Changelog

What's new in Focus

Improvements, fixes, and new features over time. Currently on version 2026.08.26.

2026.08.26

Company switching works reliably on mobile.

  • FixedChanging companies now keeps you in the current product area, performs a full refresh, and keeps every company option visible on mobile screens.

2026.08.26

Website discovery sources now advance together.

  • FixedLarge discovery backlogs no longer let Certificate Transparency retries postpone web-service intelligence for the same seeds.

2026.08.26

Large inventories advance across discovery sources.

  • FixedInitial discovery now pairs Certificate Transparency and web-service intelligence per seed so an outage or backlog in one source cannot postpone all website evidence.

2026.08.26

Certificate Transparency discovery is more resilient.

  • FixedWebsite and subdomain discovery now uses a second public Certificate Transparency index when the primary source is unavailable, while preserving the same ownership boundary and retry behavior.

2026.08.26

Website discovery now scales across large attack surfaces.

  • FixedTemporary Certificate Transparency failures now retry instead of appearing as successful searches with no results.
  • ImprovedObserved Shodan web banners now populate the Web Security inventory with existing CDN and WAF context, without storing response bodies or headers.
  • SecurityScalable passive discovery does not relax ownership checks: active website probes remain limited to authorized assets.

2026.08.26

More complete on-demand Attack Surface re-checks.

  • FixedManual Attack Surface re-checks now prioritize known internet-exposed service intelligence while staying within their safe time limit.

2026.08.26

Provider-hosted services are separated from direct exposure.

  • ImprovedService exposure now uses observed network attribution to identify low-confidence CDN and WAF provider candidates, while direct and unattributed services remain the default review focus.
  • SecurityNetwork ownership alone never claims that a website has WAF protection; stronger hostname and response evidence remains clearly distinguished.

2026.08.25

Remote-access exposure is easier to find and verify.

  • AddedAttack Surface now identifies confirmed VPN, VDI, remote desktop, and remote shell services, with clickable product and confidence filters plus evidence on asset details.
  • ImprovedServices and Web Security keep long inventories manageable with server-side paging, preserved URL filters, and direct links to the existing asset details.
  • SecurityRemote gateway vulnerabilities require an exact version and matching product identity; ambiguous or port-only observations remain inventory context and never produce a CVE finding.
  • FixedLegacy automated web vulnerability hits are no longer promoted to confirmed exploitation, while human-managed findings remain untouched.

2026.08.25

Private evidence cleanup survives scan-history removal.

  • SecurityExpired or excluded private website captures remain eligible for safe cleanup even after their scan-history record has been removed.

2026.08.25

Private capture cleanup is race-safe.

  • SecurityPrivate website capture and cleanup now coordinate per scan, so cleanup cannot delete an image while a signed capture retry is storing or adopting it.

2026.08.25

Safer and fairer private website captures.

  • SecurityWebsite capture now enforces its full 30-second limit across DNS and browser startup, rejects late off-origin requests, and blocks additional reserved IPv6 destinations.
  • FixedCapture scheduling now rotates fairly across organizations, while failed storage cleanup remains retriable without hiding or deleting a later successful private image.

2026.08.25

Private visual evidence for verified web assets.

  • AddedAttack Surface asset details can now show the latest private website capture and one previous changed capture for ownership-verified, reachable web assets.
  • SecurityVisual capture is isolated to the verified HTTPS hostname, stores no cookies or authenticated content, and keeps images private behind organization membership checks.
  • SecurityWebsite captures now block every off-origin request and redirect inside a sandboxed browser, and failed storage attempts are recorded without replacing earlier good evidence.

2026.08.25

Clearer edge protection and direct-origin exposure evidence.

  • SecurityDirect-origin checks now keep edge status, certificate identity, and exact content identity in one observation snapshot, preventing partial rechecks from mixing evidence collected at different times.
  • SecurityEdge checks now stop at the first response, cap the evidence they read, preserve the last conclusive result when a check is incomplete, and clear only the exact origin relationship that was re-tested.
  • SecurityAttack Surface can now distinguish provider-edge presence, observed WAF behavior, and direct-origin exposure. A high-severity origin-bypass issue requires two fresh, exact endpoint identifiers from distinct verified sibling hosts; a single matching signal remains context only.
  • ImprovedThe Web Security view and read API can show normalized edge, WAF, provider, and origin posture without treating positive CDN context as a security issue.

2026.06.19

  • AddedPaid plans can now add more than one company. Use the company menu in the top bar to set up a new workspace, each with its own assessment, dashboard, and billing, so you can manage several organizations from a single login. New companies start on the Free plan and can be upgraded any time.

