<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>AegiFlow releases</title>
    <link>https://aegiflow.com/en/releases/</link>
    <description>Verified release notes for the AegiFlow web protection and resilience platform.</description>
    <language>en</language>
    <item>
      <title>Whether your own server is on somebody's list</title>
      <link>https://aegiflow.com/en/releases/#address-reputation</link>
      <guid isPermaLink="false">aegiflow-release-address-reputation</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Public reputation feeds are read and every address we already hold for you is checked against them. Nothing is sent to your servers: the lists are read, and the names you gave us are resolved. The finding worth having is the uncomfortable one — your own address inside a listed network, which is how mail starts bouncing and other networks start dropping your traffic, usually without anybody telling you. Spamhaus DROP is used because its terms say plainly that it is free for everyone, and its attribution travels in every row we store. Tor exit nodes are reported too, but as context rather than as wrongdoing: running one is not an attack, and a system that called it one would be teaching you to ignore it. One well-known feed was left out because its terms never say whether commercial use is allowed, which is the same test another feed failed earlier this year.</description>
    </item>
    <item>
      <title>The snippet finally has somewhere to report to</title>
      <link>https://aegiflow.com/en/releases/#public-api-path</link>
      <guid isPermaLink="false">aegiflow-release-public-api-path</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Two capabilities had been built and could reach nobody: the browser snippet and the WordPress connector both needed a public address, and the only one published sat behind an access proxy that answers 401 to everyone. There is now a dedicated hostname carrying exactly four routes — beacon, inventory, malware reports, public scan — and a 404 for everything else, so the surface is a list somebody can read rather than a proxy rule somebody has to trust. The malware agent stopped needing its courier and posts directly. Payment page integrity moves from unavailable to available on the strength of that, not on a promise.</description>
    </item>
    <item>
      <title>Malware scanning where the files actually live</title>
      <link>https://aegiflow.com/en/releases/#malware-scanning</link>
      <guid isPermaLink="false">aegiflow-release-malware-scanning</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>For sites on our own infrastructure, an agent beside the scanner reads the web content daily and reports conclusions — a path, a signature name, a hash — never the files themselves. It caught a planted test file across 9,415 files in about seventy seconds. A web shell is critical, a packed installer is a nuisance, and the test signature is neither: reporting them all the same way would teach an operator to ignore the panel. Adds 38,927 free third-party signatures, because the core scanner is strong on binaries and thin on the PHP shells that actually turn up on shared hosting.</description>
    </item>
    <item>
      <title>Watching the checkout page from inside the browser</title>
      <link>https://aegiflow.com/en/releases/#payment-page-integrity</link>
      <guid isPermaLink="false">aegiflow-release-payment-page-integrity</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>A card skimmer never touches the server: it arrives as one more script on the checkout page and reads the number out of the form before your own code sees it. So the origin is unchanged and a content hash sees nothing. This watches from the only place it exists — the visitor's browser — and reports structure, never content: which script hosts load, whether a native browser function has been replaced, how many inputs sit where nobody can see them. The first report is a silent baseline. A replaced function is something to explain, not proof of anything: that is also how every session-replay tool works.</description>
    </item>
    <item>
      <title>The names under your domain, and the ones pointing nowhere</title>
      <link>https://aegiflow.com/en/releases/#attack-surface-discovery</link>
      <guid isPermaLink="false">aegiflow-release-attack-surface-discovery</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Certificate logs already tell us about names somebody asked a CA to certify. This finds the rest, by reading public indexes and asking DNS resolvers — nothing is sent to your servers. The finding worth having is a record pointing at a service that no longer exists: your subdomain is unclaimed at the provider, and whoever registers it there serves content from an address that still carries your name. Reported only after two consecutive sweeps agree, so a resolver having a bad minute does not become an accusation. Mapping our own estate turned up 29 names, including one host we had not listed anywhere.</description>
    </item>
    <item>
      <title>Active scanning, and the paperwork that has to come first</title>
      <link>https://aegiflow.com/en/releases/#authorized-active-scanning</link>
      <guid isPermaLink="false">aegiflow-release-authorized-active-scanning</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Everything the platform did until now was observation. This is the first capability that sends traffic somebody could reasonably object to, so it is the first that cannot run on proven ownership alone: it needs a standing authorization naming an exact hostname — no wildcards — a rate ceiling, a contact who can stop it, and an expiry. The scanner runs in its own container with no database credentials, on its own pair of networks, and does not learn whose hostname it is scanning. It re-resolves the target after the scan too, and discards the results if the name moved. A scan that runs out of time reports partial and marks nothing as fixed.</description>
    </item>
    <item>
      <title>NIS2 reports you can hand to an auditor</title>
      <link>https://aegiflow.com/en/releases/#nis2-reports</link>
      <guid isPermaLink="false">aegiflow-release-nis2-reports</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Generate a report for a period and it states a verdict for each Article 21 measure, cites the exact records behind it — audit entries, signed bundles, drill receipts, case timings — and carries a content hash so a reader can tell it has not been altered. A measure with no recent evidence is reported as Unknown, never as a pass. Three of the ten measures are organisational, and the document says plainly that we do not observe them: training, human resources security, and secured emergency communications.</description>
    </item>
    <item>
      <title>Audit trail opened up, and a licence removed</title>
