Skip to main content
Release History

Changelog

Product releases start at 1.0.0 (June 11, 2026) and follow semantic versioning: major releases break an API, wire format or schema contract; minor releases add capabilities; patches fix bugs. Development milestones from before 1.0.0 are listed below it.

v1.0.0Platformv1.0.0-rc.1June 11, 2026

First product release — the 1.x line starts here

  • Correlation Explorer dashboard for cross-pillar investigation
  • AI Gateway correlation_id propagation — all four pillars share one request trace
  • Multi-arch Docker image builds (linux/amd64 and linux/arm64) on release tags
  • Default-off telemetry, with a full data-collection disclosure (TELEMETRY.md)
  • Architecture overview with trust boundaries (ARCHITECTURE.md)
  • Demo attack-chain script for walkthroughs

Development milestones before 1.0.0

Work that went into the platform before its first product release. These builds were never tagged or shipped as versions, so they carry a date and no version number.

Development milestoneSecurityMay 9, 2026

VPC Security Sprint — 16 new modules, 202 tests

  • CloudWatch & Azure Monitor exporters for sensor fleet telemetry
  • Cognito JWT validation with JWKS auto-rotation
  • Credential stuffing detector — cross-session velocity + device fingerprinting
  • Shadow AI Discovery: detect unauthorized LLM calls in request traffic — WITHDRAWN September 2026. This shipped as a detector class with no driver, no route and no flag consumer, so it never produced a finding. Shadow API discovery, a different feature with a similar name, does work.
  • API Posture Scoring: continuous risk-score across all endpoints
  • AWS SigV4 inbound validation for Bedrock and Lambda integrations
  • Agentic SPM (Security Posture Management) for AI agent fleets
  • Security Graph: cross-pillar entity relationship mapping
  • gRPC interceptor sensor for unary, server-stream, and bidirectional calls — WITHDRAWN September 2026. This shipped as an interceptor class with no gRPC server anywhere in the deployable to attach it to, so it never intercepted a call.
  • Adaptive MFA: risk-score-triggered step-up challenges — WITHDRAWN September 2026. This shipped as a dependency that no route used, so it never challenged a request. TOTP two-factor and step-up re-verification of enrolled users are the MFA controls.
  • Datadog exporter, HIBP breach check, Lambda Authorizer
  • Kafka and MQTT protocol sensors — WITHDRAWN September 2026. These shipped as consumer modules with no startup hook and no installed broker client, so they never read a message.
Development milestonePlatformpre-customer-vpc-transition-2026-05-07May 7, 2026

Customer VPC Deployment — sensors ship into customer infrastructure

  • Common Sensor SDK (Python) — handshake, config-push, WebSocket, cert rotation
  • MCP Security Sensor: 114 tests, full tool-call interception pipeline
  • AI Gateway Sensor: 133 tests, OpenAI + Anthropic provider clients, BYOK rotation
  • Verification Engine Sensor: baseline extraction of the five layers (Layer 2 is a token-overlap heuristic), EU AI Act Article 5
  • Sensor Lifecycle: 192 tests — handshake, rollout, quarantine, version-compat, cert-reissue
  • Bulk ops, fleet pubsub, config-push, sweeper, and cert lifecycle
  • Helm charts for all sensors with HPA, PDB, NetworkPolicy, PrometheusRule
  • No traffic leaves customer VPC — sensor-to-collector ingest over mTLS
Development milestoneFeatureApril 28, 2026

Live Demo Environment — real data, live traffic, full walkthrough

  • Demo traffic generator: realistic multi-pattern attack simulation
  • Marketplace populated with real integrations from database
  • Threat map wired to live threat_events table — no more demo-mode fallback
  • Security posture stats computed from real threat_logs traffic tables
  • Demo proxy routes write to threat_events on every blocked request
  • Seed data: extended SQL, threat intelligence, and threat log fixtures
  • Demo kit: playbook, walkthrough, quick-reference, and setup guide
Development milestoneFeatureApril 26, 2026

Dashboard Rejuvenation — complete dark-theme sweep, 22 pages rebuilt

  • DemoDataBanner across all 22 dashboard pages — graceful degradation when API unavailable
  • Compare page redesign with side-by-side feature matrix
  • Verification Engine async mode + Stage 3 pipeline
  • Command-center real-data guards — zero-response now shows live demo data
  • Verification page crash fixed — LazyCharts + array guard on trend data
  • Marketplace category-grouped layout with dropdown filters
  • Rate-limit 429 RFC 7807 Problem+JSON responses with X-RateLimit-* headers
Development milestoneSecurityApril 25, 2026

AI Gateway expansion — 10+ providers, 200+ new test suites, hardening

  • Added DeepSeek, Together AI, Fireworks AI, xAI, Ollama, Mistral, Cerebras, Groq (total 10+ providers)
  • 200+ new test suites across API Security, MCP Security, AI Gateway, Verification Engine
  • 14 security hardening items: ReDoS, WebSocket XFF, CSP nonce, SSRF, Redis namespacing
  • SQLAlchemy 2.0 text() compatibility across all migrations
  • Auth login 500 error fixed — JWT refresh race condition resolved
  • Python and npm dependency security patches
Development milestonePlatformApril 14, 2026

Four-pillar platform assembled — API Security, MCP Security, AI Gateway, Verification Engine

  • API Security: ML detector trained on 78,000+ labeled attack samples, 7-layer rate limiting, anomaly detection (IsolationForest)
  • MCP Security: tool-call monitoring, RBAC, prompt injection detection, subprocess containment (rlimits, command allowlist, scrubbed environment)
  • AI Gateway: multi-provider routing (10+ LLMs), BYOK, cost tracking, failover matrix
  • Verification Engine: OpenAPI schema validation, JSON constraints, AI output verification
  • 8 compliance framework engines: SOC 2, HIPAA, GDPR, PCI DSS, ISO 27001, FedRAMP, CMMC, NIST CSF
  • Full dark-theme dashboard — 21 pages redesigned
  • Complete breadcrumb navigation across 28 API and AI pages
  • PostgreSQL Row Level Security policies on org-scoped tables, as defence-in-depth behind the application-layer organization filter
  • Internal red-team self-assessment: 5 high and 2 medium findings fixed, each with a regression test

Stay current

New releases ship continuously, and each one is listed on this page.