PlatformLatestHardened private download ticket validation
Private document delivery now rejects non-canonical Base64URL encodings as well as invalid signatures, malformed tickets, and mismatched owners.
- Required the signed payload and signature to use one canonical Base64URL representation
- Prevented alternate text encodings of the same signature bytes from passing validation
- Preserved constant-time signature comparison, account and document binding, and the existing 60-second expiry
- Kept the tampering regression in the protected integration release gate
PlatformMade database security migrations provider-portable
Corrected a deployment blocker caused by a database-owner role name that is specific to some managed PostgreSQL services.
- Removed the hard-coded postgres owner-role name from default-privilege statements
- Kept Supabase anon, authenticated, and service-role access denied when those roles exist
- Applied the same default-deny function posture through the connected database owner on other managed PostgreSQL providers
- Added a release regression that rejects provider-specific owner-role assumptions
PlatformAdded compact workspace navigation
Desktop users can reduce the shared navigation column while working in the Claim Builder and other detailed workspaces.
- Added a small collapse and expand control beside Your workspace
- Reduced the compact column from 246 pixels to 76 pixels
- Remembered the display preference on the current device
- Kept navigation links, account actions, legal resources, and accredited-representative help accessible in compact mode
- Preserved the existing tablet and mobile navigation behavior
- Added accessibility regression coverage and verified the Claim Builder with no horizontal overflow
PlatformPatched newly published Auth.js security advisories
Updated the database authentication adapter before the Exposure Record Check Staging release so every installed Auth.js core copy uses the patched release.
- Updated @auth/prisma-adapter from 2.11.2 to 2.11.3
- Removed the nested vulnerable @auth/core 0.41.2 package
- Standardized the installed Auth.js core dependency on 0.41.3
- Restored a zero-vulnerability npm audit before publication
PlatformAdded the Exposure Record Check
Added a fictional-data-only educational check that points users toward official military-exposure registries, programs, and record information without presenting a match as proof.
- Added guided service-period, duty-location, and known-or-suspected exposure selections
- Added optional fictional incident notes that remain only in the current page and are not saved or sent
- Matched answers against public information for VA exposure registries, VET-HOME, follow-up programs, and ILER
- Separated possible matches from confirmation, eligibility, disability compensation exams, and claims
- Added current official VA and military-health follow-up links
- Added responsive layouts, keyboard focus management, validation messages, and release regression coverage
FormsAdded DD Form 2860 for Combat-Related Special Compensation
Added a plain-language guide and official Department of Defense download for military retirees considering a CRSC application.
- Added DD Form 2860, Claim for Combat-Related Special Compensation
- Distinguished the Department of Defense retired-pay process from a VA disability claim
- Clarified that applicants submit through their military branch rather than VA or DFAS
- Added the official DoD form page to the source register and the official PDF to weekly link checks
- Recorded the DoD information page for human review because its gateway blocks automated requests
- Generalized the library labels so VA and DoD forms are identified accurately
PlatformRemediated the pre-Alpha application audit
Patched the framework advisory, hardened request-size enforcement, and clarified the final claim and mobile questionnaire experience without changing the fictional-data-only boundary.
- Updated Next.js to 15.5.21 and restored a zero-vulnerability install audit
- Rejected missing, invalid, oversized, and chunked request lengths before JSON or document parsing
- Made signed-out statement verification describe device-only saving instead of an account claim-package action
- Added a mobile and tablet cue that the 11-step questionnaire navigation scrolls sideways
- Added distinct browser titles to primary routes and removed duplicated Debrief suffixes
- Wrapped the sidebar legal links within their column so Sources and Licenses remain visible at every supported width
- Made the signed-in profile button open Account & data and added a direct, progress-aware Sign out control with an account-page fallback
- Added regression coverage and a dated audit record while preserving the upload, real-data, paid-AI, and public-Beta gates
PlatformAdded public service and official-content watch controls
Added privacy-safe status checks, issue-based health alerts, official eCFR and VA form review triggers, and fail-closed human publication controls without enabling real-data processing.
