Ballast 0.4.0-beta · Windows · invited beta

Your rules. Your trades. Automated.All guidesDashboard & workflowsTry the bot free

Ballast 0.4.0-beta — full release report

Release date: September 17, 2026. This release is distributed to invited beta testers. Wider public availability remains deferred. Downloads require a valid invitation at https://ballastdigital.xyz/beta.

What this release changes for you

0.4.0 combines crypto risk and execution safeguards, private credential/storage improvements, managed background operation, authenticated signed updates, and a modular learning center. It retains the published 0.3.8 improvements described below. Your ledger and existing settings are preserved by a program patch.

Crypto stops and 48-hour re-entry cooldown

Previously, a stop based only on changing recent volatility could tighten after entry. A stop sale could also be followed by another purchase in the same cycle.

The automatic policy now compares recent daily ATR14% with the 90th percentile of daily ATR14% observations over 180 completed UTC days, requiring at least 90 observations for the historical baseline. It applies the configured multiplier and captures the resulting policy for the position. Later volatility declines or additional legs do not silently tighten that captured percentage. An explicit per-coin override remains an operator risk choice.

The dashboard identifies the historical/recent/fixed basis. Data gaps use the documented fallback rather than pretending history is available. An unusably wide modeled stop blocks new risk. Existing positions cannot reconstruct their exact entry-era historical policy; they capture a baseline on eligible evaluation. Existing operators review changed risk semantics before new crypto entries; exit evaluation continues. A wider stop permits greater losses and does not establish that a particular coin or the reported SKY trade should be held.

After a confirmed stop-loss sale, a persistent per-coin cooldown blocks entries, adds and pyramids for 48 hours by default, including the remainder of that cycle and later restarts. Paper and live cooldowns are separate. Submitted or uncertain orders are not treated as confirmed fills.

Execution and portfolio integrity

Durable pending intents precede live submissions. Confirmations must match the intended account and exact order ID/client reference. Queued, timed-out, partial or unidentified orders cannot become estimated completed fills. Ambiguity blocks duplicate submission across restarts and remains visible for reconciliation.

This does not complete every historical-ledger or crash-settlement recovery case. Do not clear a pending hold to retry. A symbol blocked by uncertain execution may also need reconciliation before another exit can be submitted. Broker executions remain the authority when resolving those records.

The release preserves account-scoped portfolio data, complete/partial marks, exit evaluation when new-entry inputs are incomplete, conservative sale sizing, protected owner reserves, settings snapshots and operating-cycle guards. Capital-plan review before Start/Run now and read-only ledger diagnostics remain. Historical diagnostics do not rewrite or certify old account attribution.

Quiet Windows operation and clear version identity

Normal launches, recovery and update helpers run without a flashing terminal. One hidden supervisor manages the dashboard; the listening socket is reserved before its scheduler starts. The title and System tab identify the version.

Closing the app window leaves the engine running. Managed Quit, Restart and Cancel wait for active work. Intentional Quit is respected by background recovery; explicitly opening Ballast resumes the application. Local exits cannot run while the application is stopped. The trading STOP file is separate from terminal quit intent, and a circuit breaker blocks entries while exits continue.

Automatic startup at Windows sign-in is optional and off on a fresh install. System can enable/disable it and replace/remove legacy registrations. Windows permission failures are reported so an old recurring task does not silently remain registered.

Signed updates and versioned downloads

Eligible public or invited-beta updates offer a popup with version and changes, Update now and Update later. System retains the update action. Invited beta access is checked server-side; a claimed User-Agent is not authorization.

Archive filenames and link labels include the version. The app verifies an Ed25519-signed manifest using its pinned key, plus archive and individual file hashes. It rejects unsafe archive paths, Windows filename aliases, corrupt or oversized archives, unsigned releases and downgrades.

