Release Notes
The azuma nori Standalone Client keeps itself up to date: it checks for updates automatically, offers a one-click Restart & update, and shows a What's New window the first time you open a new version (you can reopen it anytime from the sidebar). See Installation.
The current release is 1.23.0.
1.23.0 (current)
- Check your passkey server against BSI TR-03188 — A new Preview standard analyses your FIDO2 / WebAuthn server against the BSI's passkey recommendations, scoped to the trust level you operate at: normal, substantiell, or hoch.
- Two prohibited practices the EU AI Act standard was missing — Nori now checks for AI systems that generate or manipulate realistic intimate material depicting an identifiable person without their explicit consent, and for systems that generate child sexual abuse material. Both bind from 2 December 2026, and both appear alongside the rest so you can see where you stand before that date.
- Every finding now says what kind of claim it is — A failure can mean a defect at a real line of your code, or that a document the standard requires is absent, or that Nori could not verify the claim at all. Those need completely different responses, and they all read as "Failure". Each finding now carries its evidence class beside its severity — in the report and in the app — the header breaks the failure total down the same way, and a finding Nori could not verify is labelled unknown rather than left to look like a confident one. No verdict, severity or score changes.
- Your report says whether domain knowledge reached each control — Some checks are written to draw on Nori's background material for a standard. Each control's dossier now states whether that material was applied, partially applied, or not applied, and the report header gives the totals for the run — so a result reached from a plain source scan is not read as one backed by the full reference set.
- How many problems, not just how many findings — The report's coverage summary now states how many distinct problems your findings reduce to, right where it states compliance. One missing document that eleven controls each had to check for is eleven findings but one thing to fix, and that number is now visible without scrolling to the detail. The full breakdown — how many findings report each cause, and which controls each affects — stays where it was.
- See when a standard's obligations actually start — Standards that apply in stages now say so. The EU AI Act, for example, has bound most prohibited practices since February 2025 — with two more arriving in December 2026 — while most of its high-risk obligations do not bind until December 2027 or August 2028, and some transitional provisions give you longer still. Nori checks every control either way, so you can see where you stand well before an obligation binds — now with the dates alongside, so you know what is due and what is preparation.
1.22.0
- Your recorded classification scopes the analysis — Controls now assess against the classification you confirmed instead of each deciding for themselves whether the regulation applies, and a control whose reading of your code contradicts it is held back and named in the report rather than quietly ruled out of scope or reported as passed.
- Nori notices when your classification moves on — Results reached under a different scope determination are no longer reused, and a current-state report written after a fresh guided triage opens as a Draft naming the affected controls instead of describing your new classification over old findings.
- Your results are checked against the run that produced them — If a stored result was altered after the run — a failure removed, a score raised, a control marked out of scope — the report withholds that control's verdict instead of presenting a figure it can't stand behind, and the project score no longer counts controls that were never scored.
- A control that wasn't assessed now says why — "Required evidence was not available" was the answer to six quite different situations; a control with no subject in your codebase, one the analysis failed to complete, and one needing a fresh triage now each say so in their own words, without changing any verdict.
1.21.0
- Re-confirm your classification after updating — how a confirmed triage maps to your obligations has changed, so projects classified before this release are flagged for a fresh guided triage rather than being silently re-interpreted. Your recorded decision is kept.
- An out-of-scope determination now has to name its legal ground — concluding the AI Act doesn't reach your system switches off every obligation in the report, so the guided triage now asks which exclusion you are relying on and won't let you confirm without one.
- A classification you haven't finished can no longer scope your report — a triage that hasn't established your operator role, or that reports low confidence, can't be confirmed. That applies in both directions: an unfinished "out of scope" is as consequential as an unfinished "high risk".
- Your report opens with the classification it was scoped by — a new section states the outcome, your role and, where the system is excluded, the ground that rests on. It records the decision and never changes the compliance score.
- Obligations now reach the operators they are written for — duties that apply when you deploy or rebrand someone else's system, and the registration a public authority owes as a deployer, previously landed on the wrong party or on nobody at all.
