Skip to main content
SeentrixSeentrix

What's new

Product updates, improvements and fixes — release by release.

Current version1.9.6

1.9.6

Vendor advisory checks stay reliable when a feed is denied

  • FixedVendor advisory background checks no longer treat a denied Siemens ProductCERT feed as a hard monitor failure.
  • ImprovedWhen a public allowed host denies a request, the check records a warning instead of an error.
  • ImprovedWatchtower and watchdog alerts for those checks can clear after the next successful run.

1.9.5

Honest recovery after a stall, and a Declaration that stays unissued until it is ready

  • ImprovedIf Copilot stalls or is unavailable, Retry appears only on that leftover — a finished answer or a used-up month is never shown as something you can retry.
  • ImprovedRefresh from Stripe, when it is on the page, only re-reads your billing. It will not invent a paid plan or open a customer portal you do not have.
  • ImprovedSign-in challenges keep the mapped MFA message. A raw provider leftover is not treated as a completed sign-in.
  • ImprovedIssuing a Declaration of Conformity stays gated while the product is Not ready — the Issue path is never treated as complete on an unfinished product.
  • ImprovedBackground checks now cover provider-failure recovery and Declaration attestation leftovers, so those honesty gaps are caught before they reach you.

1.9.4

Honest Copilot draft cards, and billing that stays unpaid until you pay

  • ImprovedCopilot draft cards for a Declaration of Conformity, incident narrative, researcher acknowledgement, or threat model now appear only when a real draft is ready — if Copilot cannot finish, you see that leftover instead of a completed-looking card.
  • ImprovedWhen this month's Copilot messages are used, a draft request stays empty and the composer stays locked — the month being used is never shown as a finished draft.
  • ImprovedLeaving checkout without paying now returns you to billing as unpaid, so a cancelled checkout no longer looks like an active paid plan.
  • ImprovedComing back to finish an upgrade uses Upgrade again — a cancelled checkout is not treated as a resumed subscription.
  • ImprovedManage billing only opens invoices when you already have a billing account. It will not invent a customer portal or paid access.
  • ImprovedBackground checks now cover more Copilot draft and billing leftovers, so those honesty gaps are caught before they reach you.

1.9.3

Support handled in Slack first, and a quieter admin inbox

  • ImprovedMessages you send to support or sales are now worked in Slack first, so the daily inbox is the channel the team already watches — not a second queue in the admin console.
  • ImprovedThe admin Support page is still there as a power tool for sending an approved reply, but it is no longer the daily tab staff live in.
  • ImprovedProspect and contact conversations follow the same Slack-first path, so a pricing question is not parked in a separate daily inbox.
  • ImprovedWhen staff open a support alert from Slack, they land on your exact conversation — not an empty inbox.
  • ImprovedThose Slack links now open the right thread immediately, instead of relying on a late jump after the page loads.
  • ImprovedThe admin console keeps finance, companies, deals, and other privileged tools in the main tabs, with Support under Power tools.
  • ImprovedBackground checks now cover more of the product journey — SBOM, incidents, Copilot, billing, signup, and the technical file — so more regressions are caught before they reach you.

1.9.2

Support replies that stay in the thread, and Copilot that stops when the month is used

  • ImprovedWhen you've used this month's Copilot messages, the composer now stays locked so you cannot send another one until the allowance resets — you still see the monthly limit, not a failed send.
  • FixedMessages you send to support or sales now reach the desk even when they arrive through the inbound mailbox, so a support email is no longer silently dropped.
  • NewSupport staff can draft a reply, get it approved, and send it — including when the conversation started by email — so you get a real reply instead of a lost draft.
  • ImprovedWhen support replies to an email you sent, the reply now appears in the same conversation in your inbox, instead of as a new thread.
  • FixedClosed support conversations no longer accept a new reply, so a finished thread stays finished until someone reopens it.
  • ImprovedCRA checker answers now stay with you through sign-in, a failed save, and every language — review them before they become a product, instead of starting over.
  • ImprovedBackground checks now catch more support and access regressions before they reach you.

