Collector token incident response notice
Start with the full note if you need shipped details, or jump to the roadmap and wishlist if you are comparing what to do next.
I want the release list
Go back to the index if you need to compare versions or pick another note.
I want the roadmap
Open the roadmap when the question is direction rather than a specific release.
I want to request something
Send a wishlist item if this release page surfaced a gap you want prioritized.
I want the current note
Jump to the release body and read the shipped change in full.
Release notes
Product notice
Sotiras now treats collector token exposure as an explicit incident response workflow. Collector and agent tokens are tenant-scoped credentials used for ingestion. If a tenant host, WordPress site, application runtime, deployment secret store, or admin workflow may have exposed a token, rotate or revoke the affected token from the portal.
What's new
Token exposure response guidance
The collector setup workspace now includes a token exposure response panel. It explains when to rotate a token, when to revoke it, and how to confirm recovery without guessing from the raw token table.
Customer-facing support notice
The support center now includes Collector token incident response, a customer-facing notice for breach-response handling of collector credentials.
Scoped action model
The guidance keeps response scoped to actual exposure. Rotate tokens stored on affected systems, revoke credentials that should stop working, and avoid broad tenant-wide rotation unless the breach path or containment requirement justifies it. Rotating a token issues new credentials and moves attached collectors to it automatically; revoking a token disables it and its attached collector sources immediately.