What has changed, dated
The platform’s changes, in plain language, from the most recent to the oldest. Each entry describes what is delivered, not what is planned; the detail lives on each area’s page.
Resume, schedule, correct what arrives late
A workflow run can be resumed where it failed, a schedule follows the business-day calendar, and a delivery verdict that arrives late corrects the status instead of being lost. The console tightens access to addresses and spaces.
- Resuming a run from the failed node: outputs already produced are reused, nothing is deposited again; the original run stays intact. Workflows
- Workflow recipes, starting templates: the first one alerts the space’s operational address on every failed run, without the error message.
- Business-day calendar for schedules: Saturdays, Sundays and public holidays — metropolitan France or Alsace-Moselle — skipped or moved to the next business day.
- Workflow editor: undo and redo, copy, paste and duplicate nodes, by keyboard or mouse.
- Protection against spreadsheet formulas in the CSV files produced, on by default.
- Changing a connection’s host erases its stored credentials; changing the target of a health connection requires a new attestation before any publication or run.
- The unsubscribe link in the message body leads to a confirmation page: a robot following links no longer unsubscribes anyone. One-click unsubscribe from the mail client stays immediate. Data
- Health by inference: seeing the members of a segment built on health data, or previewing a message on a real contact when membership could be read from it, requires health authorisation.
- Unknown outcome and late verdict: a message whose recipient server did not answer is not sent again at once, and a verdict that arrives after the deadline corrects the status and the counters. Deliverability
- Console: keys marked “console” that always carry the actor, addresses masked for roles without the capability to reveal them, a platform account’s role granted by a second step, single sign-on linking tightened. Authorisation
- Operations: monitoring and alerts in production, operational e-mails sent from a dedicated domain, annual rotation of infrastructure keys scheduled. Security
Secret vault, data-subject rights, hardening
A full review of the platform — security, data protection, traceability, delivery — produced a set of new rules, all enforced by the server.
- Space secret vault for workflows: OpenPGP passphrases, hashing keys, HTTP headers and signatures, never written into the definition, never returned. Workflows
- Data-subject rights: restriction of processing (art. 18), full access export (art. 15, messages included without body), objection to profiling (art. 21). Data
- Strict proof of health consent: exact wording and source required, and no health value written without that prior grant.
- Statistical masking of zero and of complements: a masked value can no longer be recovered by difference with a total.
- Mandatory TLS towards recipients for a health space: explicit failure rather than delivery in the clear.
- Brevo router: an attestation that open and click tracking is disabled on the account, required on every write to the route.
- Audit log: the console’s acts are relayed to the chained log; in the log served to platform roles, every identifier tied to a person is masked.
- Templates: no contact data in a URL, refused when saved. Templates
- Hardening: stronger guard against internal targets, redirects never followed, size bounds on imports, files and rendering, rate limiting on public pages. Security
Files and health data in workflows
A workflow no longer only sends files out: it fetches them, decrypts them, reads them into columns and turns them into contacts. And an authorised person can move health data through it, within a closed frame.
- Incoming files: SFTP, S3-compatible, HTTP, or upload at start; bounded size, logged import, consumed file recorded on the run. Workflows
- Space OpenPGP keys, generated on the platform or imported; the private key is never returned.
- SFTP connections classified as health, on attestation, and workflows declared as handling health data: authorisation required, output always encrypted, runs invisible to platform roles. Workflows
- Trying a step from the editor: the node and its ancestors run on a sample, with no action and no delivery.
Space lifecycle and readability
Less visible changes that close corners: what disappears really disappears, and what is displayed stays below the threshold.
- A deleted space becomes inert — no send, no run — then it is permanently purged after a grace period, thirty days by default, with a signed report.
- Statistics are served in the requested language, French or English.
- The layout of a workflow’s canvas is saved with its version.
- Workflow run counters follow the display threshold for platform roles.