8/20/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added support for PostgreSQL in domain map synchronization. |
| Improvement | The organization's delegation email is now always used unless the sync fails, improving reliability of domain map syncs. |
| Bug Fix | Resolved an issue where domain map syncs could get stuck. |
| Bug Fix | Applied a security fix for the axios dependency. |
8/19/26 - Single Login
| Change Type | Description |
|---|---|
| Improvement | Added support for CLI (loopback) login via popup, including organization subdomain and branding support. |
| Improvement | Addressed a security vulnerability in the gRPC dependency (GHSA-hrxh-6v49-42gf). |
8/18/26 - Single Login
| Change Type | Description |
|---|---|
| Improvement | Updated copy for the Secure Share client. |
| Bug Fix | Corrected an error boundary issue and fixed a layout problem. |
8/18/26 - Saas-s4
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
8/12/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added support for domain map v2 with PostgreSQL-backed storage. |
| Improvement | The organization's delegation email is now always used unless synchronization fails, improving reliability. |
| Bug Fix | Updated dependencies to address an Axios security vulnerability. |
v2.2.1 - 8/13/26
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue where RSA 4096 partner keys caused encryption failures. |
| Bug Fix | Fixed an issue where the Missing Required Tag flag was not being processed correctly for attachments. |
| Bug Fix | Corrected an issue where key mappings were not being applied or respected during message processing. |
| Bug Fix | Fixed an issue where email body text was being included in Event Viewer and SDK logs. |
8/12/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| New Feature | Added PostgreSQL migration support including external ID, parent group IDs, and feature flag handling. |
| Improvement | Renamed internal configuration flag for entity store to improve clarity and consistency. |
| Bug Fix | Updated dependencies to resolve security vulnerabilities including CVEs affecting UUID and Protocol Buffers libraries. |
| Bug Fix | Updated Axios dependency to address a security vulnerability. |
| Bug Fix | Fixed initialization order for tracing instrumentation to ensure it loads before instrumented modules. |
8/12/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added support for managing the maximum policy access duration setting at the organization level. |
| New Feature | External policy duration is now exposed in user settings. |
| Improvement | Reimplemented organization unit distributed cache for improved performance and reliability. |
| Improvement | Global branding now uses the default subdomain configuration. |
| Bug Fix | Corrected the naming of the maximum external policy access duration setting for consistency. |
8/12/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Improved resilience when reading SAML configurations that contain references to Okta identity providers that no longer exist. |
8/12/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
8/8/26 - Single Login
| Change Type | Description |
|---|---|
| New Feature | Added observability for the login user iframe to improve monitoring and diagnostics. |
| New Feature | App ID bundle expiry is now persisted and validated locally for improved reliability. |
| Bug Fix | Updated Caddy to v2.11.4 to address security vulnerabilities. |
| Bug Fix | Disabled caching for index.html to ensure users always receive the latest version. |
8/5/26 - Audit API
| Change Type | Description |
|---|---|
| New Feature | Added support for audit protobuf contract to improve audit data structure and compatibility. |
| New Feature | Added Connect OIDC authentication support for secure service-to-service communication. |
| New Feature | Exposed Connect audit read routes to enable querying audit data via the Connect interface. |
| Bug Fix | Malformed audit records are now skipped instead of causing the entire batch to fail, improving reliability of audit processing. |
8/3/26 - Secure Share Service
| Change Type | Description |
|---|---|
| New Feature | Added a new endpoint for submitting data to forms, enabling more flexible form submission workflows. |
| New Feature | Added subject pattern support when retrieving secure forms, allowing more targeted form lookups. |
| Improvement | Added health check integration with Auth Service to improve service reliability monitoring. |
| Bug Fix | Updated Secure Share ACM attribute fully qualified name to ensure correct attribute resolution. |
| Bug Fix | Fixed authentication token extraction to ensure proper token handling. |
| Bug Fix | Fixed pagination and added total count to form submissions retrieval for more accurate results. |
| Bug Fix | Resolved an issue with submissions pagination returning incorrect results. |
| Bug Fix | Blocked invalid characters in allowed origins validation to improve security. |
8/3/26 - Domain Map Processor
| Change Type | Description |
|---|---|
| New Feature | Added support for user/entity data storage in PostgreSQL, including dual-write capabilities for both user and organization data. |
| Bug Fix | Resolved a security vulnerability by updating the uuid dependency to address CVE-2026-41907. |
| Bug Fix | Fixed delegation email configuration to be correctly applied at both root and synchronization levels. |
| Bug Fix | Updated axios dependency to resolve a security vulnerability. |
7/30/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/29/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved a security vulnerability (CVE-2026-41907) by updating the uuid dependency. |
| Bug Fix | Updated axios dependency to address a security vulnerability. |
