Every release, on the record.
- — Public status page with live health, incident history and weekly audit-chain anchoring
- — Platform-wide security event logging (SOC 2 CC6.1/CC7.2) with 400-day retention
- — Field-level encryption at rest for MFA secrets
- — security.txt, subprocessors register and incident-response runbook published
- — Team page and multi-language support (English, Español, Français)
- — Zero-Touch Onboarding: shareable client intake links with automatic workspace creation
- — Evidence progress bar in the client portal
- — Template packs with one-click apply to any client
- — Simplified client portal with prominent Upload Evidence action
- — High-contrast status badges across compliance views
- — Session security overhaul: httpOnly cookie sessions, strict CORS, hardened headers
- — Automatic idle session timeout with warning countdown
- — Public security page detailing platform protections
- — Checkout flow fixes with pre-filled Stripe sessions
- — Initial release: multi-tenant client workspaces, compliance tracking across 8 frameworks
- — Hash-chained audit trails with public verification
- — Auditor portal, branded PDF exports, AI compliance assistant
- — MFA (TOTP + recovery codes), Stripe subscriptions
How we ship
Continuous improvement is a compliance requirement, not just an engineering habit. Every AuditVanguard release is small, reviewed and reversible: changes move through automated tests and a security review before they reach production, and each one lands here — on the record — the same day it ships. If a release hardens authentication, tightens data isolation between client workspaces or changes how evidence is stored, you will find it named explicitly rather than hidden behind a vague "improvements and bug fixes" line.
This log is also part of our SOC 2-aligned change-management story. Auditors reviewing an engagement run on AuditVanguard can trace platform changes against the same dates that appear in tenant audit trails, giving consultants a clean answer to the classic question: what changed, when, and who approved it? Backwards compatibility is a default — existing workspaces, exports and intake links keep working across versions, and anything deprecated is announced here first.
Most entries begin as feedback from practicing consultants and their clients. If something in your workflow deserves attention, tell us through the contact page — the fastest way to see your suggestion appear in a future version below.