Developer changelog
API & platform changes.
Updates that affect API and SDK consumers - model and capability changes, platform releases, and security bulletins. For the full product changelog see /changelog.
- Platform
Bounded durable orchestration for Bee Code
Bee Code 0.2.11 and Bee Code CLI 0.1.4 give each customer task a durable account-scoped run. The active subscription and selected model jointly cap logical task decomposition, parallel model calls, specialist calls, and tokens before any model capacity is provisioned. Postgres atomically reserves each call and lease, every manager, specialist, and verifier call is independently metered, cancellation is terminal-safe, and infrastructure or metering failures fail visibly. Coding, design, configuration, and form-automation tasks cannot be marked complete without mutation evidence followed by verification. VS Code advertises only tools registered in the local host, including installed MCP tools; every external invocation is revalidated and requires fresh explicit approval. Logical workers are bounded task decompositions rather than continuously hot GPUs, and common subscription enforcement does not imply identical local capabilities across Workspace, mobile, desktop, SDK, MCP, and Bee Code.
- Security
Subscription-authoritative model access
Bee model access, capacity, and quota now follow the account's active billing subscription across Workspace, API, direct Swarm, and BEE Code. Administrative permissions remain company-only and cannot wake or consume a paid model. Workspace and BEE Code enforce both the binding model-tier allowance and pooled-token allowance, stopping at the first exhausted limit before inference. Hard-limit BEE Code turns reserve their request slot atomically, so concurrent IDE calls cannot race through the final Bee Cell slot; conservative prompt-plus-output admission prevents one oversized turn from crossing the remaining hard token wall. The database usage-log trigger is the sole token-counter writer, preventing BEE Code usage from being counted twice, and metering failures now fail visibly. BEE Code 0.2.10 reconciles stale configured and resumed models before submission, sends no request while plan access is unresolved, starts new sessions with Bee Cell and Low effort, and updates the open effort control immediately when a manual choice exits Fast Mode. Its customization menu now opens live Bee output-style and memory controls plus VS Code's native Agents, Hooks, MCP, and Plugins managers; coding turns apply the account's saved communication preferences. Account usage cards, tier breakdowns, and meters now share the same anniversary billing period. Billing holds the single Bee-code redemption control, while Gift Bee is exclusively for creating gifts. Hard-limit plans explicitly show that no overage or automatic credit reload is charged; overage controls appear only for eligible paid plans. Free-plan rollovers reset every enforced counter atomically.
- Release
Canonical Bee package catalog and public release evidence
Bee Public now publishes human-readable and machine-readable catalogs for the TypeScript SDK, Python SDK, MCP server, Bee Code CLI, Microsoft Marketplace extension, and Open VSX extension. Every entry names its canonical registry, exact version, install path, license, and honest source-availability boundary. Registry verification, export checksums, the SPDX SBOM, and release assets are generated and verified locally. Routine SDK publication is local-only; GitHub Actions remains an explicit emergency backup. Bee Code CLI 0.1.3 corrects its public npm scope and issue metadata without representing its proprietary implementation as public source.
- Release
Exact model entitlements across Bee surfaces
Bee now derives Workspace, API, website, Workspace picker, BEE Code, SDK, and MCP model availability from one machine-readable entitlement matrix. Workspace subscriptions are cumulative from Cell through the purchased plan; API products retain their separately priced Pollen, Nectar, Honey, Propolis, and Royal Jelly ladder. BEE Code 0.2.9 fails closed to Cell when account-plan resolution is unavailable and does not present a setting as active without a real management destination. Version 0.2.9 is live on the Microsoft Marketplace and Open VSX. Python SDK and MCP 0.6.10 and TypeScript SDK 0.2.0 expose the same six customer-selectable request models. Android 1.0.2 (build 18) is at 100% Google Play production rollout and consumes the same live Workspace entitlement path; Enclave remains a deployment mode rather than a seventh model.
