// PLATFORM.CHANGELOG
Changelog
Every feature, security hardening, compliance update, and bug fix — in reverse chronological order.
v1.4.0major
- ▸MCP server security controls and agentic threat modelling capabilities
- ▸EU AI Act Article 9 evidence automation — automated documentation trail for high-risk AI systems
- ▸ISO 42001 AI Management System audit trail with control evidence collection
- ▸OWASP LLM Top 10 v2 scanner with updated risk categories and detection logic
- ▸AI-powered alert summarisation with configurable verbosity levels
v1.3.0major
- ▸India DPDP Act 2023 compliance module — full control mapping and evidence collection
- ▸NIST CSF 2.0 Govern function — cybersecurity governance documentation and risk register
- ▸One-click auditor export — complete evidence bundle for SOC 2, ISO 27001, and PCI DSS v4
- ▸Cross-framework mapping view — see how controls across ISO 27001, NIST CSF, and PCI DSS overlap
- ▸SCIM 2.0 provisioning improvements — group push synchronisation with Okta and Azure AD
v1.2.0major
- ▸OWASP CRS v4 upgrade — expanded WAF ruleset with improved false positive reduction
- ▸Virtual patching workflow — deploy WAF rules to protect unpatched vulnerabilities instantly
- ▸API traffic analytics — per-endpoint call volume, error rates, and anomaly detection
- ▸Bot mitigation profiles — configurable bot scoring with managed allow-lists for legitimate crawlers
- ▸Vulnerability scanner EPSS integration — prioritise findings by exploit probability score
v1.1.0minor
- ▸Conditional access policies — context-aware MFA enforcement based on location, device, and risk
- ▸MFA enforcement reporting — per-user and per-tenant MFA adoption dashboard
- ▸Identity risk scoring — composite score combining login anomalies, device posture, and session behaviour
- ▸SCIM 2.0 provisioning — automated user lifecycle management from corporate identity providers
- ▸phishing simulation: QR code attack vector support for modern vishing simulation campaigns
v1.0.0launch
- ▸Initial platform launch — unified console with multi-tenant isolation
- ▸WAF module (ModSecurity + OWASP CRS), EDR module (Wazuh agent), MDM module
- ▸CVE scanner with CISA KEV cross-reference and CVSS severity triage
- ▸SAST scanning (Semgrep) with OWASP Top 10 mapping and repository integration
- ▸Compliance baseline — SOC 2, ISO 27001, PCI DSS v4 initial control set
- ▸MSSP console — multi-tenant management with per-client isolation and reporting
