Encrypt Online
Theme

Product and Security Changelog

Selected changes that materially affect tool behavior, compatibility, public claims, or release evidence.

Last updated: July 23, 2026

This is a selected public history, not a complete commit log or a claim that an independent security review occurred. An entry describes source included in the corresponding site build; hosting and cache rollout can complete later.

July 23, 2026

  • Added vulnerability-reporting metadata and this public product-and-security changelog.
  • Added a generated tools.json catalog backed by the same manifest used for tool discovery.
  • Added shared WebApplication and breadcrumb structured data to manifest-backed tool routes without ratings or review claims.

July 22, 2026

  • Made AES-GCM the default for the main passphrase-based text workflows while retaining explicit AES-CBC and 3DES compatibility paths for older values.
  • Added a separate OpenPGP message workflow for pasted public and private keys.
  • Applied the modern versioned encryption envelope to Protect Text, Encrypt Link, and Encrypt Tweet while preserving their matching legacy decrypt paths.
  • Documented and enforced the PDF password-protection profile, tightened JWT verification policy, and clarified tools that make direct remote requests.
  • Updated Privacy, Security, About, guide, and tool copy to distinguish page-side processing from sitewide Google Analytics and Google AdSense activity.

July 14, 2026

  • Added bounded SAML, OAuth, OIDC, certificate, PEM, and HTTP security-header inspection workflows with deterministic fixtures.
  • Expanded certificate and key workflows while keeping remote artifact resolution and trust verdicts out of scope.

How changes are reviewed

See Security and Data Handling for current operating boundaries and reporting details.