Changelog
This page tracks recent and forthcoming platform updates. Previously consolidated entries have been distributed into the feature pages where their substance lives:
- NMR analysis, multiplet detection, J-coupling refinement, chemical-shift prediction, structure verification, solvent/impurity classification, NUS reconstruction, spectrum retrieval, and retrieval-augmented reasoning → SpectraCheck → NMR Interpretation.
- Quantitative region integration (Sum / Edited Sum / Peaks) and qNMR purity (internal-standard & PULCON) → SpectraCheck → qNMR Quantification.
- MS models — CSI:FingerID, METLIN retention-time corroboration, and DP4-AI candidate fusion → SpectraCheck → LC-MS/MS Annotation.
- The AI model lifecycle — model registry + inference router, datasets pipeline, evaluation harness, LoRA fine-tuning, closed-loop feedback, active learning, and MLOps monitoring + deployment gate → SpectraCheck → AI Model Lifecycle.
- Audit trail + GxP controls supporting 21 CFR Part 11 → Core Concepts → Audit trails.
- ICH + FDA impurity engines — Q3A/B thresholds, Q3C(R8) residual solvents, Q3D(R2) elemental impurities, M7(R2) mutagenic impurities, and the FDA CPCA nitrosamine classifier — plus the deterministic-first Phase 0 foundation → Regentry → ICH Guidelines and Overview.
- The dossier impurity-assessment workflow — the unified
impurities/assessendpoint, the engines wired behind the dossier assessment endpoints (with product dose + route on the dossier), and the nitrosamine cumulative-risk rollup → Regentry → Impurity assessment. - Per-user dossier access control + data isolation — owner-scoped reads/writes (migration 0015), the cross-module bridge gates, and privileged surveillance → Regentry → Access control.
- AI-decision governance for EU GMP Annex 22 (draft) — the tamper-evident per-dossier decision log, the HITL gate, and auto-recording from CPCA / M7 / Q3D → Regentry → AI-decision governance.
- Readiness-report rehydration + content-hash provenance → Regentry → Report Generation.
- Enterprise SSO (OIDC federation, JIT, enforce-SSO), SCIM 2.0 provisioning + soft auto-deprovisioning, MFA & passkeys (TOTP + WebAuthn/FIDO2) with step-up re-authentication, policy-as-code authorization (centralized PDP + deny-by-default baseline), and rotating-refresh session hardening with reuse detection → Security Policy → Access controls and → Session management.
- Argon2id credential hashing (rehash-on-login), KMS envelope encryption for sensitive fields (BYOK seam), the secrets-provider seam + CI secret-scanning gate, and TLS / HSTS + security response headers → Security Policy → Encryption, → Secrets management, and Deployment & Hosting → Transport security.
- Tamper-evident audit-chain hardening (hash-chained
audit_events, HMAC-signed checkpoints, signed high-water tail-truncation guard, admin verify / anchor + reconciliation alerts) → Security Policy → Audit trail integrity. - 21 CFR Part 11 e-signature hardening (server-attributed identity §11.100, content-bound
signature_digest§11.70, durable JSON / HTML manifestation §11.50, step-up re-auth §11.200) → Compliance → Electronic signatures. - ALCOA+ hardening for controlled records (queryable
reason_for_change, soft-delete reversibility, strict raw-vault immutability, immutable-by-design audit tables) → Compliance → ALCOA+. - GAMP 5 / CSA validation lifecycle — regenerable validation package per system release (traceability + IQ / OQ / PQ-from-CI + change-control + signature manifestations), CI evidence-ingestion seam, validated-state change-control gate → Compliance → Computer system validation.
- The opt-in GSD experimental-backend rollout policy (per-call telemetry → aggregate rollup → flip-readiness verdict → per-tenant graduation) → Deployment & Hosting → GSD experimental backend rollout.
- Secure-SDLC CI gates (SAST / SCA / IaC scanning with CRITICAL-blocks and triage SLAs), the signed supply chain (CycloneDX SBOMs, keyless SLSA provenance, verify-at-deploy), and zero-trust CI hardening (SHA-pinned actions, least-privilege workflow permissions, IaC posture-drift gate) → Security Policy → Secure development lifecycle, → Supply-chain integrity, and → Zero-trust CI hardening and IaC posture.
- API abuse protection — the token-bucket rate limiter (
429+Retry-After+X-RateLimit-*), the request-body size cap (413), and the WAF edge runbook → Security Policy → API abuse protection and Backend / API Contract → Rate limiting. - Coordinated vulnerability disclosure and penetration testing —
/.well-known/security.txt, the VDP with safe harbor, the pen-test program, threat model, and findings register → Security Policy → Vulnerability disclosure and penetration testing and Backend / API Contract → Public unauthenticated endpoints. - SIEM sink seam and security detections (impossible travel, privilege escalation, cross-tenant access, audit-chain break) plus the admin alert / detection-run endpoints → Security Policy → Security monitoring and detections and Backend / API Contract → Admin / operations endpoints.