7/29/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Updated the uuid library to resolve a security vulnerability (CVE-2026-41907). |
| Bug Fix | Updated axios dependency to address a security vulnerability. |
7/29/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added a new endpoint to retrieve recipient login methods for an organization. |
| Bug Fix | Fixed an audit-related issue and updated internal common utilities. |
7/28/26 - Saas-dsp
| Change Type | Description |
|---|---|
| New Feature | Added tenant isolation enforcement across policy services, resource mappings, group mutations, and attribute management to ensure strict data separation between tenants. |
| New Feature | Introduced a permission service to enable more granular access control across policy operations. |
| Improvement | Restricted key read access to authorized operations only, improving overall security posture. |
| Bug Fix | Resolved an issue where the isolation interceptor would execute even when disabled. |
| Bug Fix | Addressed a security vulnerability by updating a dependency with a known CVE. |
| Bug Fix | Updated the OpenTDF platform service to the latest version for improved stability and compatibility. |
7/23/26 - Accounts
| Change Type | Description |
|---|---|
| Improvement | Reimplemented membership distributed cache for improved performance and reliability. |
| Bug Fix | Fixed an issue with the health check endpoint. |
7/23/26 - KAS
| Change Type | Description |
|---|---|
| Bug Fix | Upgraded PyJWT to address a security vulnerability (CVE-2026-48526). |
| Improvement | Updated Alpine package pins to the latest available versions. |
7/23/26 - Policy-microservice
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/22/26 - RCA Link Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/21/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/20/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for sending transactions, including proper handling of BCC-only sends and prevention of duplicate recipients. |
| New Feature | Added a new endpoint to retrieve recipient authentication methods. |
| New Feature | Added MX record lookup and domain filtering capabilities. |
| Improvement | Improved validation to prevent malformed SAML certificates from being accepted. |
| Bug Fix | Resolved a security issue by sanitizing NoSQL operator injection in the Accounts API. |
| Bug Fix | Improved cache resilience and stability, including robust password rotation logic for distributed cache. |
7/16/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved OpenSSH security vulnerabilities by updating to a patched version. |
7/15/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Added support for the RFC 8252 loopback interface redirect URI exception, improving compatibility with native application authentication flows. |
| New Feature | Login method restrictions are now enforced on the authentication methods endpoint, ensuring only permitted login methods are available per configuration. |
| Bug Fix | Resolved a security vulnerability by sanitizing NoSQL operator injection inputs in the Auth Service. |
| Bug Fix | Updated internal dependencies to incorporate transitive security fixes. |
7/9/26 - Audit API
| Change Type | Description |
|---|---|
| Bug Fix | Updated golang.org/x/net dependency to address a security vulnerability (CVE fix). |
7/9/26 - Audit-worker
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to address transitive security vulnerabilities. |
7/9/26 - Domain-map-processor
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the primary organization ID was not being set correctly when saving user settings. |
| Bug Fix | Updated internal dependencies to address transitive security vulnerabilities. |
7/9/26 - Azure AD Domain Map Generator
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to incorporate transitive security fixes. |
7/9/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to address transitive security vulnerabilities. |
7/9/26 - Task-manager
| Change Type | Description |
|---|---|
| Bug Fix | Updated internal dependencies to incorporate transitive security fixes. |
7/9/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for send transactions, including handling of BCC-only sends and prevention of duplicate recipients. |
| Improvement | Added validation to prevent malformed SAML certificates from being accepted during configuration. |
| Improvement | Added a new endpoint to retrieve authentication methods available for message recipients. |
| Bug Fix | Resolved a security vulnerability related to NoSQL operator injection in the Accounts API. |
| Bug Fix | Improved cache rotation resilience to prevent disruptions during cache updates. |
| Dependency Update | Updated internal dependencies to include transitive security fixes. |
7/7/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Added support for forcing SAML NameID to unspecified format on a per-organization basis. |
7/7/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/2/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| Bug Fix | Fixed filtering of stats in the Iceberg Plugin for all ABAC protected tables. |
| Bug Fix | Fixed handling of decoded content length for streaming PUT requests to ensure correct size is used. |
6/26/26 - Secure Object Connector
| Change Type | Description |
|---|---|
| New Feature | Usage metrics now emit actual stored object sizes, with support for CopyObject and DeleteObjects operations and improved reconciliation logging. |
| Bug Fix | Token exchange is now skipped for machine-to-machine client credentials tokens, improving authentication flow for M2M integrations. |
| Bug Fix | Added scope support to Okta configuration and token exchange requests for M2M authentication. |
| Bug Fix | Updated cryptography libraries to address critical security vulnerabilities. |