- Added a public Status page that checks only public liveness, provider configuration, and anonymous session service
- Added one deduplicated GitHub health issue that opens on failure and closes after recovery without copying account or claim information
- Added a weekly read-only monitor for newer Title 38 Part 4 issue dates and unavailable or modified VA form destinations
- Required a human content-reviewed pull-request label before condition or form library changes can pass release verification
- Required every protected content change to update the public changelog
- Added an isolated Supabase PostgreSQL and private Vercel Blob recovery drill and evidence runbook while keeping provider verification open
PlatformAdded independent release-readiness controls
Added license attribution, offline AI safety evaluation, content provenance, updated authentication security, database index evidence, and privacy-safe service-health checks without enabling paid AI or real-data use.
- Published third-party software/data notices and a lockfile license gate
- Added 40-scenario AI scoring, versioned current/rollback policies, and an external-AI containment procedure
- Added per-condition and per-form versions, verification dates, authority links, and reproducible local SHA-256 fingerprints
- Updated Auth.js to pinned beta.32 after reviewing its official security release and verifying a clean production audit
- Deployed 13 query-supported Supabase indexes to Staging, cleared all 13 unindexed-foreign-key findings, and recorded privacy-safe before/after eligibility plans
- Added a data-free liveness route and public/auth/session latency checker while keeping protected event export and authenticated SLO measurement open
PlatformAdded the Phase 3 security-readiness foundation
Documented Debrief's current data and threat boundaries, established incident procedures, centralized privacy-safe security events, and narrowed the browser Content Security Policy without changing the fictional-data-only Alpha boundary.
- Inventoried every Prisma field plus browser, PostgreSQL, private Blob, OAuth, Vercel, support, backup, logging, and future AI data flows
- Added an internal threat model covering assets, trust boundaries, 17 abuse cases, residual risks, remediation order, and release-stop conditions
- Added incident roles, severity targets, six scenario playbooks, four fictional tabletop exercises, and an evidence-safe exercise record
- Routed authentication, rate-limit, storage-reconciliation, cleanup, document, and AI failures through one allowlisted and redacting security-event formatter
- Blocked inline browser event attributes, frames, media, foreign manifests, and Production insecure subresources while recording the remaining framework nonce/hash tradeoff
- Added release regressions for schema-inventory drift, event redaction and bypass, threat/incident records, and Production/Development CSP behavior
- Pinned the patched Sharp 0.35 line after new upstream libvips advisories affected Next.js's optional image dependency and restored a zero-vulnerability npm audit
PlatformAdded a privacy-safe Alpha support channel
Created one clear route for support, corrections, accessibility barriers, privacy and deletion requests, and security concerns without collecting claim or health details in a web form.
- Added Support links before sign-in and throughout the authenticated application
- Added direct correction links from the Conditions and VA Forms libraries
- Defined safe intake, triage, escalation, closure, and content-review procedures
- Established WCAG 2.2 AA as the accessibility target with a manual review and release-blocking process
- Defined measurable Alpha objectives for availability, sign-in, save, export, and incident acknowledgement
- Extended the release suite to preserve the support route, data boundary, operational standards, and canonical-link controls
PlatformReduced Alpha workflow clutter
Simplified the public entry, unified the Dashboard surface with the rest of the application, and made the path from each condition to saved statements and review explicit.
- Removed the marketing-style splash-page process cards and retained one plain introduction and sign-in action
- Made the Dashboard use the same light dossier surface as the other authenticated sections
- Kept the oversized Preparation Picture removed from the Claim Builder
- Removed the redundant claim-package metric strip
- Added direct Personal Statement, optional Buddy Statement, and Review/Download actions to every saved condition
- Added Return to Claim Builder actions to the claim package, document workspace, and buddy-statement workspace
- Rebuilt Conditions around populated body systems with condition-level diagnostic-code links and official criteria sources
PlatformAdded storage deletion reconciliation
Partial private-object and database deletion failures now leave a durable, privacy-minimized cleanup record instead of a silent inconsistency.
