10/5/26 - Credentials API
| Change Type | Description |
|---|---|
| New Feature | OIDC session caching is now enforced through Auth Service for improved authentication handling. |
| New Feature | Requests using the retired KAS_SERVICE credential purpose are now rejected to improve security and compliance. |
| New Feature | Credential access is now restricted to credential owners unless the requester has super admin privileges. |
| Bug Fix | Patched vulnerabilities in gRPC and the Go builder dependencies. |
10/5/26 - Entity Service
| Change Type | Description |
|---|---|
| Dependency Update | Updated dependencies to address gRPC and cryptography security vulnerabilities. |
9/28/26 - Audit API
| Change Type | Description |
|---|---|
| Bug Fix | Fixed incorrect log level reporting for the Audit API in Datadog. |
| Bug Fix | Deny machine-to-machine (M2M) audit Connect read requests. |
9/24/26 - Credentials API
| Change Type | Description |
|---|---|
| New Feature | Initial release of the Credentials API service with support for credential management, rotation, and access token validation. |
| New Feature | Added OpenTelemetry tracing and metrics for observability. |
| New Feature | Added Entity Service connectivity check to verify downstream service availability. |
| New Feature | Added PostgreSQL connection pooling, database migrations, and configuration support. |
| New Feature | Credential rotation is now crash-recoverable, improving reliability during failures. |
| Bug Fix | Improved service readiness checks by decoupling them from Okta availability. |
| Bug Fix | Improved error identification for credential limit errors. |
9/24/26 - Entity Service
| Change Type | Description |
|---|---|
| Bug Fix | Restricted entity creation to internal callers only, improving security controls. |
9/24/26 - Usage Metrics
| Change Type | Description |
|---|---|
| New Feature | Usage metrics row IDs are now derived from Pub/Sub message IDs for improved traceability and deduplication. |
| Bug Fix | Updated curl in the Dockerfile to address a security vulnerability. |
9/24/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Bug Fix | Improved list filtering to fail closed when a filtering decision cannot be determined. |
| Bug Fix | Stopped reflecting the exchanged token in the ACL owner to prevent unintended token exposure. |
| Bug Fix | Preserved attribute namespace when resolving attribute values. |
9/24/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Resolved managed client identities in token hook for improved client authentication handling. |
| New Feature | Stamped SPIFFE identity into workload tokens to support workload identity verification. |
| Bug Fix | Ensured super-admin claim is always set for client credentials flows. |
| Bug Fix | Made shared-domain organization lookups deterministic to prevent inconsistent results. |
9/23/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Improved handling of upstream CKS errors for more reliable key management operations. |
| New Feature | S3 object ACL is now configurable, providing greater flexibility in storage access control settings. |
9/16/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| Bug Fix | Updated js-yaml dependency to resolve a potential security or stability issue. |
9/16/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Bug Fix | Pinned libcrypto and libssl3 in the Dockerfile for improved security and stability. |
9/16/26 - Audit Worker
| Change Type | Description |
|---|---|
| Bug Fix | Resolved security vulnerabilities by updating dependencies including uuid, protobufjs, and axios. |
9/16/26 - Task-manager
| Change Type | Description |
|---|---|
| Bug Fix | Updated axios dependency to address a security vulnerability. |
9/16/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with secure no-auth policy creation. |
| Bug Fix | Fixed organization OUs not being loaded during per-policy metadata authentication. |
9/16/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Extended redirect validation to the email login flow to address a security vulnerability. |
9/9/26 - Policy Microservice
| Change Type | Description |
|---|---|
| Improvement | Addressed security vulnerabilities. |
| Bug Fix | Prevented application panics caused by certain error responses. |
9/8/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Secured magic-login redirects to prevent unauthorized access. |
| Bug Fix | Enforced required permissions for organization creation. |
9/8/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Pinned libcrypto and libssl3 in the Dockerfile for improved dependency stability. |
| Bug Fix | Added validation of Virtru domain boundaries to improve security. |
| Bug Fix | Added support for Admin Console redirect domains. |
9/4/26 - Domain Map Processor
| Change Type | Description |
|---|---|
| New Feature | Entity addresses are now written through the Postgres store. |
| New Feature | Added support for a custom batch size when fetching user settings from DynamoDB. |
| Bug Fix | Fixed an issue where data was incorrectly written to PostgreSQL for organizations that do not use the entity store. |
8/27/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added functionality to block the synchronization of group aliases. |
8/27/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added support for blocking the sync of group aliases using the ignoreGroupAliases organization flag. |
8/26/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Auth code sessions are now retired when a magic login link is used, improving session security. |
| Bug Fix | Expired SAML certificates are now allowed for IP allowlist reads, preventing access disruptions during certificate transitions. |