Dependencies and an isolated import check are prepared before shutdown. Update maintenance patches changed program files, preserves private state, and records rollback copies/journal. The candidate's health/version is checked before maintenance ends. Failure can restore the program/environment; uncertain recovery requires inspection and must not overwrite newer trading records.

This is patching in place with a full archive download, not replacement of your private account or a binary-delta download. Older unsigned clients need a trusted manual upgrade once. Old installations do not update merely because a release is published. See UPDATING.md for maintenance and recovery boundaries.

Dashboard and credential security

Untrusted news, broker, AI and user strings are escaped for their actual HTML, JavaScript-argument or URL context. Hostile rendered-payload tests cover repaired injection paths, including preserved Finance/research screens.

Private local APIs require a launcher-established session. The launch secret is DPAPI-protected, exchanged from a cleared URL fragment and kept out of query/log strings. HttpOnly/SameSite cookies, exact Host/Origin checks and a separate mutation token protect the loopback dashboard. Session expiry requires reopening from the launcher. This is a local Windows application, not a publicly exposed multi-user web service.

All saved provider credentials, including the eight news-provider key paths, use Windows DPAPI. Legacy plaintext database values, OAuth token files and supported environment-file credentials migrate through the protected store. Token response bodies are no longer written to OAuth debug logs. Unsupported credential protection fails closed instead of saving plaintext.

New private storage defaults to the local Windows profile. Existing ledgers remain in place until the explicit System migration verifies the copy and restarts with STOP engaged for review. Original files are preserved. The financial database itself is not fully encrypted; private filesystem access still matters. Encryption cannot remove old cloud versions, logs or backups; review those and rotate previously exposed keys when applicable.

Runtime, test, bootstrap and audit dependencies are pinned, including transitive versions and artifact hashes. Packaging requires a fresh known-vulnerability audit tied to those exact locks, plus source and archive privacy scans. Passing checks do not prove absence of unknown vulnerabilities or guarantee antivirus silence. Windows publisher signing and external compliance evidence remain separate public-release obligations.

Modular onboarding and patch education

Guide is now a selectable course: 8 modules, 24 lessons, about 67 minutes in initial estimates. Each lesson/module and the whole course show completion and time remaining. Choose the topic you need; only explicit completion marks it done. Stable lesson IDs preserve progress, and changed lesson revisions can require review again.

Optional timing feedback refines estimates in your local profile. It is not automatically collected from or shared with beta testers. After an upgrade, a popup summarizes changes, links this report and offers critical-change lessons. Tutorial completion does not activate trading, accept Terms or acknowledge a changed risk policy for you.

Published 0.3.8 improvements retained

preserve account/cache separation and label freshness/partial information. Options execution remains disabled; existing uncertain intents remain visible.

ledger readiness surfaces attribution/reconciliation gaps without rewriting.

category identifiers correctly, and includes all list members.

The bounded quote-clock allowance does not relax stale-quote limits.

safeguards and settings/cycle protections remain part of the combined release.

Release discipline and next steps

Full release history and user documentation are available at https://ballastdigital.xyz/releases/ and https://ballastdigital.xyz/docs/. Registered testers receive operational release notices separately from the optional marketing list. Notices respect update suppression; each release also sends a separate owner copy. No recipients are exposed through CC.

README contains current version and comprehensive recorded history, including explicitly labeled local review builds. Maintainers must update history, tutorials, privacy/security evidence and release reports for each version. Packaging now requires a reviewed published-source baseline and current file hashes so missing earlier improvements cannot be hidden by a version bump.

For your review: confirm the title version, read the release popup, explore Guide, check System's startup/private-storage preferences and review the crypto policy if prompted. Preserve your preferred trading settings; do not use live orders as a feature test. Report issues with version/time and redacted details.

Public-release readiness still requires documented provider/data rights, publisher trust, production access controls and legal/privacy review. Separate experimental order-recovery, website and onboarding branches are not part of this release unless explicitly integrated and tested. See PUBLIC-RELEASE-READINESS.md for the maintained external checklist.