6/22/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Added a warning log when a CKS organization creates a non-CKS policy, improving visibility into potential configuration issues. |
6/22/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for send transactions. |
| Improvement | Minor improvements, enhancements, and bug fixes |
6/18/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
7/7/26 - Auth Service
| Change Type | Description |
|---|---|
| New Feature | Added support for organizations to enforce SAML NameID unspecified format. |
7/7/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/22/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Improved logging for CKS orgs |
6/22/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added BCC support for send transactions. |
| Improvement | Minor improvements, enhancements, and bug fixes |
6/18/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/18/26 - Usage Metrics
| Change Type | Description |
|---|---|
| New Feature | Implemented internal authentication and session cache validation. |
6/10/26 - Domain Map Processor
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with adminGroup Protect Delegation Email. |
6/9/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue requiring a SAML profile mapping update. |
6/8/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Updated SAML profile mappings. |
6/4/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added internal auth health check endpoint for monitoring service authentication status. |
| New Feature | Added support for a public OIDC feature flag. |
| Dependency Update | Updated dependencies to support bypassing password-protected file scans. |
6/4/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Added an internal authentication health check to improve service reliability monitoring. |
| Bug Fix | Fixed an issue with ACM Common version bumping. |
6/4/26 - Auth Service
| Change Type | Description |
|---|---|
| Dependency Update | Updated qs, body-parser, and express dependencies. |
6/3/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/3/26 - Domain-map-processor
| Change Type | Description |
|---|---|
| Improvement | Reduced internal dependencies and removed unused packages to streamline the service. |
| Dependency Update | Updated several dependencies including axios, fast-xml-parser, uuid, fast-uri, and protobufjs to their latest versions. |
6/3/26 - Audit Worker
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/1/26 - Right-to-be-forgotten
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/29/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| New Feature | Added Zendesk Token Manager UI, enabling configuration and management of Zendesk delivery channel tokens. |
6/4/26 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Added internal auth health check support. |
| New Feature | Added support for a public OIDC feature flag. |
6/4/26 - ACM
| Change Type | Description |
|---|---|
| New Feature | Added an internal auth health check to improve service reliability monitoring. |
| Bug Fix | Fixed an issue with the ACM Common dependency bump process. |
6/4/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/3/26 - Google Domain Map Generator
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
6/3/26 - Domain-map-processor
| Change Type | Description |
|---|---|
| Improvement | Reduced internal dependencies and removed unused packages to streamline the service. |
| Dependency Update | Updated several dependencies including axios, fast-xml-parser, uuid, fast-uri, and protobufjs to their latest versions. |
6/3/26 - Audit Worker
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
6/1/26 - Right-to-be-forgotten
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/29/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| New Feature | Added Zendesk Token Manager UI to support Zendesk integration configuration. |
5/21/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue where the identity provider enabled state was not automatically updated when configuration state changed. |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Resolved a vulnerability by removing an unused dependency. |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Improved shared-domain SAML selection to correctly apply across login and activation routes. |
6/1/26 - Right-to-be-forgotten
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/29/26 - Delivery Channel Service
| Change Type | Description |
|---|---|
| New Feature | Added Zendesk Token Manager UI, enabling configuration and management of Zendesk delivery channel tokens. |
5/21/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Resolved an issue where the identity provider enabled state was not automatically updated when configuration changes occurred. |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Resolved a security vulnerability by removing a deprecated dependency. |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Corrected shared-domain SAML selection so it is properly applied to login and activation routes. |
5/20/26 - Lambda Retroactive CKS Key Rotation
| Change Type | Description |
|---|---|
| Bug Fix | Resolved security vulnerabilities in the service. |
| Dependency Update | Updated multiple dependencies to address security vulnerabilities and ensure compatibility. |
5/20/26 - Secure Share Service
| Change Type | Description |
|---|---|
| New Feature | Introduced API support for secure intake forms, enabling users to securely submit data through structured forms. |
| New Feature | Added endpoint to retrieve a list of submissions by form. |
| New Feature | Added public endpoint to retrieve form details by ID. |
| New Feature | Form list endpoint now returns the total count of forms. |