- Release
BEE Code 0.2.8 full model ladder and branded sign-in
BEE Code 0.2.8 for VS Code exposes the complete governed Bee ladder: Cell, Brood, Comb, Buzz, Hive, and the routed Swarm fabric. The account's subscription and API entitlements remain server-authoritative, so eligible models become available without a separate extension release. Coding requests now dispatch to the exact entitled tier, retain tier-appropriate metering, and fail closed instead of silently substituting a smaller model. Browser sign-in returns to a centred, responsive page with the official Bee identity and removes the access token from the final browser URL. Updated Marketplace documentation links directly to the TypeScript and Python SDKs, MCP resources, model matrix, and public repository. Version 0.2.8 is live and publicly verified on both the Microsoft Marketplace and Open VSX.
- Release
Stable Bee model attribution and public diligence evidence
Bee Code 0.2.6 for VS Code and @heossihq/beecode 0.1.2 now record the selected governed model by its stable product name, such as Bee Cell or Bee Hive, in the optional Co-Authored-By trailer without attaching a release-version suffix. The developer remains the primary Git author and can disable the trailer. Bee Public now includes a deterministic SPDX package SBOM, SHA-256 payload checksums, an enterprise diligence map, scenario architecture, and a repository social-preview asset; the export remains generated and validated from the private monorepo source of truth.
- Release
Bee Code attribution and public architecture centre
Bee Code 0.2.5 for VS Code and @heossihq/beecode 0.1.1 add transparent, default-on commit attribution for commits created through Bee's dedicated Git tools. The developer remains the primary Git author; the selected governed Bee model and product version are recorded in a separate Co-Authored-By trailer, and both clients provide an explicit opt-out. The public architecture centre now connects the BSIS reference architecture to reviewable IDE coding, tenant-scoped retrieval, and explicit quantum-compute scenarios, with matching Mermaid diagrams in bee-public.
- Docs
SDK and MCP domain-routing synchronization
Published bee-sdk 0.6.7 and @heossihq/bee 0.1.7. Python now sends an explicit domain in the governed chat-completion request instead of relying on the retired stateful domain-switch pattern; omitted domains use governed automatic routing, and its Tier-1 type and bundled MCP catalogue include Cryptography & Post-Quantum Security. TypeScript now exposes a typed optional domain field and forwards it through the OpenAI-compatible Bee request. Higher-tier Stage-0 families remain deliberately absent from the public SDK and MCP selection catalogues until their promotion and customer-path gates pass.
- Platform
Global specialist taxonomy normalization
Bee's global BSIS taxonomy is now expressed as 66 customer-facing specialist domain families, 17 restricted and safety profiles, 22 Bee Ignite research lanes, and two operating modes. Legal advice, education for minors, and telecommunications operations remain stricter evaluation overlays on their parent families rather than duplicate public domains. Ten globally relevant Stage-0 families were added across banking and capital markets, maritime and ports, manufacturing, governance/risk/compliance, pharmaceuticals, trade/customs/export compliance, geospatial intelligence, resources, environmental services, and transport operations. Each new family has a 140-case qualification pack but no promoted adapter or release score is claimed.
- Model
Cryptography & Post-Quantum Security specialist domain
Bee's governed taxonomy now includes Cryptography & Post-Quantum Security as a dedicated Tier 1 domain, separate from general Cybersecurity, Quantum Computing, and Ignite-only Advanced Cryptanalysis. Customer selectors, MCP, routing, training rotation, distillation prompts, BSIS documentation, and machine-readable discovery surfaces now share the same domain identity. Its standards-grounded qualification pack contains 100 full cases, 20 performance benchmarks, 10 smoke cases, and 10 safety cases. The domain remains release stage 0 with no promoted adapter until quality, safety, latency, deployment, and customer-path gates are actually executed and passed.
- Platform
Bee Specialist Intelligence System and reference architecture
Bee now documents and exposes the Bee Specialist Intelligence System (BSIS): the HEOSSI-operated control system for source rights, domain packs, retrieval, tools, evaluation, safety and release evidence. The public reference architecture separates what is implemented today from later research phases. Cell through Hive remain transparently disclosed as governed, HEOSSI-hosted releases built from a compact open-weight base model; Swarm remains a routing fabric. Bee Ignite is now the separately governed path toward an independently pretrained specialist foundation model, with pretraining not started and no released checkpoint.
