Technical evolution should leave a trail.
This changelog summarizes architectural and engineering milestones in CTG One’s professionalization. It does not replace Git history or document every commit; it identifies changes that materially affect platform capability, security, or verifiability.
Credibility hardening
Separated verified capabilities from roadmap claims and corrected outdated deployment/security narratives.
CTG One OS
Formalized the shared technology layer and maturity model across identity, data, transactions, automation, security and intelligence.
Products & case studies
Introduced evidence-based product case studies with CTG Craft Beer Investment as CASE-001.
AI architecture & governance
Defined AI boundaries, human-in-the-loop controls, evaluation requirements and promotion criteria.
Security, observability & testing
Added health checks, structured redacted logging, critical safety invariants, dependency audit thresholds and stronger headers.
Ecosystem technology mapping
Mapped each business unit to operating problems, CTG One OS modules and verified maturity states.
Public technical proof
Introduced public status, Labs framework and technical changelog as verifiable evidence surfaces.
Production readiness
Defined the Render deployment contract, health checks and production verification runbook.
AI platform architecture
Expanded CTG One AI with Citation-First RAG, agent runtime, risk tiers, evaluation, security and CTG Knowledge product architecture while retaining IN DEVELOPMENT status.
CTG Knowledge v0.1
Implemented the first authenticated RAG pilot with curated ingestion, pgvector retrieval, server-side model access, grounded answers and structured source metadata; LIVE promotion remains evidence-gated.
Grounding integrity hardening
Added deterministic post-generation citation validation so CTG Knowledge fails closed when model output lacks citations or references sources that were not supplied for the request.
Reproducible AI evaluation
Added a provider-independent evaluation harness, synthetic CI fixtures, regression thresholds and explicit separation between test evidence and authorized semantic/operating evidence.
Versioned evaluation corpus
Added a representative first-party public evaluation corpus and dataset, pinned to exact Git blob identities with fail-closed provenance and drift validation before controlled run capture.
Controlled evaluation capture
Added explicit-authorized isolated corpus seeding, real query capture, human semantic review worksheets and fail-closed conversion into authorized evaluation evidence; the first authorized human-reviewed run still pending.
Participant liquidity loop
Closed the participant settlement-to-reinvestment loop with server-priced case intent, shared balance/capacity reservations, immutable participant quantity, cancellation/rejection paths and a participant reinvestment console while retaining BETA status.
Finance reinvestment queue
Added a bounded Finance OS review queue for pending reinvestments with current KYC, source-credit, spendable-balance and target-lot context, while approvals remain immutable server-side commands.
Operational Golden Journey
Added a bounded per-lot lifecycle reconstruction and a clean-database transactional journey proving funding, payment, production, sale/return, settlement, reinvestment and confirmed payout as one conserved operating loop.
Investment production readiness canary
Added a public-safe read-only readiness endpoint and post-deploy canary that pin exact Render identity, runtime schema compatibility, PARTIAL/BETA truth and the canonical Investment surface while keeping real operating evidence explicitly pending.
Investment operating evidence capture
Added a private-by-default redacted operating-evidence pipeline with source hashing, PII/identifier rejection, financial conservation checks, explicit human review and synthetic-vs-production evidence separation; real production evidence remains uncaptured until an authorized review is performed.
Investment release gate matrix
Added a SUPER_ADMIN release-readiness read model that consolidates technical proof, Render/schema state, reviewed operating evidence, pending business decisions and fail-closed exposure controls while prohibiting automatic LIVE promotion.
Production readiness evidence capture
Extended the existing post-deploy canary with versioned, SHA-bound, public-safe PASS/FAIL artifacts and a shared validation contract reused by release governance; artifact generation never auto-accepts release evidence or changes PARTIAL/BETA maturity.
AI model gateway hardening
Introduced a shared server-only model gateway for CTG Knowledge with explicit provider allowlisting, versioned runtime configuration, bounded timeout/retry policy, request correlation and structured provider/model/token telemetry while keeping the AI layer IN DEVELOPMENT and CTG Knowledge BETA.
Observability trace and error intelligence
Added W3C trace-context propagation, a versioned structured telemetry schema and safe classified error fingerprints on critical health and knowledge paths while keeping centralized metrics, alerting and full distributed tracing explicitly PARTIAL.
VÉRTICE federation registration
Registered the existing "Entrar con CTG One" authorization-code + PKCE federation with VÉRTICE OS in public technology proof and the ecosystem contract registry, documenting the server-to-server exchange, KYC assurance claim boundary and mobile BFF reuse while keeping the entry PARTIAL/BETA pending end-to-end production operating evidence.
Changelog entries do not automatically make a capability LIVE. Technical status is published separately and requires sufficient evidence.