{
  "summary": "Renamed from Allod DAM to Allod VRM (Vendor Risk Management), reflecting where the product has grown since v0.1.0. Sovereignty scoring saw several correctness fixes: a weighted-sum renormalization bug that inflated scores when not every objective had been assessed, a dead control, redundant SOV-4/6 checks, and closed content gaps in the CSF §4 objectives (SOV-1/3/5/8) - plus manual Vendor HQ and Ultimate Owner country fields and an optional self-hosted-deployment signal that feeds SOV-3/SOV-4 suggestions without ever setting a level on its own. Added vendor e-signing for contracts: an admin uploads a document unmodified, emails a one-time link, and the vendor's approval is captured as a separate Ed25519-signed receipt (document hash, signer, IP, timestamp) rather than altering the original file. Added Contract Templates: reusable HTML or Markdown templates stored in S3-compatible object storage with bucket versioning as the version-history mechanism, an explicit publish step so in-progress edits never affect what a contract is generated from, and a sanitized (goldmark + bluemonday) preview for Markdown templates rendered in a sandboxed frame. Fixed a stored-XSS vulnerability from unescaped single quotes and added missing foreign-key validation."
}
