Quarterly review

What we shipped in Q3

A studio of nine. We publish what went out each quarter, including the work that slipped and the thing we stopped selling, because a retrospective that only lists wins is marketing.

14Releases
3Client teams
1Service retired
9People

July – September 2026

  • Added Havn — a booking flow rebuilt around a single screen. Completion moved from 61% to 83% over six weeks of live traffic.
  • Added Orrery — an internal data explorer that replaced nine spreadsheets and a standing Tuesday meeting.
  • Changed Every client project moved onto one token pipeline. Handover time roughly halved, from eleven days to five.
  • Fixed Our own site, which had been described as temporary for fourteen months.
  • Removed The open-ended retainer. Three clients moved to fixed-scope engagements; two chose not to, and that was the right outcome.
  • Note One opening in Q4, starting November.

Written in the week the quarter closed, not reconstructed afterwards.

Read the full review →

Trust centre

Policy revisions, on the record

Every change to a security policy is versioned, approved by two reviewers, and published here. Auditors read this page instead of asking us to assemble a changelog.

Revision history

  • Updated Access review cadence moved from annual to quarterly for all production systems.Rev 14
  • Added A key rotation standard covering signing keys, with a 180-day maximum age.Rev 14
  • Changed Vendor risk tiering moves to four tiers. Sub-processors are always tier one.Rev 13
  • Updated Incident severity definitions aligned to the notification windows in the data processing agreement.Rev 13
  • Removed The exception process permitting indefinite waivers. Waivers now expire after ninety days.Rev 12
  • Note Revision 11 and earlier are retained in the archive and remain available to auditors.Archive

Evidence coverage

Controls with current evidence on file, by family. The marker is the 90% threshold our auditor requires before fieldwork opens.

Access control48 / 48
Change management31 / 33
Incident response22 / 22
Business continuity12 / 14
Vendor review17 / 21

Vendor review closes the gap on 30 September, when the four outstanding questionnaires fall due. Business continuity clears after the October failover test.

Revisions are approved by the security lead and one director. Both signatures are on file.

Request the full policy set →

Patch notes

1.14 — Ashfall

The largest content drop since launch, and the balance pass players have been asking for since the spring tournament. Saves from 1.12 onward carry over untouched.

Ashfall Reach

Added

  • Added An eight square kilometre region with three settlements and weather that will genuinely kill an unprepared character.
  • Added Twenty-one recipes built on ash-glass, workable only at a forge held above 800 degrees.
  • Note Reach opens at character level 24. Existing saves qualify immediately.

Combat balance

Changed

  • Changed Heavy weapons lose twelve percent swing speed and gain armour penetration. Net damage against plate is up.
  • Changed Stamina now regenerates while blocking at forty percent rate rather than stopping outright.
  • Removed The parry cancel that chained three ripostes. It was never intended and it decided too many duels.

Stability

Fixed

  • Fixed A crash when loading a save written during the Hollow Market siege.
  • Fixed Rain rendered inside buildings throughout the eastern quarter.
  • Updated Shader compilation moved to first launch, which removes most mid-session stutter on PC.

Servers restart 18 September at 03:00 UTC. Expect roughly ten minutes of downtime.

Full patch notes →

API migration

Every breaking change, dated in advance

Nothing on this timeline moves without ninety days of notice. Dates that have already passed are kept here so you can see we held them.

v2 → v3 timeline

  • Note 14 Jan 2026v3 opens in public beta. Test keys only, no rate limits, and no commitment to the shape of new endpoints.
  • Changed 03 Mar 2026Amounts become integer minor units everywhere. 12.50 is sent as 1250, removing float rounding from settlement.
  • Removed 12 May 2026/charges is retired. /payment_intents covers every flow it supported, including off-session capture.
  • Removed 12 May 2026Currency is no longer inferred from the account default. The currency field is required on every request.
  • Updated 01 Sep 2026v2 enters maintenance. Security fixes only; no new fields, no new endpoints.
  • Info 15 Dec 2027v2 is switched off. Requests return 410 Gone with a link to the migration guide in the body.

Pin a version with the API-Version header. Unpinned keys follow the account default.

Migration guide →

Firmware

Aster One — 2.8.0

Updates install overnight while the sensor is idle and charging. If power is lost mid-write the device boots from the previous image, so a failed update has never bricked a unit in the field.

Device

Aster One

Indoor air quality monitor

ChannelStable
Image size1.84 MB
Install window02:00 local
Rollback slot2.7.3 retained
Fleet on 2.871%
SignatureEd25519

Units on 2.5 or earlier install 2.6 first. The updater chains this without intervention.

Released 2 September 2026

  • Added Particulate calibration against the reference station now runs automatically every fourteen days.
  • Added Offline logging holds ninety days of readings when the network drops, and backfills on reconnect.
  • Changed On battery, the sampling interval drops to five minutes. Runtime goes from six days to about eleven.
  • Fixed Humidity readings drifted up to four percent after prolonged operation above 35 °C.
  • Fixed The device could report one stale reading immediately after waking from deep sleep.
  • Note The 2.7 series stops receiving fixes on 1 April 2027.

