Changelog & security advisories

What changed, and when

Every shipped change to the product, dated. Security-relevant entries carry an advisory ID so they can be referenced unambiguously.

2026-09-25

  • ReleaseLP-2026-020

    New model layer — live sessions drop to $3/hour

    The live session stack moved to a new realtime multimodal model — session memory and proactive voice guidance unchanged, model cost ~4× lower. That flows straight into pricing: live time now bills at $3/hour by the minute (5-hour marathon = $15).

2026-09-24

  • ReleaseLP-2026-018

    Duo mode + /duo

    Two AI companions you just hang out with — voice-first, no camera, a dice button to change the scene. $10 for 30 minutes. Dedicated /duo page in 5 locales.

  • ImprovementLP-2026-019

    Accessibility statement on the landing

    The landing now states the mission plainly: accessibility isn't a feature we added — it's the interaction model. You talk; it watches your screen, keeps context, and gives voice-first guidance.

2026-09-23

  • ImprovementLP-2026-017

    Interview surface removed

    The /interview page and interview-practice guides are gone — LivePair is a live-work copilot, not an interview tool. The single remaining guide covers mock-interview practice only.

  • SecurityLP-2026-016

    Abuse enforcement + phone verification + 30-day sessions

    KV-backed ban list enforced at signup (email), the dashboard shell, and every authed API surface — banned accounts resolve as signed-out. Admin /admin moderation controls. Non-Google sign-ups now require phone verification (OTP SMS via Bird). Sessions are now 30-day rolling with a 'remember this browser' choice at sign-in.

  • ReleaseLP-2026-015

    Session pricing finalized — minute packs

    Live-session time now sells in minute blocks: a fixed $10 30-minute Duo anchor, plus 50–300-minute packs priced per minute at $3/hour — the product exists for long sessions, so heavy users pay the same rate as light ones.

  • ImprovementLP-2026-014

    Measurement wired end-to-end

    GA4 installed alongside the existing Ads tag (one script load, both configs). Standard funnel events now fire: sign_up, begin_checkout, purchase — so ad spend can be tied to real signups and top-ups.

  • SecurityLP-2026-013

    External review findings applied

    Token page decoupled from purchase/claim language and now states plainly that no token exists. Refund wording unified across /credits and /terms. Contract docs no longer imply launch mechanics that aren't implemented.

  • ReleaseLP-2026-012

    Sepolia contracts verified on Blockscout

    Token and merkle-claim contract source is publicly readable — anyone can confirm the deployed bytecode matches the published code. Testnet only; no mainnet token exists.

  • ImprovementLP-2026-011

    Revenue-coupled live-session cost cap

    Monthly provider spend is now bounded against revenue, so a usage spike can't outrun what the product actually earns.

  • FixLP-2026-010

    Site-wide polish pass

    Legal pages brought onto the standard palette, headings and section rhythm unified across marketing pages.

2026-09-22

  • SecurityLP-2026-009

    Payment-path fixes from internal audit

    Two bugs in the payment flow fixed before launch. Webhook fulfillment now re-runs idempotently on every paid event, and Durable Object state is bounded and versioned on load.

  • ReleaseLP-2026-008

    PayPal live for credit top-ups

    Card checkout enabled alongside crypto (BTC, ETH, USDC via NOWPayments). Both providers share the same idempotent fulfillment path.

  • ReleaseLP-2026-007

    Public /credits page + founding-supporter points

    Credits purchasable from $5 up to $500 packs. First 100 payers accrue +10% off-chain points under the 'founding' kind.

  • ReleaseLP-2026-006

    Live session surfaces shipped

    /live — one-tap mobile-first session page with PWA manifest. /demo — a 60-second scripted replay of a real session viewer. /manual rewritten around the live session.

  • SecurityLP-2026-005

    Abuse brakes

    Signup cap (KV-configurable), live-session concurrency cap, and a monthly provider-cost ceiling — all adjustable without a deploy.

  • ImprovementLP-2026-004

    Base model disclosed

    Site surfaces now state the latency and pricing model of live sessions instead of leaving them implied.

  • ImprovementLP-2026-003

    Content scope tightened

    Real-interview assistant guides removed; mock-interview practice material kept. The product positions itself for live work, not for covert use in interviews.

  • DocsLP-2026-002

    Charter + technical note published

    /manifesto — the public charter covering purpose, architecture, governance, and funding. Technical-note whitepaper PDF linked from footer and sitemap.

  • ReleaseLP-2026-001

    Initial public launch

    livepairai.com live: landing, docs, learn guides, dashboard, billing, and the agent chat.

Known limitations

CSP allows inline scripts

Content-Security-Policy currently permits unsafe-inline — a React Router hydration trade-off. Nonce-based CSP is a deferred hardening item.

Live sessions gated

The /live session path ships behind a kill switch until the session agent is cost-verified end-to-end. Chat is unaffected.

Reporting a vulnerability

Email support@livepairai.com with steps to reproduce. We acknowledge within 48 hours, and publish an advisory here once a fix ships.

Please don't probe payment fulfillment, webhook signature checks, or other users' session data. Test against your own account only.

See how a session runs

Read the guide