2026.06.16

  • AddedAttack Surface now shows your posture over time — a trend line on the overview so you can see whether your exposure is improving or slipping.
  • AddedEach Attack Surface finding now shows its fix impact — exactly how much resolving it would raise your posture score (and grade), so you can prioritize the fixes that move the needle most.
  • ImprovedThe Attack Surface overview now shows when it last scanned (and flags an overdue scan), plus a new "How this is calculated" page explaining the score, how we discover your surface, and the lines we never cross.
  • AddedA "Scan now" button on the Attack Surface overview lets admins re-run discovery on demand instead of waiting for the daily scan.
  • AddedAttack Surface now watches your domain registration and warns you before it expires (or flags it if it already has) — a common, avoidable cause of a full site and email outage.
  • AddedAttack Surface findings now track age against a remediation target by severity, flagging anything overdue on the overview and the finding page — so the things sitting too long stand out.
  • AddedNew "How you compare" view: see how your external security posture stacks up against similar-size companies in your sector. It starts from modeled industry estimates (clearly labeled) and will move to real peer data as more companies join.
  • FixedThe top navigation no longer breaks on phones: the account links collapse into a tidy menu and the company switcher stays compact, so switching companies works cleanly on mobile.
  • AddedAttack Surface findings now show their compliance relevance — the control theme each one strengthens (email security, encryption in transit, network exposure, and so on) — connecting your external posture to the frameworks you're working toward.
  • AddedNew Attack Surface "What changed" view: a 30-day activity feed of new, resolved, and returned findings plus newly discovered and retired assets, so you can see movement at a glance.
  • ImprovedActive checks now also flag open directory listings, publicly exposed API docs (Swagger/OpenAPI), and server software/version disclosure on your verified hosts.
  • AddedAttack Surface now builds a technology inventory of your verified hosts (web server, framework, CMS and versions), so you can see what software is exposed where.
  • AddedHigh-risk Attack Surface alerts can now post to Slack or Microsoft Teams — add an incoming webhook in Attack Surface setup.
  • AddedAttack Surface now detects likely subdomain takeovers — a subdomain pointing at an unclaimed hosting service (e.g. an old S3 bucket or Heroku app) that an attacker could re-claim.
  • AddedExport your Attack Surface findings to CSV (paid plan) for boards, auditors, or your own tracking.
  • ImprovedWhen you accept an Attack Surface risk you can now set an expiry (90 days, 1 year, or none) — it automatically reopens for review when the period ends, so accepted risks don't quietly get forgotten.
  • AddedA one-click plain-English summary of your Attack Surface posture — a 2-3 sentence read on where you stand and what to fix first.
  • AddedNew Attack Surface "Map" view: everything we've found grouped by host, with the tech each runs and its open-issue count, so the shape of your surface is clear at a glance.
  • AddedTag your Attack Surface assets and assign an owner, so a large surface stays organized and routable.
  • AddedChoose how often Attack Surface scans your organization — daily, weekly, or monthly — or pause automatic scanning (you can still run a scan on demand). Set it in Attack Surface setup.
  • AddedAdd comments to an Attack Surface finding, so your team can coordinate remediation in context — note who's handling it, why a risk was accepted, or what changed.
  • AddedPublish an optional public security scorecard — a shareable page showing just your letter grade and company name (never your findings) as a trust signal for customers. Off by default; publish, rotate, or remove the link anytime in Attack Surface setup.
  • AddedNew Attack Surface "Portfolio" view for anyone who manages more than one company: every company you belong to, with its grade and open-issue count, worst first — so you can see across your whole book at a glance.
  • AddedAttack Surface now flags known vulnerabilities in the software your verified hosts run — when a detected version matches a published CVE, you get a finding with the fix version. It clears automatically once you upgrade. (Based on the version a host reports; if your OS backports fixes, verify your patch level.)
  • ImprovedWhen a new vulnerability advisory is added, Attack Surface now re-checks your existing software inventory against it automatically — so you're flagged for newly-published issues affecting software we've already seen, without waiting for the next scan.
  • ImprovedYou can now tune Attack Surface alerts to critical findings only (instead of high and critical) to cut noise — set it under high-risk alerts in Attack Surface setup.
  • AddedAttack Surface read API: create a scoped, read-only API key in setup and pull your findings and assets into your own tools or SIEM (GET /api/v1/asm/findings and /api/v1/asm/assets). Keys are shown once, revocable, and limited to your company's data.
  • AddedAssign an owner to an Attack Surface finding (a person, team, or external owner) so it's clear who's handling each issue.
  • AddedMark an asset's business criticality (low to critical) on its detail page — findings on your most important assets rise up the prioritized list within their severity. It's a prioritization lens and doesn't change your grade.
  • ImprovedYour scheduled Attack Surface digest now arrives with the full findings report attached as a CSV — ready for your records, board, or auditor without opening the app.
  • AddedAttack Surface now watches for look-alike (typosquat) domains — registered domains that closely resemble yours and could be used to phish your customers or impersonate your brand — so you can act before they're used against you.
  • AddedNew Attack Surface "Triage" view: select many open findings at once and change their status or assign an owner in bulk — fast cleanup for security leads.
  • AddedPush an Attack Surface finding to your tracker: add an outbound webhook (Jira/ServiceNow/Zapier or any HTTPS endpoint) in setup, then send a finding to it as JSON from the finding page.
  • AddedAttack Surface now flags exposed secrets — API keys, tokens, or private keys that leak into a page your site serves — as a critical finding (the secret itself is never shown or stored), so you can rotate it before it's abused.

