1.13.0 2026-09-08
Added
- Where your connection sits relative to the places Helix measures from. The Overview now ends with both Helix measurement points — Falkenstein and London — with their round-trip time and loss updating live and both plotted on one graph. The rankings you read on NETStats are taken from these two boxes, and this is how far your line is from each of them. They are named by city, because a city has a distance you can check the number against.
- Per-application usage over time. The applications table answered for the last five minutes and nothing else; it now defaults to the last six hours, with a day, a week and a month beside it. Live stays first, because it is the only range that can show each application’s share of the total — a share is measured against the interface counter for the same window, and past windows do not keep one, so the historical ranges show an em dash there rather than a figure nobody could check. All of it stays on your machine, and it is deleted after thirty-five days.
- A hop that answers from more than one router shows all of them. On an equal-cost path the router that replies is whichever one the traffic hash picked, and the tables used to print the first with a count of the rest — "ECMP ×2" — which said there were others without saying what they were. Every responding address is listed now, each with its own name, on all four screens that draw a path. Saved traces keep them too, so the report you send an ISP carries what was on screen.
- Every hop on a path says what it is called. Reverse DNS runs alongside the network lookup that was already happening, so a hop reads as its own name where it has one, with the address a hover away. The name is often the only thing that says where a hop is: an AS number and a country cannot tell two cities of one carrier apart.
- Helping decide which hosts are worth measuring. Once a day Helix sends a list of the services this machine moved the most data to or from — a domain such as
example-cdn.net, or a network block where no name answers. Nothing else goes with it: not which application, not how many bytes, not when, and not individual addresses. A service is only counted once at least five separate machines have named it, and services that moved very little are left out entirely, which is the part that keeps the list from describing you: the unusual services are almost always the small ones. This is on, and turning it off is one click — Settings has a section of its own for it, What this machine shares, which states what is being sent before it offers the switch and says plainly when the machine is contributing because nobody has been asked rather than because somebody agreed.
- How a host has been behaving, on the rankings. For any ranked target: which way its round-trip time has been moving, which days were unlike the rest, when its level shifted, and — the one that matters — whether its bad days were its own or shared with everything else measured beside it. There is deliberately no forecast: a predicted figure is not a measured one.
- The Web Checker: ask a destination that ignores pings. Large services routinely answer no ping, which makes a path walk end in silence and says nothing about whether the service is up. Tick Web Checker on a trace and every round also asks the destination over HTTPS and HTTP, reporting what it answered with the response time, average, best and worst — on a line under the hop table, in the same columns, so you can read the service against the last hop straight down. It reports the service, not which hop a connection reached, and says so: per-hop attribution is not possible on Windows without bundling a driver that may not be shipped, and a column that cannot answer would be a number with nothing behind it.
- Internet Metrics: how far away the internet is, from your line. A live board of the services most people actually use — resolvers, search, AI assistants, meetings, social, news, vendors — each with its round trip as a bar you can compare across the whole board, lowest first. Hovering one gives the current, average, lowest and highest reading and how many probes are behind them. Beside each bar sits the same host measured from Helix’s own probe boxes, which is the point: slow in both places means the service is slow, slow only from here means the path is. It lives beside the Link Matrix, which answers the neighbouring question about your own connection.
- A destination that answers no ping is asked again while you watch. The standalone check sends its own echoes alongside the connection attempts rather than trusting the walk that just finished, so a host that dropped packets during a bad thirty seconds is not described as filtering them for as long as the report is open. It reports three states, not two, and where only some echoes come back it says the path is losing them — from one end of a walk there is nothing to separate that from the host dropping them, and the host is the party with no chance to answer back.
- A dedicated health view for the platform operator. Whether the cloud tier is well, and whether each measurement point is still measuring, in one place. It reports ages rather than verdicts — agents batch their uploads and the daily rollup re-computes three days, so a box a few hours behind has lost nothing — and each state says which threshold was crossed and what it costs. It also tells apart a measurement point that has stopped from one that was never finished being set up, which used to look identical.
- A way to sort out an AS number that is already registered. If registration says your AS number is held by somebody else, or you have lost access to a registration that is yours, there is now a form for it on the sign-in page rather than an instruction to find an email address. The refusal opens it for you with what you typed already filled in. It goes to a person, it changes nothing on its own, and re-sending it adds to the same appeal rather than opening a second one.
- Providers can see which of their own service IDs are sharing. One row per connection whose subscriber turned sharing on, keyed by the account number the provider issued themselves. Subscribers who run Helix on that network and have not shared are counted and never named — the count is there so a short list does not read as everybody, and they are not named because that would report somebody’s decision to the party they declined. It is not a list of machines, and there is no device, hostname or address in it.
Fixed
- Five hosts that never answer a ping are back in the agent packs, and no longer read as your line losing every packet. Netflix, PlayStation, Nintendo, Epic Games and Slack serve the web perfectly and answer no ping at all, so a sweep used to score them at 100% loss — false about your line rather than true about theirs. The packs now know which of their hosts do that: those rows check the service over HTTPS instead and read "serving, answers no ping" with the response time, rather than a loss figure the measurement never earned.
- Signing in said "connected" while the app still said "sign in". The browser pairing finished and started uploading, but never actually recorded the account: the app went on showing "local only", and restarting the service dropped the connection entirely without saying so. Pairing now stores the account the same way pasting a token always has.
- DNS never finished measuring. The resolver row on the Link Matrix sat at "gathering, 6 of 20 probes" for ever, because each check replaced the previous count instead of adding to it. It adds up now, and the level scores.
- The Link Matrix shows what each level was measured from — every host, with its own probes, losses and median, under the bar it contributed to. Those figures always existed; only the summary ever reached the screen.
- NETStats works without an account. The rankings are public and need no sign-in. The page says which host it read them from, and that nothing about your machine is sent to fetch them.
- The public rankings page rendered its own explanation unstyled. The box that says why nothing is ranked yet used a style name that exists nowhere, so it appeared as bare text on the open web.
- Paragraphs use the width they have. The line-length work in 1.12.0 was applied too tightly: notes inside wide cards were held to about a third of the space available. Long-form reading keeps its measure; a one-sentence note in a card no longer does.
- Three smaller layout faults: the responsiveness figure overlapped the ring drawn around it, the live charts ended before the description beside them did, and an operator name ran into its AS number on the rankings table.
Changed
- Text uses the full width of what it is in. Paragraphs across the app, the console and the site were capped at a reading measure, which left narrow columns in wide cards; the caps are gone and the hero on the Internet Monitor page is laid out across the page rather than beside its illustration.
- Both sites say what may be indexed. The console now serves a sitemap and refuses indexing by default for everything that needs a session — password reset, pairing and the operator console were all previously crawlable. The public site gains structured data and richer link previews. No page carries an invented change date: a sitemap timestamp is a claim about when content changed, and the only date a build knows is its own.
- The mean rating sits with your provider’s name, as a pill beside the AS number and country, rather than in a column of its own. What the figure is made of is still printed beneath it.
- NETStats is linked from the Internet Monitor page and the home page, not only from the product menu.
