What's New

Release notes and product updates for ImaraForge.

Latest

v2.1.1

April 2026

✨ New Features

  • AI Security Copilot — natural-language threat analysis and recommendations
  • Behavioral anomaly detection — impossible travel, login time anomalies, process chain analysis
  • Email threat analysis — phishing detection, BEC indicators, domain validation
  • SIEM webhook integration — real-time event forwarding with HMAC signing
  • Incident response playbooks — automated and manual remediation workflows
  • Onboarding checklist — guided first-run experience with progress tracking
  • Session management — view and revoke active login sessions
  • Platform announcements — in-app notification system

🛠️ Improvements

  • Outbound rate-limit throttling for all 7 external API dependencies
  • BFF cookie authentication pattern — HttpOnly cookies replace localStorage JWT
  • CSP nonce injection — dynamic nonces for all inline scripts
  • Unified pricing across all surfaces ($15/$25/$35 per user/month)
  • Custom 404 page with helpful navigation
  • Multi-browser E2E testing (Chromium, Firefox, WebKit)

🐛 Bug Fixes

  • Fixed org_slug bypass in checkout (security critical)
  • Fixed Host header injection in Stripe redirect URLs
  • Fixed /api/health leaking DB exception details
  • Fixed agent JWT secret shared with user auth
  • Fixed CSP connect-src being too permissive

v2.1.0

March 2026

✨ New Features

  • Azure Marketplace integration — SaaS listing with subscription management
  • Tier-gated feature access — Starter, Growth, Enterprise with 402 enforcement
  • Microsoft 365 hardening assessment
  • Automated patch management with ring-based deployment
  • Windows Security Agent with enrollment key provisioning
  • Compliance dashboard — CIS, NIST CSF, GDPR frameworks

🛠️ Improvements

  • Tallawah CIAM integration — centralized identity management
  • Production database migration — 83 tables, 93 RBAC permissions
  • Stripe billing with checkout, portal, webhooks, and dunning

v2.0.0

February 2026

✨ Initial Release

  • Core platform launch — Flask backend with Azure cloud services
  • Device management and vulnerability scanning
  • Secure score calculation and tracking
  • Admin dashboard with user and organization management
  • REST API with OpenAPI/Swagger documentation