Changelog

What changed

Only meaningful product changes — no internal noise. Security-relevant changes are marked. Follow releases with the Atom feed at /changelog/feed.xml.

  • Feature12 Sep 2026

    Enterprise platform: SSO, API, integrations, intelligence and CRA assistant

    Vellaci now runs as an enterprise product-security operating system: SAML/OIDC SSO, scoped API tokens and public API, webhooks, Jira/Linear/Slack/Teams/PagerDuty, GitLab, EPSS and exploitation signals, VEX, release gates, signed CRA submissions, drills, AI assistance, partner portal and auditor mode.

    Security & identity

    • SAML / OIDC single sign-on with domain verification, JIT provisioning and role mapping
    • Organisation MFA enforcement, recovery codes, two-person approvals for high-risk operations
    • Tamper-evident audit log (hash chain) with CSV/JSON/PDF export and integrity metadata

    Platform

    • Public REST API (/api/v1) with scoped tokens and OpenAPI 3.1
    • Outgoing webhooks with HMAC signatures, retries and dead-letter handling
    • CLI (vellaci sbom upload --wait --fail-on critical) for CI pipelines

    Integrations

    • Jira Cloud, Linear, Slack, Microsoft Teams, PagerDuty, GitLab; deeper GitHub (Dependabot, advisories, tags)

    Vulnerability intelligence

    • EPSS, exploitation signals, source provenance and conflicts, explainable priority model
    • VEX (CycloneDX) statements and signed documents, license intelligence, SBOM diff, release gates

    CRA reporting

    • Deterministic reporting assistant with field provenance, signed immutable submission snapshots and amendments
    • Runbook readiness, reporting drills, continuity sheet for outages

    Enterprise & commercial

    • Partner portal, auditor mode, saved views, bulk actions, custom fields, tags, policies
    • Contracts, trials, usage metering, customer health, scheduled reports, trust center and status page