Release Notes
Latest updates and changes to Safeguard products
Release Notes
Stay up to date with the latest features, improvements, and fixes across all Safeguard products.
July 2026
First-party Security Engines
Safeguard now ships a suite of first-party, defensive security engines, all reporting into one unified findings model and each independently admin-toggleable via server-enforced feature flags:
- Application Security Testing (SAST & DAST) - static source analysis and defensive, authorized dynamic testing.
- Red Team (Defensive Adversary Emulation) - breach-and-attack simulation and purple-teaming using benign ATT&CK detection canaries (no weaponized payloads), attack-path graph with unified risk correlation, safe recon, and an AI/LLM guardrail-validation harness - gated by a signed rules-of-engagement, scope checks, rate/blast caps, human approval for high-impact steps, a global kill-switch, and full audit.
- AI-SPM - model-artifact malware scanning (pickle opcode disassembly, torch-zip walker, safetensors/GGUF validation).
- DSPM - sensitive-data classification (PII/PHI, Luhn-validated PCI, entropy-gated secrets) with an enforced redaction mandate.
- Runtime Protection (CWPP & CNAPP) - ATT&CK-mapped runtime threat rules and cloud-native risk correlation. The eBPF runtime collector is a Linux follow-on, rolling out.
- Package Firewall - inline install-time allow/warn/block for dependencies, with audit and quarantine modes.
- AutoTriage - cross-scanner deduplication and noise reduction with a measured reduction metric; never suppresses malware or secrets findings.
January 2026
v3.0.0 - January 3, 2026
Major Release: Griffin AI General Availability
New Features
- Griffin AI GA - Purpose-built LLM for supply chain security now available to all customers
- AI Remediate 2.0 - Enhanced automated remediation with multi-language support
- MCP Server - Model Context Protocol server for AI integrations
- Container AI Analysis - Deep learning-based container image analysis
Improvements
- 60% faster SBOM generation
- Enhanced natural language search capabilities
- Improved reachability analysis accuracy
- Better transitive dependency resolution
December 2025
v2.9.0 - December 15, 2025
New Features
- IL7 Certification - Now approved for Impact Level 7 workloads
- Bulk AI Remediate - Fix multiple vulnerabilities in one PR
- Custom Export Templates - Create branded SBOM reports
- Vendor Portal - Self-service portal for TPRM vendors
Improvements
- Updated vulnerability database coverage
- Improved Go module analysis
- Enhanced Rust crate support
- Better monorepo handling
November 2025
v2.8.0 - November 20, 2025
New Features
- Third Party Risk Manager - New product for vendor SBOM management
- EPSS Integration - Exploit prediction scoring
- CISA KEV Alerts - Known exploited vulnerability notifications
- Scheduled Scans - Automatic recurring SBOM generation
Improvements
- Redesigned dashboard
- Improved search performance
- Enhanced mobile experience
- Better notification management
October 2025
v2.7.0 - October 10, 2025
New Features
- Open Source Manager - New product with Gold Directory
- Attestation Verification - SLSA and Sigstore support
- License Policy Engine - Advanced license compliance
- API v2 - New REST API with improved performance
Improvements
- 50% reduction in false positives
- Improved component identification
- Enhanced API rate limits
- Better error messages
How to Update
Cloud Users
All cloud deployments are automatically updated. No action required.
On-Premises Users
- Download the latest release from the customer portal
- Review the upgrade notes
- Follow the upgrade procedure in the deployment guide
Feedback
We value your feedback! Share your thoughts:
- Email: hi@safeguard.sh
- In-app feedback button
- Feature requests via customer portal