This is the published record of what changed in Wakemark and whether it affects you. It covers behaviour you can observe: what the product does, what it charges for, what it stores, and what it claims. Where a defect could have affected your account, it says so and says what changed.
Dates are when the change shipped. The engine reports the build it is running at GET /version, so you can always tell which of these a given deployment has.
How to read this
Entries are grouped by the part of the product they affect, not by release. Releases are cut as version tags and deployed from them, but a single tag spans several of these groups, so this page does not invent per-version sections it cannot back. The date on an entry is the date that change shipped. To check which build a deployment is actually running, ask its engine — GET /version reports it.
This is the record written for you: behaviour you can observe, including the defects behind the corrections. A separate engineering changelog is kept for contributors, with the reasoning and the internals; it is not a second list of user-visible changes.
Billing and limits
2026-07-27
Corrected how the included allowance is applied (2026-07-27). The per-cycle job allowance was resetting on the 1st of the calendar month rather than on your subscription's own renewal date. An account that subscribed mid-month could therefore receive a second allowance inside a single billing cycle, and usage past the first one could be billed as overage even with overage switched off — the setting under which the bill is not supposed to exceed the base price. The allowance now resets on your renewal date, and the usage endpoint reports which window it is counting.
2026-07-27
The ceiling, the usage meter and the invoice count the same thing (2026-07-27). All three said "jobs" and two of them measured different quantities: the hard ceiling counted every job admitted in the period, while the invoice counted only jobs that reached success. The dashboard number and the invoice line could not both be right. Everything now counts admitted jobs — a job that was routed and run is a job, whatever the provider returned — and a refused job (cap, frozen account, archived project) is rolled back with the request and can never appear on an invoice.
2026-07-23
Plan limits lift when you upgrade (2026-07-23). Free-tier ceilings were stamped at signup and nothing ever raised them, so an account that upgraded kept the free tier's hard stop and could see a paid plan next to a free-tier limit. Ceilings now follow the plan.
2026-07-23
The storage allowance shown is your plan's (2026-07-23). The dashboard displayed a flat 10 GB for every account, which matched no plan and was wrong in both directions.
2026-07-23
Set your own ceilings (2026-07-23). Job-count and storage ceilings you control, independent of your plan's. A new paid account starts with overage off and its ceiling at the included allowance, so generation stops at the number you bought and the bill cannot exceed the base price without a deliberate change. A ceiling you set is never raised by a plan change.
2026-07-23
Refusals say which limit you hit (2026-07-23). A stop because the free tier ran out, because a paid allowance ran out with overage off, because you set a ceiling, or because a project cap was reached are four different situations with four different next steps. They are now four distinct responses rather than one generic "rate limited".
2026-07-23
Customer portal and renewal date (2026-07-23). Manage a subscription from the dashboard, and see when the current period ends.
2026-07-11
Hard caps that stop generation (2026-07-11). Independent job-count and resident-storage caps per project, with an optional account-wide ceiling: a warning at 80% and a hard stop at 100%, refused before a provider is called rather than after the money is spent. Off by default.
2026-07-10
Usage metering (2026-07-10). An append-only metering record behind the usage view: jobs, stored bytes over time, and the timestamps for both. Customer-owned storage is never metered.
Provenance and the Article 50 export
2026-07-27
"Verified" now requires positive evidence (2026-07-27). A C2PA manifest whose validation verdict Wakemark did not recognise was reported as verified. That is the exact collapse the four states exist to prevent. Verified is a positive claim and now needs positive proof; anything else reads as present-but-unverified.
2026-07-08
A false "verified" on tampered assets (2026-07-08). A change in the inspection tool's output meant a manifest that failed validation could be reported as verified. Fixed, and the parsing is now pinned by tests that run the real tool against a genuinely signed asset and an unsigned one.
2026-07-27
"Not inspected" says why (2026-07-27). It used to be one bucket under one explanation — that our detector was unavailable — which for an account that had waived output custody covered 100% of its outputs and was simply untrue. It is now split by cause: custody waived, transfer failed, transfer not yet done, and detector did not run. Only the last is ours to fix, and the gap report is meant to be acted on.
2026-07-27
The report claims only what your deployment can back (2026-07-27). The export used to tell every reader that any asset id in it resolves on a public verifier without an account. That depends on switches that default off. The report now asserts the verification loop only where it is actually enabled, and where it is not, says so in words rather than printing links that lead nowhere.
2026-07-27
A downloaded report refuses to ship links that cannot resolve (2026-07-27). A downloaded report travels — it is opened from a filesystem, mailed to a lawyer, attached to a file. It was printing site-relative verification links, which resolve against whatever host the reader happens to be on. Downloads now refuse rather than emit a link to nowhere. The in-dashboard preview, where a relative link is correct, is unchanged.