| Bug Fix | Salesforce users are now correctly associated with existing organizations upon login. |
8/26/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue with handling shared-domain SAML token hooks. |
8/25/26 - Saas-s4
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
8/25/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the .tdf suffix was not being appended during multipart upload abort operations in passthrough mode. |
v1.11.0 - 8/24/26
| Change Type | Description |
|---|---|
| New Feature | Updated copy for the Secure Share client to improve clarity. |
| New Feature | Enhanced the popup login flow with authentication state snapshotting and improved payload handling. |
| New Feature | Added a Help Center link to the "Check your inbox" page to assist users who need support during login. |
| New Feature | Added support for CLI (loopback) login, delivering access and refresh tokens via query parameters along with organization subdomain and branding. |
| New Feature | Added local validation and persistence of app ID bundle expiry to improve session reliability. |
| Bug Fix | Migrated login request data storage from localStorage to cookies for improved reliability and security. |
| Bug Fix | Enhanced error handling and user feedback for login failures to provide clearer guidance when issues occur. |
| Bug Fix | Updated Caddy to v2.11.4 to address security vulnerabilities. |
| Bug Fix | Fixed a layout issue in the design system. |
| Bug Fix | Disabled caching for index.html to ensure users always receive the latest version. |
| Bug Fix | Resolved a security vulnerability in the popup login flow. |
8/21/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Enforces organization maximum access duration limits for added policy control. |
| Bug Fix | Prevents unauthorized child policy takeover when no-auth policies are in use. |
8/27/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added functionality to block the synchronization of group aliases. |
8/27/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added support for blocking the sync of group aliases using an organization-level flag. |
8/26/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Auth code sessions are now retired when a magic login link is used, improving session security. |
| Bug Fix | Salesforce users are now correctly associated with existing organizations during login. |
| Bug Fix | SAML certificates that have expired are now permitted for IP allowlist reads, preventing disruptions when certificates expire. |
8/26/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Improved handling of shared-domain SAML token hooks. |
8/25/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the .tdf suffix was not being appended correctly during multipart upload abort operations in passthrough mode. |
v1.11.0 - 8/24/26
| Change Type | Description |
|---|---|
| New Feature | Updated copy and messaging for the Secure Share client. |
| New Feature | Enhanced popup login flow with improved auth state handling and payload processing. |
| New Feature | Added a Help Center link to the "Check your inbox" page to assist users during login. |
| New Feature | Added support for CLI (loopback) login, delivering access and refresh tokens via query parameters along with org subdomain and branding. |
| New Feature | Improved session management by persisting and locally validating app bundle expiry. |
| Improvement | Enhanced error handling and user feedback for login failures. |
| Bug Fix | Migrated login request data storage from localStorage to cookies for improved reliability. |
| Bug Fix | Updated Caddy to v2.11.4 to address security vulnerabilities. |
| Bug Fix | Fixed a layout issue in the design system. |
| Bug Fix | Disabled caching for index.html to ensure users always receive the latest version. |
| Bug Fix | Resolved a security vulnerability in the popup login flow. |
8/21/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Enforces organization maximum access duration limits to ensure policies comply with organization-level restrictions. |
| Bug Fix | Prevented unauthorized child policy takeover in no-auth scenarios. |
8/26/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Auth code sessions are now retired when a magic login link is used, improving session security. |
| Improvements | Minor improvements, enhancements, and bug fixes |
8/26/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue with handling shared-domain SAML token hooks. |
8/25/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the .tdf suffix was not being appended correctly during passthrough AbortMultipartUpload operations. |
v1.11.0 - 8/24/26
| Change Type | Description |
|---|---|
| New Feature | Updated copy for the Secure Share client. |
| New Feature | Enhanced the popup login flow with improved auth state handling and payload management. |
| New Feature | Added a Help Center link to the "Check your inbox" page to assist users who need additional guidance. |
| New Feature | Added support for CLI (loopback) login, delivering access and refresh tokens with organization subdomain and branding. |
| New Feature | Improved session management by persisting and locally validating app bundle expiry. |
| Bug Fix | Improved login request data storage for increased reliability and security. |
| Bug Fix | Enhanced error handling and user feedback for login failures. |
| Bug Fix | Updated Caddy to v2.11.4 to address security vulnerabilities. |
| Bug Fix | Fixed a layout issue in the login interface. |
| Bug Fix | Disabled caching for the index page to ensure users always receive the latest version. |
| Bug Fix | Resolved a security vulnerability in the popup login flow. |
