Skip to main content
Skip to main content
Changelog

Release notes

Every feature, improvement, and fix we ship.

Latest releasev3.19.0
v3.19.0— permalink
Patch

VETR 3.19 — Meet the people behind the platform

There is now a page for the two people who build this

VETR’s strongest claim has always been who is behind it, and until today the site made that claim in prose with no faces attached. Leadership introduces both of us properly.

  • Dr. Lori Smith, founder and CEO of Acu-Elligent LLC — a retired federal Contracting Officer with 40+ years in federal acquisition and portfolios totaling $143B in awarded contracts. She spent four decades on the side of the table that reads proposals, and the VETR methodology is what she learned there.
  • Raihan, Head of Engineering & AI — who has built the platform end to end since the first commit: the application, the AI layer, and the AWS GovCloud infrastructure it runs on.

Each has a full biography, a photograph, and a direct email and LinkedIn link. The About page now carries both faces and links through.

Why bother? Because “who built this and what do they actually know” is a fair question to ask of anyone selling you software for a bid you cannot afford to lose — and it is easier to answer with names, credentials and a way to reach us than with an adjective.

No functional changes. Your data, the GovCloud boundary, and the in-boundary default for AI processing are unchanged.

v3.18.0— permalink
Minor

VETR 3.18 — Get listed in VETR Match, and hubs that tell you which program is yours

Get your business into the VETR Match directory

VETR Match is the vendor directory contracting officers and prime contractors search by set-aside, NAICS code and state. Until now the only way onto it was to already be a customer and find the switch. There is now a page that explains it, names the price, and tells you exactly what gets published.

  • On a paid plan, a listing is included — Startup, Professional and Enterprise. Nothing extra to buy. Switch it on under Settings → Organization. During a free trial it is not included yet; it starts when your subscription does.
  • Everyone else can buy one for a single one-time fee. Not a subscription, and nothing to renew: the listing stays live until you take it down.

A listing publishes your name, location, capabilities, NAICS codes and set-aside certifications — and nothing else from your account. Certifications VETR has reviewed against a certificate or a SAM.gov record are marked as verified; the rest show as self-declared, which is what makes the verified ones mean anything. You can edit or remove your listing at any time.

Why charge at all? Because VETR Match only lists businesses that asked to be listed. We do not scrape public records and publish companies who have never heard of us, and a one-time fee is what keeps the directory a list of real, reachable vendors rather than another copy of a public dataset.

The “Who it’s for” pages now answer the question you arrived with

The set-aside, agency and NAICS hubs listed their programs accurately and left you to work out which one applied to you. Each now leads with a comparison, built from the same data the individual playbooks use, so it cannot drift away from the pages it links to.

  • Set-asides — the ownership test for each program side by side, what the government has actually committed to buy under it, and which agencies buy the most. Most firms qualify for more than one, and the programs are not interchangeable.
  • Agencies — what each one buys, the contract vehicles that work flows through, and typical award size. Set-aside goals look much the same across agencies; these three do not, and together they decide whether a pursuit is worth your capture budget.
  • NAICS codes — which agencies spend under each code, and the contract type most of that money moves through. If you cannot price time-and-materials work, a T&M-dominated code is not the one to register under.

Fixes

  • Your roadmap votes now survive our edits. Rewording a roadmap item used to replace it behind the scenes, which quietly discarded the votes it had collected. Items are now tracked by an identity separate from their wording, so we can rewrite a description without throwing away what you told us.
  • One more features claim removed. “Agency budget-cycle alerts” described something VETR does not do. It had already been taken off the homepage for that reason and was missed on the features page.

Your data, the GovCloud boundary, and the in-boundary default for AI processing are unchanged.

v3.17.0— permalink
Minor

VETR 3.17 — See how every capability works, and roadmap updates that actually arrive

See how every capability actually works

The features page listed thirteen capabilities as a paragraph and a tick-list each. That reads fine if you already know what capture software does, and tells you almost nothing if you do not — every paragraph is built from the same vocabulary, so “RFP parsing” and “compliance matrix” look like the same claim written twice.

Every capability now has a “See how it works” button. It opens a short, staged walkthrough of the actual mechanism: what goes in, what VETR does to it, and what comes out. Three steps each, and you can drive them yourself rather than waiting for the animation.

  • Every step is also written out in full for screen readers and for anything else reading the page without looking at it — the walkthrough is a presentation of the words, not a replacement for them.
  • Every panel is labelled illustrative. They are diagrams of how the product works, not screenshots of a live account, and the numbers in them are shapes rather than measurements.
  • If you have reduced motion turned on, nothing auto-advances and every step is still there to click.

State & local bidding has a page at last

VETR has ingested published state and local bid feeds on a schedule for some time, and no public page said so. Six open-data feeds across five states are enabled out of the box, refreshed automatically, and carry NIGP codes — the classification state and local buyers actually use, which is unrelated to the NAICS codes federal work is filed under. A tool that only understands NAICS cannot match you to a city bid at all. Those bids land in the same pipeline, scoring and workspace as your federal work.

Roadmap updates now actually arrive

Subscribing to roadmap updates recorded your address and, we have to be straight about this, sent you nothing. The form promised one email a month and there was no working path from a published release to your inbox.

