Changelog

Shipped every second Friday

A fortnightly release train. Breaking API changes get 90 days' notice and a migration note; everything else lands behind a flag you can turn on when you are ready.

Current version4.7

Released 12 Sep 2026

Component status
4.712 Sep 2026
  • Attack paths
  • Remediation

Choke point ranking and containment states

  • Choke points are now ranked by the number of live paths removed and the estimated effort for the owning team.
  • Paths can be marked contained with a required review date, separate from closed.
  • Path detail now shows which findings would stop being urgent if the choke point is applied.
4.628 Aug 2026
  • Identity risk

Identity risk graph, machine identities

  • Service principals, deploy identities and access keys are modelled alongside human accounts.
  • Toxic entitlement pairs are raised as a single finding with both contributing grants shown.
  • Last-use data is pulled from the identity provider where available.
4.514 Aug 2026
  • Integrations

Two-way SLA sync for ServiceNow

  • Remediation state and due dates now sync in both directions with ServiceNow change and incident records.
  • CMDB reconciliation proposes owner matches for newly discovered assets.
  • Webhook payloads gained a stable entity identifier for every asset and finding.
4.431 Jul 2026
  • Threat intelligence

Look-alike domain watch

  • Certificate transparency and registration monitoring for names that imitate your own.
  • Matches are scored against the portal or brand they imitate rather than shown as a flat list.
  • Added campaign profiles with observed techniques mapped to your live paths.
4.317 Jul 2026
  • Exposure management

Change ledger

  • Every asset that appears, changes origin, gains a public route or loses its owner is recorded with a date.
  • The ledger is filterable by stratum, owning team and change type.
  • Ledger entries are exportable to the SIEM as structured events.
4.203 Jul 2026
  • Enterprise
  • Platform

Residency selection and customer-managed keys

  • Programme customers can select EU, UK, US or Canada residency at tenant creation.
  • Customer-managed encryption keys are supported for stored findings and evidence.
  • Regional status is now published per region on the status page.
Next step

Want to know before it ships?

Programme customers get the release notes two weeks early, plus an invitation to the quarterly roadmap review.

Talk to the teamRead the documentation

Illustrative product data. Nothing on this site performs a live scan.