Aegis SA
Back to app Release notes

Release notes

What's new in Aegis SA — major and minor releases, with the fixes and improvements in each. Every release links to its pull requests and commit range on GitHub.

MAJOR milestone / platform-level change MINOR new features, backward-compatible PATCH fixes & small improvements
v6.1.0
2026-09-16
MINOR

v6.1.0 — Account recovery & targeted re-submission

Two provider-experience features on top of 6.0: self-service account recovery, and the ability to reopen a submitted assessment — whole or by specific controls — for re-submission.

✨ Features

  • Self-service account recovery — a "Forgot password?" link on the client and assessor sign-in pages emails a single-use, 60-minute recovery link; the user sets a new password and re-enrolls MFA. Neutral responses avoid account enumeration; recovers accounts an admin can't see (e.g. auto-created or org-less), so stuck invitees can unblock themselves.
  • Reopen a submitted assessment for re-submission — assigning + sending an already-submitted assessment now reopens the whole thing into a new Reactivated for re-submission status instead of leaving the assignee on a read-only record.
  • Send individual controls back for update — assessors can select one or more controls and send them back with a note per control. Only those controls unlock in the evidence flow; the rest stay read-only but remain expandable for reference, and each shows its note. Works from the submitted and audit states, reopening only the chosen controls.

🌐 Internationalization

  • All new UI, emails, and status labels (recovery, reactivation, per-control notes) localized across en, fr, es, de, pt, it, nl, ja.

⚙️ Upgrade notes

  • New columns password_resets (table), assessment_controls.resubmit_note / resubmit_requested_at, and users.language are applied automatically by the startup migration — no manual step.
  • No breaking changes; existing flows are unchanged unless an assessment is reopened.
v6.0.0
2026-09-15
MAJOR

v6.0.0 — Enterprise email delivery & world-ready notifications MAJOR MILESTONE

A major release focused on how Aegis SA communicates: modern-auth email delivery through Microsoft 365, notifications and the end-to-end tutorial fully localized into all 8 languages, organization-branded reports (no country-specific chrome), and clearer AI error handling.

✨ Features

  • Microsoft Graph (app-only) email delivery — send all notifications as a shared mailbox via Graph Mail.Send, with no SMTP AUTH, no user sign-in, no refresh token, and no mailbox licence. Configured with GRAPH_TENANT_ID / GRAPH_CLIENT_ID / GRAPH_CLIENT_SECRET / GRAPH_SENDER; startup verification and a one-click "Send Graph test" button in Organization settings. SMTP (basic + OAuth2) remains supported as a fallback.
  • Recipient-language notifications — every email (invites, user invitations, assignment, mention digests, evidence submitted, ATO/iATO, pre-assessment review, and the test emails) is now sent in the recipient's language, resolved from a new saved per-user language preference. Localized across en, fr, es, de, pt, it, nl, ja.
  • Redesigned email template — one consistent, responsive, email-client-safe layout (preheader, bulletproof CTA button, access-code pill, uniform header/footer) shared by every message.
  • Organization-branded reports — the ITSG-33 assessment report and the ATO/iATO document now carry the resolved organization name and logo (project → org → platform default) instead of hardcoded country/government wording.
  • Filterable, exportable control list on the assessment record (carried in from 5.1): filter by state, fuzzy search, and CSV export of exactly the filtered controls.

🌐 Internationalization

  • The end-to-end tutorial in Help is fully translated into all 8 languages (six-phase, click-by-click walkthrough).
  • Country/government-specific wording removed from emails and reports in favour of neutral, organization-driven branding.

🛠 Fixes & hardening

  • AI provider auth/rate-limit failures now show a friendly, localized hint ("the key was rejected — check Organization settings") instead of the raw provider JSON; real diagnostics are preserved for other errors.
  • Deploy script now syncs the new mail secrets (GRAPH_*, SMTP_OAUTH_*) to Azure App Settings from the environment file.

⚙️ Upgrade notes

  • New database column users.language is added automatically by the startup migration — no manual step.
  • To enable Graph email, set the GRAPH_* variables in each environment's .env and redeploy; the sender mailbox must be scoped to the app via an Exchange Application Access Policy.
  • No breaking API changes for existing SMTP configurations; Graph is used only when GRAPH_* is configured.
v5.1.0
2026-09-08
MINOR

v5.1.0 — Read-only evidence, ownership gate & a filterable control list

A safer, clearer assessor record — evidence always visible read-only, editing gated behind assignment, a filter/search/CSV toolbar over the control list — plus a comprehensive click-by-click tutorial and polished toolbars.