There is now. Subscribing sends a confirmation email first, and the subscription starts when you click it — the form is open to the internet and anyone can type anyone’s address into it, so a single click is what separates a subscriber from an address somebody else typed. Confirming sends a short welcome with an unsubscribe link, and unsubscribing has always worked and still does.

If you subscribed before today you are already on the list and do not need to do anything.

Fixes

  • The mobile menu could not be scrolled. Opening it correctly froze the page behind it, but the menu itself had no scroll of its own — so expanding a section pushed everything below it off the bottom of the screen with no way to reach it. On a phone, roughly half the navigation was unreachable.
  • The homepage was cut off on narrow phones. Content past the right edge was clipped rather than scrollable, so it could not be reached at all.
  • A false “Please check your input” alert appeared when navigating to the API reference, on a page with no form on it.
  • The federal spending report’s tables were misaligned — column headers did not line up with their figures, and values wrapped mid-number.
  • “Schedule a demo” was invisible on the set-aside, agency and NAICS playbook pages: white text on a white button.
  • The vendor directory blamed your filters for an empty result when nothing was listed yet, and its search fields could render dark and unreadable depending on your system settings.
  • Accessibility. Nine password show/hide buttons had no name a screen reader could announce; two page sections were not exposed as lists; several tables and code blocks that scroll sideways on a phone could not be reached with a keyboard. Automated WCAG 2.1 AA checks now cover thirty-eight public pages at both desktop and phone sizes, up from five.
  • Three feature descriptions claimed things VETR does not do and have been corrected. We would rather the page be shorter and true.

Your data, the GovCloud boundary, and the in-boundary default for AI processing are unchanged.

v3.16.0— permalink
Minor

VETR 3.16 — Six guides to how each capability works, and a directory that names itself

Six guides to how each capability actually works

Every capability VETR ships had one paragraph on the features page and nothing behind it. Six of them now have a page of their own, each covering the same three things: what the capability is, how to evaluate one, and what VETR specifically does. They are written to be useful even if you end up buying something else — which is the only kind of guide worth reading before a purchase.

  • Compliance matrix — Section L and Section M extraction, why every requirement has to keep its source reference, and what happens to the matrix when an amendment lands.
  • AI proposal drafting — the difference between drafting grounded in your own past performance and a general-purpose writing assistant, and why where the model runs is the question to ask first rather than last.
  • Color-team reviews — what Pink, Red and Gold are each for, and why scoring a review against the evaluation factors tells you something a document full of tracked changes does not.
  • Teaming and subcontracting limits — how 13 CFR 125.6 decides team structure on a set-aside, and why the check is only meaningful against the priced cost volume.
  • Cost proposal — what the price volume actually has to contain, and the difference between price reasonableness and price realism.
  • Submission readiness — the failures that get a bid found non-responsive, all of which are knowable in advance.

They are linked from the features page, and each one links to the others it relates to.

Every public page now says what VETR is

The set-aside, agency and NAICS playbooks — thirty-one pages — described the program, the buyer or the industry accurately and never mentioned that VETR is software. Each now opens with a paragraph written specifically for that reader: what the platform does for an SDVOSB bidding at the VA, or a firm bidding NAICS 561612 against a wage determination, rather than one paragraph repeated thirty-one times.

Fixes

  • The VETR Match directory had the wrong page title. Both the directory and every vendor profile in it were serving the homepage’s title and description to search engines — so a listed company’s profile did not identify the company. Every profile now carries its own. If you are listed, this is the difference between being findable and being invisible.
  • Three code examples on the API reference could be reached with a keyboard but had no name a screen reader could announce.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.15.0— permalink
Minor

VETR 3.15 — Take your data with you, and a reviewer permission we had wrong

Export your organization’s data, or ask us to delete it

Our Trust page has said you can request an export or deletion of your organization’s data since the day we launched. Until now the only thing that sentence was backed by was a support address — there was a button to delete your own user account, and nothing at all for the organization. That gap has been closed.

Settings → Organization → Your data.

  • Export produces a machine-readable copy of your organization profile, people, RFPs, proposals, partners, past performance, tasks, document details and activity history. It is prepared in the background and appears on the same page when it is ready; the download stays available for seven days and is then deleted, because a single file containing your entire history is not something that should sit around indefinitely.
  • Credentials are deliberately left out. Integration tokens, webhook secrets and API keys are not in the export. An export file gets downloaded to laptops and forwarded in email, and none of those are places a live credential should end up.
  • Deletion is a request, and we want to be straight about why. You ask, we record who asked and when, we confirm by email, and you can cancel until we act. We do not purge instantly — some government-contracting records carry retention obligations that we have to check against before removing anything, and privacy law explicitly recognises that. A button that claimed to erase everything the moment you clicked it would be the easier thing to build and the wrong thing to promise.

Requesting an export and downloading one are both recorded in your organization’s audit trail.

A permission we had wrong, and have corrected

This one restricts something, so it deserves a plain explanation rather than a footnote.

The Reviewer role is defined as read-and-review: it can view your work and comment on it, and the permission matrix has never granted it editing rights. The check that actually guarded most write actions was testing the name of the role rather than what the role is permitted to do — and Reviewer is not literally named “Viewer”, so it passed. The practical result was that a reviewer could do things the role was never meant to allow, including finalising or deleting a bid/no-bid decision.