8/21/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Enforces a maximum access duration at the organization level, ensuring policies comply with configured time limits. |
| Bug Fix | Prevented an issue where a no-auth child policy could improperly take over parent policy settings. |
8/20/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added support for PostgreSQL in domain map synchronization. |
| Improvement | The organization's delegation email is now always used unless the sync fails, improving reliability of domain map syncs. |
| Bug Fix | Resolved an issue where domain map syncs could get stuck. |
| Bug Fix | Applied a security fix for the axios dependency. |
8/19/26 - Single Login
| Change Type | Description |
|---|---|
| Improvement | Added support for CLI (loopback) login via popup, including organization subdomain and branding support. |
| Improvement | Addressed a security vulnerability in the gRPC dependency (GHSA-hrxh-6v49-42gf). |
8/18/26 - Single Login
| Change Type | Description |
|---|---|
| Improvement | Updated copy for the Secure Share client. |
| Bug Fix | Corrected an error boundary issue and fixed a layout problem. |
8/18/26 - Saas-s4
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
8/12/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added support for domain map v2 with PostgreSQL-backed storage. |
| Improvement | The organization's delegation email is now always used unless synchronization fails, improving reliability. |
| Bug Fix | Updated dependencies to address an Axios security vulnerability. |
v2.2.1 - 8/13/26
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue where RSA 4096 partner keys caused encryption failures. |
| Bug Fix | Fixed an issue where the Missing Required Tag flag was not being processed correctly for attachments. |
| Bug Fix | Corrected an issue where key mappings were not being applied or respected during message processing. |
| Bug Fix | Fixed an issue where email body text was being included in Event Viewer and SDK logs. |
8/12/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added PostgreSQL migration support including external ID, parent group IDs, and feature flag handling. |
| Improvement | Renamed internal configuration flag for entity store to improve clarity and consistency. |
| Bug Fix | Updated dependencies to resolve security vulnerabilities including CVEs affecting UUID and Protocol Buffers libraries. |
| Bug Fix | Updated Axios dependency to address a security vulnerability. |
| Bug Fix | Fixed initialization order for tracing instrumentation to ensure it loads before instrumented modules. |
8/12/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added support for managing the maximum policy access duration setting at the organization level. |
| New Feature | External policy duration is now exposed in user settings. |
| Improvement | Reimplemented organization unit distributed cache for improved performance and reliability. |
| Improvement | Global branding now uses the default subdomain configuration. |
| Bug Fix | Corrected the naming of the maximum external policy access duration setting for consistency. |
8/12/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Improved resilience when reading SAML configurations that contain references to Okta identity providers that no longer exist. |
8/12/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
8/8/26 - Single Login
| Change Type | Description |
|---|---|
| New Feature | Added observability for the login user iframe to improve monitoring and diagnostics. |
| New Feature | App ID bundle expiry is now persisted and validated locally for improved reliability. |
| Bug Fix | Updated Caddy to v2.11.4 to address security vulnerabilities. |
| Bug Fix | Disabled caching for index.html to ensure users always receive the latest version. |
8/5/26 - Audit API
| Change Type | Description |
|---|---|
| New Feature | Added support for audit protobuf contract to improve audit data structure and compatibility. |
| New Feature | Added Connect OIDC authentication support for secure service-to-service communication. |
| New Feature | Exposed Connect audit read routes to enable querying audit data via the Connect interface. |
| Bug Fix | Malformed audit records are now skipped instead of causing the entire batch to fail, improving reliability of audit processing. |
8/3/26 - Secure Share Service
| Change Type | Description |
|---|---|
| New Feature | Added a new endpoint for submitting data to forms, enabling more flexible form submission workflows. |
| New Feature | Added subject pattern support when retrieving secure forms, allowing more targeted form lookups. |
| Improvement | Added health check integration with Auth Service to improve service reliability monitoring. |
| Bug Fix | Updated Secure Share ACM attribute fully qualified name to ensure correct attribute resolution. |
| Bug Fix | Fixed authentication token extraction to ensure proper token handling. |
| Bug Fix | Fixed pagination and added total count to form submissions retrieval for more accurate results. |
| Bug Fix | Resolved an issue with submissions pagination returning incorrect results. |
| Bug Fix | Blocked invalid characters in allowed origins validation to improve security. |
8/3/26 - Domain Map Processor
| Change Type | Description |
|---|---|
| New Feature | Added support for user/entity data storage in PostgreSQL, including dual-write capabilities for both user and organization data. |
| Bug Fix | Resolved a security vulnerability by updating the uuid dependency to address CVE-2026-41907. |
| Bug Fix | Fixed delegation email configuration to be correctly applied at both root and synchronization levels. |
| Bug Fix | Updated axios dependency to resolve a security vulnerability. |