1.9.1

Auditable EMB3D reviews, safer organization deletion, and Copilot quotas that fail closed

  • NewA Founders plan is now available — €19.99 a month or €199 a year — for one product and two users, with the Professional toolkit (SBOM, documents, incident reporting, weekly monitoring) and 50 Copilot messages a month. The optional AI Boost add-on now includes 1,200 extra messages at the same €49 / €490 price.
  • ImprovedReviews of historical EMB3D tags now record who confirmed them and when, appear in Activity, and add a dated note on new PDFs that those labels do not denote the official MITRE threats of the same identifier.
  • SecurityDeleting an organization now uses a scoped cleanup that can resume if a file or account step fails — failed cleanup is kept and retried instead of being lost.
  • ImprovedIf Copilot cannot check your usage quota, it still fails closed — you get a clear retry, never a guessed allowance — and we now watch those outages and recoveries independently of the HTTP response.
  • ImprovedFailed payment events are now tracked until they succeed, so a billing update that does not apply stays visible instead of disappearing.
  • ImprovedIncident reminder work that needs a human look stays visible after a later deadline takes over, and operators can recover or dismiss it in one audited step — no duplicate sends, no lost reminders.
  • ImprovedSupport can now confirm that customer-ops alerts reach the right channel, so incoming messages are not silently missed.

1.9.0

Access enforced at the data boundary, and CRA classification you can verify

  • SecurityTeam administration and account- or organization-deletion workflows are now enforced by the database itself, not only by the application: adding or removing members, changing roles and deletion requests are checked at the data boundary, and an organization can never be left without an active admin.
  • SecurityTwo-factor authentication is now mandatory for every direct data and private-file access path — the data API and file storage, not just the app pages — and anonymous access to tenant data is denied outright. Deactivating or removing a member also signs out all of their devices immediately, and reactivation requires a fresh sign-in with two-factor authentication.
  • FixedThe CRA classification catalog now follows the enacted Annex III / IV list exactly (26 entries), corrects the class of PKI and certificate-issuance software and operating systems to Class I, and retires proposal-era categories. The rules are validated by an independent check derived from the regulation text, in the app and in the database.
  • ImprovedProducts whose classification was saved under the earlier catalog now show a clear 'Not assessed' state on the dashboard, in the products list and in the product header until you confirm or re-run the assessment — nothing is silently reclassified for you.
  • ImprovedCopilot answers are grounded in your current assessment evidence and readiness data, says so explicitly when product context is unavailable, handles quota limits without repeating requests, and keeps provider details out of diagnostics.
  • ImprovedThe dashboard's vulnerability posture panel aggregates findings across all of your products, keeps counts complete, and shows clearly when a read has failed instead of displaying partial numbers.
  • ImprovedTwo-factor recovery, incident user notices and payment reminders are now durable: an interrupted step resumes where it left off, recovery codes are replaced atomically, and per-recipient delivery is tracked so nothing is sent twice or skipped.
  • ImprovedRisk assessments tagged with MITRE EMB3D threats before the official catalog was adopted now get a guided review: original labels keep their recorded meaning, you choose official canonical tags per item and confirm the review, and unreviewed legacy tags block a new PDF or release until you do. Copilot walks you through the steps; it does not change the assessment.
  • FixedGenerated PDFs show page numbers again; the system manual's headings and cover are localized in all 8 languages, with the cover title and version shown separately.

