Changelog
What's new in Focus
Improvements, fixes, and new features over time. Currently on version 2026.08.26.
2026.08.26
Company switching works reliably on mobile.
- FixedChanging companies now keeps you in the current product area, performs a full refresh, and keeps every company option visible on mobile screens.
2026.08.26
Website discovery sources now advance together.
- FixedLarge discovery backlogs no longer let Certificate Transparency retries postpone web-service intelligence for the same seeds.
2026.08.26
Large inventories advance across discovery sources.
- FixedInitial discovery now pairs Certificate Transparency and web-service intelligence per seed so an outage or backlog in one source cannot postpone all website evidence.
2026.08.26
Certificate Transparency discovery is more resilient.
- FixedWebsite and subdomain discovery now uses a second public Certificate Transparency index when the primary source is unavailable, while preserving the same ownership boundary and retry behavior.
2026.08.26
Website discovery now scales across large attack surfaces.
- FixedTemporary Certificate Transparency failures now retry instead of appearing as successful searches with no results.
- ImprovedObserved Shodan web banners now populate the Web Security inventory with existing CDN and WAF context, without storing response bodies or headers.
- SecurityScalable passive discovery does not relax ownership checks: active website probes remain limited to authorized assets.
2026.08.26
More complete on-demand Attack Surface re-checks.
- FixedManual Attack Surface re-checks now prioritize known internet-exposed service intelligence while staying within their safe time limit.
2026.08.26
Provider-hosted services are separated from direct exposure.
- ImprovedService exposure now uses observed network attribution to identify low-confidence CDN and WAF provider candidates, while direct and unattributed services remain the default review focus.
- SecurityNetwork ownership alone never claims that a website has WAF protection; stronger hostname and response evidence remains clearly distinguished.
2026.08.25
Remote-access exposure is easier to find and verify.
- AddedAttack Surface now identifies confirmed VPN, VDI, remote desktop, and remote shell services, with clickable product and confidence filters plus evidence on asset details.
- ImprovedServices and Web Security keep long inventories manageable with server-side paging, preserved URL filters, and direct links to the existing asset details.
- SecurityRemote gateway vulnerabilities require an exact version and matching product identity; ambiguous or port-only observations remain inventory context and never produce a CVE finding.
- FixedLegacy automated web vulnerability hits are no longer promoted to confirmed exploitation, while human-managed findings remain untouched.
2026.08.25
Private evidence cleanup survives scan-history removal.
- SecurityExpired or excluded private website captures remain eligible for safe cleanup even after their scan-history record has been removed.
2026.08.25
Private capture cleanup is race-safe.
- SecurityPrivate website capture and cleanup now coordinate per scan, so cleanup cannot delete an image while a signed capture retry is storing or adopting it.
2026.08.25
Safer and fairer private website captures.
- SecurityWebsite capture now enforces its full 30-second limit across DNS and browser startup, rejects late off-origin requests, and blocks additional reserved IPv6 destinations.
- FixedCapture scheduling now rotates fairly across organizations, while failed storage cleanup remains retriable without hiding or deleting a later successful private image.
2026.08.25
Private visual evidence for verified web assets.
- AddedAttack Surface asset details can now show the latest private website capture and one previous changed capture for ownership-verified, reachable web assets.
- SecurityVisual capture is isolated to the verified HTTPS hostname, stores no cookies or authenticated content, and keeps images private behind organization membership checks.
- SecurityWebsite captures now block every off-origin request and redirect inside a sandboxed browser, and failed storage attempts are recorded without replacing earlier good evidence.
2026.08.25
Clearer edge protection and direct-origin exposure evidence.
- SecurityDirect-origin checks now keep edge status, certificate identity, and exact content identity in one observation snapshot, preventing partial rechecks from mixing evidence collected at different times.
- SecurityEdge checks now stop at the first response, cap the evidence they read, preserve the last conclusive result when a check is incomplete, and clear only the exact origin relationship that was re-tested.
- SecurityAttack Surface can now distinguish provider-edge presence, observed WAF behavior, and direct-origin exposure. A high-severity origin-bypass issue requires two fresh, exact endpoint identifiers from distinct verified sibling hosts; a single matching signal remains context only.
- ImprovedThe Web Security view and read API can show normalized edge, WAF, provider, and origin posture without treating positive CDN context as a security issue.
2026.06.19
- AddedPaid plans can now add more than one company. Use the company menu in the top bar to set up a new workspace, each with its own assessment, dashboard, and billing, so you can manage several organizations from a single login. New companies start on the Free plan and can be upgraded any time.
