v1.4.0
Monitoring gets proactive. This release adds Alerts — scheduled rules that notify you by email or straight into your SIEM when runs match conditions you care about — plus device monitoring for macOS and Windows, and clearer monitor management.
Alerts
- A new Alerts view in the Monitoring Hub. Define rules that check your completed runs on a schedule and deliver the matches — no more logging in just to see if something went wrong.
- Email or HTTP delivery. Send alerts to any email address, or POST them as JSON to an https endpoint. Custom request headers let you authenticate to your tooling — including Splunk HEC (point a rule at your
/services/collector/rawendpoint with aSplunk <token>Authorization header). - Alert on what matters. Trigger on a failed-checks threshold, on explicit verdicts (Malicious, Suspicious, Clean, plus the device verdicts Critical, At Risk, Healthy), on specific run types (URL, email, file, device), or any combination. Leave the filters empty to get everything.
- Immediate, hourly, or daily. Choose per rule: immediate fires within seconds of each matching run (one alert per run — ideal for paging on Malicious or Critical verdicts), while hourly/daily rules send one batched digest per window covering all matches, with failed deliveries retried so nothing is lost. A digest lists up to 100 runs and covers up to 500 matches per window; pair an immediate rule with a digest for a guaranteed backstop.
- Test delivery instantly. A "Send Test" action pushes a synthetic alert through the rule's channel right now, so you can confirm the recipient, webhook, and tokens work without waiting for the schedule. Delivery failures come back with the reason.
- Pause and resume. Toggle any rule off without deleting it. Saved webhook header values (like tokens) are never echoed back by the API — they stay write-only.
Device monitoring
- Monitor the device itself. A new Device Monitor type joins browser and mail monitors: a lightweight agent checks each machine's security posture about once an hour and reports the results — only pass/fail results leave the device.
- macOS Agent. A signed and notarized installer, downloadable from the new macOS Agent page. Checks FileVault, System Integrity Protection, Gatekeeper, firewall, sharing services, automatic updates, and guest login. Enroll with one command.
- Windows Agent. Checks BitLocker, Secure Boot, antivirus health, UAC, RDP, SMBv1, firewall, and automatic updates. The installer is signed with an EV code-signing certificate — SmartScreen may still flag a fresh release while the certificate builds reputation, so a SHA-256 checksum is shown next to the download.
- Posture verdicts and reports. Device scans are scored Healthy, At Risk, or Critical, appear in the Monitoring Hub under the new Device filter, and open into a full device posture report showing every check with its severity and result.
- Seat-licensed only. Device monitoring runs exclusively on seat licenses (no credit fallback) — assign the monitor to a seated member and all of their monitors share that seat's daily fair-use budget.
Clearer monitor management
- Name and seat assignment are now separate. Every monitor (and API key) has a free-text display name and, separately, a seat assignment — the seated member's email its runs bill to and report as the submitter. No more overloading one field for both.
- Edit monitors in place. Rename or reassign a monitor from the Monitors table without regenerating its key — extensions and agents keep working through the change.
- Guardrails on seat assignment. Assignments must match an active seated member; the form suggests your seated members, warns before you submit a mismatch, and explains exactly how to fix a rejection.
Other improvements
- New Active Monitoring page describing all five monitors — Chrome, Outlook, Gmail, macOS, and Windows — with setup links for each.
- SOC 2 badge across the product. Our SOC 2 Type 1 attestation (Type 2 in progress) is now shown on the landing, pricing, and monitor setup pages, linking to the Trust Center.
- CSV export fix. The Monitoring Hub export now correctly includes the Submitted By column.
- Report column clarity. Runs without a report page no longer show a perpetual "Pending" state.