Changelog

What changed.
What is proven.

Product updates without the usual ambiguity. We record what shipped, what was exercised, and where a production claim still needs evidence.

A sharper story for the security team in the room.

The landing, teams, pricing, and docs now show the complete operating model: research provenance, native security sources, delivery integrations, private-model deployment options, and the enterprise deployment path.

  • Added a copyable, checksum-verifying CLI installation command and a safer inspect-first path.
  • Separated telemetry sources (Splunk, Elastic/ELK, AWS, Google Cloud, Sentinel, CrowdStrike, Wazuh) from code-review, ticketing, and notification integrations.
  • Reframed commercial options around evaluation, team delivery, and enterprise deployment rather than public-source tiers.

Deployed webhook normalization was exercised across four vendors.

A signed synthetic exercise sent Splunk, Elastic, CrowdStrike, and AWS GuardDuty payloads through the deployed intake. One attacker address converged into one correlation group; replays were rejected and future-dated events were quarantined.

  • 300-event sustained batch accepted without error or rate-limit rejection.
  • All synthetic events, sources, and correlation groups were removed after the exercise.
  • This is functional evidence only—not a scale, recovery, or provider-certification claim.

The governed agentic SOC control plane landed.

Cases, evidence artifacts, investigations, context graph memory, detection engineering, supervised response, durable jobs, inventory, and workspace integration controls became one coherent App Router application.

  • Agent plans, hypotheses, evaluations, approvals, actions, and outcomes remain inspectable.
  • Workspace-scoped interfaces keep unavailable and degraded states visible instead of inventing data.
  • The release ledger continues to separate implemented code from provider, container, scale, and production proof.
Evidence ledger

Want the exact release boundaries?

The production-readiness report is the source of truth for what has local, runtime, deployment, and scale evidence.

Request the readiness ledger