2026.06.16
- AddedAttack Surface now shows your posture over time — a trend line on the overview so you can see whether your exposure is improving or slipping.
- AddedEach Attack Surface finding now shows its fix impact — exactly how much resolving it would raise your posture score (and grade), so you can prioritize the fixes that move the needle most.
- ImprovedThe Attack Surface overview now shows when it last scanned (and flags an overdue scan), plus a new "How this is calculated" page explaining the score, how we discover your surface, and the lines we never cross.
- AddedA "Scan now" button on the Attack Surface overview lets admins re-run discovery on demand instead of waiting for the daily scan.
- AddedAttack Surface now watches your domain registration and warns you before it expires (or flags it if it already has) — a common, avoidable cause of a full site and email outage.
- AddedAttack Surface findings now track age against a remediation target by severity, flagging anything overdue on the overview and the finding page — so the things sitting too long stand out.
- AddedNew "How you compare" view: see how your external security posture stacks up against similar-size companies in your sector. It starts from modeled industry estimates (clearly labeled) and will move to real peer data as more companies join.
- FixedThe top navigation no longer breaks on phones: the account links collapse into a tidy menu and the company switcher stays compact, so switching companies works cleanly on mobile.
- AddedAttack Surface findings now show their compliance relevance — the control theme each one strengthens (email security, encryption in transit, network exposure, and so on) — connecting your external posture to the frameworks you're working toward.
- AddedNew Attack Surface "What changed" view: a 30-day activity feed of new, resolved, and returned findings plus newly discovered and retired assets, so you can see movement at a glance.
- ImprovedActive checks now also flag open directory listings, publicly exposed API docs (Swagger/OpenAPI), and server software/version disclosure on your verified hosts.
- AddedAttack Surface now builds a technology inventory of your verified hosts (web server, framework, CMS and versions), so you can see what software is exposed where.
- AddedHigh-risk Attack Surface alerts can now post to Slack or Microsoft Teams — add an incoming webhook in Attack Surface setup.
- AddedAttack Surface now detects likely subdomain takeovers — a subdomain pointing at an unclaimed hosting service (e.g. an old S3 bucket or Heroku app) that an attacker could re-claim.
- AddedExport your Attack Surface findings to CSV (paid plan) for boards, auditors, or your own tracking.
- ImprovedWhen you accept an Attack Surface risk you can now set an expiry (90 days, 1 year, or none) — it automatically reopens for review when the period ends, so accepted risks don't quietly get forgotten.
- AddedA one-click plain-English summary of your Attack Surface posture — a 2-3 sentence read on where you stand and what to fix first.
- AddedNew Attack Surface "Map" view: everything we've found grouped by host, with the tech each runs and its open-issue count, so the shape of your surface is clear at a glance.
- AddedTag your Attack Surface assets and assign an owner, so a large surface stays organized and routable.
- AddedChoose how often Attack Surface scans your organization — daily, weekly, or monthly — or pause automatic scanning (you can still run a scan on demand). Set it in Attack Surface setup.
- AddedAdd comments to an Attack Surface finding, so your team can coordinate remediation in context — note who's handling it, why a risk was accepted, or what changed.
- AddedPublish an optional public security scorecard — a shareable page showing just your letter grade and company name (never your findings) as a trust signal for customers. Off by default; publish, rotate, or remove the link anytime in Attack Surface setup.
- AddedNew Attack Surface "Portfolio" view for anyone who manages more than one company: every company you belong to, with its grade and open-issue count, worst first — so you can see across your whole book at a glance.
- AddedAttack Surface now flags known vulnerabilities in the software your verified hosts run — when a detected version matches a published CVE, you get a finding with the fix version. It clears automatically once you upgrade. (Based on the version a host reports; if your OS backports fixes, verify your patch level.)
- ImprovedWhen a new vulnerability advisory is added, Attack Surface now re-checks your existing software inventory against it automatically — so you're flagged for newly-published issues affecting software we've already seen, without waiting for the next scan.
- ImprovedYou can now tune Attack Surface alerts to critical findings only (instead of high and critical) to cut noise — set it under high-risk alerts in Attack Surface setup.
- AddedAttack Surface read API: create a scoped, read-only API key in setup and pull your findings and assets into your own tools or SIEM (GET /api/v1/asm/findings and /api/v1/asm/assets). Keys are shown once, revocable, and limited to your company's data.