1.12.0 2026-09-07
Added
- Your router, named. The devices list under System can now say what a device is, not only who made it: a product family, where its settings page usually lives, and whether it is the kind of unit an internet provider hands out. Two sources answer, and the app always says which — a curated Helix catalogue entry, or a language-model suggestion that is labelled unverified and names the model that made it. Only the vendor prefix of an address is ever asked about, and the question is asked by the service on your behalf: your MAC addresses, your IP addresses, your hostnames and how many devices you have never leave the machine. The deeper lookup is its own separate button, so it only ever happens because you pressed it.
- NETStats folds itself. The rankings pages had the fleet, the scoring and the public read, and nothing writing the daily rollup they read. Vantage points are now enrolled, weighted, retired and folded from the operator console, and their ordinary measurements become the daily rows the rankings are computed from — a vantage is still just an enrolled agent with a flag, with no separate credential and no separate wire.
- Feedback is a conversation, and somebody answers it. "Report a problem" used to send one message into the dark. It is a thread now: you write, Helix replies, and the reply arrives where you asked — in the app, in your account online, or in the ISP portal. The desktop flashes the tray when an answer lands, even with the window closed. You can attach screenshots on either side of it, up to three at a time, and both sides get an email when a message arrives — a notice saying what arrived and where to read it, never a copy of what was written. This is still not a support ticket: it goes to the people building Helix, never to your ISP, and there is no clock on it.
- NETStats: global host rankings. A new page on the desktop, the console and the website, ranking the hosts the internet runs on from vantage points Helix operates. Five weighted components you can re-weight yourself, counts beside every figure, and a host measured from too few places is listed with the reason it is not ranked rather than given a number nobody could defend. Subscriber measurements are deliberately not in it.
- Sign in from the top right. Connecting an account was reachable only from Settings. The button starts the same browser pairing the service already owned — so the desktop never sees a credential, whether you use Google, a Helix password or a Helix NMS account — and the menu links out to the website and to Helix AI Studios.
- The Overview says what it is measuring. Each live strip now leads with who runs that address: the operator, the AS it is announced from, its country, what the address is for, and why this product watches it. The gateway strip shows your own router — its vendor, and whether this machine reaches it over Wi-Fi or a cable, read from the OS rather than guessed from an adapter’s name.
- A LAN devices list, under System. Every device this machine has already resolved: address, MAC, hostname, vendor and link, with the router first. Nothing is scanned — it is the address table Windows already keeps — and the list never leaves the machine. An optional toggle, off by default, says when a device joins.
- The Workbench is now MTR Trace -- in the rail, on the page and in the Live Path pointer. The name says what the page does.
- A multi-tab MTR Trace, every tab its own session. Each tab is an independent MTR session the service starts, tracks, re-walks (non-stop) and lists; two tabs at one host are two walks; Stop on a tab stops that tab; closing a tab stops its walk; leaving the page and coming back finds the tables intact and the walks still going, and an app restart re-attaches to whatever the service is still walking. The idea of attaching to a run something else started is retired.
- Hop tables fill hop by hop. The service reports each hop the moment its probe lands, inside the round, and the round’s frame follows with the operator names. A path with a silent router used to show its first row only after that router’s timeout.
- Ping boxes are remembered and re-attached from the service’s own list of running boxes, so a box left running on another page can be seen and stopped again.
Changed
- Small text is bigger, and prose has a line length. The bottom of the type scale was carrying more of the product than the body size was, across four steps where two were nearly the same size. It is re-cut so every step has one job, the smallest text on any screen went from 10px to 11px, and notes and explanations moved up a step to where sentences belong. Paragraphs no longer run the full width of whatever card they sit in — a long line loses the eye on the way back to the left, and this affects all three of the app, the console and the website. Dark mode gets slightly more air between lines and letters, because light text on a dark ground reads heavier at the same size.
- The apostrophes are typographic now. Sixty-eight of them, plus seven quoted phrases, were still typewriter marks in shipped text across the app and the console. Quoted phrases in the app’s own screens are now checked too, which the first pass had left to the author because it could not tell copy from code.
- The Overview is a living instrument. The responsiveness score is drawn as well as printed: a ring sweeps to its value on first paint and re-sweeps when the score changes, in the number’s own grade colour. Every hero figure rolls to its next reading instead of jumping, the hour-sparklines draw themselves in, the identity band carries a heartbeat that beats once for every probe that lands (and in the down colour for one that does not), and the live strips stream: a fixed window of real time glides past at probe cadence, so the newest sample enters at the right edge rather than the whole picture stepping once a second. Nothing is interpolated or invented; under reduced motion every movement is a cut. The "canonical · closed 1-min windows" caption became the tile group’s name.
- The Link Matrix measures every level on its own, from the moment the service starts. The ISP-gateway level -- "measured by path walks" and otherwise absent until now -- is fed by every path walk that finishes anywhere in the service: the startup sweep, any pack, the Workbench, the scheduled trace, and a short unattended walk the matrix now runs for itself every five minutes. It takes the first public hop that answered; loss that stops at a rate-limiting router is not charged to it. The resolver check runs every five minutes (was ten).
- The Agents cockpit updates in real time. Hosts finished, the phase word and every cockpit figure move the moment a host completes, with a one-second reconcile while anything is running; the page’s own text says what the agents now do. The saved-workflows card and the DNS checker are gone from the tab (the resolver check still runs by itself for the matrix).
- Every workflow has its own Stop, and the global Stop is gone. The topbar’s "Stop all" is removed. A path tab stops its own walk, a ping box its own echoes, and the Agents tab’s "Stop all agents" stops every agent in flight and nothing else -- then offers "Resume" to run exactly those agents again.
- Diagnose stage results are hairline rows and the verdict is a section of the page rather than a card in a card; the Workbench legend is one wrapped row and its hop rows are shorter.
Fixed
- The alert rule dropdowns on Usage could not be clicked. A charting library bundled for the same page defines a class by the same name as the one those controls used, and its rule made them invisible to the mouse and stacked them on top of each other. Choosing a metric or a comparison for a rule was impossible. Renamed, and the row lays out correctly again.
- Three tables had a column under the wrong heading. On the LAN devices list, the Workbench and NETStats, one cell in each row had been styled in a way that quietly removed it from the table — so every column after it shifted one place left and the last heading sat above nothing. On the LAN list that meant "last seen" was printed under "Link". Found by measuring the rendered pages rather than reading the stylesheets, which is also how the next two were found.
- Long paragraphs are capped everywhere now. Nine places across the app, the console and the website still ran prose the full width of whatever box it sat in — the worst was a diagnosis verdict at 189 characters a line, on the one panel asking you to follow an argument. A line that long loses the eye on the way back to the left.
- Some form fields were smaller than the ones beside them. Text boxes written without an explicit type — including several on the operator’s release panel — were missing the house styling entirely and rendered 16 pixels shorter than their neighbours in the same row.
1.11.0 2026-09-05
Added
- A change of link is a network change too. Moving from Wi-Fi to Ethernet through the same router -- same gateway, same provider, same address -- now flashes the tray and shows the card ("Now on Ethernet 2 -- a different link, same network"). Nothing about the connection’s identity moves.
- The Agents cockpit moves. Click a running sweep in the launcher and its row morphs into its card; open a host and its row grows into the hop list. The figures on the cockpit strip roll to their next value instead of jumping, the progress bars settle instead of stepping, the all-sweeps strip stays with you as the page scrolls, and under each running agent a wire strip draws every round as a tick, one lane per host, red where the destination lost the echo. Every motion respects the reduced-motion setting.