- Verified private object absence rather than trusting a successful delete response
- Added durable HMAC-scoped reconciliation tasks for upload rollback and document, workspace, and account deletion failures
- Retried orphaned upload cleanup and included pending orphan objects in later workspace or account deletion
- Resolved or removed tasks after verified cleanup and included safe task metadata in account export without storage keys
- Emitted structured operational events without account, claim, document, filename, or storage-key identifiers
- Added a database migration, operator runbook, and regression coverage
PlatformExpanded API isolation and operating safeguards
Strengthened automated API-boundary checks and documented how Alpha access and application credentials are granted, reviewed, rotated, and revoked.
- Added foreign-origin and two-fictional-principal checks
- Enforced regression contracts for authentication, account ownership, and durable abuse controls across private routes
- Kept adversarial upload, cross-user download, account deletion, and rate-limit suites in the release gate
- Added a privacy-separated tester onboarding, access-review, session-revocation, offboarding, and deletion checklist
- Added a complete secret/configuration inventory with environment ownership, standard rotation, credential-specific cautions, and emergency revocation
- Kept true database-backed two-session handler integration explicitly open rather than overstating contract-test coverage
PlatformMade Debrief's independent role explicit
The complete educational-product boundary is now present before sign-in and throughout the working application.
- Stated that Debrief is independent educational software and is neither VA nor a VA-accredited representative
- Stated that Debrief does not provide legal or medical advice or submit claims
- Kept official VA-accredited-representative help available
- Added disclosure regressions covering public entry, sign-in, authenticated navigation, and Terms
PlatformAdded durable abuse and cost controls
High-risk authenticated operations now use PostgreSQL-backed limits that persist across deployments and server instances.
- Added fixed-window limits for claim changes, workspace creation, document upload/access/deletion, account export/deletion, and external AI drafting
- Stored only HMAC-protected account principals in rate-limit buckets
- Included user-linked counter metadata without its HMAC in account export and removed those counters during account deletion
- Returned explicit retry guidance and emitted privacy-minimized limit events without claim, document, email, or raw account data
- Kept existing document, workspace, active-claim, request-size, parser, and AI-output quotas in force
- Added per-user burst and daily AI ceilings plus a global daily Alpha ceiling
- Kept the free guided statement path outside the paid-AI budget
- Added deployment validation, regression coverage, and an operational runbook
PlatformAdded account export and verified active-data deletion
Signed-in Alpha users can now take a portable copy of their application records and receive a receipt after active account data and stored objects are verified deleted.
- Added an authenticated owner-scoped JSON export covering profiles, connection metadata, session expirations, claims, answers, evidence, statements, document metadata, legacy upload metadata, and audit events
- Excluded OAuth tokens, session tokens, password hashes, and private storage keys from exports
- Kept binary document downloads behind the existing short-lived owner-bound delivery flow
- Expanded account deletion to current and legacy stored-object records
- Verified each active object is absent before deleting the database account and verified the user record is absent afterward
- Added a downloadable deletion receipt and explicit provider-backup and infrastructure-log limitation
- Added export and deletion regressions to the release gate
PlatformAdded operational containment controls
The Alpha administrator can independently pause uploads, external AI generation, or new account registrations without changing application code.
- Added fail-closed, deployment-validated controls for uploads, AI provider calls, and new registrations
- Preserved existing-user sign-in and account/data deletion when registrations are paused
- Preserved existing-file download and deletion when new uploads are paused
- Kept the free guided narrative available without sending answers to an AI provider when AI is paused
- Added a same-commit redeployment, verification, and incident-recording runbook
- Added operational-control regressions to the release gate
PlatformHardened fictional document validation
Test uploads now fail closed when their name, extension, reported type, actual content, structure, or safe-processing limits disagree.
