Resources / Changelog
Changelog

What shipped, what changed, and what we took out.

Removals are listed with the same weight as additions, because a changelog that only grows is a marketing feed with dates on it. Where something was taken out, this says what replaced it.

ADDEDnew capability or surface
CHANGEDbehaviour differs from before
REMOVEDtaken out, with what replaced it
August 2026
current
CHANGED One metered dimension on the platform line, and the pricing page now says so correctly
The published charging model listed mechanisms we do not use — per machine, per seat, per report, per destination. None of them were ever billed and none of them exist in the product. The platform line is metered on raw volume ingested per day and nothing else; detection, response, posture, identity, search and reporting carry no charge of their own. The capability index has been corrected row by row.
CHANGED A trial is bound to a daily volume instead of a node count
Put the agent on as many machines as you like. The licence carries a daily volume figure you declare, which is the same unit a quote would later use, and one upward amendment is available without a conversation. Counting nodes measured the wrong thing: one node is a jump box or a database host, and nothing in the count says which.
ADDED What happens if a licence lapses is now published
Enforcement never degrades and neither does the obligation plane — consent, erasure, grievance, your audit record, your bill and your ability to log in. Forward motion stops after a grace window: new policy and detector authoring, the reporting surfaces, feed freshness and support. It is on the pricing page in full, along with what is never gated by a licence in any state.
ADDED Per-machine policy carriers for detection content and protected datasets
An operator can now declare which detection content and which protected datasets a given machine is served. The machine's feed reports what it received, what a named policy withheld, and what nothing could judge — so a narrow feed is attributable rather than mysterious.
CHANGED Enrolment credentials now declare their reach at issue
A join credential is minted either for a machine that reports telemetry or for an application that reads its own account. The choice is made once and cannot be changed afterwards. Previously every credential was minted the same way, and the mismatch surfaced hours later on the host as an unexplained refusal.
CHANGED Refused device credentials now name their reason
A rejected credential returns a named reason rather than a blank where the diagnosis goes. Any surface that renders the refusal verbatim now shows it. The remedy is a re-mint rather than an edit, and the message says so.
REMOVED The free tier, before it shipped
Replaced by a single full-strength trial: thirty days from issue, self-hosted, nothing feature-gated, one per organisation, non-renewing. Our reasoning is on the pricing page rather than in a footnote — a free tier of a self-hosted platform gives us no telemetry and no shutdown path while still generating support obligations.
Earlier
ADDED Guided lessons that run on the live board
Academy lessons can now walk a learner through the real screen. Every step carries copy for the case where the estate is quiet, because a walkthrough over an empty board is the common case on a first day. No lesson ever injects example data into a live board.
CHANGED Coverage is reported as counts, not percentages
Any figure spanning machines that were never measured is now stated as a count with the unmeasured named separately. A percentage over an estate containing unevaluable machines was arithmetic performed on a category error.
REMOVED Direct actuator rollback from the operator surface
It worked, which was the problem: it changed the estate without a recorded decision. Undoing an automated action now crosses the same gate as the original, so the reversal is as accountable as the act.
How to read this page
Entries describe behaviour rather than version numbers, because a self-hosted platform means your version and ours differ. What is listed here is what the current package does. If an entry matters to you and you are on an older build, the behaviour arrives when you update — the fleet updates lesson covers doing that in rings without taking your detection capability out all at once.
The platform
All 88 capabilities Capability atlas Anatomy of an event Integrations Platform support
Commercial
Pricing Sizing your estate Trial licences
Evidence
Proof Honest limits Trust Security Changelog
Who it is for
For partners For auditors Working here
Learn
Resources Research Coverage gates Academy Glossary Essays
Tools
Check a message Stop a report