The same flaw affected every custom role you may have created: because a custom role cannot take a built-in name, all of them passed that check regardless of the permissions you gave them. A role you built with view-only permissions was not view-only in practice.

Both are fixed. Write actions are now checked against actual permissions.

  • Reviewers keep colour-team reviews — scoring and completing a review is what the role is for, and that is unchanged.
  • Reviewers can no longer write to Go/No-Go or SWOT, change a proposal section’s status, or send documents for e-signature.
  • Custom roles now behave exactly as you configured them. If you built a role expecting it to be read-only, it is read-only now.

If someone on your team needs to do more than review, move them to Contributor. If you had built a custom role and found it oddly permissive, that is why.

Smaller things

  • Closed grants no longer offer “Start an application”. Starting one created a live pursuit with a deadline that had already passed — and spent one of your monthly allocations doing it. The announcement, its dates and the Grants.gov link all stay available for reference.
  • API and MCP tokens now end when the seat does. Removing or deactivating a member already blocked their access immediately; the token record itself survived, so restoring that person would have quietly handed back a credential that might be months old. Removal, deactivation and self-deletion now revoke tokens outright.
  • Changes to a RACI matrix are recorded. Replacing or clearing assignments now writes what was there beforehand into the audit trail. Nothing about the feature changes — there was simply no record of a change that cannot be undone.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.14.0— permalink
Minor

VETR 3.14 — A directory where "SDVOSB" means something, and an audit trail nobody can quietly edit

VETR Match — get found by the agencies buying what you do

There are plenty of places to look up a veteran-owned small business. Every one of them shows you what the company said about itself. That is the problem a contracting officer actually has: anyone can type “SDVOSB” into a profile.

VETR reviews certificates. When you upload an SBA VetCert approval letter or verify against SAM.gov, a human checks it. So VETR Match can do something no directory built on scraped public data can: it shows a verified badge on the set-asides we have actually seen evidence for, and marks the rest as self-declared. Both are shown — hiding a certification would misrepresent you — but only one carries the badge.

  • Listing is off unless you turn it on. Settings → Organization → VETR Match. Nothing about your account is published until you choose to publish it, and you can switch it off at any time.
  • You control what it says. Your name, location, capabilities, NAICS codes, website and a short description you write yourself. Nothing operational — no proposals, no users, no spend, no pipeline — ever appears.
  • Buyers can filter by set-aside, state and capability, and open a profile without an account.

If you hold a certification and have not uploaded the certificate yet, this is the reason to: it is the difference between a badge and a claim.

The audit trail is now genuinely tamper-evident

VETR has always refused to let privileged-action records be edited or deleted through the application. That protects against the software; it does not protect against someone with direct database access, and it does not protect against records simply ageing out.

Every day, new audit entries are now copied into write-once storage with a one-year lock. Once written, an entry cannot be altered or deleted by anyone — not by us, not by a support request, not by an administrator with every permission we can issue. That is the property an auditor is actually asking about when they ask whether your records could have been changed after the fact, and it is now true rather than intended.

Each day’s export is read back and checked before it is marked done, so a silent failure retries instead of leaving a gap nobody notices.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.13.0— permalink
Minor

VETR 3.13 — A documented API and MCP server, certifications that actually warn you, and an opportunity feed that stopped depending on one key

Build on VETR: a real developer reference, and MCP

The API has been available on Professional and Enterprise for a while. Its documentation was a summary rather than a reference — it listed twelve of the twenty-five endpoints, pointed you at a settings page that does not exist to create your token, and never mentioned that a newly created token is read-only by default, which is why writes came back “forbidden” with nothing to explain it.

  • Every endpoint is now documented — all twenty-five, with query parameters, request bodies, what each returns, and which token ability it needs. The page is generated from the API itself, so it cannot drift out of step with what the platform actually serves.
  • Token abilities are explained before you need them, along with every condition a request has to satisfy and what each error code means. Previously only the rate limit was documented.
  • Code samples in curl, JavaScript, Python and PHP, instead of one curl line.
  • Webhooks are described as what they are — shipped, and delivering signed payloads. The page had been calling them “coming soon”.

The MCP server is documented for the first time

VETR runs a Model Context Protocol server, so an AI assistant can work with your proposals, compliance status, VETR score and teaming partners directly — without you copying anything into a chat window. It has been live and reachable with your existing API token, and it was documented nowhere. It now has its own section: the endpoint, how to authenticate, every tool, and which ones need a write-scoped token.

Both the API and MCP are Professional and Enterprise features, and that entitlement is now verified on every request rather than only when a token is created. If your subscription ends, the tokens issued under it are revoked with it. Nothing changes for a current subscriber.

Certification renewals now reach the people who need them

This one was ours, and it was quiet. VETR emails you at ninety, thirty and zero days before a set-aside certification expires, shows a banner on your dashboard, and blocks a bid on a set-aside whose certification has lapsed. All three read one date — and for any certification backed by an uploaded certificate or a SAM.gov verification, that date was never being recorded. So the customers who had done exactly the right thing were the ones getting no warnings at all.