1.20.0
-
Your risk classification is on the record — and stays on your machine — when you confirm a guided triage, nori records the decision itself: the outcome, your role, the reasoning with its article references, and who confirmed it and when. Previously only the resulting list of applicability tags survived, so nothing could say why those controls were selected. Saving a project profile by hand also records that a person chose those tags, without inventing outcomes or reasoning nobody stated.
Confirming runs entirely on your computer and works offline, and the tags you see previewed before confirming are exactly the ones recorded. If the assistant reports a capability nori doesn't recognise, the classification can't be confirmed until it is restated, rather than that capability being quietly dropped and a legal duty with it. Re-running project setup no longer wipes the profile. See Project Profile.
-
A control that was never checked no longer counts as passed — a control whose evaluation failed, was skipped, or produced no result now appears in the regulatory report as Not evaluated, with the actual reason, and the run reports Incomplete instead of Pass. A clause counts as satisfied only when at least one of its controls was really assessed. A control nori could not evaluate is described as such rather than as missing evidence, so you are not sent looking for a document that was never requested.
-
Coverage you can check — the report header now states how much of the standard was actually examined: how many controls the standard has, how many this run requested, how many were determined Not Applicable, and how many were evaluated, with both percentages (of everything requested, and of everything that applied). Completion and compliance are now separate lines, so a run can no longer hide gaps and failures behind one word. A run that examined only part of the standard says so explicitly, and a run where an unusually large share of controls was ruled Not Applicable now carries a warning to re-check the project's classification.
-
Reports are complete on their own, and describe the run they name — each run now records the standard it ran against — control titles, severities, clause structure and the evaluation methodology — at the moment it runs. Reports are built from that record, so generating one later, offline, or after the standard has been revised no longer blanks out control titles or drops the clause overview. The report also states which model the AI provider confirmed it actually used, separately from the model you configured.
Asking for the report of a run whose results are no longer available now refuses, and tells you to ask for a current-state report explicitly if that is what you want. Projects that aren't a git checkout are labelled "unversioned source" rather than shown with an unknown commit.
-
Every control now shows what was actually checked — the regulatory report lists the individual objectives assessed for each control and how each one came out, including on controls that pass. A passing control used to say only "No issues were identified during evaluation", which reads exactly like a control nobody looked at. An objective the AI didn't report back on is shown as not reported — and a control with an unreported or unestablished objective is no longer reported as satisfied, because nori reports only what it can evidence. That is not the same as failing: nothing there says the requirement is unmet, and re-running the control is the first thing to try if one looks wrongly held back. Where the AI's answer is missing objectives or formats them badly, nori fills the gap itself instead of re-running the analysis, so a formatting problem never costs you a second run.
-
Evidence the AI cites is checked against your code — files the AI says it examined are now verified to exist at the revision that was analysed, and any that don't are flagged in the report. These are labelled agent-reported and unverified: confirming a file exists proves it exists, not that the AI read it, and the report says so rather than implying more. Evidence documents you upload are listed separately, because the AI receives summaries of them rather than the documents themselves. See External Evidence.
-
The finding count now reflects distinct problems, not repetition — findings are grouped by their underlying cause across all controls, and the report gives both numbers: how many findings were raised, and how many distinct problems they represent. One missing document that eleven different controls each had to check for now also appears as one root cause affecting eleven controls, with all of them listed.
Each finding is additionally labelled a code finding, a missing artifact, a missing CI gate, or unverifiable — and a finding whose cited file nori cannot find in your code is labelled unknown rather than counted as a confirmed code defect. Your per-control results are unchanged: every finding is still listed in full under the control that raised it.
-
Reports carry an integrity verdict before you send them — every regulatory report now opens with Released, Draft or Blocked, listing exactly what is wrong. A report is Blocked when something makes it unsafe to hand to an auditor: the analysed folder was empty, controls failed to execute, nothing was evaluated, or two controls contradict each other about the same file. The report is still generated — the verdict travels inside the document so it cannot be separated from the content — and the export dialog now shows the last report's state up front. See Exports.