1.8.0

OT product security, local source-to-SBOM CLI, and honest public claims

  • NewFirst-class VEX statuses (affected, not affected, fixed, under investigation) on each finding, with CSAF justifications — independent of workflow triage. CSAF 2.0 and CycloneDX VEX export now use those fields when set.
  • NewPublic Siemens ProductCERT CSAF advisories can be ingested and matched to your SBOM (CPE, PURL, then name). Shown on the Vulnerabilities tab and in the API. Business plan and above.
  • NewOffline OT scanner CLI: turn a CODESYS or Siemens TIA/AML export into CycloneDX 1.5 and SPDX 2.3, then upload into Seentrix. It does not scan a live PLC and does not open TIA binary projects.
  • NewLocal source-to-SBOM CLI for npm, Python, and Go lockfiles (CycloneDX 1.5 and SPDX 2.3). Upload through the existing SBOM path. It is not SAST, does not upload your source tree, and is not a complete repository inventory — prefer a lockfile; package.json / pyproject.toml ranges are a fallback.
  • NewSupplier due diligence on Lifecycle & Supply Chain: for each SBOM supplier, Seentrix checks security.txt, a GLEIF LEI, and a CSAF advisory URL — a process record, not a file dump.
  • NewATT&CK for ICS and MITRE EMB3D catalogs can be tagged on risk-assessment items alongside STRIDE. Copilot can draft a starter from a pasted brief or extracted PDF text; it does not write the assessment.
  • ImprovedThe public API now returns EPSS and VEX on vulnerabilities, and adds advisory export, vendor-advisory, and supplier-diligence endpoints. Academy, the user guide, and the API notes cover the OT and source-CLI workflows.
  • ImprovedVulnerability triage shows EPSS. Copilot keeps answering if the rate-limit store is briefly unreachable.
  • FixedHomepage tiles no longer claim SBOM generation or that Seentrix files to ENISA. The product still produces SRP-ready packages; it does not transmit them.

1.7.2

Company identity only

  • ImprovedLegal notices and product copy identify Seentrix Ltd and the Seentrix team only — the public legal notice lists the company, its Companies House number, and support@seentrix.com.

1.7.1

We hear you the moment you write

  • NewMessages sent through the website chat now reach our support inbox by email the moment a new conversation starts, so first contact gets a fast human response — with no change to what data is collected.

1.7.0

Your brand on your documents — and support you can hold us to

  • NewCustom branding on PDFs is here: upload your logo and set your brand colours in Settings → Organization, and your Declaration of Conformity, technical documentation, and technical file exports carry your identity. Included in Enterprise and available as an add-on; a live preview shows exactly how your documents will look.
  • NewEnterprise billing, presented properly: organizations on an Enterprise agreement now see their plan terms, included entitlements, and latest invoice in Settings → Billing — instead of self-serve buttons that don't apply to a negotiated contract.
  • ImprovedThe Enterprise order form is now a complete, signature-ready commercial document: full legal identities for both parties, an itemised fee table with the annual pricing math spelled out, clear commercial terms, and proper signature blocks.
  • ImprovedSupport response promises are now precisely worded (business days and hours, Mon–Fri 9:00–18:00 CET/CEST) and mechanically enforced: every support request is stamped with its response deadline the moment it arrives, and our team works from a queue ordered by those deadlines.
  • FixedContinuous SBOM monitoring now keeps its exact schedule. A timing drift could stretch the interval between scans — hourly monitoring on Enterprise, daily on Business — and that drift is gone; scans stay locked to their cadence.

1.6.0

Auf Deutsch, and honest about the numbers

  • NewOur six most important CRA guides are now available in German — the blog adapts to your language, with dates and categories localized in all 8 languages, and English articles shown where a translation doesn't exist yet.
  • NewPrivacy-first analytics: we now measure page views and product signups without cookies, without storing anything in your browser, and without any personal identifiers — link parameters are stripped on your device before anything is sent. The privacy and cookie policies describe exactly what is collected and for how long.
  • ImprovedSharing Seentrix pages now produces proper link previews everywhere — including CRA checker results, which show the classification verdict in the preview. Search engines also get cleaner, more precise page metadata across the site.
  • FixedAccuracy pass on our own content: the landing-page market statistic is now a verified, cited figure (Linux Foundation / OpenSSF 2026 research), and several regulatory details in older blog articles were corrected — the SBOM minimum scope, the technical-file structure per the adopted regulation, and the support-period framing.

