Alpha testing: all current functionality is free while VAT Engine is in active development

Product updates

Changelog

Track customer-facing product improvements, security outcomes, and compliance reporting updates across VAT Engine.

Archive page 14 of 33.

Latest release
3.6.506
More Complete Blog Subscriptions
Releases tracked
392
Since January 2026
Logged changes
1225
Across customer-facing categories
SecurityFeatureImprovementFix
3.6.346August 14, 2026

Service Security Protections Updated

2 changes
Security2 items
  • VAT Engine services now include the latest security protections for encrypted connections, structured data, web requests, and links.
  • Customer workflows and stored VAT records are unchanged by this maintenance update.
3.6.345August 14, 2026

Historical Shopify Buyer Classification Stays Protected

3 changes
Security3 items
  • Historical Shopify imports now use native buyer attribution only when the connected app has current approved access.
  • Resumed historical imports recheck that access before retrieving completed or partial native buyer-attribution results.
  • Unexpected or unrecognized historical data remains unresolved instead of producing a confident customer classification.
3.6.344August 13, 2026

Shopify Buyer Signals Use a Minimized Read

4 changes
Security4 items
  • Ordinary Shopify order imports now omit native buyer-attribution data until the connected app has the required approved access.
  • When approved, direct and historical imports request only the minimized buyer-type discriminator needed by the selected classification option.
  • Missing, unavailable, malformed, or unrecognized buyer evidence remains unresolved instead of being assumed to be consumer activity.
  • The current Order metafield classification workflow remains unchanged while native Shopify options await their remaining approval and policy gates.
3.6.343August 13, 2026

Shopify Classification Decisions Keep Their History

3 changes
Security3 items
  • Changes to a connected store's future customer-classification choice now retain an immutable revision history for audit and recovery.
  • The planned native Shopify choices remain unavailable until protected-data approval and both direct and Bulk Operations checks succeed.
  • Existing stores remain on the current Order metafield workflow unless an owner explicitly changes the setting after those gates are complete.
3.6.342August 13, 2026

Shopify Classification Choices Preserve Store Settings

2 changes
Improvement2 items
  • Future Shopify classification choices now retain an explicit setting for each connected store instead of changing automatically when new Shopify evidence becomes available.
  • Existing stores remain on the current Order metafield workflow, and conflicting updates cannot overwrite a newer saved choice.
3.6.341August 13, 2026

Planned Shopify Classification Uses Fewer Permissions

3 changes
Security3 items
  • The planned native Shopify buyer classification now relies on the existing order permission instead of requesting broader customer access.
  • Protected customer data approval and successful direct and Bulk Operations checks remain required before the option can be enabled.
  • The current Order metafield workflow remains unchanged and available.
3.6.340August 13, 2026

Web Application Maintenance Is Current

2 changes
Improvement2 items
  • The web application now uses the latest reviewed maintenance releases across its interface and documentation components.
  • Installation checks were refreshed so production builds continue to use one reproducible dependency set.
3.6.339August 13, 2026

Login Protection Handles Repeated Requests More Efficiently

2 changes
Security2 items
  • Repeated sign-in requests from an already blocked source now stop before creating additional account-specific checks.
  • This keeps login protection available to unrelated visitors during a temporary shared-cache outage.
3.6.338August 13, 2026

Service Updates Preserve Security Corrections

2 changes
Security2 items
  • Approved security corrections now remain available throughout service update preparation.
  • Main application and maintenance updates now use the same reviewed software inputs.
3.6.337August 12, 2026

New Recovery Sessions Replace Older Ones

3 changes
Security3 items
  • Starting a newer two-factor recovery now invalidates every older outstanding recovery session.
  • Regenerating backup codes also invalidates recovery sessions created from the previous code set.
  • Authentication throttles remain independent when unrelated request traffic rises during a temporary shared-cache outage.
3.6.336August 12, 2026

Public Navigation And Previews Are Safer

3 changes
Security3 items
  • Account recovery now returns visitors consistently to the correct public sign-in page.
  • Missing-page social previews now use the deployed VAT Engine site address.
  • Public pages reject script-bearing page attributes while preserving normal navigation and rendering.
3.6.335August 12, 2026

Account Recovery Rejects Duplicate Requests

3 changes
Security3 items
  • Password-reset and email-verification links now accept only one successful redemption even when duplicate requests arrive together.
  • Two-factor recovery now rejects reused backup codes and expired or already-completed recovery sessions before authenticator settings can change.
  • Authentication rate-limit protection keeps a fixed memory ceiling during a temporary shared-cache outage.