Changelog

What shipped,
when it merged.

Dates are the America/New‑York calendar day a release merged to main, verifiable from public history; images publish from main and production deployment typically follows the same day. Entries describe released work only. Features that are built but switched off in production say so.

35releases listed
2026-09-16latest merge
2026-07-09first entry

Your own first text

  • When a call moves to text, the first message now opens with a line you write, in your voice, on Settings → Phone. The short carrier notice follows it once instead of introducing the assistant twice.

Every phone line answers on the faster backend, and texting registrations carry your policy pages

  • The phone assistant now runs its lookups on the faster backend for every business, after side-by-side calls on both.
  • It also learns which hosts answer fastest from every call, not only the ones it picked, so a slow host is routed around sooner.
  • The self-serve texting registration sends the carriers your privacy and terms pages automatically (or links to your own), which the carriers require for new registrations.

Texting you can switch on yourself, links that stay clickable, and a phone line that never drops mid-update

  • Settings → Phone gains "Enable texting (SMS)": enter your business details once and the carrier registration runs on its own; texting switches on the moment the carriers approve it.
  • Links texted to your customers (a deposit to pay, a booking to manage) are now short, so they arrive in one message and stay clickable on every phone.
  • A software update never cuts a call in progress any more, the recorded greeting hands over to the live assistant in one clean breath, and a goodbye ends the call promptly.

The phone assistant can run its lookups on a faster backend

  • Amfion can now run the lookups behind a phone call in its own process, on a choice of AI models, instead of inside the voice provider. It is off by default and switched per business by the Amfion team after a measured comparison.
  • Every call records which backend answered it, how long each lookup took, and what it cost, so the comparison is made on real conversations, not guesses.

Faster answers on the phone, and a greeting you can talk over

  • Lookups that go to the back office are about twice as fast: the backend now runs on a priority lane with lighter reasoning, measured on production.
  • "When can I come in?" is answered on the spot. The next few openings for each bookable service are read as the call connects and offered directly; booking still confirms the slot.
  • The recorded greeting is now just the first sentence. The assistant says the rest itself the moment you are connected, so you can interrupt it like anything else it says.
  • Preview fixes: keeping a preview while signed in now lands in your new workspace instead of a "Not found" page, unclaimed previews no longer show up as workspaces, and "Try it" is back in the navigation.

The phone assistant answers like a person

  • Hours, location and prices are answered on the spot — no more "checking" pause for the questions every caller asks. Lookups and bookings still go to the full assistant behind it.
  • A shorter greeting: the business name, that it is an AI assistant, and that the call is transcribed — then it listens.
  • It says hello back when you say hello, drops the status-update phrasing, and takes a comment about how it sounds in stride.

Two dogs, one visit — over the phone and from other assistants too

  • A family booking several pets (or several cars) gets one visit, back-to-back, from the phone assistant and from third-party assistants using the gateway — the same way website chat already books them. Each pet is quoted from its own size or condition option, the summary lists every pet with the total, and nothing is booked unless the whole visit fits.
  • Your dashboard now says what the front desk will do as it stands — "customers who ask what a Full Groom costs are told the price is not listed", "calls cannot reach a person: no transfer number" — with a link to fix each one. It hides once you have looked.
  • The preview shows its receipts: what it learned from your site, what you corrected, how many conversations, test bookings and requests it handed to you, right on the "keep this front desk" card.
  • Price options and booking intake are yours to edit: on each service, add options like "Small dog $45" or "SUV $180, 3 hours", list the facts the assistant must ask before booking, and the flags that hand a customer to you instead. Until now these were set through the partner API only.

See it on your own website before you sign up

  • The preview is now the front door: every page leads with "See your front desk", and the free trial is one step behind it. Paste your website, meet the front desk it would run, keep it if you like it.
  • Busy days are welcome: the daily limit on public previews is now far above any real day, and the team is alerted as it fills instead of visitors being turned away. The per-visitor limit of three previews a day stays.