✨ Features

  • Read-only evidence on the assessment record — every control shows its evidence, even when blank and even before the assessment is submitted
  • View / edit evidence ownership gate — editing is gated behind assignment; a dialog offers View read-only or Assign to me & edit (take ownership), per control and for the record
  • Filter / fuzzy-search / Export CSV over the control list, in every phase — by state, by text, exporting exactly the filtered controls
  • Record Tools panel — overflowing actions collect under a labeled panel, and Export expands in place into report formats (PDF / Word / HTML / Markdown, CSV where tabular)
  • Evidence drafts render richly — bold guidance and colour-coded [[VALUE]]/[[ATTACH]] placeholders, in both the provider flow and the assessor view
  • Dockable navigation polish — icon rail with active highlight and an on-screen preferences popover

🛠 Fixes

  • Bulk "suggest drafts" no longer crashes for assessors (routed through the background worker) and no longer double-escapes &
  • Toolbar dropdowns no longer clipped by their card

📚 Docs

  • Comprehensive six-phase, click-by-click end-to-end tutorial (intake → decision-package close-out), and help sections refreshed for all the above
v5.0.0
2026-09-08
MAJOR

v5.0.0 — Evidence & review, reimagined MAJOR MILESTONE

AI-drafted evidence with fill-in placeholders, a background bulk drafter, an ownership + Ready/history model for providers, and a full assessor review workflow with evidence-strength scoring — plus the in-app release notes page.

✨ Features

  • Contextual assistant + per-control "Suggest a draft" (placeholders for values and attachments), and the assistant can populate fields directly with Approve / Approve all
  • Bulk "suggest drafts" as a background job — drafts only the empty controls, survives navigation/reload, live progress + error reporting
  • Mark Ready / Reactivate, per-control edit history & revert, and an "edited by X (incl. AI)" banner
  • Multi-select bulk actions + status filter (with a right-click menu) on both the evidence and review pages
  • Assessor review: evidence-strength scoring (reliability × sufficiency × impact weight) with a weighted scorecard and weak-evidence flag, review statuses and feedback
  • Return for revision & re-assign — reopens an assessment showing only the controls flagged for re-submission
  • Release notes page that reads live GitHub Releases (curated fallback)

📚 Docs

  • Help centre updated with the new evidence-gathering and assessor-review procedures
v4.0.0
2026-09-08
MAJOR

v4.0.0 — AI-assisted evidence & one-click assignment MAJOR MILESTONE

Draft evidence with placeholders, generated per-control, in bulk, or by the assistant — plus assignment that activates in one step.

✨ Features

  • AI-suggested placeholder evidence: per-control "Suggest a draft", bulk "Suggest drafts (all)", and generation at assign/tailoring time — with [[VALUE]]/[[ATTACH]] placeholders and a soft submit-time warning
  • The evidence assistant now populates fields — proposes drafts with Approve / Approve all instead of copy-paste
  • "Assign & send": assigning an assessment now activates it and sends the invite from one modal
  • Evidence editor: explicit Save, 10s autosave, and a clear "saved" indicator

🔒 Security

  • Passwordless passkey registration on every register page (account created only on passkey confirmation)

🐛 Fixes

  • AI drafts never appear as real evidence in reports (HTML/PDF/DOCX/Markdown)
v3.3.0
2026-09-08
MINOR

v3.3.0 — Evidence ownership & universal redeem

A clear owner for each assessment's evidence, and one link that redeems any invite code.

✨ Features

  • Evidence ownership: take-ownership, read-only when assigned to someone else, and persistent read-only visibility for project users
  • Invite codes are now clickable redeem links, plus a universal "Redeem a code" modal on the intake / assessment / POA&M pages

🔒 Security

  • Assignable-user lists scoped to the caller's workspace (no cross-org users)

🐛 Fixes

  • Fixed "Not found" when creating a project (cross-org name collision in matching)
v3.2.0
2026-09-08
MINOR

v3.2.0 — Multi-tenant isolation & per-user pricing

Every workspace now sees only its own data, and pricing moves to a simple per-user model.

