Release digest
Added
- PILOT-OPS-V1 (Operations) — Added an internal Pilot Ops v1 runbook for manually triaging, qualifying, responding to, delivering, and archiving Security Readiness private-pilot requests while preserving consent, retention, and sensitive-data boundaries.
- PILOT-INTAKE-STATUS-UPDATES (Admin API) — Added an admin-only pilot
intake status update endpoint for the manual operations states
received,needs_clarification,qualified,not_fit,in_review,delivered, andarchived. - PILOT-INTAKE-TRIAGE-BRIEF (Local Ops) — Added a local Markdown brief helper for reviewing pilot intake queue state without printing contact details, project names, request text, or raw UTM values.
Improved
- PILOT-INTAKE-STATUS-CONTRACT (Data) — Aligned new pilot intake persistence
and migration defaults on
receivedinstead of the earliernewstatus, and added a database check constraint for the manual status workflow. - PILOT-INTAKE-LOG-BOUNDARY (Privacy) — Redacted request-log network/client context and raw exception strings for public and admin pilot-intake routes.
Internal
- Added regression coverage for admin status update authorization, valid status updates, invalid status rejection, unknown request handling, response minimization, migration ownership, request-log redaction, and PII-safe local triage brief rendering.
- Documentation decision: canonical Security Readiness architecture, internal
Pilot Ops runbook, minimal
knowledge-baseadmin API contract, generated endpoint inventory, and changelog public release notes are updated. No deployment env, public Privacy Notice, sitemap, SEO registry,llms.txt, auth, Stripe, subscription, CRM automation, customer portal, gated-access, or public-route documentation change is required because this remains an admin-only manual operations layer with no new public surface or commercial automation.