What's Shipping

Changelog & Roadmap

Every version, every fix, and where we're heading next.

Recent Releases

v1.2 July 2026 Latest
  • New Unified connector catalog: 121 integrations across 16 categories. 27 native API connectors with one-click setup and scheduled auto-sync (15 minutes to daily), led by Rapid7 InsightVM, Tenable.io, Qualys VMDR, CrowdStrike, SentinelOne, and Microsoft Defender TVM, plus 57 file imports and 14 push endpoints. AES-GCM-encrypted credentials and full asset identity on every finding, with mitigating-controls telemetry feeding TRIS.
  • New Identity-based cross-tool deduplication. Findings match on IP, hostname, MAC, and agent UUID, so the same exposure reported by three tools becomes one work item. Teams see an average 77.5% reduction in ticket volume.
  • New Webhook ingest API. Push any scanner output (Nessus, Nuclei, Burp, ZAP, Trivy, OpenVAS, SARIF, Wiz, Prowler, Nmap, CSV, and more) with automatic format detection and per-tenant API keys for MSSP workspace isolation.
  • New Fix First remediation board. Findings grouped by the fix that closes them, ranked by TRIS, stamped with SLA timers. Push Now, Schedule, or Ticket from the same card, with every action audit-logged.
  • New Ticketing and notifications. One-click tickets to Jira, ServiceNow, GitHub Issues, Linear, and Monday.com with mapped fields, plus event delivery to Slack, Microsoft Teams, Discord, and PagerDuty with incident auto-resolve on verified fixes.
  • New Claude MCP server. Native Model Context Protocol server connecting Claude Desktop and Claude Code to your live local instance: posture queries, findings search, TRIS scoring, report rendering, and work orders as typed agent tools.
  • New Signed threat-intel bundles. ED25519-verified exploit and IOC bundles with scheduled pulls or manual import for air-gapped environments.
v1.1 April 2026
  • New Cloud Scan Engine. Proprietary Cloud Security Posture (CSPM) and cloud identity attack-path (CIEM) engine covering AWS, Azure, and GCP. 204 CIS-tagged checks (AWS 88, Azure 61, GCP 55) with a per-framework compliance coverage rollup. Scans the customer's own cloud accounts. Results stay local.
  • New AI Patch Orchestration. CVEasy generates the fix, then orchestrates deployment through existing patch and MDM consoles: Microsoft Intune, Automox, Tanium, Jamf Pro, PDQ Connect, plus a universal webhook fallback. Fail-closed dispatch, AES-GCM-encrypted credentials, and closed-loop verification via re-scan. Closes the CTEM Mobilize loop.
  • New TRIS v2 12-Layer Scoring Engine (Patent Pending). Adds five novel dimensions no competitor has: attack-path blast radius, supply-chain propagation, MITRE ATT&CK defense efficacy, predictive threat trajectory, and FAIR-based financial impact quantification.
  • New TRIS v2 priority bands: ACT (90-100), ATTEND (75-89), TRACK (50-74), MONITOR (25-49), INFORMATIONAL (0-24). Better score separation, fewer false priorities.
  • New Graph-based attack path analysis across internal network topology with blast radius quantification.
  • New SBOM-aware transitive risk propagation. Ingests software bill of materials to model dependency-tree vulnerability impact.
  • New FAIR-based financial impact quantification translates technical severity into expected dollar loss.
  • New Read the TRIS v2 white paper →
v1.0 April 2026
  • New Complete CTEM platform: all 5 stages (Scope, Discover, Prioritize, Validate, Mobilize)
  • New BASzy integrated: 150 attack modules, 158,271 payloads, AutoFuzz zero-day discovery
  • New Scanner imports at launch: Nessus, Qualys, Rapid7, OpenVAS, Nuclei, Burp Suite, OWASP ZAP, Trivy, CSV
  • New Agentless discovery: local TCP service discovery, imported multi-scanner exports, and fingerprinting consolidated into one deduplicated asset and attack-path graph
  • New TRIS v1 7-Layer Scoring engine (0-95 scale) with EPSS, KEV, threat actor correlation
  • New AI Agent Task Board: autonomous job execution with streaming output
  • New CVE Triage Queue: kanban workflow (New → Triaged → Assigned → Resolved)
  • New Policy Compliance tracker: 86 controls across 9 frameworks (HIPAA, PCI-DSS, SOC 2, NIST)
  • New Live Attack Surface Canvas: interactive network visualization
  • New Executive reporting: board-ready risk summaries with SLA tracking
v0.4 Feb 2026
  • New AI Agent Task Board: autonomous job execution with streaming output
  • New CVE Triage Queue: kanban workflow (New → Triaged → Assigned → Resolved)
  • New Policy Compliance tracker with clickable metric bubbles
  • Improved Streaming remediation with live EPSS + KEV enrichment
  • Fix Chain-of-thought stripping, clean output in all modes
v0.3 Jan 2026
  • New Multi-provider AI: cloud and local models supported
  • New AES-256-GCM API key encryption at rest
  • New Remediation script generation with per-CVE caching
  • Improved TRIS score with industry multipliers + compliance weighting
  • New AI Security Chat with model picker and streaming
v0.2 Dec 2025
  • New EPSS + KEV enrichment on every CVE ingest
  • New Watchlist with Slack/Teams webhook alerts
  • Improved SQLite WAL mode + 32MB cache for scan performance
  • Fix Streaming timeout fixed: idle timeout removed from server
v0.1 Nov 2025
  • New Initial release: NVD ingestion, CVE search, AI remediation
  • New Bun + Hono backend, React 19 + Vite frontend
  • New SQLite local cache, Docker + Railway deploy targets

What's Next

Q3 2026: In Progress
Multi-user deployment
In Progress

Team roles (Analyst, Manager, Read-Only), assignment workflows, and audit log. Enterprise license feature.

Windows, Linux, and Docker
Planned

Multi-platform builds and a Docker deployment option alongside the native macOS app.

Q4 2026: Planned
Bi-directional ITSM sync
Planned

Two-way status sync with Jira and ServiceNow. Ticket resolved means the CVE is automatically re-scanned, with SLA reporting across ticketing systems.

Later
Container image scanning
Planned

Docker and OCI image vulnerability scanning across build and registry layers. Cloud posture (CSPM) and cloud identity attack-path (CIEM) for AWS, Azure, and GCP have already shipped in the Cloud Scan Engine.

SSO / SAML
Planned

Enterprise identity provider integration for organizations with centralized authentication requirements.

Have a feature request? We're building this in close collaboration with early adopters.

Request a Feature →