Product updates

Every release - tagged, logged and provable

Release notes for a platform that runs in your environment. Filter by discipline or change type; subscribe by RSS. Semantic versioning, one bump per change, an audit trail on every ship.

23 tracked updatesSemver · one bump per changeRSS + private advisory feed
How we ship

Release discipline built for regulated estates

Most changelogs are marketing. This one is change management: versioned, attributable and verifiable, because your auditors will ask.

Semver, one bump per change

The version running in your environment is always visible in-product. No silent changes.

Audit-logged releases

Every release ties into your evidence pack - what shipped, and when - so change management has a paper trail.

Signed & self-hosted

An Ed25519-signed license and images you pull and run. You upgrade on your schedule; nothing auto-updates behind your back.

Private security advisories

Enterprise customers get an advisory feed for issues that affect a self-hosted deployment, ahead of the public notes.

The feed

What shipped, and when

Discipline
Change
23 updates
NewSASTJun 24, 2026 · v2.4.0

SAST engine reaches OWASP Benchmark 0.994

100% precision, 99.4% recall on the public OWASP Benchmark - the false-positive discrimination bar that keeps findings trustworthy enough to gate on.

SecurityPlatformJun 24, 2026 · v2.4.0

TLS ingress with automated certificate renewal

Let's Encrypt termination with auto-renew on the self-hosted ingress - no manual cert rotation.

ImprovedPlatformJun 24, 2026 · v2.4.0

Anti-freeze caps on the local LLM

Hard CPU / memory limits so AI analysis can never stall the host it runs on.

ImprovedPlatformJun 24, 2026 · v2.4.0

Host CPU / RAM / disk health metrics

Live host resource metrics surfaced on the admin Health page for self-hosted operators.

NewDASTJun 23, 2026 · v2.3.10

SSRF and XXE detectors mined from real-world writeups

New dynamic detectors held to the reachable-vs-confirmed severity discipline, so a probe is never over-claimed as an exploit.

NewPlatformJun 23, 2026 · v2.3.10

Priorities drill-down with owner and SLA tracking

Assign an owner and track the remediation SLA clock per finding, from first-seen.

ImprovedPlatformJun 23, 2026 · v2.3.10

Richer triage context on every vulnerability

More evidence and reachability context attached to each finding to speed triage.

SecurityReportingJun 23, 2026 · v2.3.9

PII masking across all exports and evidence

Sensitive values are masked in every export, report and evidence bundle by default.

NewPlatformJun 23, 2026 · v2.3.9

Per-client API rate limiting

Protects the API and downstream scanners under multi-team load.

NewPlatformJun 23, 2026 · v2.3.9

Kubernetes Helm chart for self-hosted deployment

A first-class Helm chart for running the platform on your own cluster.

ImprovedSCAJun 23, 2026 · v2.3.9

Deeper code coverage and estate-wide scanner parity

Consistent depth across the /code disciplines so posture is comparable app-to-app.

NewComplianceJun 23, 2026 · v2.3.5

Cross-framework controls with 'fix once, satisfy many'

A control-to-sub-control hierarchy that maps one remediation to every framework it satisfies.

NewComplianceJun 23, 2026 · v2.3.5

One-click audit evidence-pack export with attestation

Export a signed evidence pack recording who attested what, and when - built for auditors.

NewSCAJun 23, 2026 · v2.3.5

Supply-chain malicious-package and end-of-life feeds

Flags known-malicious and end-of-life dependencies alongside known CVEs.

NewComplianceJun 23, 2026 · v2.3.0

Gate policy export as OPA / Rego

Export the enforcement policy as OPA / Rego to run it anywhere in your pipeline.

NewComplianceJun 23, 2026 · v2.3.0

GRC review-and-attestation workflow

A formal review-and-sign path for governance teams, with rule-to-compliance mapping, scope filters and search.

GACI/CDJun 3, 2026 · v2.2.0

End-to-end pipeline gate, verified on a real repository

The full CI/CD gate reaches general availability - proven on a real repo, not a demo.

NewCI/CDJun 3, 2026 · v2.2.0

Portable, checksum-pinned CI agent

One agent (test / monitor / upload / container) that auto-detects GitHub, GitLab and Jenkins.

NewCI/CDJun 3, 2026 · v2.2.0

Per-branch baseline so pre-existing issues never block a merge

PRs gate on new-vs-default-branch only; each microservice repo maps to its own application in one posture.

NewCI/CDJun 3, 2026 · v2.2.0

PR decoration for branch protection

A commit status check plus an update-or-create PR / MR comment, wired for required-check branch protection.

NewIdentityJun 2, 2026 · v2.1.1

MFA / TOTP with one-time backup codes

Two-factor authentication for local accounts, with recoverable backup codes.

NewIdentityJun 2, 2026 · v2.1.1

Scoped, expiring, revocable API tokens

Personal and service tokens with least-privilege scopes and full revocation.

NewIdentityJun 2, 2026 · v2.1.1

Role-scoped RBAC with least-privilege defaults

Role-based access control and a secure onboarding flow, safe by default.

No updates match that filter yet - try another discipline or change type.
Security advisories

Advisories reach you before they reach the public notes

Because the platform is self-hosted, a security fix only helps once you upgrade. Enterprise customers get a private advisory feed - affected versions, severity and the exact remediation step - so you can act on your own maintenance window, not ours.

Request the advisory feed →

What an advisory carries

  • Affected version range and the fixed version
  • Severity and whether it is remotely reachable
  • The precise upgrade or mitigation step
  • A machine-readable entry and signed release note
Stay current

Follow updates the way your team already works

RSS feed Email on major releases Full changelog in docs

In-product, the running version and its release notes are always one click away on the admin page - so operators never guess what they are on.

See it on one of your own apps - live in 30 minutes

From discovery to a proven attack chain. A PoC in your own environment.