What has changed
Changes people outside the team can see and use, dated from when they shipped.
This is a selective list, not a complete changelog: dependency updates, refactors and internal work are left out. For whether the platform is reachable right now, see the status page, which reads the live health check. No history of past outages is published.
The after-loss workspace, reachable and in their own words
Someone signing in to the nominee portal now reaches the after-loss checklist straight from the landing page, instead of only through the Family Center. The page also shows the instructions the account holder published for their family. It asks nothing about claims, keys or documents, so it is useful from the first day and before any verification finishes. What a nominee is allowed to open is unchanged.
Sign in with a passkey
You can register a passkey from the security settings and use it to sign in, alongside the existing password and one-time-code options.
The owner's half of the secure document room
Account holders can now see and manage the document room their nominees read from, rather than only the nominee-facing side existing.
Recovery a trusted contact can approve
Key shares can be sealed under a twelve-word phrase, and a contact you name approves a recovery from an emailed link without creating an account of their own. Completing a recovery is a browser step; the mobile apps do not finish one yet.
Two-factor sign-in with an authenticator app
Time-based one-time codes can be turned on from settings and are then required at sign-in.
Messages that arrive afterwards
You can write a message for a named nominee and choose what releases it: verified passing, prolonged inactivity, or whichever happens first. Until then it stays sealed.
A status page that only claims what it can see
The status page reads the platform's overall health check and says so when it cannot reach it. It does not publish per-component metrics or a history of past outages, and it no longer implies that it does.