Released
Changelog Update: July 2025
We've enhanced regional compliance, improved documentation coverage, and strengthened security across our services.
Legal and Compliance
Regional Terms of Service
- Clearer Legal Entity Selection: Users can now easily identify which legal entity (EU or UK) they contract with based on their location, ensuring compliance with regional regulations and providing clear recourse for service complaints.
Documentation and Site
API Documentation
- API documentation: Added Authorizer and Gateway service OpenAPI specifications to documentation, ensuring all core services have comprehensive API documentation
- Streamlined Documentation Structure: Standardized page titles across management and services documentation for improved navigation.
- Authorizer policy documentation: Documented Authorizer policies meaning that all service policies are now documented.
- Validator error documentation: Clear documentation for each error that the validator returns. Each error is described, including possible causes and suggested resolutions.
Services
- Validator: created improved error handling to return clearer more consistent errors that link to documentation.
- Validator: now supports combining trusted sources, e.g. a Vical and provided trust certificates.
Security and Infrastructure
ISO 27001
- Surveillance Audit: Completed the scheduled ISO 27001 surveillance audit in July 2025 with no nonconformities raised.
Security Enhancements
- Critical Vulnerability Patched: Updated @cef-ebsi/ebsi-did-resolver to address CVE-2025-7783, eliminating predictable boundary value generation in form-data requests.
- API Documentation: explicitly indicated public endpoints on API documentation.