- Required PDF, JPEG, and PNG extensions and declared MIME types to agree with detected content
- Rejected path-like, bidirectional, executable/archive, control-character, and excessive filenames
- Added PDF page, object, stream, decoding-chain, active-content, and image-dimension limits
- Added JPEG frame, segment, scan, ending, and decoded-image checks
- Added PNG chunk-boundary, integrity, count, dimension, ending, and animation checks
- Rejected trailing polyglot data and added adversarial upload/parser regressions
- Kept malware scanning and real-record processing explicitly disabled
PlatformAdded short-lived private document downloads
Private test documents can now be downloaded only through a short-lived, owner-bound server handshake instead of a reusable document route or public object URL.
- Required an authenticated same-origin request before issuing any download link
- Bound each signed ticket to one user and one document with a 60-second expiry
- Revalidated the active session, ticket, and document ownership before reading private storage
- Kept storage keys and Blob URLs out of browser-facing document responses
- Added no-store, no-referrer, attachment, and content-sniffing protections to delivery responses
- Added automated checks for expiry, tampering, cross-user reuse, owner scoping, and private-only Blob configuration
Claim builderCompleted personal-statement version comparison
Saved statement revisions can now be reviewed beside the current draft before a user chooses to restore earlier wording.
- Added Compare controls to every saved statement version
- Displayed saved and current drafts side by side with word and section counts
- Summarized words added and removed without changing either draft
- Stacked comparison panels on narrow screens and kept both versions independently scrollable
- Retained the existing confirmation safeguard before replacing current editor text
- Preserved compatibility with previously saved statement revisions without a database migration
Claim builderAdded sentence-level statement source tracing
Made each factual statement traceable to the saved answer or timeline entry it came from without treating that trace as proof.
- Linked each factual sentence to direct questionnaire field names and excerpts or to a saved timeline event
- Carried source traces through account saves and revision-history snapshots
- Displayed related evidence status and uploaded file names in the statement editor, verification step, and consolidated package
- Added the same sentence-to-source trace to the downloadable condition review PDF
- Flagged manually added wording that cannot be traced and blocked untraceable AI-assisted wording from package readiness
- Kept source language cautious: a trace identifies origin but does not prove a fact or guarantee that a related document supports every word
Claim builderCompleted the first claim-package workflow
Connected condition workspaces, evidence sources, statement revisions, buddy statements, readiness checks, and official filing guidance into one coherent preparation path.
- Linked account-owned uploads to specific facts across one or more condition workspaces
- Added fact-to-source checklists to the package workspace and exported review PDF
- Added blocking, attention, and caution-level checks for incomplete statements, conflicts, pending support, unsupported relationships, duplicate uploads, and stale form verification
- Added statement revision history with save and restore controls
- Added duplicate, recoverable archive, restore, and separately warned permanent-delete actions
- Added a guided buddy-statement questionnaire and editable firsthand-observation draft
- Added manual package statuses from planned through submitted with an explicit warning that Debrief cannot verify VA receipt
- Added a three-step submission bridge linking only to official VA filing routes
PlatformAdded Staging and Production release safeguards
Prepared Debrief for an isolated tester environment without changing the current public Alpha project or its data.
- Added a persistent fictional-data banner with environment and release identification to every non-Production build
- Added build-time checks for Staging data labels and authentication-host separation
- Added a GitHub release gate for staging and production branches
- Documented the two-project setup, promotion path, smoke test, emergency fix, rollback, and migration cautions
- Added a reusable release decision record and marked the remaining provider setup in the product backlog
Claim builderAdded an intent-to-file checkpoint
Added an early filing-timeline question so users can record whether they notified VA of an intent to file or started an eligible online claim.