| New Feature | Added support for creating, retrieving, updating, revoking, and restoring secure shares. |
| New Feature | Added file share endpoint for securely sharing files. |
| Improvement | Updated allowed origins validation in the Secure Forms API to enforce HTTPS URLs for improved security. |
| Bug Fix | Resolved issues with admin access and API error handling. |
| Bug Fix | Fixed authorization check for admins within their own organization. |
5/20/26 - Lambda KMS Manager
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with invalid encrypted payloads. |
| Dependency Update | Updated multiple dependencies including axios, lodash, node-forge, protobufjs, validator, and others to address security vulnerabilities and maintain compatibility. |
5/20/26 - Lambda Dynamo Streams Trigger
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/21/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
5/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Corrected SAML provider selection for shared-domain login and account activation flows. |
5/20/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Minor improvements, enhancements, and bug fixes |
5/18/26 - virtru-kas
| Change Type | Description |
|---|---|
| Improvement | Minor improvements, enhancements, and bug fixes |
5/6/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Minor improvements |
5/6/26 - Auth Service
| Change Type | Description |
|---|---|
| Improvements | Minor improvements |
5/6/26 - Accounts
| Change Type | Description |
|---|---|
| Improvements | Improved behavior when a domain exists in two tenants |
| Improvements | Minor improvements |
4/29/26 - Single Login
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an OAuth login issue affecting Safari users. |
| Bug Fix | Fixed a caching issue that could cause incorrect application bundles to be retrieved. |
| Bug Fix | Fixed a sign-in issue preventing users from accessing Secure Reader. |
| Bug Fix | Resolved security vulnerabilities. |
| Bug Fix | Fixed an OIDC CORS issue affecting authentication flows. |
| Improvement | Improved popup login experience. |
| Improvement | Improved mobile client identification for Single Login. |
| Improvement | Added cookie support to handle email verification flow. |
4/29/26 - Bounce Handler
| Change Type | Description |
|---|---|
| Improvements | Improved bounce messaging with additional diagnostics information. |
| Dependency Update | Updated dependencies to resolve security vulnerabilities. |
4/20/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Added system_wrap action type to ensure CSE system‑wrap audit events are recorded with the correct action type |
4/20/26 - Accounts
| Change Type | Description |
|---|---|
| Bug Fix | Resolves an issue where users with domains that exist in multiple Virtru accounts may see incorrect branding |
| Improvements | Minor improvements |
4/7/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Various bug fixes |
| Improvements | Resolved vulnerabilities |
4/1/26 - ACM
| Change Type | Description |
|---|---|
| Improvements | Internal optimizations |
1/12/26 - Auth Service
| Change Type | Description |
|---|---|
| Bug Fix | Fixed an issue with expired certs in inactive SAML configs causing activation failures |
1/8/26 - ACM
| Change Type | Description |
|---|---|
| Bug Fix | Fix an issue with OU admins "Decrypt Secure Content" permission |
11/20/25 - ACM
| Change Type | Description |
|---|---|
| Dependency updates | Updated js-yaml and validator dependencies to address security vulnerabilities |
11/20/25 - Accounts
| Change Type | Description |
|---|---|
| New Feature | Improved DLP Rules: Enhanced warning messages for DLP conditions using 'is not in' logic, providing clearer visibility into which rules are triggered |
| Bug Fix | DLP Rule Auditing: Fixed validation logic that prevented auditing "log only" default DLP rules. |
| Dependency update | Updated js-yaml and validator dependencies to address security vulnerabilities |
11/4/25 - ACM
| Change Type | Description |
|---|---|
| Dependency updates | Regular security patches to our internal services |
| Bug Fix | Fix an issue with OU admins "Decrypt Secure Content" permission |
10/8/25 - Audit API
| Change Type | Description |
|---|---|
| Dependency updates | Regular security patches to our internal services |
| Improvement | Optimized Database Connection Handling Improved efficiency and stability of backend database connections for better performance under load. |
| Documentation | Swagger Documentation Cleanup Refined API documentation for clearer integration and developer experience. |
10/1/25 - Auth Services
| Change Type | Description |
|---|---|
| Dependency updates | Upgraded Axios from version 1.11.0 to 1.12.1 for improved stability and performance |
| Improvement | Introduced OIDC activation flow for Control Center More details here: https://support.virtru.com/hc/en-us/articles/1500010826821-Control-Center-Admin-Overview |
10/1/25 - ACM
| Change Type | Description |
|---|---|
| Dependency updates | Upgraded Axios from version 1.11.0 to 1.12.1 for improved stability and performance |
10/1/25 - Accounts
| Change Type | Description |
|---|---|
| Features | Added a new endpoint that retrieves subdomain branding information via email domains |
9/18/25 - Accounts
| Change Type | Description |
|---|---|
| Bug fix | Resolved an issue where non-public S3 buckets were incorrectly assigned a public-read ACL. This fix ensures tighter access control and improved data security. |
| Dependency Updates |
Upgraded Axios from version 1.11.0 to 1.12.1 for improved stability and performance |
9/15/25 - Domain Map Processor
| Change Type | Description |
|---|---|
| Improvement | Improvement to UPN handling for Microsoft 365 Organizations |