Every new feature of the platform with its date: what was built and where to find it.
From app to business
Inside every web project, above the composer: the road a business owner cares about — built, published at a link, found on Google, taking orders and payments (Paymob, Stripe and more, or WhatsApp), first visitors, own domain — each step ticked by what really happened, with one button for the next one.
Try it without an account
A visitor types their idea on the home page and watches the agent build it, with the live preview — before making an account. When they like it they sign up in a second and the project comes with them, open where they left it. Publishing, domains, payments and integrations wait for the account; there is a daily cap, two tries per device, a small budget of its own, and a try never turned into an account is deleted after a week. The owner switches it on and off in the launch checklist.
“Your data privacy” in account settings
keep your conversations always or for 1/7/30/90 days — anything older is deleted for good automatically (the agent's conversations in your projects, chats, the browser and desktop agents' conversations), at once when chosen and then every 6 hours; checkpoints and bills stay. With a written guarantee that nothing you write or build is used to train any model.
“Team policies” in the Team tab
the account owner sets once, for everyone working on their projects (account teammates and partners), who may publish apps and who may change secret keys (whole team or only them), and a monthly cap on how much of their balance each member may spend across all projects; the server refuses anything against them with a clear message (from the UI or the API), shows each member's spend this month against the cap, and every change is recorded in the activity log.
A public “Trust center” (/trust), linked from the footer
the platform's uptime as actually measured — the server records every minute it was up, any minute without a record counts as down — for the last 24 hours, 30 and 90 days, with every outage of 3 minutes or more, its time and length; published apps' uptime from the monitor's real visits. An SLA whose target and credit the owner sets on the same page, shown beside this month's figure. Checkable facts on data (no training, retention, Germany), protection (AES-256-GCM, scrypt, a container per project, backups), access (SAML/SCIM, roles, team policies, activity log), and who handles data from the same source as the privacy policy — and it says plainly there is no SOC 2 or ISO certification yet.
A “Workflows” tab in every project
draw the app's logic without code as a chain — a start (“the app or another service calls a secret link”, “every hour/day/week”, or “when I press run”) then steps in order, added with a + between any two and moved up or down: a condition (equals, contains, greater than…) that stops the chain when not met, an email from the app, a notice to you (bell, Slack, Telegram…), a web request GET/POST (guarded from internal addresses), or a task for the agent. Each step can use what came before ({{trigger.email}}, {{steps.1.body.id}}). The server runs it; every run is kept with each step's result and colours the chain (green/red/skipped), with a test run on JSON data.
Sign in with ChatGPT (SIWC)
“Continue with Infera Agent” on the ready-made sign-in pages of every app built on the platform: a visitor with an Infera account enters the app in one tap — a consent page on the platform says the app gets only their name and email, then they return signed in. Protected by a one-time code valid two minutes, a random value in a cookie on the app's address that must match, and a return allowed only to that app's own address. The app owner turns it on or off in the Users tab; people who used it carry an “Infera” mark.
AI answer engine check (AEO)
The website check now has a sixth section, “AI answers”, with its own score: whether robots.txt shuts out the ChatGPT, Claude, Perplexity and Gemini crawlers, whether there's an llms.txt, structured data (JSON-LD), clear questions and answers and a short summary — covered by the summary, the fix plan and the PDF report.
MCP connectors the agent uses
People add any MCP server (Linear, Notion, Sentry, Stripe or their own) by its address and key, and the agent gets its tools beside its own and uses them while building. Calls go only to public internet addresses (checked and pinned), the key is stored encrypted and never shown again, and replies are screened for planted orders and reach the agent as information. This is on top of Infera itself being an MCP server that Claude and ChatGPT connect to.
Team provisioning from Okta and Entra ID (SCIM)
The account owner makes a SCIM token in the Team tab and adds it in Okta, Microsoft Entra ID or OneLogin: people added in the company directory join the team as editors, and people switched off or removed there lose access here automatically. SCIM 2.0 (users, lookup by e-mail, update, deactivate and delete); the token is stored only as a hash and can be replaced or revoked in one tap.
Each user's data private by default
The agent builds the data of an app's users (their orders, notes, messages) as theirs alone from the start: an owner column, and every read, change and delete filtered by the signed-in user from the session rather than an id sent by the browser, tested with two accounts. The deep security scan now flags any change or delete by id alone. (This protection lives in the app's own code, not in Postgres RLS policies.)
Start a routine from GitHub, Slack or Jira
Every routine (a scheduled agent task) now has a secret trigger link: add it as a webhook in GitHub, Slack, Jira or Zapier and the agent runs when an issue is opened or a command is typed. What the service sends reaches the agent as fenced information, screened for planted orders — never as instructions; at most once a minute, and the link can be removed or replaced in one tap. Ready-made routines: “Fix GitHub issues” (the agent reproduces the issue, fixes it and pushes to GitHub citing the issue number) and “Slack requests” — run only when their link is called.