Previews say exactly what they know

  • The "what I learned" panel now tracks every service and every field on its own: a price you typed is "confirmed by you", the rest stay "from your site", and hiding a service changes the counts. A preview built from a Google listing alone calls its catalog "suggested" — never something we found on your listing.
  • Your rules are enforced, not just remembered: a rule like "any bite history reaches a groomer before we book" becomes a booking gate — the assistant hands that customer to you instead of booking.
  • Test bookings never take a real customer's seat. Bookings made in a preview or in your dashboard test never block a live slot, never get reminders, and show as "Test" on your bookings page after you claim the workspace.
  • Honest small print: the preview contacts no customer; the one email it sends is the booking confirmation to the address you type.

Previews read more of your site, faster

  • The "see your front desk" preview now reads up to 16 pages of your website (up from 6) in parallel, inside a fixed time window, so a slow host can no longer stall the build. The full import after you claim a workspace reads up to 24.
  • Price lists are never cut short: pricing and services pages are read in full, whatever their length.
  • Every price comes from your pages. A service whose price is not stated is shown without one — never as "$0".
  • Extraction runs on an open-weight model served by zero-data-retention providers in the United States, with the previous model as an automatic fallback. Each build records which model produced it and what it cost.

Your phone assistant answers in about a second

  • Callers hear your greeting the moment the call connects — about a second after the ringing stops, where it used to take six. The greeting is recorded once in the voice you chose, so every call opens with the same warm line, and the assistant picks up the conversation from there.
  • Change the greeting, the voice or your business name and the recording is redone automatically within a minute; the old one is never played.
  • The demo line for previews answers the same way, so a prospect calling their own preview hears their business name right away.

Book the whole family: multi-pet visits, sized to the dog

  • One visit for several pets: the assistant collects each pet’s details, quotes each one, shows times that fit the whole visit back to back, and books it in a single confirmation — one appointment per pet, tied together, with every pet’s safety notes on its own booking.
  • Appointment lengths can now follow the size band: a “Large dog” groom books 90 minutes where a small one books 60, on the calendar and in what the assistant tells the customer.
  • The website preview reads deeper and faster: the most useful pages (prices, services, hours, FAQs) are read in parallel before the assistant thinks, script-built sites are rendered instead of skipped, “from $45” prices are quoted as starting prices, and the preview workspace no longer jumps while it builds.
  • No website? Paste your Google Maps link, or your business name and city, and the preview is built from your listing — name, hours, phone and a starter menu for your kind of business.
  • Call your preview from your own phone: link your mobile number on the preview page and, for the next 30 minutes, calls from it to the demo line are answered by your preview — same knowledge, same sample calendar.

Test your front desk: paste your website, meet your AI receptionist

  • Paste your website at amfionhq.com/try and, in about a minute, talk to a front desk that knows your services, prices and answers — before you sign up. Ask it a price, book a test appointment on a sample calendar, throw it a hard case.
  • Fix what it assumed in place: prices, appointment lengths, booking hours and plain-sentence rules. Then keep it — signing up claims the preview, and its knowledge, your edits, your test conversations and the booking come with you.
  • Nothing leaves the preview: no messages are sent, bookings are test bookings, and an unclaimed preview is deleted after seven days.

WhatsApp is live: message your business, get answers, book

  • Customers can now reach your assistant on WhatsApp — the same knowledge, live availability, and real bookings that already work over SMS, chat, email, and phone. Verified end to end with a real conversation, a human takeover reply, and the thread in the Inbox.
  • WhatsApp conversations appear in your Inbox next to every other channel; take over any time and your reply is delivered back on WhatsApp.
  • Requires a Meta-approved WhatsApp sender on your number — we handle the approval with you during onboarding.

