Hummand presents

Changelog

Releases of the production repositories, from the gateway to the front ends and the verifier.
Every entry comes from the repository's own changelog.

Category
ResourcesChangelog

Releases

C01gateway0.5.12026-09-07

Fixes before deploy; 0.5.0 never went live

Four defects found in adversarial review, fixed before going up.

Retention did not reach the context of acts created by the new API; irreversible erasure now requires a scope of its own that no integration receives by default; the public proof no longer exposes the act position in the chain; mandate revocation inherits sandbox mode.

Documented the erasure limit: standalone document validations are not reached on request, only by the period.

See Security
C02gateway0.5.02026-09-07

Mandate, chaining, exception and alerts; acceptance scenarios; what the front ends asked for

Three phases of the plan in one release, replaced by 0.5.1 before going live.

Dual operator with composite receipt; agent mandate with scope and revocation; delegated act; exception proof triggered by the client or a source; alerts computed on read, with the expiry event; deciding the review queue requires the reviewer's fresh presence.

Two test tenants and four scenarios as the acceptance suite, every act with its receipt verified outside the gateway. Read-only policy, data subject privacy, receipt by link token and revocation from the dashboard.

See Act
C03dash · verificar · admin2026-09-07

The front ends in the act vocabulary

Dashboard, journey and console speak of acts, receipts, mandates and policy.

Dashboard: screens for acts, receipts with batch export, mandates with revocation, alerts, read-only policy and privacy on the real routes. Journey: mandate scope step, proof at the end, accessibility for elderly users, initial bundle from 1.39 MB to 209 kB. Console: queue decision only with the reviewer's fresh presence.

Types generated from the OpenAPI contract in all three; ninety hand-written types removed.

C04gateway0.4.02026-09-06

A failed match makes the act negative

Product decision: API and receipt now say the same thing.

Live presence with a failed match is a negative act, no longer positive with a separate match verdict. A match requested and not computed is a technical failure, with the reason in the receipt.

C05gateway0.3.12026-09-06

A key-module error no longer brings down the API

Fix after the 0.3.0 deploy.

The app did not start because the key policy denied the receipt service the right to read the public key. Now the error goes to the log, the JWKS comes out empty without cache and is retried on every request; the key policy was fixed and documented.

C06gateway0.3.02026-09-06

humanproof/1 receipts

Issuance on every terminal transition, endpoints, webhook, public key and expiry by deadline.

Receipt per act and batch in chain order; recibo.emitido event with ids and hashes, never content; public JWKS; expiry sweep every minute moving overdue acts to expired, with a receipt.

See Receipt
C07humanproof-verify0.1.02026-09-06

Command-line verifier

First release, with binaries for Linux, macOS and Windows and checksums.

Verify a receipt or a batch against a JWKS from a file, report in text or JSON, exit codes 0, 1 and 2; hash, genesis and canonicalization. Offline by construction.

C08humanproof-core2026-09-06

The receipt library

One implementation in Rust for the server, the command line and the browser.

RFC 8785 canonicalization restricted to safe integers, hashing, ES256 signature, JWKS, per-client chain with genesis, coherence and the embedded format schema. Python binding with two-step issuance to sign in the key module; WebAssembly target for verification only.

C09labs2026-09-06

labs.hummand.com.br is live

The verifier in the browser and the first note.

Verification page entirely in the browser, with the JWKS pasted or fetched from the gateway; the note "The humanproof/1 format". Published by Cloudflare Pages from the main branch.

Go to Labs
C10gateway0.2.02026-09-06

The act domain in production

Checks become acts; the policy resolves the steps; the contract comes first.

Catalogue of the twelve types with defaults, global policy v1 and pure, deterministic resolution; act routes with the journey link; batch with a common deadline; versioned OpenAPI contract and a TypeScript client generated from it, checked in CI. The check routes remain as an alias.

C11gateway0.1.02026-08-22

First tagged version

What was in production after June to August 2026.

Verifications with live presence and transient match, consent per step, policy-driven journey by link, dashboard authentication with MFA, operations console, signed webhooks, notifications, envelope per record, decryption trail, row-level isolation and crypto-shred.

1.0

Verify a receipt

Paste the JSON and the public key. No account, nothing sent: it runs in your browser.

Open the verifier
2.0

Talk to us

A technical conversation, straight with the people who build it, no sales script.

Contact