- Security
Model improvement default with persistent opt-out
Improve Bee is enabled by default for authenticated account and service interactions under policy version 2026-07-29.1. Account holders and authorised customer administrators retain a persistent opt-out. Incognito and history-off conversations remain excluded, as does provider output where provenance or contract does not permit training use. Customer documents remain tenant retrieval data rather than shared training material, and enterprise custom training remains separately instructed and contracted.
- Security
Gateway output safety enforcement across customer paths
The API and workspace gateways now apply the shared output-danger scanner to buffered and streaming completions across serving tiers. For streams, the fragment that completes a dangerous pattern is withheld, the upstream is cancelled, the canonical refusal is emitted and the block is captured for audit. Already delivered fragments that were individually harmless cannot be recalled; the completing fragment is not delivered.
- Security
Subprocessor notice: optional Android push through Google FCM
Advance notice under the Bee DPA: effective 27 July 2026, Google LLC (Firebase Cloud Messaging) will be added for optional Android push delivery. Push is off until a user enables it in the Bee Android app. Processing is limited to Firebase installation/registration identifiers, basic app/device metadata, delivery state, and privacy-minimised notification routing; lock-screen notifications do not include prompts, responses, documents, or scheduled-task result content. Bee's Vercel sender uses short-lived Google Workload Identity credentials and has no stored Google private key. Controllers may raise a reasoned data-protection objection through bee-privacy@heossi.com during the 14-day notice period.
- Docs
Global policy pack: AI transparency, accessibility, copyright, government requests
Four new legal documents at bee.heossi.com/legal: AI Transparency & Disclosure (you are interacting with an AI; capabilities and limitations; the synthetic-media stance stated honestly - embedded provenance marking for generated media is in development, not yet shipped; EU-AI-Act-aligned prohibited practices; and the ML-DSA-signed machine-readable facts contract), an Accessibility Statement (WCAG 2.2 AA target with current status stated honestly and a feedback channel), a Copyright & DMCA Policy (notice, counter-notice, repeat-infringer termination), and a Government & Law-Enforcement Data Requests policy (valid legal process only, narrowest scope, customer notice by default, MLAT for foreign authorities). The Privacy Policy adds an other-jurisdictions rights clause (Brazil LGPD, India DPDPA, Japan APPI, Australia Privacy Act).
- Security
Cryptographically verifiable product facts
Bee now publishes a machine-readable product-facts contract at /facts.json - tiers, capabilities, pricing, and recent releases - dual-signed with ML-DSA-65 (NIST FIPS 204, post-quantum) and Ed25519 (classical). Anyone can verify the facts are authentically ours and untampered against the public keys at /trust/facts/keys.json; the verifier is published in the repo. The same source renders /llms.txt for AI answer engines, so every surface states the same thing and cannot drift. Also shipped: a developer changelog at /docs/changelog and a What's new panel in the workspace, all rendered from one curated source.
- Model
1M-token context, video input, tool calling and JSON mode - live
Bee Comb and Bee Buzz now serve up to 1,010,000 tokens of context through a dedicated long-context mode (proven with a real 285,501-token request that retrieved a needle at 70% depth); Bee Swarm serves 1M natively. Native video input is live on Comb, Buzz and Hive. Tool / function calling and JSON mode (structured output) are live on Comb, Buzz and Hive. Every capability listed here was proven against the running production backend before it was advertised - the capability matrix on /models is generated from those live checks, not from intent.
- Docs
OpenAPI 3.1 contract + Postman collection
The Bee API publishes a machine-readable OpenAPI 3.1 contract (api.bee.heossi.com/openapi.json) and a Postman collection (api.bee.heossi.com/postman.json), so you can generate a client or import the API instead of hand-writing request shapes.
- Security
Post-quantum encryption at rest + the signed PQ coverage register
Conversation messages and titles, personal memories, and the research queue are now encrypted at rest. Each object is sealed with a fresh AES-256-GCM data key, and that data key is wrapped by genuine NIST ML-KEM (FIPS 203) encapsulation under a per-tenant key-encryption key - verified in production as a real ML-KEM wrap, not a symmetric key-wrap wearing a post-quantum label. Encrypted-content semantic search is preserved. Bee also publishes a post-quantum coverage register at /trust, signed with ML-DSA (FIPS 204) under an offline root key, with the verification key at /trust/keys and daily probes that continuously re-test the register's claims.
