Changelog
A dated record of changes to tools, compatibility, and site security.
- Added recipient-ready share links to Encrypt Text. A link opens Decrypt Text with the encrypted message already loaded; the passphrase stays separate.
- Published a sender and recipient guide for testing the link and delivering the passphrase separately.
- Published versioned evidence records for six diagnostic tools, with synthetic cases, expected results, and source hashes.
- Added a root llms.txt discovery map for tools, guides, public evidence, and site operating boundaries.
- Rewrote the short meta descriptions identified in the Bing report and added a generated-site regression check for them.
- Added deployment configuration for a permanent
www-to-apex redirect and a CloudFront security-header baseline. The Content Security Policy starts in report-only mode.
- Expanded the OpenPGP message workflow with full recipient-key inspection and clearer sender and recipient guidance.
- Added a client-side Curve25519 OpenPGP key-pair generator with passphrase protection and revocation material.
- Added security.txt and the first public Changelog.
- Published a generated tools.json catalog backed by the tool manifest.
- Added shared application and breadcrumb structured data to manifest-backed tool routes.
- Made AES-GCM the default for new passphrase-based text while keeping explicit AES-CBC and 3DES compatibility for older values.
- Added a separate OpenPGP message workflow for pasted public and private keys.
- Applied the versioned encryption envelope to Protect Text, Encrypt Link, and Encrypt Tweet, with matching legacy decrypt paths retained.
- Documented and enforced the PDF password-protection profile, tightened JWT verification policy, and clarified tools that make direct remote requests.
- Clarified the difference between browser-side tool processing and sitewide Analytics or advertising activity.
- Added bounded SAML, OAuth, OIDC, certificate, PEM, and HTTP security-header inspection workflows with deterministic fixtures.
- Expanded certificate and key workflows with local inspection as the focus; remote artifact resolution and trust verdicts remain outside those tools.
Current security information
See Security and Data Handling for current processing boundaries, limitations, and reporting details.