      <link>https://aegiflow.com/en/releases/#hygiene-and-audit-trail</link>
      <guid isPermaLink="false">aegiflow-release-hygiene-and-audit-trail</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Every audited action now shows who took it and what the configuration looked like before and after; the records always held this and the screen never showed it. Periodic jobs moved off the shared loop so a slow scan no longer delays anything else, and failed background jobs now back off and dead-letter instead of retrying forever. The Wordfence feed was removed: it is not licensed for the commercial use we intend. WordPress advisories now come from NVD's public CPE data, which is thinner and slower, and says so.</description>
    </item>
    <item>
      <title>A beacon for sites that do not route through us</title>
      <link>https://aegiflow.com/en/releases/#client-beacon</link>
      <guid isPermaLink="false">aegiflow-release-client-beacon</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>A short snippet, pasted into a page the way an analytics tag would be, reports content-security-policy violations and uncaught JavaScript errors from real visitors' browsers. The key is public and carries no secret; only aggregates are stored, never a visitor.</description>
    </item>
    <item>
      <title>The pages that must keep working, checked every five minutes</title>
      <link>https://aegiflow.com/en/releases/#transaction-checks</link>
      <guid isPermaLink="false">aegiflow-release-transaction-checks</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>You name the URL and what proves it is healthy — a status code, a marker in the page. Every five minutes we check it from outside, and a failure opens a case instead of waiting for a customer to notice.</description>
    </item>
    <item>
      <title>Look-alike domains, watched</title>
      <link>https://aegiflow.com/en/releases/#lookalike-domains</link>
      <guid isPermaLink="false">aegiflow-release-lookalike-domains</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>We generate the names a fraudster would register against yours - a dropped letter, a swapped ending, a zero for an o - and check which of them actually resolve. Across the current portfolio that surfaced 45 registered look-alikes.</description>
    </item>
    <item>
      <title>Certificates, watched as they are issued</title>
      <link>https://aegiflow.com/en/releases/#certificate-transparency</link>
      <guid isPermaLink="false">aegiflow-release-certificate-transparency</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Public Certificate Transparency logs are read for every monitored domain. What exists when we start watching is recorded silently as a baseline; a certificate that appears afterwards opens a case, because that is the moment to ask whether you issued it.</description>
    </item>
    <item>
      <title>An outside reading of every domain, with a grade</title>
      <link>https://aegiflow.com/en/releases/#external-posture</link>
      <guid isPermaLink="false">aegiflow-release-external-posture</guid>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>TLS, security headers, cookie flags, version exposure, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and CAA are checked from outside the perimeter and summarised as a grade from A to F. Nothing is installed and no traffic is redirected; a domain can be monitored this way and nothing else.</description>
    </item>
    <item>
      <title>Cases you can work, and settings that are real</title>
      <link>https://aegiflow.com/en/releases/#operations-settings</link>
      <guid isPermaLink="false">aegiflow-release-operations-settings</guid>
      <pubDate>Sat, 01 Aug 2026 12:00:00 GMT</pubDate>
      <description>Cases can be picked up, annotated, closed, reopened and snoozed, with the operator queue filtered and paged. Notification email with double opt-in and a periodic digest. Account, team and plan settings on their own pages instead of one long form. Autonomy presets with exceptions.</description>
    </item>
    <item>
      <title>Control plane v5.16: activation gates and recovery proof</title>
      <link>https://aegiflow.com/en/releases/#control-plane-v5-16</link>
      <guid isPermaLink="false">aegiflow-release-control-plane-v5-16</guid>
      <pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate>
      <description>Activation guidance, recovery hostname drill and private origin proof landed in the control plane. Enforcement remains gated behind stability windows and rollback evidence.</description>
    </item>
    <item>
      <title>Edge telemetry v5: live traffic windows</title>
      <link>https://aegiflow.com/en/releases/#edge-telemetry-v5</link>
      <guid isPermaLink="false">aegiflow-release-edge-telemetry-v5</guid>
      <pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
      <description>Minute-level traffic rollups, observation attribution and verified status displays now power the operational dashboard without entering the visitor request path.</description>
    </item>
    <item>
      <title>Customer dashboard V4</title>
      <link>https://aegiflow.com/en/releases/#production-experience-v4</link>
      <guid isPermaLink="false">aegiflow-release-production-experience-v4</guid>
      <pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate>
      <description>The customer dashboard moved to route-scoped data loading, explicit unknown states and a persistent product shell for portfolio and per-domain operations.</description>
    </item>
    <item>
      <title>Policy replay and origin outage drill</title>
      <link>https://aegiflow.com/en/releases/#policy-replay-drills</link>
      <guid isPermaLink="false">aegiflow-release-policy-replay-drills</guid>
      <pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate>
      <description>Policy replay evidence, customer edge fallback routes and freshness controls were exercised end to end, including an origin outage drill.</description>
    </item>
    <item>
      <title>Self-hosted identity with step-up</title>
      <link>https://aegiflow.com/en/releases/#identity-step-up</link>
      <guid isPermaLink="false">aegiflow-release-identity-step-up</guid>
      <pubDate>Mon, 27 Jul 2026 12:00:00 GMT</pubDate>
      <description>Sign-in moved to the self-hosted AegiFlow identity flow: OIDC sessions, passkeys, TOTP and step-up verification before sensitive actions, with Romanian onboarding.</description>
    </item>
    <item>
      <title>Single-source public website</title>
      <link>https://aegiflow.com/en/releases/#single-source-public-site</link>
      <guid isPermaLink="false">aegiflow-release-single-source-public-site</guid>
      <pubDate>Thu, 23 Jul 2026 12:00:00 GMT</pubDate>
      <description>The public website moved to a single bilingual Astro source with immutable releases, checksums and a tested rollback path.</description>
    </item>
  </channel>
</rss>
