Every change,
shipped transparently
38 releases, 284+ changes, and 18 months of continuous development. See exactly what we shipped and when.
Development velocity
18 months of continuous shipping - features, fixes, and enterprise capabilities delivered every month.
Release Cadence
Shipping every month
Consistent delivery cadence with monthly releases, quarterly major versions, and continuous security patches - 38 releases across 18 months.
Release Activity
Changes shipped per version
Release timeline
Every version, every change, with full details. Filter by category or search for specific changes.
v5.1.0
Two New Verticals & Operational WiringLatestTwo compliance verticals, mental-health services and Australian financial services, join NDIS, so providers in those sectors start against a real control set instead of a blank framework. Several capabilities that existed in the data model but had no way in, structured incident investigations, regulatory-notification tracking, the medication chart’s add action, executive-digest scheduling, are now wired end to end. The automation engine that had been dormant since we removed the external task runner runs again, this time on the platform’s own scheduler.
v5.0.0
FORMAOS, New IdentityMajorA full visual rebrand. The product is now FORMAOS, with a charcoal wordmark and an “FO” monogram in place of the previous cyan shield, and a near-monochrome palette across the app, the marketing site, the sign-in screens, email and PDF exports. Alongside the new look, every marketing claim was re-checked against what the codebase actually does, invented personas, round-number metrics and any statement the product could not stand behind were removed.
v4.5.0
Verifiable Audit Trail & Public Trust SurfaceMajorThe audit trail moves from a plain hash chain to a keyed, externally-anchored one, and customers can now verify it themselves without having to trust us. New public pages give procurement and security reviewers the evidence they ask for: a live status page and a self-serve audit-bundle verifier. Account security gains login lockout and tighter MFA handling, evidence files are hashed on upload and re-checked on download, and GDPR erasure now runs as a queued, auditable purge.
v4.4.0
Privacy Self-Serve & Operational ContinuitySelf-serve data-rights surface so customers can exercise GDPR Article 15 (access), Article 17 (erasure), and Article 20 (portability) without filing a ticket. Public operational runbooks and a low-fidelity integrity probe close the trust-page gaps procurement teams flag in security questionnaires. Account deletion now cascades into Stripe correctly, and the /changelog page itself paints noticeably faster after a long-running cookie-banner LCP regression was resolved.
v4.3.0
Tenant Integrity & Billing HonestyMajorAudit re-pass on the v4.0 Foundation Audit work. Two independent passes, a fresh end-to-end audit and a verification of the resulting fix sweep, surfaced gaps that a single pass missed: a cross-org permission leak, a defence-in-depth IdP-init SAML gate, billing webhooks that could be steered by attacker-controlled metadata, three silent try/catch blocks in the compliance evaluator, and care-plan mutations on PHI that had no audit trail. Thirty PRs landed (v4-001 through v4-031). This release block is what changed in the final round plus the substantive themes from the sprint as a whole.
v4.2.0
Compliance FoundationsMajorPer-control evaluator infrastructure for SOC 2 and ISO 27001, typed registry, expanded framework packs to standard control counts, twelve working SOC 2 evaluators, real PDF report engine with brand typography, and a production-database bootstrap that finally landed eleven outstanding April migrations.
v4.1.0
Mobile SurfaceTrack 1 of the two-track mobile plan: the existing /app routes polished for phone and tablet browsers. Eighteen routes audited at iPhone 14, iPhone SE, iPad portrait, and iPad Pro. Track 2 (a separate native app for frontline employees) is scoped in mobile/SCOPE_DECISION.md but intentionally not started.
v4.0.0
Foundation AuditMajorWide-spectrum audit pass across authentication, authorisation, billing, observability, compliance honesty, and CI discipline. Closed seven blockers and thirteen high-severity findings identified during a from-scratch code-and-runtime review. Real row-level security replaces never-evaluated placeholder policies on fourteen multi-tenant tables; MFA is enforced at login rather than enrolled-then-ignored; trust packets are signed; CI gates actually block merges.
v3.8.0
Evidence IntegrityMajorEvidence and audit integration pass: obligation uploads now write to Supabase storage, evidence rows link back to obligations and typed entities, the obligations register reads real evidence counts, and audit-trail activity is available through a new entity-filtered API.
v3.7.4
Guided StartFirst-session onboarding now guides users through real setup work across care plans, goals, progress notes, evidence, and tasks, with persistent progress and contextual guidance inside the app.
v3.7.3
CareflowCare Plans moved from static records into a working module with goals, supports, progress calculation, participant context, status transitions, journey boards, and RLS hardening.
v3.7.2
Operating MotionBuying paths, dashboard signals, and workflow handoffs were cleaned up so the public site and authenticated app better match FormaOS as compliance infrastructure.
v3.7.1
Reconcile IIAudit re-pass: added CSRF origin validation to three admin mutation routes that relied on SameSite cookies alone, brought in-app plan comparison copy back in line with marketing, and cleared all remaining eslint warnings.
v3.7.0
ReconcileEnd-to-end audit sprint: fixed in-app upgrade prices to match marketing and Stripe, hardened the billing checkout API with schema validation and role gates, repaired a dashboard CTA link, and tightened trust claims on marketing.
v3.6.0
HorizonMajorEnterprise marketing overhaul: 100x homepage upgrade with social proof and visual refresh, enterprise marketing pages Phase 1 & 2, Stripe webhook billing fix, Tailwind class audit with legacy btn migration, and reduced layout bloat across all marketing pages.
