Changelog

What shipped, and when.

  1. Policy Library

    Bring your own security policies and enforce them in plain language.

    • NewUpload policies as PDF, Word, Markdown or text and ask them questions in plain language, including Vietnamese.
    • NewTurn any policy section into a rule from a few example messages. Rules warn first and block when you switch them on.
    • NewBlocked requests show the policy sections they relate to, in one click.
  2. AI detection in 50-100 ms

    The AI prompt-injection check now decides in 50-100 ms in production.

    • ImprovedMeasured across multiple production workspaces under attack traffic, down from 130-150 ms.
  3. Real-time notifications

    The dashboard now tells the right people the moment something needs them.

    • NewLive alerts for pending Copilot approvals, High and Critical intercepts, blocked pull requests, quota at 80% and 100%, and webhook delivery failures. Each alert goes only to members whose role can act on it.
    • ImprovedIDE intercept history with full totals and paging through older records.
    • ImprovedSecrets found in pull-request scans are masked in every stored record.
  4. Faster AI detection

    The AI prompt-injection check now decides in 130-150 ms in production.

    • ImprovedThe AI check runs only when it is needed, so most requests are decided in under a millisecond.
  5. Stronger API protection

    Safer webhooks and API traffic.

    • ImprovedStronger protection for webhook destinations and API traffic.
  6. Two-factor authentication

    Protect every account with TOTP.

    • NewTwo-factor authentication with any authenticator app, plus single-use backup codes.
    • ImprovedDashboard browsing no longer counts toward your request quota.
    • ImprovedGitHub App scans are metered without ever blocking a webhook.