What’s actually shipped.

A running record of what's landed in ScanPosture, newest first. No roadmap items, no maybes — only changes that are live in the product.

View status
10 releases loggedStatus feed available

April 2026

6 releases
25 Apr 2026Trust

Security and sub-processors pages

Two new pages dedicated to procurement and SecOps reviews: /security publishes the four pillars (UK residency, read-only, verified publisher, UK company), eight technical-control areas, the framework readiness vs certification split, and a coordinated-disclosure process at security@scanposture.com. /sub-processors lists every vendor with purpose, data category and processing region, grouped by region.

25 Apr 2026Status

status.scanposture.com launched

A dedicated public status subdomain. Live operational status with a hero card, monitored-services grid, 30-day uptime history, incident timeline, and email + Atom subscriptions for incident notifications. Browser tab title reflects current overall status (✓ / ⚠ / ✕).

24 Apr 2026Platform

UK data migration — Supabase London (eu-west-2)

All customer data now stored in our Supabase region in London. Application traffic and email delivery routed through UK / EU infrastructure end-to-end. No US round-trip and no replica outside the United Kingdom.

24 Apr 2026Product

Demo deployment isolation + UK demo project

A dedicated demo Supabase project in London powers the public demo at demo.scanposture.com. Demo trial signup is now blocked at three layers (link, page redirect, API) and routes prospects to the live signup on app.scanposture.com.

22 Apr 2026Reports

External-assessor evidence audience added

Reports now explicitly support the external-assessor audience: framework readiness views map onto Cyber Essentials, ISO 27001, GDPR Article 32, NIST CSF, CIS Controls and SOC 2 evidence requests during third-party assessments.

18 Apr 2026Product

Premium login experience

Login screen rebuilt with proof cards (continuous monitoring, drift detection, prioritised actions, framework readiness), MSP white-label support, and an MFA-first session flow.

March 2026

4 releases
30 Mar 2026Platform

201 read-only checks across 9 weighted security domains

The check registry now totals 201 unique checks, evaluated across nine weighted security domains: Identity & Authentication, Privileged Access, Conditional Access & Policy Enforcement, Account Lifecycle & Governance, Application & Non-Human Identity Security, Data Access & Collaboration Security, Monitoring / Drift / Posture, Logging & Audit, and Device Security.

25 Mar 2026Reports

6 framework readiness views

Findings now map onto six compliance frameworks: Cyber Essentials, ISO 27001, GDPR Article 32, NIST CSF, CIS Controls and SOC 2. Each view is a readiness lens, not certification.

20 Mar 2026Product

AI-generated executive summaries + per-finding helper

Every completed scan gets an AI-generated executive summary. Individual findings have an "Explain this finding" + AI remediation helper. Both are clearly labelled as AI-generated and sit alongside the step-by-step Microsoft-sourced remediation guides.

15 Mar 2026MSP

Dedicated MSP portal with role-based access

Fleet-wide visibility across managed customer tenants, role-based access (MSP admin, MSP analyst, customer admin, customer viewer), MSP branding on customer-facing reports where enabled, per-customer drill-down from the fleet view.

Want incident notifications instead of feature updates? Subscribe on the status page — email or Atom.