2026.06.13

  • AddedIf you belong to more than one company, a company picker now appears in the top-right — switch between them and the whole app shows that company's data. The picker names the company you're currently viewing.
  • ImprovedYour plan now reads plainly as "Free subscription," "Paid subscription," or "vCISO subscription" on Settings and Billing.

2026.06.11

  • ImprovedA friendlier, on-brand page when you land on a link that doesn't exist, with a quick way back.
  • ImprovedIf a page ever errors, you now get a clean recovery screen with a one-click retry instead of a broken view.
  • FixedSmaller teams are no longer auto-marked non-compliant on backup-recovery-targets and log-integrity controls just for their size — those controls are now scored on your actual answers.
  • FixedYour framework recommendations no longer list the same framework twice — each one now appears once, at its highest priority.
  • ImprovedBrowser tabs now show the page you're on (e.g. "Dashboard · Focus"), so several open Focus tabs are easy to tell apart.

2026.06.10

Reliability pass across assessments, billing, and Attack Surface.

  • AddedThis changelog, so you can see what's new over time.
  • AddedReport an issue — tell us about a bug or request a feature right from the app (footer link).
  • FixedAssessment scoring is more accurate: the multi-factor authentication gap question now scores the way it reads.
  • FixedDownloaded PDF reports now match your on-screen grade after you mark gaps remediated.
  • FixedYour letter grade and percentage score are always consistent at the band edges.
  • FixedCanceling your account now reliably stops billing; duplicate checkouts are prevented.
  • ImprovedOnboarding reliably captures your company profile, so the questions you're asked match your size and sector.
  • ImprovedAttack Surface results are more accurate and rotate fairly across all monitored hosts; resolved issues that come back are flagged as regressions.
  • SecurityAttack Surface management actions (adding targets, verifying ownership, dispositioning findings) are limited to organization admins and owners.
  • ImprovedClearer wording on the terms-of-use screen for new accounts.
  • FixedThe dashboard progress bar now reflects real progress when you re-run an assessment from scratch (it no longer counts prior answers).

2026.06.07

Attack Surface notifications and clearer navigation.

  • AddedWeekly or monthly Attack Surface email digests, plus high-risk alerts to owners and admins.
  • AddedExposed Services view — every internet-reachable port and service on your perimeter, grouped by host.
  • ImprovedA two-tier top navigation that scales as Focus adds modules.
  • ImprovedClearer asset origins (what we found vs. what you told us) and seed management.

2026.06.05

Attack Surface Management (ASM) module.

  • AddedAttack Surface Management: passive discovery of your internet-facing assets, with ownership-gated active checks.

2026.06.02

Self-serve billing and a clearer remediation workflow.

  • AddedSelf-serve subscriptions for the Paid plan.
  • AddedMark controls as remediated to see your posture improve without re-running the whole assessment.
  • AddedA team page and the ability to split an assessment across teammates by area.
  • ImprovedGet notified when we publish a new security guide or post.

2026.05.29

Pricing published.

  • AddedPublic pricing: Free, Paid, and Fractional CISO plans.

2026.05.28

More frameworks and richer reports.

  • AddedAssess against many more compliance frameworks in a single pass (Paid).
  • AddedUpload evidence for controls and export your answers.
  • AddedDownloadable PDF report with your score rating and top priority gaps.

Spotted something off, or have an idea? Report an issue.