- Agents: one row per host. While a pack runs, each host’s row carries its round, its own progress bar and, opened, its hop list as it fills. The cockpit strip says how long the slowest path has left. The second list of the same hosts beneath the card is gone.
- Usage: applications and hosts as a pair of tabs, so the page is no longer two wide tables stacked.
Changed
- The three sweep buttons are one row; their explanation is on hover.
- One card-title size across the desktop, and the ping frame presets, the settings switches and the hosts grouping share the segmented control.
- One text field and one table header across the desktop: every input and select shares a ground, an edge and tabular figures, and every hop, host and system table carries the same small uppercase header -- the Workbench’s was the one Title Case header on the app.
- One button and one segmented control across the desktop: the troubleshooter’s tabs, the usage ranges and the attribution tabs share a shape, and the speed-test, consent and copy buttons are the house buttons.
Fixed
- Releases register within a minute of publishing, and cannot be rate-limited into not registering. The cloud learns the newest release from GitHub’s own redirect (no API quota) and asks the API only for a release it has not seen. The two-minute API poll that 1.10.1 shipped with hit GitHub’s unauthenticated limit within the hour and answered 403 on every tick; cloud-side only, nothing to install.
1.10.1 2026-09-05
Changed
- Updates arrive faster. The service checks for a new version every minute instead of every three, and the cloud notices a published release within two minutes instead of ten -- a fix now reaches a running machine in about two minutes from publish, under five at worst.
1.10.0 2026-09-05
Added
- A startup sweep. Thirty seconds after the service starts it runs the Quick sweep once -- resolvers, Google, Meta and social -- so the Agents page has a picture of the line before anyone presses anything. It stands down if a sweep is already running.
- Ping shows the TTL each reply arrived with, beside its round-trip time -- distance in hops, read off the packet.
- The installer downloads under one name,
HelixInternetMonitor-Setup.exe, whatever version it carries. The version is in the file’s Properties and on the download page beside its checksum.
- Every network change flashes the tray icon -- a different provider, a new public address, or a different gateway (another Wi-Fi network, a VPN taking the route). The card that comes with it can be switched off in Settings > Notifications; the flash cannot.
- Colour-coded readings on hop tables and ping rows. Worst round-trip, jitter and loss on every hop, and each ping reply, carry a glyph, a colour and a word on hover saying what the figure was judged against -- always the line’s own baseline, never an absolute scale.
- The Agents cockpit. A running or finished agent opens with a strip of live figures -- hosts finished, paths measuring, echoes lost, the slowest hop by name -- and the per-host live paths fold beneath it. The sweep launcher carries the same strip across every sweep in flight.
- Custom packs have their own tab under the Troubleshooter.
- Usage opens with six counts -- today, 7 days, 30 days, the busiest quarter-hour, upload share and the busiest application -- above shorter charts.
- The Overview leads with Cloudflare, above the gateway, and its hero is one row: six tiles including the slow tail (95th percentile) and the probe count behind the figures. The live strips sit about 100 px higher.
- Light is the default theme on the website too, matching the app and the console; dark stays one toggle away.
Fixed
- Running agents show their rounds, not "starting…". A pack’s row only moved when a whole host finished, and a host takes about a hundred seconds, so every sweep looked stuck for its first two minutes. Rows now read the host and round in progress with a real progress bar.
- Stop All marks every running sweep "Stopping…" at once, and a row that says "Stopping…" stays that way until the service confirms the stop -- it used to flip back to "Stop" a second later.
- Usage history drew no bars for the day. The "Today" view asked for one-minute detail, which by afternoon is hundreds of bars thinner than a pixel. It now shows fifteen-minute bars.
- Hop tables no longer print an operator’s name twice ("X LIMITED - X LIMITED") on the Agents, Workbench and History pages.
1.9.0 2026-09-05
Added
- A Ping page. A shell of independent ping boxes, each with its own host, a count or continuous choice, an interval, a frame size (with the common presets, 32 bytes to a full 1500) and a "don’t fragment" switch — the path-MTU probe: a frame too big to pass a hop whole comes back as too big rather than as ordinary loss. Boxes run side by side, so the same host at two frame sizes is one click apart. Loss is shown as counts until 300 echoes, then as a rate.
- Custom packs can be edited, and run. Your own host lists — saved on this machine, validated as you save them, run and stopped like the built-in agents, with the same live progress. (The saving half had shipped in 1.8.0 with no screen for it; and a saved pack could not be run on demand at all, nor did a "continuous" one ever run twice.)
Changed
- One reading, not two. The Home / Operator switcher is gone from the desktop. The app always shows the fuller view: live strips first, every probed target, raw figures. Nothing was gated behind a mode; nothing is now.
- A cohesive, more compact desktop. One button system, one pill, one set of radii, status words on their own inks, inset panels that are visible in the light theme and not solid slabs in the dark one. Ten colours and sizes the stylesheets had been asking for that were never defined — square notice cards, a black spark baseline, a Stop-all hover you could not read — are defined now, and a test refuses the next one.
- Stop means stop, and says so. Every Stop reads "Stopping…" the instant it is pressed and settles on a final stopped from the service, not a guess. "Stop all" no longer restarts a continuous agent a minute later, and the Workbench’s Stop-then-Run somewhere else actually stops the first trace (a race left two walks running).
Fixed
- Nothing queues, and nothing says it does. The Agents tab’s "queued · next" labels described a waiting line that no longer exists; a running agent whose first host had not finished read as queued. The Workbench refused to trace while any agent was sweeping; it now paces through the same traffic governor the agents use.
- The per-agent "Continuous" checkbox never re-ran anything. It does.
- A host another agent was already measuring was reported as "not reached". It now says covered by another run — neither reached nor unreached.
- Settings said to download and run the installer yourself. The service installs updates in the background and has since 1.2.0; the page now says so, and links the page that exists.
- Connection errors were invisible on the Account page (they showed only inside the folded "paste a token" section), and there was no Disconnect without opening it. Both fixed.
- The Live Path panel was unreadable during a sweep — it drew every host’s rounds interleaved. It follows one path to its last round now.
- The Workbench’s service-tools card showed the previous host’s result under the new host. It clears when the host changes.
- The topbar’s run count and the System page counted one sweep and invented a queue. Both count every sweep and every ping box.
- Two more. A stopped-and-restarted ping box could become unstoppable (a stale "finished" removed the new box’s stop handle); and looking up a host name for Ping, the service tools or a custom pack could stall every measurement for seconds when the resolver itself was down — exactly when you would reach for those tools.
1.8.1 2026-09-04
Fixed
- "Stop all" now actually stops everything. With several troubleshooting agents running at once, the panic button (and the Agents tab’s own "Stop N running") cleared what the screen showed without stopping the agents underneath — so running a sweep again right after queued behind hosts that were never released. Both now stop every agent that is actually running.
- Every running agent shows its progress, not just the first one. With several sweeps going at once, only one card ever showed its live hop-by- hop detail and progress bar; the rest sat looking idle even while measuring. Every card now shows its own.
- A card’s Stop button no longer stops every other agent too. It now stops only the one you clicked.
