v1.5.0
The platform grows past the inbox. This release retires the credit model in favor of a Free Tier and flat Seat Licenses, adds bring-your-own-EDR integrations for CrowdStrike Falcon and Microsoft Defender, introduces the AI Exposure scan, connects personal Outlook.com mailboxes with one click, and expands the attestation report.
Free Tier and Seat Licenses
- Credits are gone. Every personal account now gets 30 free Scan Now runs a day across the email, URL, and file analyzers, with full reports and no card required. Cached repeat submissions do not count.
- One flat price. A Seat License ($15 per seat per month) covers one monitored person and unlocks everything that runs without you clicking: org-wide Gmail and Microsoft 365 integrations, device agents, browser and mail extensions, the forwarding mailbox, and API keys, with fair use up to 500 runs per seat per day. Shared organization accounts run on seats only.
- Clearer account pages. The Account overview shows your plan, today's usage, and a subscription card with invoice history; the Tasks view badges which setup steps need a seat.
Bring your own EDR
- CrowdStrike Falcon. Connect a read-only API client (Hosts: Read, User Management: Read, Alerts: Read) and every Falcon-protected device gets a daily health run: sensor online, sensor healthy, prevention policy assigned, and no active alerts. Runs appear beside agent scans in the Monitoring Hub and the attestation report.
- Microsoft Defender for Endpoint. The same for Defender P2 and Defender for Business tenants, through a read-only Entra app registration, with a Defender-specific antivirus health check. Both integrations attribute devices to owners conservatively and never read host contents, vulnerabilities, or alert details.
AI Exposure
- Which AI tools can touch your data. A new daily scan on the Google Workspace and Microsoft 365 integrations inventories third-party OAuth grants and flags AI tools that can reach mail, files, or calendars, plus unverified apps holding data scopes (the classic OAuth-phishing shape). It reads grant metadata only, never message or file content.
- New everywhere it matters. AI Exposure is a monitor type in the hub, has its own report page, can be targeted by alert rules (a rule on Critical or At Risk fires when a new risky app appears after the first baseline scan), and adds an AI Exposure section to the attestation report.
Personal Outlook.com mailbox
- One-click monitoring for individuals. Personal accounts can connect their own Outlook.com, Hotmail, Live, or MSN mailbox with a single Microsoft sign-in. New inbox mail is analyzed automatically, read-only and inbox only, and can be disconnected at any time.
Reports and monitoring hub
- URL Threat Analyzer. The URL Detonation Engine is now the URL Threat Analyzer (same engine, friendlier name) at
/url-analyzer; old links redirect. - Analyze any link from an email report. Every email report now lists all extracted links, not only the flagged ones, each with an Analyze button that sends it to the URL Threat Analyzer.
- Clearer URL report details. Clean detail sections read "No results" instead of a field count, behaviour findings such as ClickFix clipboard lures are explained when detected, and check rows jump to their exact detail.
- Attestation report. Gains the AI Exposure section, an AI-apps summary tile, and EDR-vendor-blind device checks.
- Product tour. First-time personal accounts get a guided tour of the hub, integrations, account, organizations, and Scan Now, replayable from the Account page.
Other improvements
- Landing page updated around the small-business positioning, with the coverage table covering AI exposure and EDR integrations.
- Sales inquiry form replaces the mailto link on the Cyber Security Snapshot page.
- Documentation pages added for the Monitoring Hub, the Security Attestation Report, and both EDR integrations.