- Added Yes, online-started, No, and Not sure paths without requiring an unknown date
- Recorded the VA-received, confirmed, or online-start date when known
- Added the checkpoint to readiness review and the downloadable condition-review package
- Linked directly to current VA intent-to-file guidance and VA Form 21-0966
- Clarified that the intent preserves only a potential effective date, generally requires filing the completed claim within one year, and does not guarantee retroactive payment
PlatformAdded Alpha release verification and accessibility safeguards
Expanded repeatable Alpha checks and corrected navigation and questionnaire barriers found during responsive and accessibility testing.
- Added one release command covering canonical links, accessibility contracts, authentication boundaries, 40 fictional claim scenarios, and privacy-safe Alpha metrics
- Verified the public Alpha across representative mobile, tablet, and desktop sizes
- Completed a fictional claim through guided drafting, section verification, local save, and fresh-claim restart
- Removed closed mobile navigation from the accessibility tree and restored focus when it closes
- Added descriptive questionnaire step names and programmatic progress values
- Improved small-text contrast, touch areas, visible keyboard focus, and reduced-motion behavior
- Added a canonical-address test that rejects protected Vercel deployment aliases in tester-facing repository content
PlatformHardened closed-Alpha Google sign-in
Replaced opaque authentication failures with safe recovery guidance and added controls to detect configuration drift without recording private account data.
- Added a Debrief-branded authentication error page with sanitized reference codes and a fresh-login action
- Disabled repeat login submissions while Google authorization is starting
- Redirected Production aliases to the canonical Alpha domain before OAuth begins
- Added structured authentication events containing timestamps and error codes but no names, emails, tokens, cookies, or claim data
- Added a Production environment check for required Google variables, secret strength, HTTPS, and canonical origin
- Added repeatable HTTP authentication boundary tests and a dedicated fictional-account callback runbook
- Added monthly Auth.js release monitoring and recorded the decision to retain v5 beta during closed Alpha pending defined re-evaluation triggers
PlatformCompleted the closed-alpha security and transparency scrub
Tightened the fictional-data alpha boundary, removed known dependency vulnerabilities, and gave testers clearer control over their account data.
- Removed the unused email-authentication dependency and resolved the npm audit findings
- Added browser security headers, no-index directives, cross-origin mutation checks, request-size limits, and alpha storage quotas
- Rejected oversized document uploads before reading them into server memory and added client-side size feedback
- Added Alpha Privacy Notice and Alpha Terms of Use pages with Google sign-in, AI transfer, retention, health-data, and VA accreditation disclosures
- Added account-wide deletion for claims, drafts, sessions, authentication records, and stored test documents
- Replaced the inactive settings placeholder with Account and data controls
- Added direct VA-accredited-representative guidance and tightened fictional-data warnings across login, intake, and claim building
- Rechecked every official VA form destination and replaced the obsolete VA Form 10182 PDF link
- Documented unresolved legal, security, accessibility, vendor-retention, and real-data launch gates
Claim builderConnected intake, questionnaires, and claim-package review
Simplified the end-to-end preparation path so every screen identifies the next useful action and each condition statement collects in one package view.
- Simplified workspace creation and document upload into one focused intake flow
- Added clear continue-to-claim and skip-documents actions
- Made every previously visited questionnaire section directly clickable
- Separated drafting blockers, wording cautions, optional improvements, and pending evidence on the readiness review
- Replaced the export dead end with a condition verification and Add to claim package action
- Added an account-level claim package with one statement per condition, preparation status, uploaded-document counts, pending-record reminders, common form resources, and official VA filing guidance
Claim builderSeparated evidence availability from evidence planning
Each major claim fact can now distinguish available records, personal recollection, witness evidence, pending records, and facts with no identified support.