  • An approved certificate’s expiry now reaches the reminders, the dashboard banner and the bid-integrity check.
  • There is a recertification checklist on your certifications page: the countdown, the agency you recertify through, and the concrete steps for that specific certification. The emails and the dashboard banner now land there, rather than on the settings form.
  • An expired EDWOSB is judged against your EDWOSB date, not your WOSB one. They are separate certifications with separate expiry dates, and a current WOSB was masking a lapsed EDWOSB on EDWOSB set-asides.

Your WOSB eligibility answers are kept

The WOSB / EDWOSB eligibility check asked seven questions and then forgot them — reload the page and you started again from scratch, with nothing recorded about what your organisation had assessed. Your answers are now saved with the date and who ran it, the wizard opens with them filled in, and it tells you when the annual reassessment is due. Previous assessments are kept rather than overwritten. This remains a self-assessment, not a certification.

Opportunities and sign-in

  • The opportunity feed no longer depends on a single rate-limited key. It now tries the primary data source first and falls back to SAM.gov, so a daily call cap on one provider no longer empties the feed.
  • Two-factor sign-in submits when you finish typing the code, on the sixth digit — and never while you are typing a recovery code.
  • The dashboard header counters appear. They were being sent under a name the page did not read, so they had never once rendered.
  • The government-updates admin page reports freshness per source rather than as one figure, which had been hiding a source that stopped updating nine days earlier.

Accessibility

VETR’s accessibility checks ran against the desktop layout only. They now run against mobile as well, on every build. Doing that found three real problems, all fixed — most notably the organisation switcher in the header, which on a phone had no accessible name at all for anyone using a screen reader.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.12.0— permalink
Minor

VETR 3.12 — Tools that say "I don't know" instead of guessing, and a proposals list that behaves

When VETR cannot answer, it now says so

Three features used to produce a confident-looking answer when they had nothing to work from. That is worse than an error, because there is no way to tell the difference.

  • The AI compliance checklist no longer invents items. If the RFP’s requirements had not been parsed, or the model returned something unusable, VETR quietly saved ten generic template items labelled as generated from your solicitation. It now creates nothing and tells you which of the two happened. If you have previously generated a checklist that reads generically and does not cite your sections, it was this — re-parse the RFP and generate again.
  • The free VetCert consistency checker refuses text it cannot read. Pasting anything at all — including nonsense — returned “Ready to submit. Everything reconciles.” It was reporting the absence of extractable names, addresses and ownership as proof that they matched. It now checks the text actually looks like a SAM record, Articles or an Operating Agreement, and asks you to paste the real document instead of scoring nothing.
  • Past-performance capture requires delivered work. Drafting a CPARS-style record on a contract with no accepted deliverables and no completed milestones produced a narrative about work nothing recorded as done. It now declines and tells you what to record first.

Proposals

  • Duplicate asks first. It was a single unlabelled click on every row, and a duplicate permanently consumes one of your plan’s monthly proposals — deleting the copy does not give it back. It now lives in a “More actions” menu behind a confirmation that says exactly that. Duplicating also now copies the proposal’s outline, which it previously left behind.
  • Cards are clickable. In the list view the title was not a link at all. Both list and grid cards now open the proposal, and each row has a menu with View, Edit, Export CSV, Duplicate and Delete.
  • “Back” returns to the proposal you were editing, not to the top of the list.
  • Attaching a document from the workspace works. Uploads from the Docs tab were being rejected before they were saved, with nothing shown to explain it. The tab also now lists the documents already attached to the proposal instead of appearing empty.

Government updates

  • Award dates are labelled “Awarded”, not “Deadline”. An award is a contract that has already been decided and has no deadline — showing its date under “Deadline” made a feed of current information read as entirely expired.
  • “Closing soonest” only shows things that are still open. It had no cut-off at today, so it ranked the longest-expired solicitations first.

Security

A document flagged by malware scanning can no longer leave in a submission package. VETR already refused to let you download a flagged file, but the assembled submission package did not apply the same check — so a file the platform would not hand you individually could still be included in the package you file with an agency. The package now withholds it and names it in the manifest, so you see it before you file rather than after.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.11.0— permalink
Minor

VETR 3.11 — Grants you can act on, lists in the right order, and AI that no longer holds up your password reset

Grants: what you can act on, and what you cannot

Grants.gov publishes a forecast when an agency intends to fund something — before there is an announcement, application forms, or a firm deadline. 517 of the 1,754 grants VETR indexes are forecasts, and until now they looked exactly like grants you could apply for today.

  • A forecast no longer offers “Start an application”. It offered one, and starting it created a real proposal against a solicitation that does not exist yet — consuming your plan’s monthly allowance for it. The page now explains what a forecast is, keeps the link to the notice on Grants.gov, and tells you the action returns the moment it is posted.
  • The grants list defaults to what you can apply for. It used to report “1,700 open of 1,714 indexed” when only 1,182 could actually be applied for. There are now two honest numbers — open to apply, and forecast — and forecasts are one deliberate click away under “Open + forecast”.
  • An empty result tells you why it is empty. Search a term whose only matches are forecasts, or grants that have already closed, and VETR says so and points at the filter that shows them, instead of “No grants matched”.
  • The compliance matrix is built from the official announcement. Converting a grant used to produce an empty matrix with nothing to say why. VETR now reads the announcement attachment from Grants.gov and fills it — and when it cannot, it marks the read as failed rather than leaving you with a blank page that looks finished.