Rehearsal Studio: test your assistant before customers do

  • Every account now has Rehearsal Studio (Admin → Rehearsal Studio): scripted customer conversations run against your real assistant in a sandbox — nothing is booked, sent, or charged — and each one is graded against a checklist of what must happen.
  • Real conversations that go wrong become rehearsals automatically: a thumbs-down answer, a conversation handed to a human, or a booking abandoned at the deposit step arrives as a draft carrying the customer’s actual messages, ready to review and activate.
  • Runs compare setups side by side — the current model against a candidate on identical conversations — so changes are proven before they meet a customer. We use it ourselves: recent changes to how the assistant retrieves knowledge and remembers long conversations shipped only after passing their rehearsals.
  • Smarter under the hood, too: the assistant now finds your uploaded knowledge by meaning as well as wording — “do you take walk-ins” can find the policy page that says “appointments preferred” — and long conversations stay fast without losing what was said early on.

Texting is live: your assistant now answers SMS

  • Customers can text your Amfion number and the assistant answers from your own services, prices, hours and policies — checks live availability, and books, right in the thread. Verified end to end with a real booking made entirely over text.
  • Every text conversation lands in your Inbox next to calls, chats and emails — take over and reply from there, and your reply is texted back. STOP, START and HELP are handled at the carrier level.
  • Optional missed-call text-back: when a call can’t be answered, the caller gets one text inviting them to continue by text — once per caller per day, with opt-out instructions, off by default and enabled per business in Settings → Phone.
  • US numbers require carrier registration (10DLC); we handle it with you during onboarding.

Share photos and PDFs in chat

  • Customers can attach photos and PDF files in the website chat — a photo of the problem, a reference picture, a document — and the assistant actually reads them when answering and booking.
  • Files are validated by content, size-capped, and stored privately; your Inbox shows them on the conversation. The assistant only re-reads a file on the message it was sent with, so long conversations stay fast.
  • Deposits got stricter, too: a service can now require the deposit to HOLD the slot — the payment link is valid for 30 minutes, and unpaid holds release the time automatically (waitlisted customers are invited when a slot opens).

New plans: Digital, Front Desk and Growth

  • Plans are now named for what they do. Digital ($99/mo) answers your website and email and takes bookings. Front Desk ($249/mo) adds a local phone number with 200 call minutes a month, warm transfer to your team, and white label. Growth ($449/mo) includes 500 minutes and two numbers. Annual billing saves about 20%.
  • Beyond your plan’s minutes, calls are $0.49 per minute — never cut off mid-conversation — and additional phone numbers are $10 a month. Settings → Phone shows exactly what is included and what would be billed.
  • Keeping your existing number still works the same way: forward the calls you miss to your Amfion number with your carrier’s standard dial code.

Phone channel: your assistant answers calls

  • Get a local phone number in seconds from Settings → Phone (or forward the calls you miss from your existing line). The assistant answers, says it is an AI, answers from your knowledge, checks live availability and books the appointment on the call — reading names, emails and numbers back before confirming.
  • Warm transfer: when a caller asks for a person, the assistant rings your transfer number first with a short brief and connects the caller when you press 1; if nobody picks up, it takes a message.
  • Every call is transcribed into a conversation in your Inbox next to chats and emails (no audio stored); Settings → Phone shows recent calls, minutes used, what your plan includes, and overage.
  • Foundation merged 2026-08-17 (OpenAI Realtime over SIP with the tenant’s MCP gateway as its tools; migration 059); the first live calls the same day drove four fixes; self-serve numbers, warm transfer and usage-based billing followed on 2026-08-18 (migration 060).

Your email address, in the product and on the site

  • Settings → Sharing shows your assistant’s email address with a copy button — only on instances where the channel is actually enabled — and /integrations/email documents what the email channel does and does not do yet.

Inbox, email channel, widget upgrades, and a sharper admin

  • Inbox with human takeover: conversations the assistant or the visitor flags for a person land in /admin/chats; take over (the assistant pauses), reply, hand back, resolve or reopen, and keep internal notes the visitor never sees. The widget shows a handoff banner and picks up your replies live. One email per flagged conversation to the business.
  • Inbound email channel: customers can email the assistant at [email protected]; it answers with the same knowledge, trust rules and booking tools as chat, replies stay in one thread, and takeover replies are emailed too. Merged switched off; switched on in production the same day.
  • Widget: owner-editable suggested prompts, thumbs up/down on answers, clear conversation, English/Spanish chrome, voice input, a “Sources (n)” panel that shows each citation’s stored trust state, and “Powered by / Booked with Amfion” badges (removed on white-label plans).
  • Admin visual revamp: one design-token set for the admin and the widget (cool grays, brand blue, 6px radius, soft cards), a three-pane Inbox (list · thread · notes and customer history), and a Knowledge table with trust chips and a “questions the assistant couldn’t answer” card whose Answer button turns a gap into a confirmed Q&A source.
  • The email channel’s internal “unrouted” placeholder no longer appears in the Inbox or counts as a conversation (migration 058).