2026-07-27
Two definitions the report was missing (2026-07-27). "Jobs covered" counts every generation request admitted in the period — succeeded, failed, cancelled and still running alike — which is not a count of outputs, and printing it directly above an output count without saying so invited the wrong subtraction. Jobs still running when the report was generated are now counted separately. And the declared role is now labelled as declared: it is your legal determination about your own business, never something Wakemark detected or assumed.
2026-07-27
What we hold, separately from what is stored (2026-07-27). A purge keeps an asset's record so its digest survives, so "stored" was never the same as "bytes we hold". The report now distinguishes them, and bytes in a customer-owned bucket we have concluded we cannot reach stop counting as bytes we hold.
2026-07-27
A rendering fault in the downloaded report (2026-07-27). The arrow in every provenance-chain line was rendering as the wrong characters — in the section a reviewer reads to follow lineage. Fixed, along with a blank-page fault in the document footer.
2026-07-10
The audit export (2026-07-10). The ledger rendered as the report a compliance reviewer reads: coverage per output asset, a gap report broken down by cause and provider, provenance chains across providers, and the statements of what the document does and does not attest, carried inside the document itself. The coverage summary and the full gap report are free; the auditor-ready document is part of a paid plan.
2026-07-08
Public verification (2026-07-08). A public page and a public read for checking an asset's digest, model, timestamps and C2PA state without an account. The response is redacted to non-sensitive provenance fields, and an unknown id returns the same answer as a purged one.
2026-07-23
No fragment of a provider key is kept anywhere (2026-07-23). A display fingerprint of connected keys was briefly added to the dashboard. It put part of a customer secret outside the encryption envelope for the first time, and three documents said we never do that. It was withdrawn entirely — the column, the field, the API property and the UI.
2026-07-08
A signed URL's credential could reach a public response (2026-07-08). The public verification proxy dropped prompts, raw provider URLs and storage keys, but passed one metadata field through untouched — and a provider's pre-signed URL carries a credential in its query. That field is now stripped at the proxy as well as upstream.
Storage, retention and your data
2026-07-27
Inline outputs are no longer kept in the database (2026-07-27). Some providers return the generated file inline rather than as a link to download. That inline copy — the whole asset — was being retained in our database indefinitely under the default retention policy. It is now dropped as soon as the file is in storage with its digest recorded. Two cases deliberately keep it: before the transfer runs, and after a transfer permanently failed, because in both it is the only copy of your output that exists.
2026-07-27
Email preference links change with each email (2026-07-27). The token behind the "manage preferences" link in email footers is now stored only as a one-way hash, so it cannot be handed out twice. Each email carries a fresh link and the previous one stops working. Your most recent email always has a working link, and preferences can now be changed from the dashboard holding no link at all.
2026-07-27
Account deletion removes email preferences (2026-07-27). They previously survived a deletion. One consequence worth knowing: if you administer more than one account and one of them is deleted, your remembered email preferences reset to the default and can be set again from the dashboard.
2026-07-27
Asset views are served from the edge (2026-07-27). Platform-stored asset bytes are served directly from object storage at the edge rather than proxied through the web tier. Faster views, and the bytes are never re-encoded on the way. Assets in your own bucket keep the authenticated path.
2026-07-09
Bring your own bucket (2026-07-09). Connect your own S3-compatible storage and Wakemark writes generated bytes there, with the same byte-exact write, the same digest in the ledger, and the same provenance record beside the file. Bytes in your bucket are never metered, and account deletion removes our access and our records without touching them.
2026-07-09
Per-project retention (2026-07-09). Independent lifetimes for inputs and outputs, per project. When a deadline passes, the bytes are deleted and the content-bearing fields of the record are replaced by a marker carrying the digest and length of what was removed — so what was purged is provable without being kept. The record survives as a tombstone, which means a file you downloaded a year ago can still be checked against its digest.
2026-07-09
Account deletion and erasure (2026-07-09). Request deletion and the account freezes and provider credentials are purged immediately; a grace period follows in which you can cancel or export everything; at the deadline a hard purge removes the content stores we control. What survives is a content-free receipt and anonymised usage records.
2026-07-10
Storage accounting corrections (2026-07-10, 2026-07-12). Several situations where bytes could remain in storage without a corresponding record, or a deletion could be counted twice, were closed. These affected the accuracy of the storage figure on your usage view.
Reliability and routing
2026-07-15
Failover, retries and circuit breakers (2026-07-15). A job fails over only on failures scoped to the provider it was attempted on, never on ones that would fail identically everywhere — retrying a content refusal or an invalid input would just spend your money twice. Submit retries use backoff with jitter under a budget, and a circuit breaker tracks each provider and capability separately, so one provider's video endpoint being down does not demote its image endpoint.
