Release digest
Added
- PILOT-INTAKE-NOTIFICATIONS (Operations) — Added best-effort internal
email notifications after a hosted pilot intake request is saved, using the
existing SMTP environment pattern and a dedicated
PILOT_INTAKE_NOTIFICATION_EMAILrecipient.
Fixed
- PILOT-INTAKE-EMAIL-EXPECTATION (Reliability) — Kept the public form success path fail-open: missing SMTP config or notification delivery failure no longer blocks request capture, and honeypot submissions remain accepted without persistence or email notification.
Internal
- Added regression coverage for notification delivery, honeypot suppression, fail-open notification errors, and SMTP message construction without using a real SMTP server.
- Documentation decision: canonical Security Readiness architecture, deployment
environment inventory, and user-facing docs in the public Privacy Notice are
updated because pilot request fields may now be routed to an internal triage
inbox after database persistence. No sitemap,
llms.txt, SEO registry, auth, Stripe, subscription, customer portal, or gated-access documentation change is required because no public route or product entitlement behavior changed.