Changelog

What shipped, when

A factual record of platform updates. We only list changes that are actually live.

Disclosure, status & changelog pages

  • Published a Responsible Disclosure / vulnerability-reporting policy at /disclosure/
  • Published a manually-checked System Status page at /status/
  • Published this changelog and a public API reference

Team members (backend) & Trust Center

  • Added team-member invite, accept, login and remove — owner can grant read-only dashboard access to teammates API only
  • Audited and locked down every privileged write endpoint to owner-only access
  • Published the Trust Center at /trust/ — encryption, MFA, tenant isolation, incident response and certification status, written honestly

Enterprise SSO, SAML & AI SOC assistant upgrade

  • Customer-side Single Sign-On via OIDC — log in with Okta, Azure AD, Google Workspace and similar identity providers
  • Customer-side SAML 2.0 Service Provider support
  • AI SOC Assistant now reasons over each domain's real scan findings, not just a summary score
  • Homepage security hardening: hash-based Content-Security-Policy, published security.txt, tightened robots.txt

Foundation

  • Account system: signup, email & phone verification, 2FA, progressive lockout, secure account deletion with 30-day recovery
  • Real passive security scanner: TLS, HSTS, CSP, SPF, DKIM, DMARC, DNS and exposure checks
  • Continuous domain monitoring dashboard
  • Stripe billing, compliance-report generation, and white-label agency accounts for MSPs