New sign-in and service status

This release is about trust: how each person on your team signs in, how you know the service is working and how we protect the site. We redesigned sign-in end to end, published a standalone status page and strengthened the website's security.

Faster, more secure sign-in

The sign-in screen offers three ways in: Google, email or your company's SSO. It remembers the last method you used and notes it under that button, so your team signs in without thinking. The links we email no longer depend on the browser they were requested from: request one on your computer and open it on your phone. We removed passwordless magic-link sign-in, as it didn't offer the guarantees a CRM holding customer data requires.

Service status, in public

status.closeford.com shows the live status of the app, the database and sign-in. It includes uptime over the last 90 days, response times and incident history, and re-checks on its own while you keep it open. The website footer links to it with an indicator that changes colour if something fails.

Site security

We updated the framework to close a published vulnerability and added a Content Security Policy, which limits which scripts and resources each page can load. It's an extra layer of protection against code injection, with no visible change for your team.

  • StatusA status page at status.closeford.com, with uptime over the last 90 days, response times and incidents.
  • Sign-inThe last sign-in method is remembered and shown on the sign-in screen.
  • DocsLearn and the API and webhooks reference in the documentation.
  • WebA theme switch and the service status in the footer.
  • SEOA share image for every page, and a sitemap.
  • Sign-inSign-in email links work on any device, not only in the browser where they were requested.
  • Sign-inPasswordless magic-link sign-in is removed.
  • BookingThe booking page moves to /book/…; previous links keep working.
  • WebType, cards, buttons and fields unified across the site.
  • Sign-inAccounts with a workspace were sent back to the initial setup when signing in.
  • SecurityA published framework vulnerability, fixed with an update and a Content Security Policy.
  • APINew API keys start with cf_, and CSV exports download as closeford-….csv.