2026-07-15
Routing policy per project (2026-07-15). Restrict which providers a project may use, pin specific models per capability, and choose between failover order and cheapest-first.
2026-07-15
Provider health, from real traffic (2026-07-15). A public status view of circuit state per provider and capability, derived from actual job outcomes. It reports "no data" as no data rather than as health, and publishes no uptime percentages, because none are measured.
2026-07-07
A job could hang after succeeding (2026-07-07). The playground could sit on "Generating…" after a job had already finished. Fixed.
Dashboard and playground
2026-07-24
The dashboard is an application shell (2026-07-24). Providers, storage and the audit export are primary destinations rather than settings sub-pages; settings keeps only what you configure. Every page states its scope, which closes a case where switching projects could silently change what you were looking at. Plus a command palette and a consistent table treatment across every list of records.
2026-07-23
Settings rebuilt (2026-07-23). Billing, account, projects, retention, API keys and usage on one consistent pattern.
2026-07-08
The playground as a workspace (2026-07-08). Model-centric, with parameter controls generated from each model's real schema, a passthrough for provider-specific parameters the unified API does not model, a provenance receipt on every output with a copyable digest and a verification link, and a compare mode that runs one prompt across several providers with a per-output receipt and a cost estimate before you run it.
Providers and models
2026-07-09
A catalogued model has been run (2026-07-09). Nothing appears in the model catalogue as supported unless a real end-to-end run passed, and each entry carries the date it was last verified. Enforced by a test, not a convention.
2026-07-07
Browse models and providers before connecting (2026-07-07). Public pages for every model Wakemark routes to, with capabilities, verified dates and price estimates, plus a staleness flag on any price older than 30 days.
2026-07-06
Credential checks that do not cost anything (2026-07-06). Connecting a provider key verifies it against a no-cost endpoint rather than by spending money on a generation.
2026-07-07
A credential check reported invalid keys as verified (2026-07-07). For one provider, Wakemark's verification accepted keys that were not valid. Fixed — only a positive response affirms a key now.
2026-07-07
A credential check rejected valid keys (2026-07-07). For another provider, restricted-scope keys that worked were reported as invalid. Fixed.
2026-07-07
A shared parameter failed on three providers (2026-07-07). The canonical aspect-ratio parameter returned an error on three adapters instead of being translated. Fixed.
Trust, privacy and documentation
2026-07-27
This changelog (2026-07-27). A published record of what changed and whether it affects you, kept separately from the engineering changelog our contributors read. The two answer different questions and one document cannot do both well: theirs carries reasoning and internals, this one carries behaviour you can observe — including the defects behind the corrections above.
2026-07-27
Public documentation (2026-07-27). Conceptual documentation at /docs: what Wakemark is and is not, how bring-your-own-key works and what we can and cannot see, custody and what the digest proves, provenance and the four C2PA states, storage connectors, retention, the Article 50 export, and how a third party verifies a record. An API reference is not published yet: the contract is maintained and will generate one, and a hand-written reference to an API that is still moving would be wrong within a week.
Every page ends with what it can be checked against — the public verifier, the model catalogue, the legal documents, the AI Act's own text, the open-source C2PA implementation — rather than asking to be taken on our word. Where a claim rests on something only we can see, the page says what it is rather than citing a document you cannot open.
2026-07-13
Subprocessor disclosure by category (2026-07-13). The public legal surface discloses the third parties that process data by functional category and region — cloud object storage, managed database, key management, compute, authentication, transactional email, and web hosting and analytics; in the EU except authentication, email and hosting, which are in the US. The itemised named list is provided to customers under the data processing agreement on request, with at least 30 days' notice before any addition or replacement.
2026-07-10
The legal set, published (2026-07-10). Privacy Policy, Terms, a data processing agreement, an AI transparency addendum for Article 50, a subprocessor page and a security page — each grounded clause by clause in what the system actually does, and each downloadable.
2026-07-13
Source-available licensing (2026-07-13). The repository is published under the Business Source License 1.1.
2026-07-16
Content-blind error tracking, off by default (2026-07-16). When error reporting is enabled by an operator, events carry an opaque account identifier, a request id, a route pattern and an error code — never a prompt, a credential, a URL, an email address or an output byte.
2026-07-27
Credentials removed from logs (2026-07-27). Request paths that embed a one-time token were being written to the access log. The log now records the route pattern rather than the concrete path, and a last-mile scrub covers error text.
---
Wakemark is designed to support EU AI Act Article 50 marking and logging workflows. It does not establish compliance with the AI Act or any other law, and the obligations remain yours. The audit export states this in the document itself; see the [Article 50 documentation](/docs/article-50) for what it does and does not attest.