Lists are in the order you would expect

Several lists were ordered arbitrarily rather than newest-first — a database detail, not a choice: the columns they sorted on allow empty values, and the database put those first. Webinars, checklists, citations, release notes, help results and the government updates feed now read newest-first, and help search ranks title matches properly instead of discarding them.

Billing and sign-in

  • Your plan’s premium AI model is honoured. Organisations entitled to the Professional model were being served the default one regardless of the setting.
  • Refunds always apply. Whether a refund reached your account depended on the order two internal handlers happened to run in. It no longer does.
  • Signing in works regardless of how you typed your email. Address casing is now handled consistently, and completing a password reset verifies the address — operator-created accounts could previously clear onboarding and then hit a verification wall with no way through.

The platform stays responsive while AI is working

Long AI work — parsing an RFP, running an agent, drafting compliance responses — shared a queue with short tasks like password-reset emails. Because a worker handles one job at a time and cannot interrupt itself, a single fifteen-minute AI job could hold everything behind it. All long-running work now runs on its own dedicated, separately-scaled worker pool, so a password reset never waits behind a proposal agent.

Security

  • A denial-of-service advisory in a text-rendering library was patched within hours of publication. No customer data was involved and no VETR feature was affected; the release gate refused to ship until it was fixed.
  • The build cannot package uploaded documents. A hardening review found that a manually-built image could have included uploaded solicitations from a developer machine. The build now excludes them and verifies their absence before an image is allowed to deploy.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.10.0— permalink
Minor

VETR 3.10 — Grants you can actually work on, a certification check that was wrong, and a site that holds up under load

Federal grants became a workflow

VETR has searched Grants.gov for a while, and the only thing you could do with a result was follow a link off the platform. That is a data source, not a feature. Grants now behave like every other opportunity here.

  • A grant opens inside VETR, and it leads with who can apply. Most of the Grants.gov corpus is open only to states, universities and 501(c)(3)s, so “can I apply for this at all?” is the first question a contractor has — not the award amount and not the deadline. Where we have not retrieved eligibility for a notice, the page says so rather than implying it is open to everyone.
  • Filter by who can apply, and by CFDA. Both controls existed on the server and neither was on the page, so neither could be used. The applicant types offered are read from the grants we actually hold, so the filter can never offer you a value that matches nothing.
  • Start an application from a grant. It becomes a working proposal with the sections a federal grant reviewer actually scores — statement of need, goals and measurable objectives, approach, work plan, organisational capacity, evaluation plan, budget narrative and sustainability. Not the contract sections: a grant has no transition plan and no quality assurance surveillance plan, and asking you to write them would be asking for work no reviewer reads.
  • We do not invent a set-aside or a NAICS code for a grant. Those are contract vocabulary. A grant scopes by applicant type and classifies by CFDA, so those fields are left empty rather than filled with something plausible.
  • Saved searches can watch grants, matching on eligibility and CFDA — never on NAICS or set-aside weights, which a grant does not carry and which would have quietly matched nothing forever. Existing saved searches are unchanged until you add grant criteria to them.
  • The nightly index now covers every open grant rather than the ten keywords it used to walk. A grant matching none of those terms was invisible by construction.

A certification check that was telling people the wrong thing

Entity verification could report a genuinely certified SDVOSB as not certified. The federal registry returns entity records in more than one shape, and VETR was reading only one of them — so registration status came back “Inactive” and the socio-economic designations came back empty, for entities whose registration was active and whose certifications were on file. Every shape is now read correctly. If you saw VETR fail to confirm a certification you hold, that was this, and it was ours.

Capacity and responsiveness

  • The web tier serves substantially more work in parallel. Its concurrency ceiling had been inherited from a framework default rather than set deliberately; it is now sized against measured memory use, so short bursts of traffic no longer queue behind a handful of workers.
  • Requests for files that do not exist are answered by the web server rather than waking the application, which makes routine internet background noise very much cheaper to absorb.

Choose the AI engine behind your work

Professional and Enterprise organisations can now select Claude Sonnet 4.5 as the model powering their AI, alongside the existing in-boundary options. It is a choice, not a change: nothing switches unless you switch it, and every option runs inside the same GovCloud boundary as before. No content leaves it, and there is still no way to bring your own external key — that is the point.

An integration retired

The third-party vendor registry VETR used for partner discovery and eligibility cross-checks has been removed; the subscription behind it ended. Partner discovery runs on federal award history and SAM.gov, which is what ranked results anyway. The Eligibility Sentinel now watches what the federal registry can actually answer — your SAM registration expiry, any exclusion recorded against your entity, and certifications your profile claims that SAM does not list. It no longer claims to compare certification expiry dates against SBA records, because the data source that made that possible is gone and we would rather change the sentence than keep it.

Things that were quietly broken

  • Workshop sandbox links could not be copied. A generated link was shown once and only a fingerprint of it was stored, and the one-time reveal was being dropped before it reached the screen — so the link was unrecoverable. Links generated between 3 and 5 August were lost; new ones display correctly.
  • Three administrative pages had no link to them. Sandbox links, certification review and help categories were all built, tested and reachable only by typing the address.
  • Daily blog generation had been silently declining to run for 44 days because its topic queue was empty. It reported success every time. It now says why it stopped, where someone can see it.
  • SAM.gov showed as not connected while working perfectly on the administrator checklist, because the check looked in one place for a key that lives in another.
  • Video tutorial cards show their thumbnails again — the card was asking for an image size that does not exist for videos under 720p.