✨ Features

  • Per-user Basic pricing ($49.99/user, all features); centered 3-tier pricing grid
  • Direct edit / view links to an assessment's evidence for the creator

🔒 Security

  • Full multi-tenant data isolation: workspace scoping on every list, detail, and by-id mutation route
  • Client auth parity: passwordless passkey on client login; standardized, localized client registration

🐛 Fixes

  • Fixed intake document analysis exceeding the model context limit
v3.0.0
2026-09-08
MAJOR

v3.0.0 — Reporting engine & dockable navigation MAJOR MILESTONE

A unified multi-format reporting engine and a compact, dockable navigation system.

✨ Features

  • Unified report engine: HTML, PDF, DOCX and Markdown from one model, with org/project branding and a report catalog
  • Prominent Export on every record; per-record intake report; navbar Reports link
  • Compact, dockable navigation + record action toolbar (icons ⇄ text) + round dockable assistant/collaboration buttons
  • Help centre rebuilt as a rendered, refreshed page (assistant how-to rolled in)

🐛 Fixes

  • Fixed "Report not found" on export; phantom blank pages in report PDFs; HTML-escaped inline JS
v2.2.0
2026-09-08
MINOR

v2.2.0 — Decision packages, POA&M & process flow

The authorization workflow: business-process flow, immutable decision packages, and POA&M as conditions.

✨ Features

  • Business-process flow (Intake → Assessment → Decision → Authorized) chevrons
  • Decision packages with immutable assessment pinning + project collaboration
  • POA&M becomes the conditions of a decision package
  • Single unified assistant surface; in-app + batched-email mention notifications

🔒 Security

  • Encrypt tenant secrets at rest

🌐 Content & i18n

  • Whole admin UI localized
v2.1.0
2026-09-08
MINOR

v2.1.0 — Custom domain, integrations & assessment versioning

Custom-domain readiness, real integration validation, and assessment history you can revert.

✨ Features

  • Custom-domain cutover support: multi-origin passkeys + secure cookies
  • Real validation for every org integration, with last-valid-check and 24h logs
  • Assessment versioning: audit history + revert to any prior version
  • Assessment UX: family-focus fix, assistant polish, chat history, version summaries
  • Organization settings: full CRUD incl. delete

🐛 Fixes

  • Stop a stale static overview page from shadowing the live route
v2.0.0
2026-09-08
MAJOR

v2.0.0 — Aegis SA — AI Assessment Assistant + full internationalization MAJOR MILESTONE

The platform becomes Aegis SA: an AI assistant embedded across the assessment lifecycle, fully localized in 8 languages, and mobile-responsive.

✨ Features

  • AI Assessment Assistant: chat-driven control tailoring, plus review and evidence modes with per-control refine and "Approve all"
  • Aegis SA rebrand; mobile-responsive across the app and the assistant
  • Brand logo routes signed-in users to their dashboard

🌐 Content & i18n

  • Full internationalization in 8 languages (nav, register, pricing, product brief, privacy notice); localized external reference links per language

🐛 Fixes

  • Assistant renders replies as a conversation (no raw JSON); several contrast fixes
v1.1.0
2026-09-08
MINOR

v1.1.0 — Bring-your-own AI + token metering

Connect your own AI provider or MCP, or use the built-in AI with transparent metering.

✨ Features

  • Bring-your-own AI provider / MCP endpoint; built-in AI token metering, limits & top-up
  • Global MFA kill-switch (off by default) — no forced QR on sign-in

🐛 Fixes

  • Fixed AI token-pack leak and keyless custom-endpoint fallback
v1.0.0
2026-09-08
MAJOR

v1.0.0 — Commercial foundation — billing, RBAC, licensing & passkeys MAJOR MILESTONE

The first production platform release: self-serve billing, role-based access, licensing, and passwordless sign-in.

✨ Features

  • Stripe hosted-checkout billing + registration funnel
  • RBAC, AI licensing gate & break-glass accounts; licensing/seat console; root-admin console (own SMTP/SMS/domain)
  • Role-scoped dashboards; notification centre; deep-link assignment emails
  • Passwordless passkeys: FIDO2 sign-in and passkey sign-up

🔒 Security

  • Finer per-action assessment RBAC

🐛 Fixes

  • Self-assessment submit spinner fix
v0.9.0
2026-09-08
MINOR

v0.9.0 — Foundations

The first tracked release — project lifecycle basics.

✨ Features

  • Project archive + GitHub-style delete confirmation