Changelog
What changed
Only meaningful product changes — no internal noise. Security-relevant changes are marked. Follow releases with the Atom feed at /changelog/feed.xml.
- Feature12 Sep 2026
Enterprise platform: SSO, API, integrations, intelligence and CRA assistant
Vellaci now runs as an enterprise product-security operating system: SAML/OIDC SSO, scoped API tokens and public API, webhooks, Jira/Linear/Slack/Teams/PagerDuty, GitLab, EPSS and exploitation signals, VEX, release gates, signed CRA submissions, drills, AI assistance, partner portal and auditor mode.
Security & identity
- SAML / OIDC single sign-on with domain verification, JIT provisioning and role mapping
- Organisation MFA enforcement, recovery codes, two-person approvals for high-risk operations
- Tamper-evident audit log (hash chain) with CSV/JSON/PDF export and integrity metadata
Platform
- Public REST API (
/api/v1) with scoped tokens and OpenAPI 3.1 - Outgoing webhooks with HMAC signatures, retries and dead-letter handling
- CLI (
vellaci sbom upload --wait --fail-on critical) for CI pipelines
Integrations
- Jira Cloud, Linear, Slack, Microsoft Teams, PagerDuty, GitLab; deeper GitHub (Dependabot, advisories, tags)
Vulnerability intelligence
- EPSS, exploitation signals, source provenance and conflicts, explainable priority model
- VEX (CycloneDX) statements and signed documents, license intelligence, SBOM diff, release gates
CRA reporting
- Deterministic reporting assistant with field provenance, signed immutable submission snapshots and amendments
- Runbook readiness, reporting drills, continuity sheet for outages
Enterprise & commercial
- Partner portal, auditor mode, saved views, bulk actions, custom fields, tags, policies
- Contracts, trials, usage metering, customer health, scheduled reports, trust center and status page