Fixed a cross-tenant SOC event forgery vulnerability — ingest now requires authentication and derives organization from the verified token, never the request body.
Fixed billing webhook signature verification failing open on an unconfigured secret — now fails closed.
Replaced fabricated EASM discovery output with real DNS/TCP/TLS/HTTP probing.
Fixed a deployed-but-non-functional continuous re-scan scheduler.
Extended AI safety guarding to the analyst copilot endpoints (previously only the customer chat had it).
Added self-service password reset and account settings — previously staff-only.
Added role-based access control to DFIR case management (previously any authenticated org member could modify cases).
2026-07-09
Public launch readiness pass
Rebuilt AI guard around a retrieve-by-default architecture.
Fixed a critical Enterprise-tier billing edge case.
Real Kubernetes rehearsal, backup/restore test, and 150-user load test.