- The live path view for a ten-host agent no longer looks like a garbled mess. Columns now line up consistently row to row, host to host, instead of shifting with each hop’s provider name.
- The Workbench no longer makes you wait to trace a different host. Typing a new host and pressing Run now switches immediately — no more Stop, wait, then Run.
1.8.0 2026-09-04
Added
- Run every troubleshooting pack at once, honestly. Sweeps no longer queue behind each other — the serial limit existed only because concurrent runs used to rate-limit each other at the shared early hops and blame your own ISP for loss the measurement itself invented. That problem is now solved properly: every host walk starts on the same measured spacing a single pack always used, and a host already being walked by one sweep is never walked twice by another. The Agents tab opens with Quick, Standard and Full — each a superset of the last — and shows one row per sweep in flight with its own progress and its own Stop.
- Name your own hosts to watch. Save a list of hosts as a pack of your own, run it on demand or continuously, and it behaves exactly like a built-in pack — without ever becoming one of the fixed target lists the app ships with. Every host is checked when you save it, so a typo is caught in the editor rather than failing mid-sweep.
- The Link Matrix’s DNS level fills itself. It used to read "runs with the resolver check" until someone pressed a button; the service now keeps it current on its own, every ten minutes. Every level’s figures are compact chips now — loss, probes, median — with a pulsing badge while a level is still gathering its first readings.
- The live bandwidth chart opens already full. It used to draw an empty plot that took three minutes to fill, even though the service had been measuring the whole time your window was closed. It now opens with the last three minutes already on screen.
- The Workbench remembers where you’ve been. The host field is a search box over your own history now, ranked by how often and how recently you’ve used each one, filtered as you type.
Improved
- A provider’s name reads once. "Safaricom Limited - Safaricom Limited, KE" now reads as "Safaricom Limited" — on the desktop’s connection identity, in the Workbench’s hop table, and on the console’s Home page and provider-claim screen. Where a provider’s handle and its proper name differ, the proper name wins.
- Every page in the console has a clean address.
/portal, /admin, /pros, /claim and /pair no longer show .html in the address bar — nor does anywhere they’re linked from. Old links you’ve already bookmarked or been sent still work.
- Loss counters stay readable at any size. A running total past a thousand now compacts (
46.6K) instead of growing a digit at a time; the exact figure is always one hover away.
- A simpler provider identity band. The row of three verdicts that only restated the mean rating beside them is gone; the mean is still computed from the same three ratings underneath.
Fixed
- Browser pairing and provider claims rendered nothing at all. Since the browser-pairing feature shipped in 1.7.0, both the pairing page and the provider-claim page have failed to render for every single visitor — a placeholder that said "Reading the code…" and never progressed. Anyone who tried to connect a computer with a browser, or accept a provider’s claim, could not.
Added
- The Helix Link Matrix. A new page that reads your connection as five levels — your LAN, your ISP’s gateway, DNS, nearby content and the international haul — each scored live from the measurements already flowing, with one overall figure weighted across whatever has been measured so far. It starts speaking within the first minute of the service running, and a level that cannot score yet says why instead of showing a dash. Every score carries its probe counts, because a figure without its sample is one nobody can check.
- Connect with your browser. Linking this computer to your Helix account no longer involves copying a token: click Connect, sign in the way you already do (Google included), approve the computer by name, and the agent does the rest. The old paste-a-token path is still there, folded away, for machines where a browser is not an option.
- Your provider can ask, and you decide on this screen. When an ISP or reseller you buy from claims your service ID, the request appears as a card in the corner of the app — who is asking, their support contacts to check out-of-band, and Accept/Decline. Accepting connects the line you actually measure; declining tells them only that the code was used.
- Messages from the operator. A short notice from the Helix operator (planned maintenance, a heads-up) can now appear as a dismissable card. It is plain text in a fixed frame — it cannot carry links or buttons, by design.
- Report a problem. Settings → About now has a feedback box: a sentence about what looked wrong, optionally with your latest diagnosis report attached so we can see what the agent saw. It goes to the people building this, not to your ISP.
- A System panel. A task-manager view of the agent itself: the service, every worker it runs (probes, sweeps, diagnosis, DNS, speed test, cloud sync, updater, pairing), what each is doing right now, and the run queue.
- Continuous sweeps. Each troubleshooting pack now has a Continuous toggle: when its sweep finishes, it queues again a minute later, along with the resolver check. Sweeps still run one at a time — parallel sweeps would measure each other.
- Helix infrastructure as a benchmark. The server this product’s own cloud runs on is now a measurable target, addressed directly by IP so the reading is the real path to our machine, not a CDN edge in front of it. If your line is fine and this path is not, the fault is ours.
Improved
- One diagnostic, shown everywhere. If a host is already being measured — by a sweep or another page — the Workbench now attaches to that live stream instead of launching a duplicate run at the same target, and its Stop button stops the run that actually owns the stream, saying so before the click.
- Every connection to the cloud rides one hardened channel. All agent-to-cloud traffic now goes through a single TLS-only transport: plaintext addresses are refused when entered, not discovered failing later, and a redirect can never downgrade the connection mid-flight.
- VPN awareness. When a tunnel adapter is up, the app says your measurements may describe the tunnel rather than your line — named as an observation, never guessed as a verdict.
1.6.0 2026-08-26
Added
- A proper application shell. Everything that tells you where you are now lives in a slim column down the left — Overview, Live Path, Workbench, Diagnose, Usage and Settings, grouped by what you are trying to do rather than listed in a row. The bar across the top is reduced to what it should have been all along: on the left, what your connection is and whether Helix is watching it; on the right, the handful of controls that change how the app looks and behaves. Nothing was removed — every page and every control is still there, and the panic "Stop all" button is still one click away from any screen.
- A map for the Agents page. The troubleshooting agents used to be a long unbroken scroll. There is now a summary at the top — one line per group, what it last found, whether it is running — and a button beside each that jumps you to it.
Improved
- The diagnosis leads with its answer. When a full diagnosis finishes, the verdict, its evidence and what to do next are now the first thing on screen. The eleven steps it took to get there fold away underneath, one click from view. Nothing about the evidence changed — both the supporting and the contradicting columns are still shown in full, always.
- The Usage page is one workflow. Alert rules have moved out of the narrow side column, where six fields never fitted, into the main column with room to work. The side column now shows your data quota alone, and both the quota and your alert rules refresh on their own instead of going stale while the page is open.
- Live Path gives the path the room. The list of routers between you and the internet — the part carrying the verdict about where trouble starts — now takes the wider half of the screen. With no trace running the page no longer draws an empty chart with nothing in it.
- Settings without dead ends. Two sections existed only to tell you something had moved elsewhere; they are gone, and what they pointed at is where you would look for it. The About section separates into three plain subjects: what is running, updates, and crash reports.
- The app fits smaller windows properly. Every screen was re-measured at common laptop sizes and at the smallest window the app allows, and the layouts now reflow against the space the content actually has rather than the size of the window.
Fixed
- Data volumes on the Usage page are consistent again. The "Where it went" table was counting in a different unit system from the rest of the page, so the same traffic could read as two different numbers. It now matches everything else — and the way your provider bills you.