-
nori checks the folder it is about to analyse — before a run starts, nori confirms the analysed folder exists, contains files, looks like a recognisable project, and has usable version information. It reads your files only: nori never builds, restores or runs anything from the code it analyses, so a check reported as "could not check" is a limit of what can be established without executing your code, never a claim that your repository is broken. A folder with no recognised project file, or that isn't a git checkout, is reported as unverified rather than invalid.
-
Every control explains itself, in the evaluator's own words — a control's deep-dive section now works through each objective in turn: whether it was met, the reasoning behind that, and the files examined — or looked for and not found. A control that didn't pass previously showed only a short note saying the write-up had been withheld; the objective-by-objective record now is the write-up. A file the AI looked for and couldn't find reads as the missing artefact it is when the objective wasn't met, instead of as a doubtful citation.
-
The window no longer slides out of place — moving between pages could leave the app shifted upward, with the sidebar logo and the page heading cut off along the top edge and no way to scroll it back. Pages also opened part-way down when you arrived from a scrolled list; they now open at the top.
-
An errored run shows as Error — a run that failed used to appear as Completed in the run list, with its own error message displayed next to the wrong status.
-
Executive summaries are chosen when you export — the Generate Executive Summaries checkbox has been removed from project settings. Whether a report includes an executive summary is set by the report type you choose in the Export & Summary dialog. See Exports.
1.19.1
-
Scanned documents are read with Codex and Antigravity too — uploaded images and scanned, image-only PDFs are now read visually by every local agent CLI: Claude, Codex, Cursor, and Antigravity with a Gemini or Claude model. Previously only Claude and Cursor did this, so the same document came back as no readable text on Codex or Antigravity even though those models can read it. Re-index your documents to pick up the content that was skipped.
Direct Cloud API models still receive text only, as do Antigravity's text-only models such as
gpt-oss— for those, a scanned or image-only document remains unreadable. -
A clearer reason when a document can't be read — when a scanned or image-only document really cannot be read, the placeholder now names the model you have configured and which models would work, instead of pointing at the wrong cause.
-
A document that produced nothing is no longer listed as indexed — if the AI returns an empty summary for a document, that document is marked Failed with the reason instead of appearing successfully indexed with an empty summary. This also fixes Antigravity reading uploaded documents: it can only open files it has been granted, so documents stored outside your project folder previously came back blank.
1.18.0
-
Tell us when a result is wrong — control results, wiki pages, the AI summaries of your uploaded documents, and the standard your project runs against now have a Share Feedback action. Say whether what you are looking at is right or wrong, add a comment, and optionally attach the actual result — the control's findings, the wiki page, or your project's nori data folder — so the problem can be reproduced. Attaching is off by default.
Three things are never uploaded, whatever you attach: the evidence documents you uploaded, the text nori extracted from them, and your project's
config.json, which can hold your API key. They stay on your machine.Before anything is sent, the dialog shows you the exact contents of the attachment: every top-level folder with a file count and size, expandable to every individual file name, with nothing truncated — plus a line naming what was held back and how much of it. For the data-folder attachment you must tick a second box confirming you have reviewed that list. If the folder changes while you are writing (a background analysis run, for example), nori refuses to send, shows you the updated list, and asks you to confirm again — so what is uploaded is always what you reviewed. Attachments go to azuma's private storage and are used only to reproduce and fix the problem.
-
Discuss findings and see who changed what — controls and individual findings now have a comment thread, so several reviewers can talk a finding through in place instead of overwriting one shared note. Every comment and every status change is recorded with the name of the reviewer who made it and when, and shown as a change-history timeline — including when a finding is marked False Positive and later restored, even if that was done by two different accounts on the same machine. You can edit and delete your own comments; a deletion clears the comment text but stays visible in the history. Your existing notes and status overrides are carried over automatically, and now stay visible after you reopen a control. Everything is stored locally in your project's data folder, exactly as before — nothing is uploaded.