Elsewhere

  • The two dark panels on the homepage now carry a graduated tone rather than a flat fill, and the homepage is checked for accessibility on every build — it had been left out of that check.
  • Environment toggles in the administrator console say what “on” and “off” will actually do before you flip them.

Your data, the GovCloud boundary, and the guarantee that all AI processing stays inside it are unchanged.

v3.9.1— permalink
Patch

VETR 3.9.1 — Proposal sections save, signing in lands on a working dashboard, and notices open again

Fixes

  • Saving a proposal section works, including an empty one. The workspace returned a red “Save Failed” when you cleared a section, or moved away from one you had not written in yet. The save was being refused for the sole reason that the section was empty — which is an entirely ordinary thing for a section to be, and the editor had no way to tell you that was the objection. Empty sections save now. Separately, a save aimed at a section that no longer exists reports the failure instead of showing “Saved” for a write that did not happen.
  • Signing in lands on a working dashboard. If you opened VETR on a public page first — the homepage, pricing, one of the guides — and then signed in, the dashboard and most pages inside the application could fail to draw and show an error card instead. The application was still working from the shorter list of destinations it had loaded for a logged-out visitor, and nothing replaced it when you signed in. It now switches to yours before the first page renders. A page that somehow still hits this recovers on its own rather than leaving you on the error card.
  • Opportunities open again from SAM.gov search. Opening a notice reported “Opportunity not found. Please search again to view the latest results” even though the notice was right there in the results. The list was being served from VETR’s own copy of the federal opportunity feed while the detail page insisted on fetching the notice from SAM.gov again — against a daily call allowance that is quickly exhausted. It now opens the copy VETR already holds, so it is both reliable and free of that allowance, and it still links out to the full notice on sam.gov. Create proposal from this opportunity and save to pipeline were failing for the same reason and now work as well.
  • Partners you add from a partner search arrive with their details. Adding a company found by partner search saved little more than its name, identifier and certifications — so the partner page had almost nothing on it. The named points of contact, the federal award history the company was suggested on, its city and its website were all being discarded on the way in. They are kept now: the contacts fill the partner’s primary and secondary contact fields, and a short note records the obligated dollars, contract count, most recent award and buying agencies that put the company in front of you. Partners added before this release are unchanged.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.9.0— permalink
Minor

VETR 3.9 — Federal rules measured against your real bid, and the parts that were built but unreachable

Federal rules, measured against your actual bid

Set-aside contracts cap how much of the work you may subcontract. VETR could already evaluate that rule — but from percentages typed onto a teaming agreement, which meant the compliance figure and the bid could quietly disagree. It now reads the money.

  • The limitation on subcontracting is calculated from your priced cost volume. Every labour line and direct cost records who performs it, so moving work to a subcontractor moves the compliance number with it. The limit that applies depends on the type of work — 50% for services and supplies, 85% for general construction, 75% for special trade — and the last three exclude the cost of materials, which VETR now applies correctly rather than using one rule for all four.
  • “Similarly situated” is checked, not taken on trust. Work performed by a subcontractor holding the same set-aside status as you does not count against the limit. If the partner you named does not actually hold that certification, VETR shows the figure as claimed beside the figure as verified, and names the line and the reason. An unsupported claim is what turns a compliant-looking bid into a protest.
  • A bid that breaches the limit is held back from submission readiness. A volume nobody has classified is reported as unevaluated rather than as compliant — VETR does not guess in your favour.

The pricing schedule, without retyping it

  • Contract line items are read out of the solicitation. Section B is parsed into CLINs and sub-line items with their quantities and units, including option years, and imported into your cost volume. The extraction is deterministic rather than AI-guessed: a fabricated line item would seed a cost volume pricing work the government never asked for.
  • Labour categories are transcribed too — the job titles the schedule names, exactly as written. Where the schedule states hours, they come across; where it does not, the field is left empty rather than filled with a guess.
  • Importing never sets a price. Rates arrive at zero for you to fill in. A rate VETR invented would produce a confident grand total nobody calculated.
  • Costs roll up by contract line item, the way a contracting officer reads a price schedule. Anything not yet linked to a line is shown as such rather than dropped, so the roll-up always reconciles with the total.

Contract vehicles and the work competed under them

  • Record the vehicles you hold — GSA schedules, IDIQs, GWACs, BPAs — including ones held by a teaming partner, since that decides who can prime the order.
  • Opportunities competed under them are flagged in your feed. An order against a vehicle you already hold is a far shorter path than an open solicitation, and it used to sit in the list looking like everything else. Matching is deliberately conservative: an expired vehicle is excluded, and a vehicle whose name is a common word is matched only by its contract number, because a wrong flag is worse than no flag.

Teaming agreements you can actually create

Workshare tracking, negotiation preparation, BATNA, the priority matrix and red-flag review all hang off a teaming agreement — and there was no way to create one, so none of it could be reached. There is now, and creating an agreement takes you straight to recording who performs each item of work.

Compliance responses you can read before you approve them

  • The response text is visible and editable. AI-drafted answers are exported into the compliance matrix you submit to the government; until now no screen displayed them, so approving was a click over prose nobody had seen. Drafts are marked AI drafted — not yet reviewed until a person saves them.
  • Approving records who stood behind the text. The headline compliance percentage now reflects a sign-off that can be audited, not just one that happened.