- The incident-response program — severity model, roles, containment levers, runbooks, the breach-notification deadline engine, and the endpoints IR depends on → Security Policy → Incident-response program and Backend / API Contract → Endpoints that incident response depends on.
- The SOC 2 / ISO 27001 control-evidence register (a self-assessment of control coverage — neither a SOC 2 report nor an ISO/IEC 27001 certificate is held), the inherited-vs-operational control boundary, and the Trust Center with its sub-processor register → Compliance → Framework control-evidence register, → What the register does not claim, and → Trust Center.
- The 2026-07 infrastructure migration off Render to Google Cloud — the backend on Cloud Run (
moltrace-backend, projectmoltrace-prod,us-central1, scale-to-zero), Cloud SQL for PostgreSQL 16 on a private IP over Direct VPC egress, Cloud Storage / Secret Manager / Cloud KMS / Artifact Registry / Cloud Build, keyless CI/CD deploys via Workload Identity Federation, and the Vercel frontend behind the same-origin/api/backendproxy → Deployment & Hosting → Platform hosting (Google Cloud), → CI/CD keyless deploy, and Security Policy → Infrastructure and hosting. - The Cloud Storage raw-FID vault backend that keeps the write-once ALCOA+ vault working on serverless (create-only
if_generation_match=0writes, SHA-256 verification, bucket retention + versioning as the WORM mechanism) → Deployment & Hosting → Raw-FID vault on serverless and Security Policy → Write-once raw-evidence vault on serverless. - Backup and disaster-recovery resilience — what is backed up, the RTO / RPO objectives, the restore-integrity verifier, and the restore-drill cadence → Deployment & Hosting → Backup & disaster recovery, → Recovery objectives, and → Restore-integrity verification.
- Repho Phase C heavy-ML reaction engines as default-off governed guests — the six engines and their site-installed extras, the surfaces that need no heavy dependency (yield predictions, route scores, forward checks), the deliberately unwired generative paths, the absent SDL execution surface, and the capability honesty readout → Reaction Optimization → Phase C engines and the capability readout, → Enabling the optional Phase C engines, and → Reading Phase C predictions, route scores, and forward checks.
- GDPR data-subject requests and the right to erasure — the library-only DSAR / erasure planner (Art. 15 discovery, Art. 17 per-store plan, Art. 12(3) deadline), the classified personal-data map with its four dispositions, the pseudonymisation-is-never-erasure invariant, and the plainly stated limit that identity cannot be erased from the immutable audit ledger (crypto-shredding is a documented seam, not a capability) → Privacy Policy → Data-subject requests and the right to erasure and Compliance → Privacy: data-subject requests and residency.
- Data residency — single-region hosting with no tenant region pinning (no EU-pinned deployment available), and the honest per-item status of what pinning would require → Privacy Policy → Data residency.
- The security-documentation accuracy sweep from the retired Render deployment to Google Cloud — the corrected shared-responsibility posture, and the two postures the migration genuinely improved (private-IP Cloud SQL with no public interface, keyless Workload Identity Federation deploy authority in place of stored deploy-hook secrets) → Security Policy → Documentation accuracy sweep after the Google Cloud migration.
- The three open Medium findings the migration opened in the security findings register — the per-instance rate limiter on multi-instance Cloud Run, the missing container-image vulnerability scan, and the database RPO gap against the documented ≤ 5 min objective → Security Policy → Open findings from the infrastructure migration, → Rate limiting across multiple Cloud Run instances, Deployment & Hosting → Container-image vulnerability scanning gap, and → Where the stated RPO is not met today.
- API contract surface (new endpoints, audit events, admin actions, cross-cutting request gates) → Backend / API Contract, including the Phase C reaction optimization endpoints.
- Documentation, brand, and navigation history → Brand Identity & Navigation → Shipped.
The canonical, version-pinned source of truth for backend releases remains moltrace_backend/CHANGELOG.md.
Recent updates
Section titled “Recent updates”Everything through v0.63.0 (2026-07-23) has been distributed into the feature pages listed above — including the v0.53.0 – v0.61.0 security program (Prompts 14–22), the migration of the backend from Render to Google Cloud with its three open findings, the P23 privacy / data-residency posture, and Repho Phase C. Nothing is pending redistribution. New releases land here first, then move into the relevant feature page when stable.