholder.
Security
- The three data-retention policies that had been declared but never had a handler now run.
v2026.07.10Firmware
Fixed
- The fleet shares one clock it can trust.
- A network fault is named in the log instead of being swallowed, and the platform stops forgetting its state on every boot.
Changed
- Single-path OTA and a rebuilt platform image.
v2026.06.20Server
Added
- The owner is notified when the load cell detects an arrival.
- The owner is notified when a firmware boot fails after an OTA.
- Network milestone email when the network crosses a size threshold.
v2026.05.30Server
Added
- Payment failure notifies the customer on both Stripe and Revolut.
- First-activation email when a platform comes online for the first time.
- Refund email wired to the admin panel.
Fixed
- Abandoned-cart snapshots stay in sync when the cart is emptied.
v2026.04.20Server
Added
- /press — public media kit page with brand facts, swatches, and email-gated asset delivery.
- /changelog — this page, with per-release Added/Changed/Fixed/Security groups.
- Newsletter double-opt-in signup at /newsletter.
- Platform transfer flow with token accept/decline landings.
- Two-factor authentication: TOTP enrolment and verification pages.
v2026.04.19Server + firmware
Security
- PBKDF2 device_key migration with dual-path verification (CPU-serial -> PBKDF2).
- SSH restricted to key-only on Raspberry Pi images; cross-domain PBKDF2 routing closed.
- Removed HTTP portal attack surface by killing GET /connect on firmware.
- wipe-sd.sh gained four safeguards against wiping the wrong disk.
Fixed
- Admin audit findings (4 items) resolved across page/i18n surfaces.
v2026.04.01Firmware
Fixed
- Captive portal probe retries now redirect via 302 instead of replying 200.
- DHCP option 114 (RFC 8910) announces portal URL; dnsmasq boots before hostapd.
- brcmfmac reloads cleanly after a wrong-password attempt via rmmod/modprobe cycle.
- Access point self-refreshes every 15s when no client is connected.
Changed
- WPA2 access point uses per-device password drawn from device.conf at boot.
Want an email when we ship something new?