-
Antigravity replaces the Gemini CLI as a local agent — nori's supported local agent CLIs are now Claude, Antigravity, Cursor, and Codex. Antigravity (
agy, Google's successor to the Gemini CLI) is driven in its read-only--mode plan, so it can read and search your code but never modify it. It is locally executed but cloud-backed: your repository is sent to Antigravity's cloud model service for evaluation, so it is not an on-device or air-gapped option. The previous Gemini CLI option has been removed — Gemini remains available as a Direct Cloud API model, and a model saved with the old Gemini CLI transport will prompt you to migrate. -
Antigravity analysis is read-only too — when you analyse with an Antigravity CLI model, nori runs the Antigravity agent in its read-only "plan" mode (
--mode plan), so it can read and search your code but cannot create, modify, or delete any file in the project you analyse — the same read-only guarantee it already enforces for Claude, Codex, and Cursor. Before a run starts nori verifies this with a harmless test write and stops with a clear message if the read-only mode isn't in effect.
1.17.0
- Analysis runs read-only against your code — when nori analyses your project with a Claude CLI model — control analysis, wiki generation, and document indexing — the model can no longer create, modify, or delete any file in the project it analyses. It reads and searches your code exactly as before; only control analysis may still save its results into nori's own data folder. nori also verifies this read-only mode is actually in effect before a run starts and stops with a clear message if it isn't.
- Choose the AI model for triage document indexing — documents you upload during guided triage are now indexed with the model you selected in the triage panel, instead of your project's default indexing model. Pick a Claude CLI model to have scanned or image-only PDFs read visually, so they can inform the classification.
- Choose the AI model for the AI Management Summary — the Export & Summary dialog now lets you pick which AI model writes the AI Management Summary, defaulting to your project's configured model. The AI cost reminder now appears only when an export actually uses AI, so the deterministic Regulatory Report and Rules-based Markdown export no longer show it.
- Clear error when the Codex CLI can't read your code — when you run with the OpenAI Codex CLI and its sandbox is blocked from reading your project, nori now stops with a clear message telling you how to fix it, instead of quietly finishing with "Source inspection unavailable" on every control.
- Codex analysis is verified read-only — when you analyse with the OpenAI Codex CLI, nori now actively confirms — before a run starts — that its sandbox really does block writes to your project: it makes a harmless test write and checks that the sandbox refused it. If the sandbox is set to allow writes, or the block can't be confirmed, nori stops with a clear message instead of continuing — so analysis can never create, modify, or delete your files, the same read-only guarantee it already enforces for Claude.
- Cursor analysis is read-only too — when you analyse with a Cursor model, nori now runs the Cursor agent in its read-only "plan" mode, so it can read and search your code but cannot create, modify, or delete any file in the project you analyse — the same read-only guarantee it already enforces for Claude and Codex. Before a run starts nori verifies this with a harmless test write and stops with a clear message if the read-only mode isn't in effect, instead of letting analysis touch your source.
- Gemini analysis is read-only too — when you analyse with a Gemini CLI model, nori now runs the Gemini agent in its read-only "plan" approval mode instead of the previous auto-approve-everything mode, so it can read and search your code but cannot create, modify, or delete any file in the project you analyse — the same read-only guarantee it already enforces for Claude, Codex, and Cursor. Before a run starts nori verifies this with a harmless test write and stops with a clear message if the read-only mode isn't in effect, instead of letting analysis touch your source.
- More reliable Codex CLI connections — nori now finds the Codex program automatically even when it isn't on your PATH, so runs no longer fail with "'codex' is not recognized", and testing a Codex connection against a folder now confirms nori can actually read that folder instead of silently passing.
- Stopping a run cleanly ends the AI CLI — cancelling or closing a run now reliably stops the AI CLI process nori launched (Claude, Gemini, or Codex), instead of leaving it running in the background and using up your CLI plan's usage after you've stopped.
- Clearer macOS file-access prompt — on macOS, the permission prompt shown the first time nori reads a project now explains that nori analyses your code locally and never modifies or uploads it, so it's clear why access is needed. macOS remembers your choice, so you're asked once per folder rather than on every run. See Installation.