- Added five explicit evidence statuses to the fact-to-evidence map
- Required an evidence type when a fact is marked as supported by an available or pending record
- Counted personal recollection and witness evidence as identified support without presenting them as medical records
- Stopped records identified but not obtained from counting as available support
- Added separate readiness counts for support identified, available records, and records pending
- Added pending-record readiness guidance
- Converted older string-based saved evidence maps when they are opened
- Added evidence statuses and record types to the PDF review package
- Added regression coverage for pending records and legacy-map conversion
Claim builderExpanded fictional claim testing to 40 scenarios
Added adversarial and edge-case veteran scenarios to exercise the free claim workflow without using real veteran data or paid model calls.
- Expanded the repeatable suite from 18 to 40 fictional scenarios
- Added conflicting dates, conflicting frequencies, uncertain memories, treatment gaps, intermittent symptoms, bilateral conditions, attributed clinician opinions, sensitive narratives, witness observations, and uncertain claim paths
- Added forbidden-wording, repetition, paragraph-assembly, and cross-claim-isolation checks
- Paused drafting when explicit onset years or materially different current frequencies conflict
- Made Not sure yet statements neutral instead of treating uncertainty as a claim type
- Preserved appropriate uncertainty and clearly attributed medical discussions
- Kept zero known questionnaire-style transitions and zero unsupported medical conclusions in generated drafts
Claim builderSeparated new claims from resumable drafts
Links labeled New claim or Create another claim now always open a clean questionnaire instead of restoring the browser's active unfinished draft.
- Added an explicit fresh-start route for new-claim entry points
- Kept selected saved-claim links tied to their claim IDs
- Preserved a recoverable browser draft in the local workspace archive before clearing it
- Updated dashboard, statement, condition-guide, and post-completion new-claim actions
- Kept the general Build a claim navigation route available for resuming an active browser draft
Claim builderLayered the interview and grounded statement drafting
Reduced questionnaire overload with progressive disclosure and changed statement drafting to request missing facts before producing a narrative.
- Kept essential questions visible while moving deeper symptom, service, treatment, and evidence questions into optional layers
- Removed repeated service-event and specific-example questions
- Added claim-path-aware minimum-fact checks before statement generation
- Added structured AI responses that either return a cohesive draft or up to three targeted follow-up questions
- Prevented drafting when core facts are missing instead of allowing the model to fill gaps
- Clearly separated true AI drafting from the non-AI guided-template fallback
- Removed AI data-transfer consent from template mode and retained it whenever OpenAI is connected
PlatformIntroduced the Debrief briefing experience
Added a public introduction before the claim workspace and established Debrief as the product identity for MVP review.
- Moved the existing workspace from the public root to /dashboard
- Added a responsive mission-brief splash page with sign-in and dashboard entry points
- Redesigned sign-in to match the new identity
- Updated dashboard and questionnaire links for the new route
- Introduced a midnight, graphite, intelligence green, and amber visual system
- Recolored the main dashboard as a graphite command center with cool dossier surfaces
- Updated product labels and independent-resource disclaimers across the application
PlatformIntroduced test document intake
Added the secure, test-only document foundation for a future evidence-assisted claim workspace without enabling real medical-record processing.
- Added claim-workspace document, page, and audit-event records
- Added authenticated fictional PDF, JPEG, and PNG test uploads with a 4 MB limit
- Validated file signatures instead of trusting file extensions
- Added private storage adapters for local development and Vercel Private Blob
- Added owner-restricted list, download, and permanent-delete routes
- Added no-store download headers and avoided filenames or contents in audit metadata
- Added an explicit fictional-data confirmation and repeated real-record warnings
- Kept OCR, AI analysis, malware scanning, and real-record authorization disabled
PlatformAdded account-based claim saving
Signed-in users can now save questionnaire workspaces to the hosted database and continue them later from the dashboard or another device.