Knowledge center and activation signals

  • Self-serve knowledge center: add web pages, sitemaps, PDF/Word/text/Markdown/HTML/CSV files, pasted text and Q&A pairs; the assistant retrieves the most relevant passages per answer under the same trust rules as the rest of your knowledge, and you can mark a source “Confirmed by you”. Web sources are re-checked on a schedule; failures say why.
  • Activation funnel: first-touch milestones (site ingested, knowledge applied, first preview answer, first test booking, first live conversation and booking, widget embedded on your own site) recorded server-side and shown in the setup guide.
  • Admin API returns 404 (not 400/500) for another business’s record ids.

Dependency audit at zero

  • The production dependency audit reports zero advisories at every severity; the temporary 23-advisory baseline was retired and CI now fails on any new high-severity advisory.

Contract precision patch

  • Changelog dates are now defined as America/New‑York release days (previously stated as UTC, which twice drifted from the wall-clock day releases actually happened).
  • Custom-domain resolution distinguishes “domain does not exist” (404) from “the database could not answer” (503) — a transient failure can no longer make a customer domain look nonexistent — and resolves only verified custom-domain records.
  • Outbound IPv6 screening is now default-deny: only globally-allocated unicast space (2000::/3, minus documentation, benchmarking, tunneling, and 6to4 carve-outs) is reachable; everything unallocated is refused.
  • Machine-readable prices are minor-unit-correct: zero-decimal currencies like JPY and KRW render as whole units (¥12,000, not ¥120).
  • The dependency gate became a real ratchet: any new high-severity advisory fails CI immediately, and the existing 23-advisory baseline hard-expires on 2026-08-18.

Truth and edge-case patch

  • Security page corrections: webhook and custom-tool signing secrets are stored in access-restricted application tables, not Supabase Vault (calendar/OAuth credentials are in Vault; moving the rest is staged work) — the page previously claimed otherwise. The booking-capability guarantee is now stated precisely: at most one local booking row per capability; external-calendar duplicates are reconciled best-effort.
  • Custom-domain businesses now get their own llms.txt: hostnames resolve through the same cached domain lookup the API uses, with unknown hosts returning 404 instead of Amfion’s corporate map.
  • Machine-readable prices are formatted in the service’s actual currency; service summaries carry full source provenance (source, label, observation and verification dates), not just a trust state.
  • Outbound request screening expanded to block IPv4 special-purpose ranges (documentation, benchmarking, protocol assignments) beyond the private ranges.

Machine-contract accuracy release

  • Every public description of the Agent Gateway now derives from the live tool registry: the docs page is type-checked against the shared tool contract, and each business’s llms.txt renders its tool list and services directly from its gateway manifest. The previously documented one-shot create_booking tool never existed on the gateway — booking is two-phase (prepare, explicit user approval, confirm) and every surface now says so.
  • Business llms.txt services are policy-filtered: a service hidden by the business’s answer policy no longer appears in any machine-readable surface.
  • llms.txt status semantics fixed: unknown businesses return 404 and upstream failures return 503 instead of silently serving Amfion’s corporate map on a customer domain.
  • The security page’s tenant-isolation section was rewritten to state precisely what is enforced today and what remains staged work — including that row-level security is not yet a runtime backstop.
  • Security checks (dependency audit, container scans including the proxy image, SBOM, secret scan) now gate image publication instead of running only in a parallel workflow.