1.16.0
- Cost reminders before running AI — every screen that starts an AI operation — analysis, wiki and document indexing, guided triage, and AI summaries and reports — and the AI Models pages now remind you that running AI incurs cost. The reminder adapts to how the model connects: Direct Cloud API ("on-demand") models are billed per token by your provider, while CLI models use your local CLI plan's usage and quota. Self-hosted local models show no reminder.
1.15.1
- Attach documents during guided triage — uploading an evidence document while working through a guided triage now attaches it reliably and feeds its content into the assistant's proposed classification. Previously the upload could finish without the document ever being attached or taken into account.
- Unreadable documents are clearly flagged — scanned or image-only PDFs that the selected indexing model can't read now appear disabled with the reason, instead of looking attachable but adding nothing. Re-index them with a Claude CLI model to have them read visually.
1.15.0
- Browse the standards catalogue — a new Policies entry in the sidebar lists every standard nori can analyse against, with search and a maturity filter. Open one to see what it actually checks: its controls grouped by category, the wiki topics it builds, the documents it expects as evidence, and its profile options. Standards your plan doesn't cover stay listed and clearly marked, so you can see what a full licence unlocks before you buy.
- See every profile option on the free plan — the Project Profile tab now lists all of a standard's profile options, not just the ones the free plan samples, so you can see the full shape of a standard like the EU AI Act and pick the profile that really matches your project. Controls and wiki topics that need a full licence are shown greyed out with a lock, and each option tells you how much of it is locked.
1.14.0
- Free plan now samples every standard — the free plan now includes a few example controls from the newer standards too — the EU Cyber Resilience Act, EU AI Act, OWASP ASVS, and BSI A5 — so you can try them before upgrading, just like the established ones.
- Preview standards now available — standards still in preview (EU AI Act, OWASP ASVS, and BSI A5 Draft) now appear when you create a project, so you can explore and analyze against the latest catalogues.
1.13.0
- Accept the licence agreement — you're now asked to confirm you've read and accept the azuma nori on-premise licence agreement (linked for you to read): once at sign-in (remembered afterwards), and again each time you start a purchase on the Plans & Billing page — for both direct checkout and pay-on-invoice.
- Choose the Claude reasoning effort for analysis — Project AI settings now let you pick the reasoning effort Nori's analysis uses on Claude CLI models (Model default, Low, Medium, High, or XHigh). The new default, Medium, delivers the same analysis quality for roughly a third less cost than the previous High — pick a different level to trade cost against depth. Applies to Claude CLI models only.
1.12.2
- "Free" quick-filter for controls and wikis — the Controls and Wiki tabs now have a one-click Free filter that shows just the controls and wiki topics available on the free plan.
- Locked wikis now visible on the free plan — the Wiki list shows locked wiki topics too, clearly marked and with an upgrade prompt, so you can see everything a full license unlocks — matching how locked controls already appear.
- Wiki pages readable in light mode — wiki document pages no longer show faint, hard-to-read text when you're using the light theme.
1.12.1
- Live-updating results — project pages now refresh on their own as analysis, wiki, and indexing runs progress and finish, so results and run history stay current without a manual reload.
- Theme toggle on the sign-in screen — the light/dark quick toggle is now available on the login screen, so you can switch appearance before you sign in.
- Tidier running-jobs widget — the in-progress runs widget now displays cleanly.
- A readable What's New window in light mode — the What's New window no longer shows faint, hard-to-read text when you're using the light theme.
1.12.0
- Light and dark themes — the Standalone Client now follows your operating system's light or dark appearance automatically, and you can choose System, Light, or Dark yourself from Settings or the quick toggle in the sidebar. Your preference is remembered across restarts.
- Refreshed, on-brand look — a new azuma design system brings updated typography, refined colors, and a cleaner, more consistent interface across every screen.
- Easier AI model management — the Models page now lets you search by name, sort your models, filter by provider, and quickly narrow to just API or CLI connections. Models you no longer use can be archived to keep the list tidy and reactivated whenever you need them again. See LLM Models & Usage.