7/30/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/29/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved a security vulnerability (CVE-2026-41907) by updating the uuid dependency. |
| Bug Fix | Updated axios dependency to address a security vulnerability. |
7/29/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Updated the uuid library to resolve a security vulnerability (CVE-2026-41907). |
| Bug Fix | Updated axios dependency to address a security vulnerability. |
7/29/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added a new endpoint to retrieve recipient login methods for an organization. |
| Bug Fix | Fixed an audit-related issue and updated internal common utilities. |
7/28/26 - Saas-dsp
| Change Type | Description |
|---|---|
| New Feature | Added tenant isolation enforcement across policy services, resource mappings, group mutations, and attribute management to ensure strict data separation between tenants. |
| New Feature | Introduced a permission service to enable more granular access control across policy operations. |
| Improvement | Restricted key read access to authorized operations only, improving overall security posture. |
| Bug Fix | Resolved an issue where the isolation interceptor would execute even when disabled. |
| Bug Fix | Addressed a security vulnerability by updating a dependency with a known CVE. |
| Bug Fix | Updated the OpenTDF platform service to the latest version for improved stability and compatibility. |
7/23/26 - Accounts
| Change Type | Description |
|---|---|
| Improvement | Reimplemented membership distributed cache for improved performance and reliability. |
| Bug Fix | Fixed an issue with the health check endpoint. |
7/23/26 - KAS
| Change Type | Description |
|---|---|
| Bug Fix | Upgraded PyJWT to address a security vulnerability (CVE-2026-48526). |
| Improvement | Updated Alpine package pins to the latest available versions. |
7/23/26 - Policy-microservice
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/22/26 - RCA Link Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/21/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/20/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for sending transactions, including proper handling of BCC-only sends and prevention of duplicate recipients. |
| New Feature | Added a new endpoint to retrieve recipient authentication methods. |
| New Feature | Added MX record lookup and domain filtering capabilities. |
| Improvement | Improved validation to prevent malformed SAML certificates from being accepted. |
| Bug Fix | Resolved a security issue by sanitizing NoSQL operator injection in the Accounts API. |
| Bug Fix | Improved cache resilience and stability, including robust password rotation logic for distributed cache. |
7/16/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved OpenSSH security vulnerabilities by updating to a patched version. |
7/15/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Added support for the RFC 8252 loopback interface redirect URI exception, improving compatibility with native application authentication flows. |
| New Feature | Login method restrictions are now enforced on the authentication methods endpoint, ensuring only permitted login methods are available per configuration. |
| Bug Fix | Resolved a security vulnerability by sanitizing NoSQL operator injection inputs in the Auth Service. |
| Bug Fix | Updated internal dependencies to incorporate transitive security fixes. |
7/9/26 - Audit API
| Change Type | Description |
|---|---|
| Bug Fix | Updated golang.org/x/net dependency to address a security vulnerability (CVE fix). |
7/9/26 - Audit-worker
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to address transitive security vulnerabilities. |
7/9/26 - Domain-map-processor
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the primary organization ID was not being set correctly when saving user settings. |
| Bug Fix | Updated internal dependencies to address transitive security vulnerabilities. |
7/9/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to incorporate transitive security fixes. |
7/9/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to address transitive security vulnerabilities. |
7/9/26 - Task-manager
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to incorporate transitive security fixes. |
7/9/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for send transactions, including handling of BCC-only sends and prevention of duplicate recipients. |
| Improvement | Added validation to prevent malformed SAML certificates from being accepted during configuration. |
| Improvement | Added a new endpoint to retrieve authentication methods available for message recipients. |
| Bug Fix | Resolved a security vulnerability related to NoSQL operator injection in the Accounts API. |
| Bug Fix | Improved cache rotation resilience to prevent disruptions during cache updates. |
| Dependency Update | Updated internal dependencies to include transitive security fixes. |
7/7/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Added support for forcing SAML NameID to unspecified format on a per-organization basis. |
7/7/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/2/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Bug Fix | Fixed filtering of stats in the Iceberg Plugin for all ABAC protected tables. |
| Bug Fix | Fixed handling of decoded content length for streaming PUT requests to ensure correct size is used. |
6/26/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| New Feature | Usage metrics now emit actual stored object sizes, with support for CopyObject and DeleteObjects operations and improved reconciliation logging. |
