Changelog
What shipped, and when
Every entry is something you can see in the product. Work that changed nothing a customer could observe is not listed here.
The API, documented and typed
- The API reference now documents every public endpoint — including the credit balance and the bot registry, which it had been quietly omitting — with a copy-pastable request and a real sample response for each.
- API keys can be given their scopes and their own rate limit at creation, and renamed, re-scoped or re-limited afterwards without minting a new one. Keys that can reach the MCP server can now be created in the product at all.
- The MCP server page opens with a two-minute quickstart, and the API keys screen shows the exact client configuration to paste, with a placeholder where your key goes.
- A typed TypeScript client for the REST API — one method per endpoint, typed errors, and retries that stop rather than turning a rate limit into your outage — is documented ahead of its release.
Credits you can see before you spend them
- Usage is now denominated in credits, with a published price per engine check and per action, so the cost of a scan can be worked out before it runs rather than inferred afterwards.
- Billing shows a credits meter with the plan allowance, what rolled over, and any top-up, and unused allowance carries into the next month up to twice the allowance.
- Credits are currently measured and displayed only — running the meter down refuses nothing yet.
- The public API gained a usage endpoint returning that balance, the price table, and whether the balance is being enforced.
A first run that finishes, and copy that tells the truth
- Prompt generation no longer fails outright when one suggestion comes back malformed, and it reports real progress with elapsed time instead of a spinner that says nothing for a minute.
- Generating twice at once is prevented, so a refresh or a second tab cannot spend twice.
- Onboarding is resumable: leaving mid-wizard returns you to the step you left, and a step you would rather skip can be skipped explicitly.
- Failures that used to be silent now say so — a checkout that cannot start, an email that cannot be sent, a trial that ends when it actually ends.
- Around thirty dead-end empty states gained a sentence explaining the emptiness and a way out of it.
- The prompt quota is described correctly at last: it is a cap on how many prompts are active at once, not a monthly allowance that resets.
- Prompt and log tables become cards below 640px, and unfamiliar terms carry a plain-English gloss linked to the methodology behind them.
- A reports index makes past reports reachable: until now a generated report could only be opened in the moment you created it.
AI traffic the tag was silently dropping
- The visitor tag now reports a counters-only daily aggregate as well as individual visits, so the AI traffic it previously discarded — the overwhelming majority of it — is visible without retaining anything about the people behind it.
- DeepSeek, Grok, Meta AI, Mistral, Phind and duck.ai are recognised as AI referrers, and traffic that looks AI-referred but cannot be proven is counted separately rather than claimed.
- A healthy installation is no longer accused of having stopped reporting after two weeks — the freshness check was reading a value written once at install.
- AI Traffic opens with a panel stating the tag's health, today's hits and the AI / possibly-AI / other breakdown, so an install can be confirmed in one look.
Sign-in protection and honest spend
- Repeated failed sign-ins are rate-limited and an account locks for fifteen minutes after ten of them; completing a password reset clears the lock immediately.
- Changing your account email is confirmed from the old address, so a stolen session cannot quietly take the account with it.
- Account security settings are reachable from one place, and several workspace actions that a member could reach now require an admin.
- A model call that fails with a provider error releases what it reserved instead of counting against your spend, and third-party search and grounding fees are now included in what a call costs rather than being invisible.
Attribute-level competitive insight
- Insights now extracts the attributes AI answers actually credit you for — pricing, onboarding, support — and shows them as a treemap sized by share and coloured by rate.
- Leading, parity and behind are decided by whether two confidence intervals overlap, never by comparing raw ratios, and a competitor needs at least three extracted records before it is compared at all.
- Topic Analysis gained per-topic competitor cards listing each rival's visibility, rank and average position, with “beats you in …” chips for the attributes they are credited with and you are not.
- A card with nothing to compare now tells you which kind of nothing it is: the attribute was never mentioned, extraction has not run, no rival cleared the evidence floor, or no rival actually beats you.
- Charts across Insights, Traffic and LLM Analytics now draw their labels at the intended size on narrow screens instead of shrinking the type along with the drawing.
- Wide tables, dialogs and code blocks scroll inside themselves rather than dragging the whole page sideways on mobile.
Recommendations that explain themselves
- Every opportunity now opens with a written rationale and concrete implementation steps, generated once on first open and cached, with the measured figures rendered separately above the prose.
- Prompt-gap cards name the competitors that are winning the prompt, with their counts and the share of that prompt's answers naming any competitor — instead of naming only the leader.
- New recommendation: audit a page AI already cites. Pages the engines use as a source that the audit queue has never checked are now surfaced directly.
- New recommendations for content-type gaps, duplicate competitor entries, unused prompt/sample/audit capacity, and topics that are mostly AI-generated and never reviewed.
- Each card's primary button now goes to the surface that actually fixes it, and a setup recommendation you have declined stays declined even after it re-detects.
Brand facts, narratives and a way to reach us
- AI answers state things about your brand as fact. Those claims are now extracted, listed, and can be confirmed or disputed — and disputed claims raise their own recommendation.
- Insight views now lead with a written narrative of what the data shows, rather than leaving you to read the chart cold.
- A support contact is reachable from inside the product, including a “report a bug” action that prefills the page you were on.
Pricing, privacy, terms and security in public
- Public /pricing, /privacy, /terms and /security pages. Pricing reads from the same plan catalog the checkout and the entitlement checks use, so it cannot advertise a limit the product does not enforce.
- Terms acceptance is now recorded at signup.
Security fixes and operational safety nets
- Shared report links now carry a real per-link secret instead of failing open to a shared default.
- CSV exports are escaped against spreadsheet formula injection.
- Post-signin redirects are restricted to this site, and analytics beacon traffic is authenticated so it cannot be forged.
- The background worker reports a heartbeat and the queue raises an alert when jobs start aging, so a stalled sync is noticed rather than discovered.
Spend ceilings you control
- Every paid model call is now reserved before it runs and settled at its real price afterwards, so usage is accounted for even when a call fails part-way.
- Each workspace has a daily spend ceiling. Reaching it degrades the affected view to what can be shown honestly — it never silently substitutes an estimate.
- A round of security hardening across authentication, session handling and API input validation.
Card-required trial and billing controls
- Every plan starts with a 7-day trial. A card is required to begin it, nothing is charged until it ends, and the trial is once per workspace.
- Plan limits — tracked prompts, daily samples, monthly audits, seats — are now enforced from a single catalog shared by billing, entitlements and the pricing page.
Team invites
- Invite teammates by email, with revoke and resend. Invites are seat-capped at both send and accept, and accepting is bound to the invited address.
- Transactional email is wired up for invitations.
Get started
Start tracking your AI visibility
A 7-day trial on every plan. A card is required to begin it and nothing is charged until it ends.