Agentic-browsing and dependency updates

  • PageSpeed agentic-browsing fixes: the marketing typing indicator gained correct ARIA semantics, and llms.txt became a proper Markdown map with absolute links — with CI now fetching every same-origin link so a dead link cannot ship.
  • Dependency wave: pino 10, vitest 4, dotenv 17, @fastify/cors 11, lucide 1.x, and grouped GitHub Actions updates — each merged only on a fully green check set.

Truth & indexability release

  • Fixed the www subdomain serving a de-indexed duplicate of the homepage; www now permanently redirects to the apex domain.
  • Truth audit of the marketing site: removed placeholder testimonials and unverifiable statistics, relabeled Twilio SMS as not yet available, and made the ROI calculator label its output as the visitor’s own assumption.
  • CI now crawls the fully rendered site and fails on broken canonicals, accidental noindex, invalid structured data, or structured data that advertises content not on the page — plus browser-level journey and accessibility tests.
  • Closed DNS-rebinding attacks on outbound requests: customer- and partner-supplied URLs are re-screened at the resolved address and pinned at connection time.
  • Published this changelog, the security page, and the about page.

Q&A-only partner catalogs

  • Partner catalogs can now be contract-restricted to Q&A-only knowledge, enforced server-side rather than by convention.

Exchange v1 (feature-flagged) and reliability hardening

  • Exchange v1: cross-partner service discovery with explicit opt-in, deterministic trust-aware ranking, geo constraints, and conversion attribution. Feature-flagged OFF in production while supply density grows.
  • A week of correctness hardening across booking confirmation, replay windows, idempotency leases, and lease takeovers — verified against the real database layer in CI.
  • Docker publishes are now cross-compiled; multi-hour emulated builds eliminated.

Gateway two-phase booking and transactional provisioning

  • Third-party AI agents now book through a prepare/confirm capability flow: single-use, expiry-signed tokens, server-stored arguments, and a database uniqueness guarantee that one capability can produce at most one booking.
  • Tenant provisioning became a single database transaction — a mid-sequence failure can no longer strand a half-created business.
  • Lead capture became exactly-once: duplicate submissions converge on the same lead and the same notifications.
  • Partner fleet API: directory search across a partner’s own businesses with policy-filtered visibility and idempotent lead routing.

Agent Gateway: every business is agent-bookable

  • Every Amfion business can expose a standard MCP endpoint: third-party AI assistants inspect verified business information, check live availability, capture leads, and book — under the same limits, deposits, and answer policies as the website assistant.
  • Discovery via /llms.txt and /.well-known/mcp.json on every business domain.

Verified knowledge and the internal scheduling engine

  • Knowledge trust platform: every fact carries an assertion state (unverified through verified) with source provenance; answer policies are enforced server-side and answers report the stored trust of what they cited.
  • Internal scheduling engine: businesses can take bookings without any external calendar account — weekly hours, group capacity, staff assignment, and database-enforced concurrency.
  • Google Calendar sync with busy-block awareness; revoked connections surface a reconnect prompt instead of silently failing.

Activation-first onboarding

  • Signup now takes a website URL and trains the assistant from it before the owner first lands in the dashboard.
  • Agent-directed website import: the extraction model chooses pages through a sandboxed crawler with strict origin pinning and budgets; nothing applies without owner approval.
  • The admin home became a milestone setup guide with a live assistant preview.

Lifecycle email engine, customer memory, and deposits

  • Lifecycle emails went live: waitlist slot-open backfill, booking reminders (off by default), rebooking nudges, and review requests — each send exactly-once, marketing kinds honoring suppressions with unsubscribe links.
  • The assistant now recognizes returning customers: linked sessions carry contact and coarse visit history.
  • Booking deposits through Stripe Connect: services can require a deposit; funds settle directly with the business.

SEE IT ON YOUR OWN WEBSITE · NO ACCOUNT NEEDED

See your front desk
before you sign up.

Paste your website and meet the front desk it would run — your prices, your hours, a sample calendar. Keep it, and it becomes your workspace: 14 free days, no card.

Prefer to start a free trial? Sign up here.