Ballast 0.4.7-beta · Windows · invited beta
Ballast 0.4.7-beta — full update report
This update combines the unpublished 0.4.6 security candidate with subsequent improvements.
1
Referral statistics now pass an explicit server-side schema for both fresh responses and cached fallback: both counts must be nonnegative integers no larger than JavaScript can represent exactly. Invalid responses show unavailable counts or previously validated counts. Text-only rendering is retained.
2
The launcher verifies the server challenge and the signed ticket response before opening the browser. Spoofed health responses and a listener swap during the handshake fail closed. The reusable DPAPI launch key never enters HTTP, browser URLs or logs; one-use tickets expire after 30 seconds and cannot survive server replacement.
3
An optional Robinhood account referral link is available in System setup and the website setup checklist, with a reward disclosure and a reminder that account creation does not guarantee Agentic access or compatibility.
4
Reviewer and installation documents now identify this exact version. The evidence companion includes referral regressions alongside launcher checks; a release regression prevents stale document versions. Launch-key recovery and remaining local HTTP limitations are documented.
5
Finance keeps verified dividend rows, partial calendars and basic risk observations visible when another asset lacks research. Missing symbols and coverage are identified; incomplete data never becomes a zero dividend or a complete portfolio score.
6
System adds optional profit-to-core retention settings separately for paper and live. The feature starts disabled. Once explicitly confirmed, future positions capture the selected percentages and can retain more profit-funded shares while returning cash profit. Existing positions keep their captured behavior.
7
Retention uses confirmed executions and deducts reported costs after tax and income allocations. Stops do not graduate new shares to core. Paper settlement markers retain the exact order identity when concurrent live activity changes inserted IDs.
8
The website uses clearer heading typography and a detailed privacy page covering local storage, external services, choices and deletion. The release includes updated guides, walkthroughs and complete version history.
Installation and choices
The signed updater patches managed program files and preserves private data, settings, credentials, ledgers and STOP. Trading protection is unavailable during the brief restart. Existing live parameters and existing position policies remain unchanged. Reopen Start Ballast if a browser session needs refreshing.
Profit retention starts disabled. Review the separate paper/live profile, percentages and confirmation in System before enabling it. The displayed 40% is a review example applied to the remaining profit allocation after tax and core-income funding, not 40% of gross proceeds. Retained core has no ordinary automatic trading exits. Test paper behavior first.
Finance reports known values and missing coverage without inventing portfolio totals. Retry may recover unavailable research, but this update cannot guarantee a provider supplies it.
Verification scope and limitations
Release gates and exact-artifact regressions use synthetic data without broker calls or live orders. Final counts and signed inventory are in the matching reviewer evidence. Passing checks are not a safety certification. Windows Authenticode signing and independent clean-device acceptance remain outstanding. Same-user malware and existing-cookie exposure to a replaced local HTTP listener are outside launch-ticket protection.
Crypto execution spreads use confirmed effective prices; separately reported fees are deducted, but providers may not itemize every cost. Existing daily-bar backtests do not model the new retention policy. Paper results do not predict live outcomes. Partial Finance projections are estimates, not guaranteed payments.