Signed images and release hashes are published alongside every firmware build.

Download image →

Design system

Meridian 3.0 is out

Three years of component drift, reconciled. Every token was renamed once, documented, and shipped behind a codemod so a product team upgrades in an afternoon rather than a quarter.

3.0.0 — 4 September 2026

  • Added Twelve density tokens, so tables, forms and dashboards stop inventing their own spacing.
  • Added A codemod that rewrites v2 token names across a repository. Dry-run is the default.
  • Changed Colour tokens moved to OKLCH. Every value round-trips to its old hex within one percent.
  • Changed Button ships four sizes instead of seven. The three removed had forty usages between them.
  • Removed The legacy Grid wrapper. Use CSS grid directly; the abstraction earned nothing.
  • Note v2 continues to receive security patches until 1 March 2027.

Adoption

Product surfaces already on v3

94%target 80%

Audit

312Components reviewed
41Marked deprecated

Each deprecation carries a named replacement and a codemod. None are removed before v4.

Migration guide, codemod and the full token diff are in the handbook.

Read the upgrade guide →

Deployment log

Every change to production, in order

Nothing reaches production without landing here first. The log is written by the deploy pipeline, not by hand, so it cannot drift from what is actually running.

6Deploys today
4m 12sMedian pipeline
0Rollbacks this week
99.98%30-day uptime

Tuesday 9 September 2026

  • Updated 16:41Search indexer rolled to 2.9.4 across all six regions. Reindex completed in 11 minutes.eu-west-1 +5
  • Fixed 15:08Connection pool exhaustion under sustained write load on the billing shard.billing
  • Added 13:22Read replicas in ap-southeast-2, cutting p95 read latency for the Sydney region to 34 ms.platform
  • Changed 11:47Default request timeout lowered from 60s to 30s. Long-running exports move to the job queue.api-gateway
  • Removed 09:30TLS 1.1 termination retired at the edge. Six accounts were contacted in July; all have migrated.edge
  • Note 08:00Maintenance window opens 18 September, 02:00–04:00 UTC. No downtime expected.scheduled

Entries are written by the pipeline at deploy time. Retained for seven years.

status.page →

Release notes

What shipped in 4.2

Every release is documented here within an hour of deploy. Breaking changes are announced twelve weeks ahead on the API changelog, never in a patch release.

4.2.0

Stable channel

Released11 Sep 2026
Builda7f3c19
Commits34
Contributors6
Bundle delta−18.4 kB
MigrationNone required

Signed with the release key ending 4C1D. Verify the tarball before deploying to a self-hosted instance.

Changes in this build

  • Added Saved view filters now persist across sessions and sync to every device on the workspace.#4821
  • Added Bulk CSV export on the reporting tab, capped at 250,000 rows per request.#4790
  • Changed Webhook retries are batched into 30-second windows, cutting outbound volume by about 40%.#4776
  • Fixed Timezone drift on recurring events that crossed a DST boundary in the southern hemisphere.#4833
  • Fixed Avatar uploads over 8 MB failed silently instead of returning a validation error.#4829
  • Removed Legacy /v1/reports endpoint, deprecated since 3.6. Use /v2/reports instead.#4801

Releases ship on Thursdays. Security patches ship the day they are ready.

RSS · JSON feed →

Who does the work

Four analysts, and
the models are theirs

Every figure we publish carries a named author. If you want to argue with a number, you can argue with the person who produced it.

pexels photo 38670590 1

Ingrid Sorensen

Head of research

Sets the method and signs the quarterly outlook.

pexels photo 5670175 1

Ravi Chatterjee

Grid modelling

Builds the half-hourly dispatch model and stress-tests it.

pexels photo 7471637 1

Joon-ho Park

Data engineering

Owns the pipeline from meter reading to published series.

pexels photo 7597466

Lucie Berthold

Policy analysis

Reads the consultations so that nobody else has to.

Method notes and the full series are published alongside every report, in CSV and as a dated PDF.

The bench

Four pairs of hands,
in the order you meet them

A full binding crosses four benches. These are the people who will hold your book, and the order in which they do it.

01Consultation & structure

Takes the brief, then chooses the sewing structure and the board thickness with you.

pexels photo 38670590 1

Iwan Marchbank

Proprietor · structure

Takes the brief, then chooses the sewing structure and the board thickness with you.

02Forwarding

Sews, rounds and backs the text block, then laces the boards on by hand.

pexels photo 5670175 1

Rafi Sadeghi

Forwarder

Sews, rounds and backs the text block, then laces the boards on by hand.

03Covering

Pares the leather thin enough to turn, and covers. The corners are hers.

pexels photo 7471637 1

Liesel Vane

Coverer & finisher

Pares the leather thin enough to turn, and covers. The corners are hers.

04Tooling & lettering

Lays the gold and cuts the lettering on the spine with hand tools.

pexels photo 31869535 1

Desmond Achebe

Finisher · gold tooling

Lays the gold and cuts the lettering on the spine with hand tools.

Commissions are quoted in writing, and we will say so if a repair is the better answer.