- Added account-owned claim create, read, update, and delete API routes
- Added version checks that prevent an older browser tab from silently overwriting newer work
- Added automatic saving after questionnaire changes and visible saving, saved, and error states
- Replaced sample dashboard claims with the signed-in user's saved workspaces
- Added a browser-only mode for signed-out users and transfer of that draft after sign-in
- Added database fields and a migration for versioned questionnaire snapshots
- Kept medical-document uploads disabled until private object storage and file-security controls are configured
Claim builderIntroduced fact-to-evidence statement preparation
Expanded the builder from a general questionnaire into an adaptive preparation workflow that checks facts, chronology, supporting information, and statement accuracy before export.
- Added claim-path-specific questions for original, increased-rating, and secondary claims
- Added condition-aware prompts for symptom patterns and functional effects
- Added an editable condition timeline with approximate-date labeling
- Added a fact-to-evidence map
- Added deterministic checks for missing details, vague absolute wording, and unsupported medical conclusions
- Added paragraph-by-paragraph accuracy confirmation
- Added local workspaces for separate condition statements
- Added a downloadable PDF review package with statement, timeline, evidence map, readiness checks, signature area, and page numbering
- Kept the PDF clearly separate from an official VA form or proof of submission
Claim builderAdded personal-statement drafting
The guided questionnaire can now produce an editable first-person personal-statement draft using only the information supplied by the veteran.
- Added personal-statement questions for continuity, concrete examples, and optional context
- Added server-side AI drafting with input validation, request limits, timeouts, and model-storage disabled
- Added explicit acknowledgement before questionnaire answers may be sent to OpenAI
- Excluded the optional display name from source material sent to the AI model
- Added a clearly labeled guided-template fallback when AI is not configured
- Added editing, local draft saving, copying, and plain-text download
- Added warnings requiring the veteran to verify every sentence before use
ConditionsMade rating schemes the center of each condition guide
Redesigned condition discovery around the question users ask first: which percentage levels exist and what distinguishes them.
- Added a quick rating reference at the top of every condition profile
- Added diagnostic-code and shared-formula switching for conditions with multiple rating paths
- Separated knee flexion and extension into their correct rating tables
- Added verified evaluation levels to condition and diagnostic-code search results
- Added A–Z browsing alongside the 14 body-system groups
- Clearly labeled indexed codes whose full plain-language tiers still require verification
FormsAdded official form download actions
Every form resource now provides a direct VA-hosted PDF or the official DBQ download directory alongside its VA information page.
- Added download metadata for all 10 form resources
- Recorded the date each destination was verified
- Added download actions to form cards and detail pages
- Kept DBQs linked to the directory because there is no single universal DBQ PDF
PlatformLaunched the public change log
Added a durable place to record content, source, and platform changes as recurring verification work is introduced.
- Added a chronological change history
- Added category labels and source links
- Added Change log to primary navigation
ConditionsIntroduced body-system and diagnostic-code browsing
Restructured Conditions so plain-language guides sit above a regulatory diagnostic-code catalog rather than implying one condition always has one rating table.
- Added all 14 Part 4 body-system groups
- Indexed an initial 27 diagnostic codes
- Connected profiles to multiple potentially relevant codes
- Added symptom, synonym, body-part, and code search
- Prepared source metadata for future eCFR synchronization
PlatformCompleted initial MVP reliability fixes
Corrected misleading prototype behavior before wider review.
- Implemented mobile navigation
- Added global condition and form search
- Replaced dead links with working destinations or clear availability labels
- Made demo dashboard data explicit
- Aligned sign-in copy with available authentication
Claim builderExpanded the guided questionnaire
Moved beyond a migraine-only flow to support preparation for a broad range of claimed conditions.
- Added condition selection with an Other option
- Added claim-path, health, service, treatment, and evidence steps
- Added local draft saving and preparation summary
FormsCreated the VA forms library
Added plain-language guides for frequently used disability and decision-review forms.
- Added searchable form cards
- Added form-purpose and completion guidance
- Added common-error notes and official VA source pages