- A clearer projects home page — the main projects view now shows each project's compliance policy at a glance, flags projects whose folder can no longer be found, and lets you sort and filter your project list to find what you need faster.
- Documentation link in the sidebar — a new Documentation entry in the sidebar opens the nori docs directly, so help is always one click away.
- Paged analysis & indexing history — a project's Analysis, Indexing, and Indexing File history now show a page at a time (5 rows by default, adjustable), so long run histories are quick to scan.
- Search and filter your controls and wikis — the Controls and Wiki tabs now include a search box, a category filter, and quick status filters (for example analyzed, missing, or outdated), with tidy, readable category names — so you can find what you need at a glance.
- Faster selection when starting a run — the Run New Analysis, Run New Indexing, and Run New Docs Indexing dialogs now let you search, filter by category and status, select a whole category at once, and use Select visible / Clear, so choosing exactly what to run is much quicker.
- Open a control's results in one click — each analyzed control in the Controls tab now has a "View Results" link that jumps straight to its latest analysis.
- Clearer Export & Summary dialog — the export dialog is wider and now opens on the Regulatory Report, with AI Management Summary and Rules-based Markdown alongside; the Rules-based Markdown tab starts with a ready-to-edit example so you can export right away.
1.10.0
- Use OpenAI models through the Codex CLI — Add an OpenAI model with the connection type set to "CLI" to run wiki and analysis through your local, already-signed-in OpenAI Codex CLI — no API key needed, just like the Claude and Gemini CLI options. Testing the connection now works instead of failing with an "empty key" error, and a direct OpenAI model that's missing its API key now shows a clear message telling you to add a key or switch to the CLI. See LLM Models & Usage.
- Free plan — Sign in with any azuma account, even without a nori license. Free workspaces can run three essential code-analyzable BSI TR-03161 controls (hard-coded secrets, strong password policies, and secure generation of session/user identifiers); the remaining controls stay visible but locked until you upgrade. See Freemium.
- Create an account from the login screen — New users no longer need a pre-existing azuma doa login. A "Create one" link on the sign-in screen opens a registration form that creates your account together with your own azuma workspace. Verify your email with the code we send you and sign in right away.
- Analysis-Only projects — Create a project that runs compliance analysis directly against your code without building source-code wikis first. Pick "Analysis-Only" when creating a project for a leaner workflow: the source-code wiki tab, indexing, and related settings are hidden, while evidence documents ("Wiki (Files)") still work as usual. Each project's type is now shown at a glance — on the project cards, the project header, and its settings — so you can tell Discovery + Analysis and Analysis-Only projects apart. The project type is chosen at creation and can't be changed later.
- See which code version each control was checked against — Analysis results now record the git commit (and branch) of the exact repository state each control was evaluated against, shown on the control result and cited in regulatory reports, so every result can be traced back to the source it came from.
- Mark a finding as "Not Applicable" — When reviewing analysis results you can now suppress a finding as Not Applicable, alongside the existing False Positive, Accepted Risk, and Mitigated overrides; suppressed findings no longer count toward failures or warnings.
- Use a self-hosted or local AI model — Run wiki and analysis against a model hosted on your own machine or network over an OpenAI-compatible endpoint (Ollama, llama.cpp, LM Studio, vLLM, and similar). Pick "Local / OpenAI-compatible" when adding a model, point it at your endpoint, and your code and findings never leave your network — no cloud API key required. See LLM Models & Usage.
- New BSI TR-02102 cryptography policies — Evaluate your project against the German BSI Technical Guideline TR-02102-1 (cryptographic mechanisms) and TR-02102-2 (TLS), now available as ready-to-use policies.
- Custom CLI model path now applies to every run — A custom CLI executable path or working directory configured on a model is now used for analysis, wiki, and document-indexing runs too, not just the connection test — so a custom install that tested fine no longer fails mid-run.
- Nori's own data folder is left out of analysis — When your Nori data folder sits inside the scanned project, it's no longer treated as source code, so analysis and wiki results stay focused on your actual codebase.
