Skip to content

Changelog

What shipped, what we caught, what's next. We publish the gaps too.

Website refresh v2.0

2026-04-17

New

  • Privacy Ledger page — every capability, what it runs on, what leaves your device, how to turn it off.
  • Network Flows page — every hostname Viola contacts, when, why. Verifiable with Wireshark.
  • Security page — MFA, passkeys, session rotation, signed installer, encrypted memory, responsible disclosure.
  • Phone page — Viola answers and places calls on your behalf. Dual-mode local / cloud.
  • Viola vs. Alexa, Google, Siri page — honest capability comparison.
  • What can I say to Viola? page — 50+ real voice commands.
  • Internal security & architecture review doc — Claude Opus 4.7, published in full with known gaps.
  • NOTICES.md doc — third-party open source attribution with LGPL-3.0 / PySide6 compliance statement.
  • Phone cloud bridge threat model doc.
  • SHA-256 and signing certificate thumbprint now published on download with PowerShell verification steps.
  • Legal: GDPR 16+ age-of-consent, Illinois BIPA notice, California AADC disclosure all added to Terms.

Changed

  • Hero reframed from "Nothing leaves your home" → "Private by default. Cloud only when you say so." (the former overclaimed once phone cloud mode + managed subscription routing shipped).
  • Homepage replaced three abstract cards with six concrete capability cards (multi-room, phone, agent, household, integrations, privacy receipts).
  • Pricing uses concrete numbers: Free = $1/mo managed cap + 0 phone minutes, Pro = $6 cap + 60 minutes, Max = $12 cap + 300 minutes.
  • Honest platform list: Windows hub ships today; macOS/Linux soon; spokes in any browser.
  • LICENSE changed from MIT to proprietary EULA (repo was never public; no retroactive effect).
  • Terms and Privacy bumped from v1.1 → v2.0.

Fixed

  • Correction Terms § 2.3: removed "smart home is on the roadmap" — smart home ships today via Home Assistant.
  • Correction Terms § 6.2 / § 7.1: removed Apache 2.0 licensing language left over from a prior draft.
  • Correction Network Flows + audit: fabricated updates.useviola.com endpoint removed; there is no auto-update at this release.
  • Correction Audit + security page: fixed "Argon2id" claim — Viola actually uses bcrypt cost-factor-12 with SHA-256 prehash.
  • Correction Privacy Ledger: clarified OAuth tokens are Fernet-encrypted on disk; the encryption key lives in the OS keyring.

Gaps disclosed

  • Ops F-SUP-03: Azure Code Signing cert for ViolaRelease profile expired 2026-04-15. Existing signature on ViolaSetup-1.0.0.exe remains valid per PKIX; next release needs a renewed cert.
  • Code F-AGENT-03: absolute-path resolution now lives in the approval dialog; see mcp_hub/approval_bridge.py.
  • Docs Third-party security audit targeted Q3 2026 to supersede the internal Opus 4.7 review.

Where it started

2026-02

  • Closed beta on Windows, signed installer, basic multi-room, wake word, calendar + email integration.
  • First pass at pricing and public-facing copy.

Subscribe via email at contact to hear about new releases. No marketing list; just release notes.