Alpha testing: all current functionality is free while VAT Engine is in active development

Product updates

Changelog

Track customer-facing product improvements, security outcomes, and compliance reporting updates across VAT Engine.

Archive page 4 of 23.

Latest release
3.6.383
Cross-platform Decision Replay Is Clearer
Releases tracked
270
Since January 2026
Logged changes
785
Across customer-facing categories
SecurityFeatureImprovementFix
3.6.344August 13, 2026

Shopify Buyer Signals Use a Minimized Read

4 changes
Security4 items
  • Ordinary Shopify order imports now omit native buyer-attribution data until the connected app has the required approved access.
  • When approved, direct and historical imports request only the minimized buyer-type discriminator needed by the selected classification option.
  • Missing, unavailable, malformed, or unrecognized buyer evidence remains unresolved instead of being assumed to be consumer activity.
  • The current Order metafield classification workflow remains unchanged while native Shopify options await their remaining approval and policy gates.
3.6.343August 13, 2026

Shopify Classification Decisions Keep Their History

3 changes
Security3 items
  • Changes to a connected store's future customer-classification choice now retain an immutable revision history for audit and recovery.
  • The planned native Shopify choices remain unavailable until protected-data approval and both direct and Bulk Operations checks succeed.
  • Existing stores remain on the current Order metafield workflow unless an owner explicitly changes the setting after those gates are complete.
3.6.342August 13, 2026

Shopify Classification Choices Preserve Store Settings

2 changes
Improvement2 items
  • Future Shopify classification choices now retain an explicit setting for each connected store instead of changing automatically when new Shopify evidence becomes available.
  • Existing stores remain on the current Order metafield workflow, and conflicting updates cannot overwrite a newer saved choice.
3.6.341August 13, 2026

Planned Shopify Classification Uses Fewer Permissions

3 changes
Security3 items
  • The planned native Shopify buyer classification now relies on the existing order permission instead of requesting broader customer access.
  • Protected customer data approval and successful direct and Bulk Operations checks remain required before the option can be enabled.
  • The current Order metafield workflow remains unchanged and available.
3.6.340August 13, 2026

Web Application Maintenance Is Current

2 changes
Improvement2 items
  • The web application now uses the latest reviewed maintenance releases across its interface and documentation components.
  • Installation checks were refreshed so production builds continue to use one reproducible dependency set.
3.6.339August 13, 2026

Login Protection Handles Repeated Requests More Efficiently

2 changes
Security2 items
  • Repeated sign-in requests from an already blocked source now stop before creating additional account-specific checks.
  • This keeps login protection available to unrelated visitors during a temporary shared-cache outage.
3.6.338August 13, 2026

Service Updates Preserve Security Corrections

2 changes
Security2 items
  • Approved security corrections now remain available throughout service update preparation.
  • Main application and maintenance updates now use the same reviewed software inputs.
3.6.337August 12, 2026

New Recovery Sessions Replace Older Ones

3 changes
Security3 items
  • Starting a newer two-factor recovery now invalidates every older outstanding recovery session.
  • Regenerating backup codes also invalidates recovery sessions created from the previous code set.
  • Authentication throttles remain independent when unrelated request traffic rises during a temporary shared-cache outage.
3.6.336August 12, 2026

Public Navigation And Previews Are Safer

3 changes
Security3 items
  • Account recovery now returns visitors consistently to the correct public sign-in page.
  • Missing-page social previews now use the deployed VAT Engine site address.
  • Public pages reject script-bearing page attributes while preserving normal navigation and rendering.
3.6.335August 12, 2026

Account Recovery Rejects Duplicate Requests

3 changes
Security3 items
  • Password-reset and email-verification links now accept only one successful redemption even when duplicate requests arrive together.
  • Two-factor recovery now rejects reused backup codes and expired or already-completed recovery sessions before authenticator settings can change.
  • Authentication rate-limit protection keeps a fixed memory ceiling during a temporary shared-cache outage.
3.6.334August 5, 2026

Shopify Classification Access Checks Are App-Bound

3 changes
Security3 items
  • Planned native Shopify classification cannot be enabled by stale evidence or authorization from a different app or store installation.
  • Missing permissions, invalid Shopify responses, and incomplete Bulk Operations checks continue to keep the feature unavailable instead of weakening review requirements.
  • The existing Order metafield workflow and currently requested Shopify permissions remain unchanged.
3.6.333August 5, 2026

Native Shopify Classification Remains Approval-Gated

3 changes
Improvement3 items
  • VAT Engine now records the exact Shopify access that must be approved and verified before native buyer attribution can become available.
  • The planned native check uses only the order buyer-attribution type and does not request customer names, contact details, addresses, company details, or tax identifiers.
  • The existing Order metafield workflow remains unchanged while Shopify access and direct and Bulk Operations compatibility are reviewed.