- A colour that was too faint to read. The live download figure and the speed-test direction arrows were drawn in a colour tuned for chart lines, not for text, and in the dark theme it fell just below the readable standard. Both are now a shade deeper, and still match the lines they describe.
- The About section could fail to appear. If the service did not answer the update question, the whole section vanished instead of showing what it knew. It now says what it is waiting for.
1.5.0 2026-08-26
Added
- Every figure now shows its last hour. The four numbers at the top of the dashboard — latency, jitter, loss and call quality — each carry a small chart of the past sixty minutes underneath, so you can see at a glance whether the number you are looking at is normal for your line or something new. A steady line means steady; for loss, a flat baseline means an hour was measured and nothing was lost, and small bars count the probes that were — counts, not percentages, because a percentage of a minute’s dozen probes would overstate what one dropped packet means.
- Your score, once and properly. The connection score used to appear twice on the dashboard — once small, once in a card of its own further down. It is now a single large figure beside the speed dial, where it belongs, and the page is shorter for it.
Improved
- Easier to read, measured rather than promised. Every screen in both the desktop app and the web console now passes the WCAG 2.2 AA contrast standard, checked by an automated measurement of the rendered screens — including the translucent glass surfaces, which is where most of the shortfalls were hiding. Status labels, badges and the remote support consent button are all a shade deeper and easier to read, especially in the light theme.
- Panels that keep up with you. The Troubleshooter’s past-diagnoses list now stays in view while you scroll through a long report, the same way the Usage page’s quota panel already did — and both now step aside correctly on narrow windows instead of pinning to the top.
- Tidier spacing and type throughout. Both apps’ styling was measured against the design system and 127 stray values were brought onto the scale — the layout rhythm is now consistent everywhere, and the compact density setting reaches panels it previously could not.
1.4.0 2026-08-25
Added
- See how your line compares. Your dashboard now shows what your connection actually delivers next to what other Helix subscribers in your country see, and what everyone measures worldwide. A slow evening is one thing; a line that is slower than everybody else on the same network is a conversation with your provider — and now you can show them the difference instead of describing it. Every figure says how many subscribers and how many measurements are behind it, and nothing is shown at all until enough different people have contributed that no single household can be picked out of it.
- Open statistics, published. A new public page at helixaicloud.com/monitor-stats.html shows latency, loss and speed by country and by network, measured entirely by subscribers’ own agents. It carries no numbers of its own: everything is fetched live, and when there is not enough data to publish a network safely the page says so rather than showing a figure. It is deliberately not a league table — the sample is people who chose to install a monitoring tool, and the page says that above the figures rather than in a footnote.
- Your network, on the front page. The dashboard now opens with who you are paying: their name, AS number and country with its flag, and three plain ratings for what the line is currently good for — calls, gaming and streaming — measured against published thresholds you can check.
- Speed-test history, and a link you can share. Every test your agents have run is now listed in your account, and any one of them can be shared as a link. The page shows the result, names your ISP and nothing else about you, and says plainly that one test is not a verdict on a connection. You can revoke the link at any time, and the result is frozen when you share it — whoever you sent it to sees the number you quoted, not whatever you measure next week.
- Send a diagnosis to your account. The Link Troubleshooter can now hand its report to your Helix account, where you can publish a shareable link, download it as a PDF or attach it to a ticket with your ISP.
- A Stop button that stops everything. One control in the toolbar ends every diagnostic run, empties the queue and closes any live support session your provider has open. It tells you what it stopped, and it never turns off monitoring — that keeps running, because the evidence you are collecting should not have a hole in it.
- Name and service checks on the Workbench. Look up what a name resolves to on your resolver against two public ones, and check whether the service on a host actually answers. A refused connection is shown as the good sign it is: the packet arrived and the host replied.
- Country flags throughout. Every network on a path now carries its flag, so you can see your traffic leave the country at a glance rather than reading AS numbers.
Changed
- The live throughput chart puts upload and download on the same side. Upload used to hang below the axis as a mirror image, which spent half the chart on a reflection and left the smaller direction as a flat smear on most home connections.
- The speed test says who measured it. Cloudflare and the edge that answered are now shown with the result, and you can re-run from the result view. While a test runs, all three figures update live with the one being measured highlighted.
- Cleaner tables. Path results no longer wrap every number in a coloured box — colour is now used only where it means something, so the hop that is actually causing your problem stands out.
- Your data allowance and alerts follow you down the Usage page instead of scrolling away as soon as you look at the detail.
Fixed
- The ISP portal’s theme button sat in the middle of the header for every signed-in operator.
- Ending a support session from the operator’s side could silently fail and leave the subscriber’s "someone is watching" indicator on.
- Notifications on the web dashboard now match the desktop app’s, and no longer rely on colour alone to tell success from failure.
- Speed tests uploaded by agents were being stored and never shown anywhere.
- Country flags render on Windows, which ships no flag font at all.
1.3.0 2026-08-21
Added
- Live support — with your permission, and never without it. When you call your internet provider, their support desk can now ask to watch your connection live while you are on the phone. The request appears on your screen and nothing is shared until you answer. If you allow it, the engineer sees the same live readings this app shows you — latency, loss and the network path — for the number of minutes you allowed, you see an indicator the entire time, and a Stop button always works. Saying no is one click. Nothing is recorded either way: it is a window, not a recording, and it closes on its own when the time runs out.
- Live Path. A new panel that shows your connection working in real time: every probe as it happens, and the live route your traffic takes, with the same honest reading as everywhere else in the app — only the first hop whose loss actually reaches the destination is blamed.
Changed
- Update checks now run every 3 minutes, permanently. An earlier changelog said the faster checks were temporary and would return to fifteen minutes; that was wrong — the three-minute cadence is now the permanent setting. It was kept because it gets fixes to every machine within minutes, and it stays cheap: almost every check is a tiny “anything new?” request answered with “no”.
- The app and service from this release still work with the previous release during the update window — the wire between them is unchanged, as the versioning note above promises.
1.2.12 2026-08-21
Fixed
- The notification card is dark glass everywhere, not gray. On machines where Windows disables transparency effects — remote desktop sessions among them — the card fell back to a plain gray rectangle with square corners. It now carries its own colour and shape without asking the system for help.
- If the app’s window was open when an update arrived, it opens again afterwards. Previously an update that happened on its own closed the window and brought the app back only in the notification area, quietly undoing what was on your screen. The window now returns — without taking your keyboard — and if you close the app to the notification area during the update warning, that choice is respected and it stays closed. Because the remembering is done by the app being replaced, this first takes effect on the update after this one.
1.2.11 2026-08-21
The agent is functionally identical to 1.2.10. Like 1.2.1 before it, this release exists to exercise a mechanism in front of the people watching for it: 1.2.10 changed how update warnings look — the product’s own dark-glass card instead of the standard Windows notification — and the card announcing an update can only be seen while a real update is arriving. This is that update. If a glass card slides in above the notification area, names this version and counts down while the app restarts, the new surface works; if not, it is the surface that is broken and not the update.
1.2.10 2026-08-21
Changed
- Notifications now look like Helix, not like Windows. Warnings and connection findings appear as the product’s own dark-glass card above the notification area — the app’s mark, a coloured edge, and a thin line showing how long the card will stay. Hovering holds it; clicking it opens the app; the × dismisses it. The card never takes keyboard focus away from what you are doing. If the card cannot be shown for any reason, the standard Windows notification is used instead, which since 1.2.9 carries the app’s own name and icon. One honest trade, made deliberately: the card appears even when Windows Do Not Disturb would have hidden the standard kind.