- Fewer false alarms in the hard-coded-secrets check — The BSI TR-03161 "no hard-coded keys or other secrets" control now judges each flagged secret by whether it can actually reach production, so secrets that exist only in development-only configuration or in test and example code are treated as expected and no longer reported, while anything that ships to production is still flagged.
1.9.0
New experimental Documents feature.
- Turn your evidence documents into AI-readable summaries — Index uploaded or referenced evidence files (PDFs, images, Word/Excel/PowerPoint, and text) into concise per-document summaries so their content is actually understood during control analysis. PDFs, scanned pages, and diagrams are captured visually when you index with a Claude CLI model. See External Evidence.
- New "Wiki (Files)" tab — Browse the generated summary for every indexed document, see which controls each one is linked to, and open the full write-up — just like the existing source-code Wiki.
- Run New Docs Indexing — A new button lets you choose exactly which evidence files to (re)index and which AI model to use; files that are missing or have changed are pre-selected.
- Automatic control linkage you can override — Each document is automatically suggested as "General" or linked to specific controls, shown in Wiki (Files). You can override this per file in the Evidence tab, where referenced folders now expand into individually mappable, individually indexable files.
- Analysis uses the curated summary, not the raw file — During control analysis the evaluator is given each document's summary (general documents contribute a one-line synopsis, control-specific ones their full summary), keeping evidence focused and costs predictable. Documents that still need indexing are clearly flagged.
- Indexing File History — Track your document-indexing runs — status, timing, and document count — alongside the existing analysis and wiki indexing history.
1.8.1
- Clearer errors when a run fails — When an analysis or wiki run fails, both the result and the live execution log now show the actual cause (for example an authentication problem, an unknown model, a missing CLI, or an API error) instead of a blank "exit 1" or a generic "Operation failed after retries" message — so failures are far easier to understand and fix.
- Large Gemini (Direct API) requests no longer time out prematurely — Gemini models connected via Direct Cloud API now allow up to 10 minutes per request instead of a fixed 100-second limit, so longer wiki and analysis generations on big codebases complete instead of failing with a timeout.
- Less noise in the execution log — Running against a project that isn't a git repository no longer spams the log with raw "fatal: not a git repository" lines.
1.8.0
- Failed wiki runs now show as failed — When a wiki indexing topic can't be generated, the run is correctly marked Failed and shows the underlying error, instead of silently appearing Completed.
- Gemini via API key or CLI — Gemini models now work both through your local Gemini CLI login and directly with a Gemini API key. Choose "Direct Cloud API" on the model and the API key you enter actually connects, with token usage tracked the same way as your other models. The direct connection now uses Google's native Gemini API, so the latest Gemini 3 thinking models work reliably during wiki and analysis runs.
- Separate AI models for wiki and analysis — In the project's AI settings you can now pick a dedicated model for wiki generation and another for control analysis. Use a cheaper model for the mechanical wiki indexing while analysis keeps your strongest model — same quality at a fraction of the cost.
- Concise wiki output — A new option generates shorter, fact-dense wiki pages. Wiki content feeds into every control evaluation, so brevity lowers analysis cost — especially when paired with a cheaper wiki model.
- Pick an AI model per run — When starting an analysis or wiki indexing run, you can now choose a different AI model just for that run. Your project's default model stays unchanged.
- See which model produced a result — Control results and wiki pages now show the AI model that generated them, alongside the existing run-level details.
1.7.0
- See what's new after updates — A "What's New" window now appears automatically the first time you open a new version, and you can reopen it any time from the sidebar item to catch up on recent changes.
- General documentation for analysis — Point a project at external files or folders on disk and mark them "applies to all controls" so they're always considered during analysis, without mapping each document to individual controls.
- Reduced token usage — Optimizations to reduce token usage.
- More accurate run cost & token reporting — Analysis runs now report exact token usage and cost, giving you a clearer picture of what each run consumes (Claude CLI only).
1.6.0
- Hide projects — Hide projects you don't actively work on to keep your project list focused. Hidden projects stay on your device and can be shown again at any time.
1.0.0 – 1.5.0
- Welcome to azuma nori.