Things that were quietly broken

  • Re-reading an amended solicitation works. It previously failed once a proposal had compliance items — and the obvious repair would have deleted the responses your team had written, so the fix keeps them.
  • The autonomous agents are available. They were built, tested and advertised, and no plan actually granted access — every organisation including Enterprise was refused. Professional and Enterprise now carry them.
  • The recompete radar returns results. It requested a field the federal data source always returns empty, so it had shown nothing since it launched.
  • Partner matching counts set-aside status again. The scoring read those fields under names that do not exist, so being SDVOSB, HUBZone, WOSB or 8(a) contributed nothing.
  • Past-performance records are properly permissioned. A read-only member could create, edit and delete them. Those records are what a proposal cites to prove it can perform.
  • Three analytics dashboards and the partner pipeline board are reachable. All four were finished and nothing linked to them.
  • Relevance scoring ranks correctly. A “very good” CPARS rating was scoring as unrated and ranking below “marginal”, and below “unsatisfactory” in the exported volume. Contracts marked ongoing now receive full recency credit rather than none.
  • FPDS search explains itself. An unreachable federal feed is reported as unavailable instead of failing with a technical error.

Claims checked against the software

Every capability statement on the public site was re-checked against what the code does, and corrected where it outran it — a forecasting horizon we do not offer, a content-library figure with nothing behind it, a recompete window longer than the one we search, and a price on the ROI calculator that differed from the pricing page. The accessibility badge now states what was measured — automated checks — rather than implying a full audit, consistently on every page. Marketing statistics asserting a customer base are no longer seeded.

Your data, the GovCloud boundary, and the guarantee that AI processing stays inside it are unchanged.

v3.8.0— permalink
Minor

VETR 3.8 — Pages that answer the question you actually asked, and a public site two-thirds lighter

Being findable

We measured how VETR shows up when someone asks an AI assistant for proposal software — forty buyer questions across ChatGPT, Claude, Perplexity and Google's AI Mode. VETR appeared in one of the forty. The reason was not obscure: buyers ask for a category — "the best capture management software", "an RFP response platform" — and VETR had no page whose subject was any of those phrases. This release writes them.

  • Six category guides. Proposal management software, federal proposal tools, RFP response platforms, capture management software, past performance libraries and government bid software. Each one covers what the category means, how to evaluate products in it, who the alternatives are, and where VETR fits — written to be useful even if you buy something else. We name real competitors and describe them from their own public positioning; where we could not verify something, the page says so rather than guessing.
  • Three comparison guides. VETR versus spreadsheets — including an honest account of when a spreadsheet is genuinely enough. VETR versus general-purpose proposal tools. And a plan-by-stage guide covering which tier fits which size of team, and what actually triggers an Enterprise conversation.
  • One FAQ, in one place. The questions were spread across pricing, help and features; /faq now answers the whole set — what VETR is, who it is for, what it does, what it costs, where the AI runs — on a single page.
  • A page that says which VETR this is. Four letters, and other organisations use them. /vetr-proposal carries the canonical company facts: legal entity, founding date, headquarters, founder and trademark.

Speed

  • Public pages are 68% smaller. Every marketing page was shipping the application's entire internal route map — twice — which came to two thirds of the page. A logged-out visitor now receives only the routes a logged-out visitor can use. The homepage went from 263 KB to 84 KB.

Security answers, in writing

  • A security FAQ on /security, written as the questions a security reviewer actually asks: where the AI runs, which region your data sits in, how CUI is handled, how one organisation's data is kept from another's, and what documentation you can obtain. It answers the uncomfortable ones too — SOC 2 Type II remains in preparation and VETR is not FedRAMP authorised.
  • Multi-factor authentication, stated precisely. Two-factor is supported for every account and required for organisation owners and administrators. A control letting you mandate it for every member of your organisation is on the roadmap and does not ship today — if a security questionnaire asks, that is the honest answer.
  • Autonomous agents now require an administrator to switch on. They spend from your organisation's shared AI allowance, so enabling or disabling one is an owner-or-admin decision rather than something any member can change.
  • The Eligibility Sentinel says what leaves the boundary. It sends your SAM UEI to the federal registry once a day to check your registration status, its expiry date and any exclusion recorded against your entity. No proposal content, documents or personal data leave the boundary, and no AI model is called. The switch says so before you flip it. (Amended 2026-08-05: as first published this described a daily cross-check against a third-party vendor registry. That integration has been retired and the agent no longer contacts it. The sentence is corrected here rather than left standing, because it is a statement about where your data goes.)

Terms and policies

  • The Terms now cover one-time purchases. Paid webinar registrations are charged once rather than as a subscription; cancelling a plan does not refund one, and if we cancel an event the fee is refunded in full.
  • Included AI usage is described. Allowances exist to stop runaway cost, not as a metered charge — we do not bill you past yours. When one is reached, AI features pause until the next period; the rest of the platform keeps working.
  • Governing law is consistent across our agreements. The Terms of Service and the Enterprise MSA named different states; both now read the same.
  • Both policies carry accurate dates.