Fixed
- Updates no longer leave a leftover installer copy behind. The cleanup ran at a moment when the file was still in use by the update itself; it now retries shortly afterwards.
1.2.9 2026-08-21
Fixed
- The warning before an update restarts the app now actually appears. It has been sent since 1.2.3 and never shown: Windows only displays a notification from an app it can identify, and the installed app was never registered in the way Windows checks. The installer now registers it properly, so the app’s notifications carry its own name and icon. Because the warning is shown by the app that is about to close, the first update onto this version still updates quietly; the warning appears from the next one on.
Changed
- The background service is now
helix-monitor-service.exe (it was helix-service.exe), and it now carries a proper description, publisher, version and icon — so what you see in Task Manager says what it is and who it belongs to, instead of an anonymous process. Recognisable names are part of being trustworthy software; a process you can identify is one you do not kill or report. Updating from any earlier version handles the rename automatically, and the old file is removed.
1.2.8 2026-08-21
Fixed
- The app comes back after an update. Actually, this time, and here is why it is different from the last two times this changelog said so. The reopening machinery has been rebuilt twice and each time one link in the chain had never really run: 1.2.6 built the right mechanism in the wrong order, 1.2.7 fixed the order but the step that notices the app was open could not see it from where updates run. That step read the answer to “did the app close politely?” — a question that cannot be asked across the boundary between the update and your desktop. It now asks a question that can. The difference this release: the failure was found by reading the disk’s own journal of what happened during a real update, the fix was probed in the exact context updates run in, and the put-the-app-back step has been watched working on a real machine.
Known
- The warning that an update is about to restart the app does not appear yet. The message is sent; Windows has nothing it recognises to show it as, so it shows nothing. A fix is queued. The update itself is unaffected.
1.2.7 2026-08-21
Fixed
- The app really does come back after an update now. 1.2.6 built the right mechanism and ran it in the wrong order: the note telling the new version to reopen the app was written moments after the new version had already looked for it. Updating worked; the app stayed closed. The note is now written first. This is the release where the reopened app has actually been watched appearing — as a window when you asked for the update, in the notification area when it happened on its own — rather than reasoned about.
Changed
- Updates are noticed within about three minutes, temporarily. The usual cadence is a check every fifteen minutes. During the current development sprint the agent checks every three, so fixes land quickly on the machines testing them. The check is tiny — a question to the server whose usual answer is "nothing new" — and the cadence returns to fifteen minutes when the sprint ends.
1.2.6 2026-08-21
Fixed
- The app now comes back after an update from any older version. The 1.2.5 fix for the vanishing app only worked when the machine was already on 1.2.5 — a computer that had been switched off through a few releases and then updated in one jump still lost its app until the next sign-in. The step that notices the app was open now travels inside the update itself, so it is always the current version doing the noticing, however old the installation being replaced. One consequence is honest rather than clever: on a jump from an old version the update cannot tell whether you asked for it, so the app returns to the notification area instead of guessing that a window is wanted.
1.2.5 2026-08-21
Fixed
- The app did not come back after updating itself. 1.2.3 added a step to put the app back once an update had finished, and on a real machine it never worked: the update runs as a background service, and a program started from there cannot reach the desktop you are signed in to. Nothing reported an error, so the app simply closed and stayed closed until you opened it again. The service now starts it in your own session, which is the one place it can actually appear.
- An update you asked for now brings the window back. If you press Check now and watch the app close, it reopens as a window, because you are sitting there waiting for it. An update that happens on its own in the background still returns quietly to the notification area instead of interrupting whatever is on screen — that part is unchanged, and it was never possible to tell the two apart before.
- Updates no longer leave the installer behind. Each one left roughly 5 MB of temporary files in the install folder, because the step that cleaned them up ran inside the process the update itself shuts down. They are cleared at startup now, including any left by earlier versions.
1.2.4 2026-08-21
Fixed
- Signing in threw a maximised window across the screen. The app is meant to start quietly in the notification area when Windows signs you in, and to open a window only when you ask for one — by clicking the tray icon, the Start menu entry or the desktop shortcut. The installer had been asking for the quiet start since 1.2.0 and the app had never listened, so every reboot put a full-screen window over whatever you had signed in to do. It now starts in the tray, and the window is one click away. Monitoring was never affected either way: the service measures whether or not the viewer is on screen.
1.2.3 2026-08-21
Added
- A warning before an automatic update restarts things. A notification appears about five seconds beforehand saying what is happening and that monitoring continues throughout. It comes from the app rather than the service, because a Windows service has no access to the desktop and cannot show anything — so the only thing that can give you notice is the app that is about to close.
Fixed
- The app did not come back after updating itself. A silent install deliberately does not open a window, so nobody is interrupted mid-task — but a self-update is a silent install that just closed a window somebody had open, and leaving it closed meant their app vanished until the next sign-in. It now returns to the notification area if it was running before, without raising a window over whatever you were doing.
1.2.2 2026-08-21
Fixed
- An automatic update stopped the app and the service and never brought them back. Windows runs a service inside a job object and child processes inherit it, so when the installer stopped the service — its own parent — the job closed and killed the installer part way through. The app was closed, the service was deregistered, and nothing restarted: the machine simply stopped measuring, with no error anywhere. The installer is now launched outside that job so it survives the service it replaces.
- 1.2.1 was withdrawn rather than left serving, so no further machine could reach it. A machine left in that state is repaired completely by running the installer once by hand.
1.2.1 2026-08-21
The agent is functionally identical to 1.2.0. This release exists to exercise the automatic update that 1.2.0 introduced: the only difference a running agent can observe is the version string it reports. If an update applies and the app comes back working, the mechanism works; if something breaks, it is the mechanism and not the payload.
Fixed
- A release could be published with no update signature, and nothing said so. That is how 1.2.0 was first registered: through the console, which has no signature field. Every agent correctly refused to apply it, so the release that introduced automatic updates could not be automatically applied — while the download page, the console and the fleet panel all looked healthy. Publishing unsigned is now refused unless it is explicitly asked for, which keeps download-only releases possible and stops the omission happening by accident.
- The internal check that every table the API queries actually exists could read ordinary prose as SQL, because of how it paired backticks. It reported an error message containing the words "update signature" as a missing database table. It had been wrong since it was written.
1.2.0 2026-08-21
Added
- The app updates itself. No prompt, no installer to run, no elevation after the first install. The agent checks every fifteen minutes as before, and now downloads, verifies and applies what it finds.
- Releases are signed, and an unsigned one is never applied. This is not a code-signing certificate and SmartScreen still warns on first install — it is a key pair we hold, whose public half is compiled into the agent and whose private half never touches the server. An attacker who took over the cloud tier completely could serve any update they liked and every agent would refuse it, because they could not sign it.
- Crash reports reach us. Both halves of the product have written crash reports to disk since 1.0 and nobody has ever read one, because they never left the machine. They now upload, tagged with the version that actually crashed — which is not always the version the machine last reported, since a build that cannot finish starting never gets to say anything.
