Workspace and evidence foundation
Start with the full note if you need shipped details, or jump to the roadmap and wishlist if you are comparing what to do next.
I want the release list
Go back to the index if you need to compare versions or pick another note.
I want the roadmap
Open the roadmap when the question is direction rather than a specific release.
I want to request something
Send a wishlist item if this release page surfaced a gap you want prioritized.
I want the current note
Jump to the release body and read the shipped change in full.
Release notes
What's new
Tenant workspace and authentication
Sotiras now supports multi-tenant workspaces with isolated data, clear role boundaries, and audit history. You can register an organization, sign in, and manage your workspace from /portal. Multiple people can be invited to the same workspace with different roles: Owner, Admin, Operator, Incident Responder, MSP Collaborator, Auditor, and Viewer.
Asset inventory
You can manually add and manage assets in your workspace: servers, applications, endpoints, identities, SaaS systems, networks, data, and vendors. Assets are the foundation for all risk, control, and incident tracking.
Risk register and control checklist
Findings from collectors and audits are normalized into a prioritized risk register. You can assign risks, track remediation tasks, and check controls off as you build your security posture.
Collectors and agent setup
Register collectors with scoped tokens, view heartbeat and health, and download configuration templates for syslog, fail2ban, WordPress, Next.js, nginx, Payload CMS, and Laravel agents.
Threat intelligence
Threat indicators from collector events, community signals, and assessments are tracked in the threat intelligence workspace with policy modes (monitor, assisted, proactive, strict), allowlists, block rules, and AI-assisted assessment.
Incident workspace
Incidents now have their own workspace with evidence capture, task assignment, playbook seeding, and AI summary runs. Operators can escalate, contain, and record recovery steps.
AI-assisted analysis
AI runs can be queued for risk summaries, incident analysis, audit findings, and security assessments. Results are reviewed by an operator before actions are taken. Deployments can use the configured platform model and optional second-opinion providers when tenant policy allows it.
Support documentation
Customer support docs are available at /support/docs covering setup, security operations, incident response, billing, exports, and all agent types.