# Changelog of Ai Claim Readiness Checkpoint (`filipmajchrzak/ai-claim-checkpoint`) Actor

- **URL**: https://apify.com/filipmajchrzak/ai-claim-checkpoint/changelog.md
- **Full Actor documentation**: https://apify.com/filipmajchrzak/ai-claim-checkpoint.md

## Changelog

### 0.5 post-publication listing correction — 2026-08-13

- Updated buyer-visible documentation from release-candidate wording to published paid-public-beta wording.
- Recorded the confirmed USD 0.49 `verified-decision` pay-per-event configuration and pre-publication 0.5.1 smoke evidence.
- Changed the source metadata `buildTag` from `beta` to `latest` for future CLI-consistent deployments; Git-repository deployment settings remain controlled in Apify Console.
- No evaluator, wrapper runtime, policy, dependency, input/output semantics, or billing fence code changed.

### Unreleased — v0.5.0 / R7 paid public-beta candidate

#### Added

- One Apify pay-per-event unit, `verified-decision`, for a completed verified evaluation and replay bundle.
- Equal billing semantics for verified `ALLOW`, `BLOCK`, and `NEED_MORE_EVIDENCE` decisions.
- Explicit non-charge policy for malformed/rejected input, fail-closed outcomes, and unverified outcomes.
- Durable `BILLING_ATTEMPT`/`RESERVED_NO_RETRY` write-ahead fence, bound to the run and exact verified output and read back with that output before billing, to suppress a second Dataset/charge attempt after serialized restart or resurrection.
- Buyer-favouring delivery of verified output without retry when fence persistence, Dataset delivery, or billing outcome is uncertain.
- Explicit residual boundary: the ordinary Key-value store fence is not claimed as atomic compare-and-create protection for hypothetical overlapping containers or deleted storage.
- Paid-beta terms, privacy notice, support/access-consent policy, and charge-review procedure.
- Owner-configured private Apify price of USD 0.49 per `verified-decision`; the public offer remains unavailable until final build binding and publication.
- B2B/professional-only target audience; the beta is not intended as a consumer offering.

#### Changed

- Hosted product wrapper advances to v0.5/R7 while the evaluation engine remains the byte-frozen R6 runtime.
- Actor memory is fixed at 256 MiB for the release candidate.
- Commercial copy now describes payment for deterministic processing and replay evidence, never for an `ALLOW` result, certification, or favorable outcome.
- Local candidate JSON and Apify schema validation now run in disposable, resource-bounded process groups with lexical JSON budgets, bounded diagnostics, hard time/memory/output ceilings, and mandatory descendant cleanup.
- Process-cleanup regressions now require a child-readiness handshake and prove that descendant activity stops without confusing an unrelated Linux thread ID with a surviving process.
- The delivery builder's future independent-audit contract now binds the exact buyer-favouring billing fence and its explicit serialized-storage limitations; no delivery build has been run.

#### Commercial release blockers

- Private Apify billing details and payment method are complete; payout KYC remains pending.
- Private monetization is active as pay per event with only `verified-decision` at USD 0.49, no synthetic start/default-Dataset paid event, and no platform-usage pass-through. Final API/post-build read-back is still required for the exact release.
- The exact Checkpoint 016 source must be imported to the isolated GitHub branch, bound to one Apify build, and verified through a limited smoke run.
- A genuine independent U1–U5 session must be bound to that exact build and a session identifier.
- The publisher must personally accept any current legal terms or checkboxes and authorize final Store publication.
- Exact Apify-managed final-image digest verification remains unavailable unless support supplies a route; the owner selected Apify and accepted the documented limitation with compensating controls, without allowing a false exact-image PASS.

#### Preserved

- The R6 evaluator, trusted launcher, portable verifier, and runtime freeze remain the active evaluation engine and retain their published byte bindings.
- Historical R4 and R5 runtime files remain byte-identical for evidence preservation.

### Prior candidate — v0.4.0 / R6 public beta

#### Added

- Public experimental Easy Mode limited to `software_release_basic_v1`.
- Unmistakably synthetic public default producing a verified `ALLOW` fixture.
- Public wrapper output schema v2 and adjacent MIT license for the bundled verifier.
- Bounded public failure codes without raw exception disclosure.
- Literal independent golden vectors and public-surface adversarial tests.
- Digest-pinned base image and wheel-only hash-verified dependency lock.
- Versioned R6 public runtime with a distinct trusted verifier launcher and portable MIT verifier.
- Exact replay archive grammar, small implementation resource ceilings, and descriptor-relative evidence traversal.
- Bounded scan of the actual ZIP central-directory records before Python parses the directory, including rejection of forged EOCD counts.
- One immutable replay-ZIP byte snapshot for digest, sidecar, grammar preflight, parsing, and semantic verification.
- Exhaustive local-record and central-directory cross-checking that rejects hidden local records, preambles, gaps, and trailing data-area bytes.
- Non-materializing JSON grammar budgets before `json.loads`.

#### Changed

- Public scope states `experimentalBeta=true` and `privateEvaluationOnly=false`.
- Public API rejects the historical Strict and model-evaluation contracts.
- Application logs omit user-controlled identifiers.
- Controlled failures leave the Apify lifecycle with status `1` without exposing Python tracebacks.
- Local validation now pins the complete Node validator tree; wheel licenses are authenticated before archive parsing.
- Delivery packaging uses one immutable byte snapshot and re-verifies both ZIP bindings before any write.
- Validation and packaging use the same globally path-sorted candidate-source manifest.
- Local validation requires an independently supplied source-manifest digest and a hash-bound absolute Node executable.
- Delivery packaging requires independently supplied hashes for the source manifest and all six required reports.

#### Preserved

- Historical OCOI Evidence Gate Lite R4 and public R5 runtime files remain byte-identical.

#### Limitations

- Soft checkpoint only; no truth verification, production-readiness claim, hard enforcement, SLA, or market-validation claim.
- Publication remains blocked pending GitHub import, KYC, one exact Apify build, the maximum available image/SBOM evidence, post-build configuration read-back, a smoke run, U1–U5, personal acceptance of current platform terms, and final publication authorization. The evaluation engine remains R6.
