Changelog
Two things change in this product: the app, and the legal data behind it. Both are listed here. The second stream includes entries where the number of reviewed answers went down — those are not embarrassments, they are the evidence gate doing the job it exists to do.
-
Website
carrysafe.app
- This site. Built on the app's own design tokens so the two cannot drift apart, and deliberately static: it makes no requests to any legal endpoint, so it cannot invent an answer when an endpoint fails.
- Coverage is published as one dated measurement, and the site's own publish check fails once that stamp goes stale.
- No reciprocity grid, no “states covered” badge, no user counts, no testimonials. Each of those would be a claim our own release gate does not support.
-
Legal data
Coverage measured, and the nationwide claim refused
- A single fail-closed gate was measured across all seven review axes. It reports that a nationwide legal-coverage claim is not supportable, and it names the axes blocking it.
- That answer is now what gates our own copy: while it says no, the app, the store listing and this website may not describe our legal review as nationwide or complete.
- The measured numbers.
-
App (TestFlight)
Background nearby warnings, as a separate opt-in
- A limited iOS region-monitoring opt-in was added to a TestFlight build. It is off by default and needs Always Location, Precise Location, notifications and Background App Refresh.
- It monitors a small rotating set of eligible cached records, does not extend state-boundary alerts, does not sample GPS continuously, makes no background network calls, and keeps no location history.
- Advisories for records whose legal status has not been reviewed are a separate, lower-priority tier that says so in the notification and never labels the place restricted or prohibited.
- Delivery is not guaranteed, and no screen in the app claims otherwise.
-
Legal data
Recognition rebuilt around the destination policy — and every generated answer withdrawn
- An audit found that the installed recognition matrix had been generated in a single pass from 51 destination policies, then given one shared review timestamp across every cell. Citations were present; independent review was not.
- The destination's complete policy is now the controlled legal object. Every derived pair answer is recomputed and compared against it field by field, with a fingerprint over every legal input — issuer set, residency gates, permit types, conditions, age, source, effective dates.
- Two destination policies were demoted to pending review: one whose published list had already expired on its own terms, and one whose cited page did not actually expose the issuer list the policy turned on.
- Same-state cells were reclassified out of reciprocity entirely — whether your own state's permit works at home is a permit-validity question, not a recognition one.
- Net effect: the number of publishable cross-state answers went to zero, and the app now says Not reviewed for all of them. Why we did not keep the grid.
-
App
Three plans, enforced by the server
- Local preview, CarrySafePlus and CarrySafePro became distinct entitlements checked on the server rather than trusted from the client.
- The free preview binds to one municipality, with a county-equivalent fallback in unincorporated areas. Plus opens one home state and one effective resident permit. Pro opens the national map and a multi-permit wallet.
- Raw permit rows are the holder's data and survive every plan change — downgrading hides a card, it never deletes what you typed.
-
Legal data
The review desk
- Staff review moved onto a desk with database-enforced roles, a fresh re-authentication required before any write, and an audit row for every change.
- A determination cannot be saved without a direct official source. “Unknown” is not a saveable verdict — a reviewer who cannot support an answer retires the row instead.
Older work — geometry loading, the permit wallet, Carry Mode, the news and community surfaces — predates this log and is described on how it works.