A documented API for automation
A REST API at /api/v1 with the same personal token: create a project from a description, follow the agent until it finishes, ask for a change, and publish — for customers' scripts, Zapier, n8n and CI. Described by an OpenAPI document and a /docs/api page with ready examples, limited to 60 requests a minute.
Italian, Dutch and Czech
The platform now speaks eight languages: Arabic, English, French, German, Spanish, Italian, Dutch and Czech — the whole interface and the public pages search engines read (/it, /nl, /cs), with each visitor greeted in their browser's language. Economical models in chat and support now type their answer live, word by word, like Claude.
Suggest an idea for the platform from Support
Support has an “I have an idea for the platform” button: the assistant understands the idea and passes it to the platform team's Future Lab (an idea several people ask for rises in importance), while problems still become tickets. The platform's owner is notified of each new idea.
A public “What's new” page
A public page in Arabic and English with every new feature, its date and where to find it, updated by itself from the build log (the owner's tools stay out), in the sitemap and linked from every page's footer.
The agent never follows orders hidden in what it reads
Everything the agent reads from outside (project files, a page in the browser, visitor data in the database, command output, logs) is checked: text that tries to give it orders (“ignore your instructions”, “send the keys to…”, in English and Arabic) is marked right there as data, not instructions, and the agent doesn't act on it; the owner gets a notice in Problems (the kind and the project, not the project's data). A standing rule: only the project's person gives orders.
An “Improve” button in the message box
turns a short description into a clear brief (screens, features, data, look, languages) before the agent starts; inside a project it sharpens a change request; “Undo” restores the original; charged like any AI call.
A “Project rules” tab in every project
the owner writes what the agent must always follow (brand and colours, language, tone, what never to change, naming) with ready starters; the agent reads them before every request, above its habits, and asks when a request conflicts.
Real photos in apps instead of placeholders
The agent fetches real, openly licensed photos allowed for commercial use (Openverse) into the app instead of placeholders, writes each one's credit to CREDITS.md and shows the author where the license asks; non-commercial ones are skipped.
A “Knowledge files” section under the project rules
upload the project's documents once (PDF, Word, Markdown, text, CSV, JSON, HTML, up to 25 files); they're read and cut into passages, and with every request the agent searches them, uses the relevant parts as the source of truth and names the document; scanned PDFs are read by the AI; a try-it search shows what the agent would find.
“Clone a site's design” on the home page
paste any site's link; it's opened safely (public addresses only), photographed on a computer and a phone, and read for its colours, fonts, button corners, section order and menu; one tap starts a project where the agent builds the same look and layout with your own content — none of their text, logo or trademarks.
“Notification channels” in Settings
every bell notice (agent done, app down, new lead, balance…) also goes to Slack, Discord, Telegram or a signed (HMAC) webhook that works with Zapier, Make and n8n; each channel picks its groups, has a test button, addresses and tokens are stored encrypted, and a channel failing 10 times in a row is paused and its owner told.
An “A/B tests” tab in every project
say what to try and what counts as success (a click on a button, reaching a page, or an event in the code), and the agent builds version B next to the current one; on the live app each visitor gets one version before the page is drawn (no flicker), and a view counts only once the tested part is on screen; each version's conversion rate with a clear statistical verdict (two-proportion test at 95%) and a notice when a winner shows; one tap has the agent keep the winner and remove the other from the code.
Email from apps with no account or key
every app has INFERA_MAIL_URL and INFERA_MAIL_KEY and sends order confirmations, receipts and notices to its owner, its signed-up users and addresses the owner allows — nobody else, so no spam — with a daily limit, a log of every message and a line naming the app; the building agent knows how to use it. The built-in sign-in now has “forgot password”: an emailed link valid for 30 minutes and once, without revealing whether an address is registered.
Google Account Sign-in
Sign in to the platform with a Google account (OIDC) from the login page; the owner turns it on in sign-in settings.
Large-scale Context Management
Long conversations with the agent are condensed automatically before they reach the memory limit; the agent carries on from the summary without losing the task.
The “Starter” plan is free
trial credits and one published project, no card.
Containerized sandbox runtime
Every project runs in its own container with memory, CPU and process limits and no extra privileges; web requests pass a guard against internal addresses.
RBAC + Audit Logs
Team roles (editor/viewer) on the account and on each project, staff department permissions, and an activity log of every important action with who and from where; an enterprise page (/enterprise) with a contact request, plus SAML, SCIM, team policies and the SLA.