- Start with Windows. The viewer returns to the notification area when you sign in. Monitoring already ran regardless; this is only the window. The service has always started at boot.
- The app opens by itself once installation finishes.
Changed
- Automatic updates were previously recorded as impossible without buying a code-signing certificate. That was wrong, and it had been written down as permanent. Two different problems had been given one name: SmartScreen needs a certificate authority, and telling our update from an attacker’s needs a key we control. Only the first costs money.
- A release that changes the install layout also applies by itself now. The service runs the verified installer silently, so the one remaining elevation prompt is gone. This is only safe because of the signature above — before it, the only thing vouching for those bytes was a TLS certificate.
Fixed
- A failed update leaves the previous version running. The replacement is downloaded and verified in full before anything is touched, both files are confirmed present before either is moved, and a swap that fails part way puts everything back. An agent that dies mid-update is worse than one that never updated: it stops measuring, and nobody finds out until they look.
1.1.3 2026-08-20
Added
- Path evidence now arrives without anyone pressing a button. MTR only ever ran on demand, so the whole trace subsystem — the hypertable, an ingest that refuses an unclassified hop, the shared shaper, the first-propagating-hop rule — was built and starved: four stored hops against thirty-five thousand measurement windows. The agent now traces one internet consensus target every hour, rotating, jittered from its per-install seed. One target rather than all four: tracing all of them hourly costs only 6.7% more probes but 66% again as much stored data as everything the product currently records, to trace three paths that share most of their hops. One rotating target is +1.7% on probes and +16% on rows.
- A trace at the moment the line breaks, which is the one moment path evidence cannot be collected afterwards — by the time somebody opens the workbench the path has usually healed. Rate-limited to one per ten minutes, on outage starts rather than outages, because a flapping line produces transitions continuously and a trace per transition would make the monitor part of the problem.
- A live ping in the workbench, alongside the running trace. It costs no extra packets: an MTR round already sends an ordinary echo to the destination, so at one round per second the ping was being sent all along and merely not shown. Running a second pinger beside the trace would have put two measurements of the same line in contention.
- A curated menu of targets worth tracing, in four groups, each entry saying why you would pick it. It sits beside the free-text field rather than replacing it.
- Path history, a third Troubleshooter tab listing the traces the agent collected on its own. Without it the automatic evidence accumulated somewhere the person whose connection it describes could not look. It answers a question the live workbench cannot: was it like this an hour ago? A trace run after noticing a problem describes the network at the moment you looked, which is usually after it recovered.
- Stop buttons on every trace, agent pack and diagnosis. A stopped trace keeps its rounds — twelve of forty is twelve rounds of evidence. A stopped diagnosis keeps nothing, deliberately: a verdict drawn from a truncated stage list cannot tell a check that never ran from one that found nothing wrong.
Changed
- Agent packs measure their hosts in parallel, cutting a five-host run from about three and a half minutes to about forty-five seconds. The hosts are phase-staggered across the round period rather than started together, and that stagger is load-bearing: every path out of the machine crosses the same gateway and ISP edge, so simultaneous starts would hand those shared hops five bursts at once, routers rate-limit ICMP, and the resulting false loss would land on the earliest hops — making the pack accuse your own ISP of a fault the measurement invented.
- Pack progress now counts completed hosts rather than started ones, so the bar no longer shows 20% before any work has been done, and every host’s hop table stays on screen instead of one shared panel flipping between them.
Fixed
- Opening the app again built a second copy of it. The window hides on close rather than exiting, so the process outlives its own window; with no single-instance guard, every launch from the Start menu started another app with its own tray icon and its own connection to the service, and nothing on screen said either was a duplicate. Reopening now shows the one already running.
- A failed hop lookup was retried on every round. Only successful ASN lookups were cached, which was survivable when one trace ran at a time and became a flood once packs traced five hosts at once — hundreds of DNS queries for a single unresolvable hop, sent from the machine whose connection was being measured. Failures are now remembered too, briefly.
- Hop lookups run concurrently rather than one after another, so a long path no longer delays the first round it is waiting on.
- The diagnosis report named bare addresses. Its path table never carried the operator, network or country, even though the renderer had columns ready for them — so the report a subscriber attaches to a ticket left the attribution to the reader, which is the step that decides whether a complaint reaches the right network.
- The agent pack view was dropping the same attribution for the same reason.
1.1.2 2026-08-20
Fixed
- The migration off the old install directory left it standing. 1.1.1 moved an existing install into
Program Files\\Helix Internet Monitor and deleted three files behind it, but not helix-desktop.exe — the app under the name Tauri emitted before 1.0. The directory removal is deliberately non-recursive, so one unnamed leftover keeps the whole folder, which is the thing the migration exists to prevent. The old Start Menu folder goes too; it was named for the vendor and held a shortcut into a directory that no longer exists.
- The uninstaller had the same gap and now removes that binary as well.
- Reinstalling after an uninstall could fail permanently. Neither half closed the desktop app. The service was always deregistered before its binary was replaced; the viewer never was. So an uninstall with the app open removed the shortcuts and registry keys, reported success, and silently left the executable -- NSIS
Delete does not report a locked file -- after which every reinstall aborted with "Can’t write: ...Helix Internet Monitor.exe". Both halves now close it first, and the uninstaller says so plainly if the file survives instead of finishing quietly.
Changed
- A running agent shows what it is doing. A pack run takes about a minute per host and previously showed the word "Running". It now streams the host it is on, the MTR round within that host, and the hop table filling in live — with the first hop whose loss carries downstream marked as it appears. Both progress bars are determinate because the wire carries both fractions. None of this is new measurement: it was already being sent and discarded.
- The Troubleshooter’s agents panel spans the page. It was being placed in the 260px history rail, which also displaced the diagnosis panel beside it.
1.1.1 2026-08-20
> Numbered on the 1.1 line rather than as 1.2.0, which the amount of new > capability here would otherwise call for. 1.1.0 is tagged, published and > serving downloads, so it cannot be re-cut — two different binaries behind > one version string would also defeat the update check added below, which > compares version strings and would never offer an agent on 1.1.0 a > different 1.1.0.
Added
- Troubleshooting agents. A curated pack is now something you run, not only something you subscribe to. A run sends an MTR to every host in the pack and reports where the path breaks rather than whether it is slow, naming only the first hop whose loss carries downstream — everything after it inherits that loss, so marking them all points at nobody. Runs keep no target, which is why every pack can be present and runnable on a fresh install: continuous measurement is limited to 16 probe slots and the five packs hold 18 hosts between them. Every run is coarse by construction, 40 probes against a floor of 300, and shows counts rather than a rate.
- The packs moved to Troubleshooter → Agents, which is where somebody with a stuttering game looks. They were in Settings, which was one of the three reasons nobody found them.
- The agent checks for its own updates, every fifteen minutes, jittered from the same per-install seed the probe scheduler uses so a fleet does not wake in unison. The check is performed by the Helix service rather than the app: the service already runs with the privileges an update needs, so there is no consent prompt to train anyone to click through. It reports what it finds and does not yet apply it — downloading and swapping binaries is gated on a signed installer.
- Version distribution across the fleet, for operators. Share is measured against agents seen in the last seven days, because a denominator including machines nobody has switched on since March never reaches 100% and makes a finished rollout look stalled. Counts only — no device or account is named.