- AddedAssign an owner to an Attack Surface finding (a person, team, or external owner) so it's clear who's handling each issue.
- AddedMark an asset's business criticality (low to critical) on its detail page — findings on your most important assets rise up the prioritized list within their severity. It's a prioritization lens and doesn't change your grade.
- ImprovedYour scheduled Attack Surface digest now arrives with the full findings report attached as a CSV — ready for your records, board, or auditor without opening the app.
- AddedAttack Surface now watches for look-alike (typosquat) domains — registered domains that closely resemble yours and could be used to phish your customers or impersonate your brand — so you can act before they're used against you.
- AddedNew Attack Surface "Triage" view: select many open findings at once and change their status or assign an owner in bulk — fast cleanup for security leads.
- AddedPush an Attack Surface finding to your tracker: add an outbound webhook (Jira/ServiceNow/Zapier or any HTTPS endpoint) in setup, then send a finding to it as JSON from the finding page.
- AddedAttack Surface now flags exposed secrets — API keys, tokens, or private keys that leak into a page your site serves — as a critical finding (the secret itself is never shown or stored), so you can rotate it before it's abused.
2026.06.13
- AddedIf you belong to more than one company, a company picker now appears in the top-right — switch between them and the whole app shows that company's data. The picker names the company you're currently viewing.
- ImprovedYour plan now reads plainly as "Free subscription," "Paid subscription," or "vCISO subscription" on Settings and Billing.
2026.06.11
- ImprovedA friendlier, on-brand page when you land on a link that doesn't exist, with a quick way back.
- ImprovedIf a page ever errors, you now get a clean recovery screen with a one-click retry instead of a broken view.
- FixedSmaller teams are no longer auto-marked non-compliant on backup-recovery-targets and log-integrity controls just for their size — those controls are now scored on your actual answers.
- FixedYour framework recommendations no longer list the same framework twice — each one now appears once, at its highest priority.
- ImprovedBrowser tabs now show the page you're on (e.g. "Dashboard · Focus"), so several open Focus tabs are easy to tell apart.
2026.06.10
Reliability pass across assessments, billing, and Attack Surface.
- AddedThis changelog, so you can see what's new over time.
- AddedReport an issue — tell us about a bug or request a feature right from the app (footer link).
- FixedAssessment scoring is more accurate: the multi-factor authentication gap question now scores the way it reads.
- FixedDownloaded PDF reports now match your on-screen grade after you mark gaps remediated.
- FixedYour letter grade and percentage score are always consistent at the band edges.
- FixedCanceling your account now reliably stops billing; duplicate checkouts are prevented.
- ImprovedOnboarding reliably captures your company profile, so the questions you're asked match your size and sector.
- ImprovedAttack Surface results are more accurate and rotate fairly across all monitored hosts; resolved issues that come back are flagged as regressions.
- SecurityAttack Surface management actions (adding targets, verifying ownership, dispositioning findings) are limited to organization admins and owners.
- ImprovedClearer wording on the terms-of-use screen for new accounts.
- FixedThe dashboard progress bar now reflects real progress when you re-run an assessment from scratch (it no longer counts prior answers).
2026.06.07
Attack Surface notifications and clearer navigation.
- AddedWeekly or monthly Attack Surface email digests, plus high-risk alerts to owners and admins.
- AddedExposed Services view — every internet-reachable port and service on your perimeter, grouped by host.
- ImprovedA two-tier top navigation that scales as Focus adds modules.
- ImprovedClearer asset origins (what we found vs. what you told us) and seed management.
2026.06.05
Attack Surface Management (ASM) module.
- AddedAttack Surface Management: passive discovery of your internet-facing assets, with ownership-gated active checks.
2026.06.02
Self-serve billing and a clearer remediation workflow.
- AddedSelf-serve subscriptions for the Paid plan.
- AddedMark controls as remediated to see your posture improve without re-running the whole assessment.
- AddedA team page and the ability to split an assessment across teammates by area.
- ImprovedGet notified when we publish a new security guide or post.
2026.05.29
Pricing published.
- AddedPublic pricing: Free, Paid, and Fractional CISO plans.
2026.05.28
More frameworks and richer reports.
- AddedAssess against many more compliance frameworks in a single pass (Paid).
- AddedUpload evidence for controls and export your answers.
- AddedDownloadable PDF report with your score rating and top priority gaps.
Spotted something off, or have an idea? Report an issue.