- Platform
See Bee think - reasoning traces and a thinking toggle
Workspace chat now surfaces the model's reasoning trace, with an explicit per-conversation toggle to turn extended thinking on or off. Each tier also gained its own sampling profile, so a tier answers at its intended temperature rather than inheriting a single global default.
- Platform
Free-tier fairness + launch offer codes
Free tiers now reset on a rolling window rather than a per-invoice counter: Bee Cell allows 30 requests per 5-hour session, and the free API tier 250 requests per 24 hours - both reset automatically, so an active free user is never left without a working allowance. Added shared, capped, one-redemption-per-user promo codes with optional start dates for launch offers, redeemable to the prepaid usage wallet. Verified end-to-end against production. (Commits 844fb96, 159374b, 213d251.)
- Platform
Gift Bee - send credits or a plan
You can now gift Bee: prepaid usage credits, or N months of any plan. Purchase and redemption flows are live, and the gift code is emailed to the recipient on payment. (PRs #28-#35.)
- Platform
Passwordless sign-in
Sign-in is now passwordless - a one-time email code; the password field has been removed. Accounts show their linked sign-in methods (email plus Google / GitHub / Microsoft / LinkedIn), and the download page lists the real editor and MCP integrations. (Migration 055_email_login_codes; PRs #23-#27.)
- Platform
One codebase across web, desktop, and mobile
Workspace, desktop, and the iOS app now run on a single web codebase via a hybrid WebView shell, so new features land on every surface at once. (PRs #1-#2.)
- Security
Cost-safe evolution engine
The autonomous adapter-evolution loop was redesigned to be event-triggered, bounded, and human-gated, and it ships OFF by default - no training runs inside the serving path. (PRs #3-#5.)
- Model
Honest serving ladder
Each tier now serves from its own dedicated backend, with an explicit Cell last-resort fallback and an internal alert if a higher tier is unavailable - rather than silently degrading a request to a smaller model without saying so.
- Model
Correction: cybersecurity adapter no-op de-promoted
A correction to the 2026-05-05 cybersecurity-adapter notes: a served cyber adapter was found to be a no-op - it had not effectively trained and returned base-equivalent output. It has been de-promoted, and a promotion guard now blocks any no-op adapter from reaching production. We publish corrections rather than quietly editing history.
- Platform
Hosted MCP, documents & memory, tenant-scoped RAG
Shipped the hosted Model Context Protocol server with a plan-aware tool surface, plus document and personal-memory resources over both the connector and the SDK, and a tenant-scoped /bee/documents RAG passthrough. SDK and API usage is now correctly metered and billed on the gateway (closing a streamed-call metering gap found in audit).
- Security
Trust page: real, reproducible eval scores
Replaced fabricated benchmark numbers on /trust with real, reproducible Cell-base eval scores from an industry-standard runner. If a number can’t be reproduced, it doesn’t ship.
- Platform
Partner Program, VC Partner Program, BEE for Startups
Three program intakes shipped: /partners (Build / Service / Resell / Cloud lanes - integrators, resellers, MSPs, cloud platforms, app builders), /vc-partners (venture firms backing AI-native startups), and /startups (early-stage AI-native companies - credits up to $25,000, architecture review, /platform listing, compliance head-start). All three back JSON POSTs at /api/{partners,vc-partners,startups}/apply, fan-out to bee-partners@heossi.com with structured emails, and ship dedicated legal docs at /legal/{partner,vc-partner,startup}-program-terms. Startup credits are reviewed manually - no auto-grants - and use the existing credit_ledger when accepted.
- Model
Governed Intelligence Ladder and Enclave deployment mode
Six intelligence tiers locked: Cell · Brood · Comb · Buzz · Hive · Swarm. Enclave is the private, regulated, and sovereign deployment mode for Hive- and Swarm-class workloads-not a seventh model tier. Each tier is delivered as a controlled Bee release under our governed release policy; supplier lineage and deployment manifests remain controlled governance records disclosed where contractually or legally required. Bee Ignite remains an internal R&D track, not a customer-selectable tier. Source of truth for engineers and auditors: governance documentation + per-adapter validation records published at /trust.
