Changelog & security advisories
What changed, and when
Every shipped change to the product, dated. Security-relevant entries carry an advisory ID so they can be referenced unambiguously.
2026-09-25
The live session stack moved to a new realtime multimodal model — session memory and proactive voice guidance unchanged, model cost ~4× lower. That flows straight into pricing: live time now bills at $3/hour by the minute (5-hour marathon = $15).
2026-09-24
Two AI companions you just hang out with — voice-first, no camera, a dice button to change the scene. $10 for 30 minutes. Dedicated /duo page in 5 locales.
The landing now states the mission plainly: accessibility isn't a feature we added — it's the interaction model. You talk; it watches your screen, keeps context, and gives voice-first guidance.
2026-09-23
The /interview page and interview-practice guides are gone — LivePair is a live-work copilot, not an interview tool. The single remaining guide covers mock-interview practice only.
KV-backed ban list enforced at signup (email), the dashboard shell, and every authed API surface — banned accounts resolve as signed-out. Admin /admin moderation controls. Non-Google sign-ups now require phone verification (OTP SMS via Bird). Sessions are now 30-day rolling with a 'remember this browser' choice at sign-in.
Live-session time now sells in minute blocks: a fixed $10 30-minute Duo anchor, plus 50–300-minute packs priced per minute at $3/hour — the product exists for long sessions, so heavy users pay the same rate as light ones.
GA4 installed alongside the existing Ads tag (one script load, both configs). Standard funnel events now fire: sign_up, begin_checkout, purchase — so ad spend can be tied to real signups and top-ups.
Token page decoupled from purchase/claim language and now states plainly that no token exists. Refund wording unified across /credits and /terms. Contract docs no longer imply launch mechanics that aren't implemented.
Token and merkle-claim contract source is publicly readable — anyone can confirm the deployed bytecode matches the published code. Testnet only; no mainnet token exists.
Monthly provider spend is now bounded against revenue, so a usage spike can't outrun what the product actually earns.
Legal pages brought onto the standard palette, headings and section rhythm unified across marketing pages.
2026-09-22
Two bugs in the payment flow fixed before launch. Webhook fulfillment now re-runs idempotently on every paid event, and Durable Object state is bounded and versioned on load.
Card checkout enabled alongside crypto (BTC, ETH, USDC via NOWPayments). Both providers share the same idempotent fulfillment path.
Credits purchasable from $5 up to $500 packs. First 100 payers accrue +10% off-chain points under the 'founding' kind.
/live — one-tap mobile-first session page with PWA manifest. /demo — a 60-second scripted replay of a real session viewer. /manual rewritten around the live session.
Signup cap (KV-configurable), live-session concurrency cap, and a monthly provider-cost ceiling — all adjustable without a deploy.
Site surfaces now state the latency and pricing model of live sessions instead of leaving them implied.
Real-interview assistant guides removed; mock-interview practice material kept. The product positions itself for live work, not for covert use in interviews.
/manifesto — the public charter covering purpose, architecture, governance, and funding. Technical-note whitepaper PDF linked from footer and sitemap.
livepairai.com live: landing, docs, learn guides, dashboard, billing, and the agent chat.
Known limitations
CSP allows inline scripts
Content-Security-Policy currently permits unsafe-inline — a React Router hydration trade-off. Nonce-based CSP is a deferred hardening item.
Live sessions gated
The /live session path ships behind a kill switch until the session agent is cost-verified end-to-end. Chat is unaffected.
Reporting a vulnerability
Email support@livepairai.com with steps to reproduce. We acknowledge within 48 hours, and publish an advisory here once a fix ships.
Please don't probe payment fulfillment, webhook signature checks, or other users' session data. Test against your own account only.
See how a session runs
Read the guide