The homepage

  • Movement with a reason. The statistics count when they reach you, the agency row drifts to say the list continues, and the headline arrives a word at a time. If your device asks for reduced motion, you get the finished state immediately rather than a faster animation.

Your data and the GovCloud boundary are unchanged, and all AI processing remains inside it.

v3.7.0— permalink
Minor

VETR 3.7 — Your proposal has the sections your solicitation asks for

The outline is yours now

A proposal's section list is the shape of the document you are going to submit, and VETR was not building it properly. This release rebuilds it end to end — from the solicitation, through the editor, into the file you send.

Sections

  • Every proposal gets its full set of sections. When a solicitation's Section L was parsed, VETR built the outline from that alone and dropped the core narrative sections — so a proposal could open with a single section and no Executive Summary or Technical Approach. Section L now adds to the standard set instead of replacing it, and the solicitation's own items keep the order it specifies, because ordering against Section L is itself an evaluation criterion. Proposals already affected repair themselves the next time you open the workspace.
  • The proposal page and the editor now show the same sections. The Sections tab listed four fixed names while the workspace listed your real outline. It now lists the real one, with each section's number, title and status.
  • You can add your own sections. Use the + in the Document Outline for anything the solicitation asks for that the parse missed — a Small Business Participation Plan, a Section 508 conformance narrative, an agency-specific plan. Give it a title, and optionally a line or two on what it should cover; the AI reads both alongside the solicitation when you draft it. Sections you add can be removed again.
  • Renaming a section is safe and the editor's prompt now follows the section you are actually in.

Exports

  • Your export contains what you wrote. The export offered a fixed list of eight items and only ever wrote four of them into the document. Sections you added were dropped without warning, and the Transition Plan, Quality Assurance Plan and Risk Mitigation Plan were never included at all — even when written. The export now offers your proposal's real outline, in its real order, under its real headings.
  • Past Performance is offered only when you have not written your own, so the topic no longer appears twice.

Scanned documents

  • OCR now reads your document. Text extraction from scans ran through a component that was never installed, and returned a fixed sample statement of work — saved against your file as though it had been read from it. Extraction now runs on Amazon Bedrock inside the GovCloud boundary, the same engine that already reads your RFPs. Where a file cannot be read, VETR says so instead of returning something.

Elsewhere

  • The VETR score is legible — the overall score is now a ring showing where you sit, with each pillar scored against the same bands, in both light and dark themes.
  • Deleting your account closes your subscription. Deleting the workspace owner previously left a subscription billing an account nobody could reach. If teammates still use the workspace, VETR asks you to contact support so ownership moves across first.

Your data and the GovCloud boundary are unchanged, and all AI processing — including document text extraction — remains inside it.

v3.6.0— permalink
Minor

VETR 3.6 — Cancellation that works, documents that are scanned, numbers that stay honest

A second correctness pass

3.5 stopped VETR showing scores it had not calculated. This release finishes that job in the places 3.5 did not reach, and fixes a set of billing problems we found while auditing the payment path end to end.

Billing and cancellation

  • Cancelling actually cancels. Cancelling a free trial, or a plan with no card attached, previously showed a success message while nothing happened. Every cancellation and resume now reports exactly what it did — and names the date your access runs to, instead of saying "the end of the billing period".
  • A cancellation made in Stripe now shows up in VETR. Cancelling through a card statement, a billing portal, or by letting a payment lapse used to leave your VETR billing page looking untouched.
  • You can start a plan again after cancelling. Re-subscribing from inside the app previously failed with a generic error once a subscription had ended.
  • Access now ends when your paid period ends, and everything you paid for keeps working right up to that date — including every AI feature, which used to switch off early.
  • A refund closes the account cleanly. A full refund now also ends the Stripe subscription, so you are never invoiced again for a workspace you no longer have. Partial refunds leave your plan running, unchanged.
  • Payments that need bank confirmation are surfaced rather than failing quietly.

Documents

  • Stricter upload checks everywhere VETR accepts a file. A document's real content must now match the file type it claims to be, on every upload path — including document versions and files sent for signature, which previously had weaker checks than the rest.

Numbers and documents you send out

  • No invented win probability. An unscored proposal now says so and offers to run the scoring agent, instead of reporting a low percentage nobody calculated.
  • Go/No-Go starts empty. A new assessment no longer arrives pre-filled at "Average" with a recommendation attached, and it will not let you finalise a decision you have not made. Criteria you have not reached yet no longer count against your score.
  • Your proposal's past-performance volume uses the references you cited for that bid, strongest first — it previously included an arbitrary five from your whole library, and could differ between two exports of the same proposal.
  • Exported documents only state what was recorded. A contract with no end date is no longer described as "Ongoing", and an unscored proposal no longer exports as a 0% "Underdog".
  • RFP parsing reports the confidence the model actually gave, rather than filling in a default.

Security and compliance

  • Two-factor codes are covered by the same account lockout as passwords.
  • Session data is encrypted at rest. You will have been signed out once when this took effect.
  • The compliance page reports only what VETR can actually verify. Controls it cannot check automatically are now shown as not assessed instead of being counted, and the page states plainly that these figures are a self-assessment of our own configuration — not a certification. SOC 2 Type II remains in preparation and we are preparing to engage for FedRAMP 20x.

Your data and the GovCloud boundary are unchanged, and all AI processing remains inside it.