New Features
- E-Signature Platform — Complete document signing system with drag-and-drop field placement, sequential and parallel signing workflows, typed or drawn signatures, and multi-signer support.
- Drag-and-drop field placement — Place signature, initials, date signed, name, email, company, and title fields directly onto PDF documents. Fields are color-coded per signer.
- Sequential and parallel signing — Configure signing order when assigning documents. Sequential mode notifies each signer only when it's their turn. Multiple signers can share the same order number to sign in parallel.
- Typed signatures — Choose from 8 cursive font styles to generate a typed signature, in addition to drawing freehand. Signatures can be saved for reuse across documents.
- Signature validation — Canvas signatures are validated for quality: minimum size, ink coverage, and stroke complexity. Trivial scribbles are rejected with a clear error message.
- Audit trail PDF — Every signed document can be downloaded with a full audit trail appended, showing all signers' names, emails, timestamps, and signing status.
- Document sharing without signature — Documents can be shared for review without requiring a signature. Recipients receive a notification and email.
- Department head document permissions — Configurable read and create permissions for department heads. Create access implies read. Bulk Send remains admin/executive only.
- Breached password detection — Passwords are checked against the Have I Been Pwned database in real-time as users type during registration and password changes. Breached passwords are blocked from being set. Existing users with breached passwords are notified via in-app notification and email on their next login.
- Remember Me — Server-enforced session vs persistent login. Unchecked by default — users must opt in to stay logged in across browser sessions.
- Leave approval from detail modal — Approvers can now approve or reject leave requests directly from the leave detail modal without navigating away.
- Group booking restricted — Group leave booking is now restricted to administrators and executives only.
Improvements
- Documents index redesigned — Sidebar navigation with My Documents, All Documents (admin), Action Required, Completed, and Drafts views. Admins and executives can see all documents across the organization.
- Table layout rebuilt — Documents table uses a proper table layout with status badges, action buttons, and a Recipient column in Action Required view for admins.
- Browser back button support — Switching between document views now uses
pushStateso the browser back button works correctly. - Signature timestamp on PDF — Each signature and initials field in the rendered PDF shows the signer's name and timestamp.
- Email messaging for shared documents — Emails for non-signature documents say "shared a document with you" instead of "sent for signing."
- Due date timezone handling — Due dates are now inclusive with a 24-hour buffer. A document due on March 20 is not marked overdue until March 21.
- Dept head uploader filtering — When department heads upload documents, the user autocomplete is filtered to their department only.
- Self-approval prevention — Users can no longer approve their own leave requests, even if they have approver permissions.
- Dashboard scroll optimization — Scrollbar only appears on screens below 1320px width.
Security
- Data encryption at rest — Sensitive personal data (phone numbers, addresses, tax IDs, emergency contacts, bank details, webhook URLs, leave reasons) is now encrypted at the application level using AES-256-GCM, in addition to database-level encryption.
- HttpOnly cookie authentication — Refresh tokens are now stored in HttpOnly secure cookies instead of browser-accessible storage, protecting against cross-site scripting (XSS) token theft.
- Security headers — Content Security Policy, Strict Transport Security, X-Frame-Options, Referrer-Policy, and Permissions-Policy headers are now set on all responses.
- SSRF protection — Webhook URLs (Slack, Teams) are validated against private IP ranges, localhost, and cloud metadata endpoints before making server-side requests.
- SSO domain verification — DNS-based domain verification for SSO prevents cross-organization domain hijacking. HMAC-signed state parameters protect against CSRF in SSO flows.
- Breached password blocking — New passwords are checked against 900M+ known breached passwords via Have I Been Pwned before being accepted.
- Auth gate hardening — Unauthenticated users no longer see a brief flash of authenticated UI. API requests are blocked immediately when no session exists.
- Guided tour security — Tours no longer fire for unauthenticated users.
Privacy & Data Protection
- Data export — Users can export all their personal data in machine-readable JSON format from their account settings.
- Data deletion — Users can request deletion of their personal data. Data is anonymized to preserve organizational reporting integrity.
- Data sharing opt-out — Users can opt out of third-party data sharing.
- Data retention automation — Automated cleanup of data beyond the configurable retention period (default 7 years for tax/financial record-keeping).
- Privacy policy updated — Added sections for legal basis of processing, international data transfers, data breach notification, children's privacy, and Do Not Track signals.
- Cookie policy updated — Added details for authentication cookies and security cookies.
- Terms of use updated — Added sections for data processing, data portability, and service availability.
Bug Fixes
- Completed view duplicates — Fixed documents appearing multiple times when they had multiple signers.
- Action Required filtering — Shared documents no longer appear in Action Required. View now only shows documents assigned to the current user.
- Unassigned fields not rendering — Legacy fields with null assignment correctly render in the PDF.
- Billing: immediate charge on upgrade — Plan upgrades and add-on purchases now charge proration immediately instead of deferring to the next invoice.
- Settings access — Fixed /settings being blocked for non-admin users.
- TOTP login flow — Fixed 2FA verification being blocked by the API interceptor during login.
- Email verification resend — Fixed resend verification endpoint missing auth headers.
- Password change token refresh — Fixed token handling after password change to prevent unnecessary logouts.