| Bug Fix | Token exchange is now skipped for machine-to-machine client credentials tokens, improving authentication flow for M2M integrations. |
| Bug Fix | Added scope support to Okta configuration and token exchange requests for M2M authentication. |
| Bug Fix | Updated cryptography libraries to address critical security vulnerabilities. |
6/22/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Added a warning log when a CKS organization creates a non-CKS policy, improving visibility into potential configuration issues. |
6/22/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for send transactions. |
| Improvement | Minor improvements, enhancements, and bug fixes |
6/18/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/7/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Added support for organizations to enforce SAML NameID unspecified format. |
7/7/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/22/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Improved logging for CKS orgs |
6/22/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for send transactions. |
| Improvement | Minor improvements, enhancements, and bug fixes |
6/18/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/18/26 - Usage Metrics
| Change Type | Description |
|---|---|
| New Feature | Implemented internal authentication and session cache validation. |
6/10/26 - Domain Map Processor
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with adminGroup Protect Delegation Email. |
6/9/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue requiring a SAML profile mapping update. |
6/8/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Updated SAML profile mappings. |
6/4/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added internal auth health check endpoint for monitoring service authentication status. |
| New Feature | Added support for a public OIDC feature flag. |
| Dependency Update | Updated dependencies to support bypassing password-protected file scans. |
6/4/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Added an internal authentication health check to improve service reliability monitoring. |
| Bug Fix | Fixed an issue with ACM Common version bumping. |
6/4/26 - Auth Service
| Change Type | Description |
|---|---|
| Dependency Update | Updated qs, body-parser, and express dependencies. |
6/3/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/3/26 - Domain-map-processor
| Change Type | Description |
|---|---|
| Improvement | Reduced internal dependencies and removed unused packages to streamline the service. |
| Dependency Update | Updated several dependencies including axios, fast-xml-parser, uuid, fast-uri, and protobufjs to their latest versions. |
6/3/26 - Audit Worker
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/1/26 - Right-to-be-forgotten
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/29/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| New Feature | Added Zendesk Token Manager UI, enabling configuration and management of Zendesk delivery channel tokens. |
6/4/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added internal auth health check support. |
| New Feature | Added support for a public OIDC feature flag. |
6/4/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Added an internal auth health check to improve service reliability monitoring. |
| Bug Fix | Fixed an issue with the ACM Common dependency bump process. |
6/4/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/3/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
6/3/26 - Domain-map-processor
| Change Type | Description |
|---|---|
| Improvement | Reduced internal dependencies and removed unused packages to streamline the service. |
| Dependency Update | Updated several dependencies including axios, fast-xml-parser, uuid, fast-uri, and protobufjs to their latest versions. |
6/3/26 - Audit Worker
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/1/26 - Right-to-be-forgotten
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/29/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| New Feature | Added Zendesk Token Manager UI to support Zendesk integration configuration. |
5/21/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the identity provider enabled state was not automatically updated when configuration state changed. |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Resolved a vulnerability by removing an unused dependency. |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Improved shared-domain SAML selection to correctly apply across login and activation routes. |
6/1/26 - Right-to-be-forgotten
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/29/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| New Feature | Added Zendesk Token Manager UI, enabling configuration and management of Zendesk delivery channel tokens. |
5/21/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue where the identity provider enabled state was not automatically updated when configuration changes occurred. |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Resolved a security vulnerability by removing a deprecated dependency. |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Corrected shared-domain SAML selection so it is properly applied to login and activation routes. |
5/20/26 - Lambda Retroactive CKS Key Rotation
| Change Type | Description |
|---|---|
| Bug Fix | Resolved security vulnerabilities in the service. |
| Dependency Update | Updated multiple dependencies to address security vulnerabilities and ensure compatibility. |
5/20/26 - Secure Share Service
| Change Type | Description |
|---|---|
| New Feature | Introduced API support for secure intake forms, enabling users to securely submit data through structured forms. |