- Model
Hive / Swarm expansion + Enclave deployment work + Vertex auto-post + Kaggle multi-slug
Vertex training pipeline extended beyond Comb: Hive cybersec adapter smoke RUNNING on A100 SPOT (~10h ETA); Swarm cybersec dispatched on A100 80GB (~14h ETA); Enclave queued pending H100 80GB quota approval. Vertex worker now auto-posts to /api/training/runs (closes the gap that produced manual backfills), so eval-gate logic, the cutoff badge, and /admin/training see Vertex runs going forward. Kaggle dispatcher gained a multi-slug path so up to 3 kernels can run concurrently. With Vertex (~10 jobs), Kaggle (3), and Colab (2) live simultaneously, Bee now sustains roughly 15 parallel training jobs across the four-pipeline architecture. None of Hive / Swarm / Enclave is shipped - adapters are in training, not merged into routing. (Commit 1c285de.)
- Model
Stage 0.5 - cybersec adapter pipeline + research queue
Wired the elite cybersec adapter pipeline: Vertex Comb cybersec adapter landed at train_loss 0.314 over ~6h on L4. Tier-1 CII (Critical Information Infrastructure) wrapper and Bee Ignite research queue both online. Across today's haul: 12 Cell / Brood rotations across 9 domains via Colab (all candidate_worthy), 3 Comb domain adapters via Kaggle (cybersec, quantum, infrastructure). (Commit 9d20b3b.)
- Security
Stage 0 - runtime safety wrapper + marketing-claim audit
Added a runtime safety wrapper around every API call and ran a full marketing-claim audit so the public-facing copy matches what's actually live. Honest APK launch ready. (Commit 45a597e.)
- Security
Bee Security Eval Harness - 52 cases across 10 categories
Shipped the eval harness that gates every release: 52 cases, 10 categories (insecure code generation, prompt injection, agent tool abuse, tenant isolation, authz/authn, cloud IAM, dependency CVEs, secret leakage, unsafe cyber responses, hallucinated security claims). Source of truth: evals/yaml_harness/cybersecurity/. (Commit 96c751c.)
- Platform
NVD apiKey + pagination, CISA KEV cron, NVD history backfill
Daily NVD CVE pull and CISA KEV ingestion are wired and running (apps/web/src/app/api/cron/cve-ingest, apps/web/src/app/api/cron/kev-ingest). Added scripts/data/backfill_cve_completions.py and scripts/data/push_cve_corpus_to_hf.py for the historical backfill. (Commit b2ff987.)
- Model
Teacher-model distillation + CVE prompt backfill
Wired an external teacher model into the distillation pipeline and added the CVE prompt backfill so the cybersec adapter trains on grounded vulnerability content rather than synthetic prompts. (Commit b3d4e03.)
- Platform
Workspace + Marketing site split
We separated the customer workspace (workspace.bee.heossi.com) from the marketing site (bee.heossi.com) and published the comprehensive Trust & Evidence index, the comparison-vs-incumbents matrix, the Singapore-jurisdiction legal pack, and per-page JSON-LD + llms.txt for AI crawlers.
- Platform
Native email-confirmation + OAuth (Google · GitHub · Microsoft)
Sign-up now uses a first-party email-confirmation flow plus three OAuth providers. JWT verification is local (HMAC-SHA256 against SUPABASE_JWT_SECRET) so middleware works at the edge with no GoTrue round-trip.
- Platform
Per-plan RAG quotas + per-tenant document store
Replaced 'unlimited' RAG copy with concrete plan-level document and storage caps. Document upload now enforces per-tenant quotas at write time, fixing a privacy regression where uploads could land in the wrong tenant store.
- Model
/models page + canonical model catalogue
Single-source-of-truth model catalogue with per-1M-token pricing for Cell, Comb, Hive, Swarm, plus the Enclave deployment mode and the Ignite research track. Adapter routing reads the same catalogue.
- Platform
Production SMTP mailer + /contact form
Pooled Namecheap-Private-Email transport, the eleven bee-*@heossi.com forwarders, contact-form submissions with file attachments, honey-pot spam protection, and 5/15min/IP rate limiting.
- Security
Direct-Postgres + local-auth fallback
When Supabase egress restriction was active we needed signups to keep working - local JWT verification + a pg-shim path were added so middleware and account routes don't depend on the GoTrue HTTP API.