- A speed-test dial leads the dashboard, with latency, jitter, loss, MOS and score beside it. It was previously one of four reorderable panels and sorted last in the default mode.
Changed
- The live throughput chart is 320px rather than 150. Mirrored, the old height gave each direction about 65 usable pixels, at which bufferbloat, a sawtooth under congestion and a clean saturated transfer look identical.
- The taskbar icon is the white artwork. The Windows taskbar is dark by default and does not read the app’s theme, so the deep-navy tile sat nearly flush against it.
- The IPC protocol is version 2. Additive only, and the service accepts both 2 and 1, so an app and a service from adjacent releases interoperate during an update window.
Fixed
- The installer could never move an existing install into the branded directory. The default was corrected in 1.1 and every machine that had the old
Program FilesHelix layout inherited it forever, because the installer reads the recorded path and reuses it. A legacy path is now migrated; any other recorded path is still honoured.
- Right-clicking the tray icon opened the window instead of the menu. The click handler matched every mouse button, so the window took focus and dismissed the menu Windows was showing on the same gesture. The menu had been correct and unreachable since it was written.
- The tray icon is kept out of the Windows 11 overflow flyout, which matters more than it sounds: promotion is recorded per executable path, so the directory migration above would otherwise have silently un-pinned it.
- A test-harness reset trusted
TRUNCATE ... CASCADE for two tables that have no foreign key, so rows leaked between database-backed tests.
1.1.0 2026-08-20
Added
- Per-hop MTR reaches the cloud. Each hop carries its loss classification as part of the row rather than as a rendering decision: whether a hop’s loss persists downstream is a property of the whole trace, so a reader holding one row cannot recompute it. A hop arriving unclassified is refused at ingest, because the only thing left to render would be a bare percentage - the reading that gets an innocent transit provider blamed. Only the first propagating hop is marked as the culprit; everything downstream inherits the loss.
- Diurnal profile - a 7x24 weekday-hour grid. Cells recombine from counts, never from averaged rates, so a 12-probe window does not weigh as much as a 600-probe one, and bucketing happens in the subscriber’s local zone, because a fixed offset is wrong twice a year in every DST zone and moves the evening peak into the wrong column. The worst hour is a ratio against the line’s own median and is left unnamed below a coverage floor.
- Per-application usage on Windows, collected via ETW.
- Target packs - mode-specific host sets selected by id. The list is compiled in and the type deliberately does not implement
Deserialize, because constructing one from bytes is exactly the ability to name a host from outside the binary. Pack targets never join outage consensus, so a Discord outage is not reported as the subscriber’s line going down.
- On-site CDN and IP-transit checks, with HTTPS health checks alongside ICMP and MTR. One catalogue entry records that
www.netflix.com blocks ICMP by policy, so its ping failure is not read as a fault.
- DoH resolver catalogue with filtering levels and a lowest-latency pick.
- User-defined watched hosts, labelled, visible on the desktop and in the cloud.
- Tiered providers and ticketing - bilateral
provider_links invited by the customer and accepted by the provider, escalation as a forward rather than a move, attach-time redaction against an allowlist, and an SLA clock that runs in business hours.
- Crash reporting for the desktop app. Reports stay on the machine.
- The app now opens maximised.
POST /v1/admin/releases/fetch registers a release by downloading it from its published URL and measuring it, rather than hashing a copy placed on the server by hand. Cutting a release no longer needs shell access to production. The digest still describes bytes the server received rather than a claim the caller made, which is the property that matters while the installer is unsigned.
Changed
- Dark is unconditional; light is an explicit opt-out. There is no
prefers-color-scheme: light block anywhere, so a visitor whose OS prefers light still gets the intended theme. The theme control lost its third "auto" state in the same change, because with the media query gone "auto" and "dark" selected identical pixels.
- The chart palette is six series, not eight. The shipped values were measured against a CVD simulation rather than read: two of them sat adjacent at roughly half the required separation under deuteranopia - indistinguishable to about one man in twelve, and the exact defect the code comment claimed the ordering prevented. No seven-hue set clears all-pairs separation inside the required lightness band, so both palettes are now generated rather than chosen. A seventh series folds into an "Other" bucket or a second encoding channel.
- Installs to
C:\Program Files\Helix Internet Monitor, with a branded installer.
- Gauges are determinate only when the wire carries a real fraction. The loss gauge refuses to draw an arc below 300 probes and shows counts instead; latency is graded against the line’s own baseline, never an absolute scale.
- Release downloads are served from GitHub. The counted, rate-limited
/v1/downloads/him URL is unchanged - only what it redirects to moved.
Fixed
- A cross-organisation ticket could leak an internal article. The read predicate compared author and reader organisation without a non-null guard, and JavaScript’s
null === null is true where SQL’s NULL = NULL is not, so the two halves of the check disagreed. Unreachable in practice only because subscribers cannot author internal articles.
- Loopback traffic was counted as internet usage by the ETW collector.
- Recovery notices were swallowed by the packet-loss cooldown, so a line coming back could go unannounced.
- Hop tables are never cropped. A
58vh cap on the desktop hid exactly the row nearest the fault.
- The sign-in pages now say which password they want.
- Every
/v1/admin route in the download area was unreachable. They call requireSuperAdmin(), which reads a principal that only the requireUser preHandler sets, and none of them registered it -- so release registration and the whole download console answered 401 to a valid super-admin token, looking exactly like a bad one. No behavioural test could have caught it: an anonymous request gets 401 either way, so the wiring is now pinned structurally and a missing principal raises a named error instead of impersonating an authentication failure.
- The published release body began with a byte order mark, and its unsigned-installer warning was absorbed into the table above it by markdown, so the one paragraph that has to be seen rendered as a table row.
Security
- The subscriber sign-in identifier uses
autocomplete="username", which is what makes a password manager offer the saved Helix password rather than leaving the user to type a remembered - and often reused - one.
- Release redirect targets are validated against a compiled-in host allowlist, on write and again on read.
/v1/downloads/him is public and unauthenticated and it hands out executables, so a free-text target would be an open redirect wearing the product’s own domain.
Known limitations
- The installer is not code-signed. SmartScreen will show "Windows protected your PC" and Chrome will warn on download. Signing is blocked on a certificate whose key must live on FIPS 140-2 Level 2 hardware, a CA/Browser Forum requirement since June 2023. The published SHA-256 is the honest mitigation until then.
Method::SetTargets is refused by the service pending an elevated confirmation flow.
1.0.0 2026-08-18
First public release: the measurement service, the desktop viewer, the cloud API and the four-tenant ISP model.
- Latency, packet loss and outage detection, with counts and run lengths on the wire rather than percentages, because a percentage cannot be re-aggregated. Loss below 300 probes is flagged coarse rather than quoted as a rate.
- A diagnosis engine whose verdicts carry
contradicting[] as well as supporting[]; one that cannot populate the second is not shipped.
- Consent, scope and article-visibility as three separate gates, each in one module, so a widening shows up in a diff.
- Maintenance windows suppress fault attribution only when declared at least fifteen minutes before the fault, or the feature inverts into a retroactive amnesty.
- Desktop app talking to the service over a named pipe on a versioned wire.