v3.5.0
PrismMajorProduct maturity and growth sprint: full billing, emails, onboarding, and monitoring infrastructure, comprehensive SEO engine with IndexNow and structured data, LCP performance fix from 4.2s to sub-2s, enterprise theme upgrade across all 5 themes, blog internal linking, and updated marketing mockups.
v3.4.0
SentinelMajorQuality and performance sprint: TypeScript any cleanup across 65+ files, admin command center decomposition from 1,908 to 303 lines, 47 WCAG 2.1 AA accessibility fixes, mobile responsiveness for 6 pages, statement coverage from 53% to 55% with 200+ new tests, and performance validation with clean production build.
v3.3.0
CatalystMajorMaster sprint: guided onboarding wizard, demo seed data for 6 industries, financial services compliance dashboard, branch coverage from 34% to 50%, TypeScript any cleanup across 50 files, and employer dashboard decomposition from 1,840 to 528 lines.
v3.1.1
BastionEnterprise audit remediation: resolved all 5 blocking issues - XSS sanitization, global API rate limiting, error handling across 36 route files, dependency vulnerabilities patched to zero, and full test suite passing at 896 tests.
v3.1.0
CitadelMajorEnterprise governance expansion: framework cross-mapping, task management, usage analytics, permissions matrix, policy lifecycle, document retention, org branding, dashboard builder, integration marketplace, and enhanced audit trail.
v3.0.0
NexusMajorPlatform infrastructure overhaul: third-party integrations, threaded comments, report generator, webhook relay, evidence versioning, risk analytics, AI insights, email system, compliance scanner, dashboard widgets, API v1, and scheduled tasks.
v2.2.4
MeridianFull platform audit at extreme level, marketing homepage expansion from 6 to 11 visible sections, flagship page copy hardening, and comprehensive test suite fixes.
v2.2.3
HorizonQA stability hardening for signup, smoke checks, release verification, and dashboard pages still touching fragile auth-admin paths.
v2.2.2
SentinelProduction hardening for onboarding, invitations, report exports, and live validation across roles, industries, and dashboard states.
v2.2.1
KeystoneEnterprise audit remediation focused on auth correctness, schema migration cleanup, test coverage, and non-mutating quality gates.
v2.2.0
VanguardMajorAI-powered compliance assistant, SOC 2 self-certification engine, and automated evidence collection.
v2.1.0
AuroraCommand palette 2.0, real-time collaboration, and 3 new integrations.
v2.0.0
SovereignMajorMajor release: SCIM 2.0, compliance gates, risk heatmap, and workflow automation.
v1.9.0
MeridianPCI-DSS framework, incident management, and evidence version control.
v1.8.0
BastionNIST CSF framework, automation templates, and data residency controls.
v1.7.0
VectorCIS Controls framework, Slack integration, and compliance scoring engine.
v1.6.0
PrismGDPR framework, notification center, and task management overhaul.
v1.5.0
AegisMajorSOC 2 framework, evidence vault with SHA-256, and immutable audit trail.
v1.4.0
CipherInline comments, global search, and care plan management for NDIS providers.
v1.3.0
SentinelAutomation engine, webhook integrations, and framework cross-mapping.
v1.2.0
KeystoneTeam management, role-based access, and compliance dashboard v1.
v1.1.0
FoundationEvidence upload system, control library, and basic task management.
v1.0.0
GenesisMajorInitial launch with ISO 27001 framework pack and core compliance platform.
By Category
Change breakdown
Distribution of changes across categories - reflecting our focus on features, security, and enterprise capabilities.
Version History
Complete release history
Key Milestones
The journey from Genesis to Horizon
18 months of continuous development - from single-framework launch to enterprise compliance operating system.
Platform Launch
FormaOS v1.0.0 Genesis launched with ISO 27001 framework pack and core compliance infrastructure.
Evidence Vault Shipped
SHA-256 cryptographic evidence verification with immutable chain-of-custody and version control.
7 Framework Packs
Full coverage across ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, NIST CSF, and CIS Controls.
Enterprise SSO & SCIM
SAML 2.0 SSO with Okta, Azure AD, and Google Workspace plus SCIM 2.0 automated provisioning.
Platform Infrastructure Overhaul
v3.0 Nexus: integrations engine, REST API v1, report generator, webhook relay, AI insights, and scheduled tasks.
Enterprise Governance Expansion
v3.1 Citadel: framework cross-mapping, task management, permissions matrix, policy lifecycle, dashboard builder, and integration marketplace.
Enterprise Marketing & Growth
v3.6 Horizon: 100x homepage redesign, comprehensive SEO engine, LCP performance fix, 5-theme enterprise upgrade, and full product maturity infrastructure.
Foundation Audit
v4.0 Foundation Audit: closed seven blockers and thirteen high-severity findings, real row-level security on fourteen multi-tenant tables, MFA enforced at login, signed trust packets, default-on CSRF, hardened SAML, AUD/GST checkout, and CI gates that actually block merges.
Compliance Substrate
v4.2 Compliance Foundations: per-control evaluator registry, framework packs expanded to all 64 SOC 2 TSC criteria and 93 ISO 27001:2022 Annex A controls, twelve working SOC 2 evaluators, and a real PDF report engine with brand typography for board packs and posture reports.
Stay Updated
Never miss a release
Get notified when we ship new features, framework packs, and platform improvements. No spam - just releases.