| New Feature | Added endpoint to retrieve a list of submissions by form. |
| New Feature | Added public endpoint to retrieve form details by ID. |
| New Feature | Form list endpoint now returns the total count of forms. |
| New Feature | Added support for creating, retrieving, updating, revoking, and restoring secure shares. |
| New Feature | Added file share endpoint for securely sharing files. |
| Improvement | Updated allowed origins validation in the Secure Forms API to enforce HTTPS URLs for improved security. |
| Bug Fix | Resolved issues with admin access and API error handling. |
| Bug Fix | Fixed authorization check for admins within their own organization. |
5/20/26 - Lambda KMS Manager
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with invalid encrypted payloads. |
| Dependency Update | Updated multiple dependencies including axios, lodash, node-forge, protobufjs, validator, and others to address security vulnerabilities and maintain compatibility. |
5/20/26 - Lambda Dynamo Streams Trigger
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/21/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Corrected SAML provider selection for shared-domain login and account activation flows. |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
5/18/26 - virtru-kas
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/6/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Minor improvements |
5/6/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvements | Minor improvements |
5/6/26 - Accounts
| Change Type | Description |
|---|---|
| Improvements | Improved behavior when a domain exists in two tenants |
| Improvements | Minor improvements |
4/29/26 - Single Login
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an OAuth login issue affecting Safari users. |
| Bug Fix | Fixed a caching issue that could cause incorrect application bundles to be retrieved. |
| Bug Fix | Fixed a sign-in issue preventing users from accessing Secure Reader. |
| Bug Fix | Resolved security vulnerabilities. |
| Bug Fix | Fixed an OIDC CORS issue affecting authentication flows. |
| Improvement | Improved popup login experience. |
| Improvement | Improved mobile client identification for Single Login. |
| Improvement | Added cookie support to handle email verification flow. |
4/29/26 - Bounce Handler
| Change Type | Description |
|---|---|
| Improvements | Improved bounce messaging with additional diagnostics information. |
| Dependency Update | Updated dependencies to resolve security vulnerabilities. |
4/20/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Added system_wrap action type to ensure CSE system‑wrap audit events are recorded with the correct action type |
4/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Resolves an issue where users with domains that exist in multiple Virtru accounts may see incorrect branding |
| Improvements | Minor improvements |
4/7/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Various bug fixes |
| Improvements | Resolved vulnerabilities |
4/1/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Internal optimizations |
1/12/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with expired certs in inactive SAML configs causing activation failures |
1/8/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Fix an issue with OU admins "Decrypt Secure Content" permission |
11/20/25 - ACM
| Change Type | Description |
|---|---|
| Dependency updates | Updated js-yaml and validator dependencies to address security vulnerabilities |
11/20/25 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Improved DLP Rules: Enhanced warning messages for DLP conditions using 'is not in' logic, providing clearer visibility into which rules are triggered |
| Bug Fix | DLP Rule Auditing: Fixed validation logic that prevented auditing "log only" default DLP rules. |
| Dependency update | Updated js-yaml and validator dependencies to address security vulnerabilities |
11/4/25 - ACM
| Change Type | Description |
|---|---|
| Dependency updates | Regular security patches to our internal services |
| Bug Fix | Fix an issue with OU admins "Decrypt Secure Content" permission |
10/8/25 - Audit API
| Change Type | Description |
|---|---|
| Dependency updates | Regular security patches to our internal services |
| Improvement | Optimized Database Connection Handling Improved efficiency and stability of backend database connections for better performance under load. |
| Documentation | Swagger Documentation Cleanup Refined API documentation for clearer integration and developer experience. |
10/1/25 - Auth Services
| Change Type | Description |
|---|---|
| Dependency updates | Upgraded Axios from version 1.11.0 to 1.12.1 for improved stability and performance |
| Improvement | Introduced OIDC activation flow for Control Center More details here: https://support.virtru.com/hc/en-us/articles/1500010826821-Control-Center-Admin-Overview |
10/1/25 - ACM
| Change Type | Description |
|---|---|
| Dependency updates | Upgraded Axios from version 1.11.0 to 1.12.1 for improved stability and performance |
10/1/25 - Accounts
| Change Type | Description |
|---|---|
| Features | Added a new endpoint that retrieves subdomain branding information via email domains |
9/18/25 - Accounts
| Change Type | Description |
|---|---|
| Bug fix | Resolved an issue where non-public S3 buckets were incorrectly assigned a public-read ACL. This fix ensures tighter access control and improved data security. |
| Dependency Updates |
Upgraded Axios from version 1.11.0 to 1.12.1 for improved stability and performance |
9/15/25 - Domain Map Processor
| Change Type | Description |
|---|---|
| Improvement | Improvement to UPN handling for Microsoft 365 Organizations |