1.5.2

Saying exactly what we deliver

  • ImprovedA precision pass over our public claims: data hosting is now described exactly (hosted in Europe — London and Frankfurt), the Enterprise SLA is stated as it really works (custom, agreed in writing), and support channels are described precisely (live chat, Mon–Fri 9:00–18:00 CET). Nothing about the service changed — only the wording, which now matches it exactly.
  • ImprovedOur public claims are now backed by automated checks: if a pricing or marketing statement ever drifts from what the product actually does, our test suite fails before it can ship.

1.5.1

Built for big SBOMs

  • ImprovedThe vulnerability and incident lists now load in pages, keeping them fast even with thousands of findings. Sorting always shows the most urgent items first (actively exploited, then KEV-listed, then by severity), all filters search your complete data — never just the visible page — and the summary counts stay exact.
  • SecurityTightened internal database access controls: internal functions are now callable only by the parts of the system that genuinely need them, and the remaining access is documented function by function.
  • FixedClarified the audit-trail description to precisely match its behaviour — tamper-evident, immutable through the product, with the automatic GDPR redaction on account erasure stated as the one exception — plus a reliability improvement to the training-completion check and a typography fix in the Terms.

1.5.0

A sharper Academy and three redesigned views

  • NewTwo new Academy lessons: 'Products already on the market' (the transitional regime and substantial modification — including that incident reporting applies to ALL in-scope products from 11 September 2026) and 'When the regulator knocks' (market-surveillance powers, your duties, and the penalty tiers). The Academy now covers 23 lessons in all 8 languages.
  • ImprovedA full legal-accuracy review of the Academy against the regulation text: the Article 14 final-report deadlines are now taught correctly (one month after notification for severe incidents; 14 days after a fix is available for actively exploited vulnerabilities), the 5-year support period is correctly framed as a default tied to expected use time, and the conformity-route guidance for critical products was corrected. Deadline wording was aligned everywhere it appears — incident screens, PDF reports, pricing and the copilot.
  • ImprovedClassification results for critical products now name the correct conformity route: third-party assessment via a notified body — European certification becomes mandatory only once the Commission requires it for your category.
  • ImprovedThe dashboard's readiness-by-product view was redesigned: products needing attention sort to the top, gaps stand out visually and each one links directly to the screen where you fix it, with a proper phone layout.
  • ImprovedThe CRA Readiness page now opens with a clearer picture: a complete/partial/missing distribution bar, glanceable stat tiles and a 'start here' link to your weakest product.
  • ImprovedThe Organization chart in settings shows more: member detail popovers, pending invitations, deactivated accounts, and what each role is allowed to do — with accurate seat counts everywhere.

1.4.0

A complete audit trail of every change

  • NewAudit trail: every change to your organisation's records — products, compliance data, team membership and settings — is now captured automatically at the database level, with who changed what, when, and the exact before/after values. Browse it under Settings → Audit trail, filterable by record type and team member.
  • NewThe trail is tamper-evident by design: entries are immutable to every application role and can't be edited or deleted through the product by anyone, including Seentrix staff — only read by your admins and compliance officers. The one exception is the automatic GDPR redaction described below. Secret values (API keys, tokens, webhook secrets) are never stored in it.
  • ImprovedPrivacy by default: when a team member's account is deleted, their personal details are automatically scrubbed from the audit trail while the record of what changed is preserved, and account deletion now also removes the member's profile picture from storage.
  • ImprovedThe privacy policy and data processing agreement now describe the audit trail, its retention and the erasure behaviour, and the user manual was updated in all 8 languages.

1.3.0

A dashboard that shows your whole CRA program

  • NewSix new dashboard widgets: a 26-week compliance trend chart, a product-by-obligation readiness heatmap, a live vulnerability posture panel, a 90-day regulatory horizon with countdowns, SBOM & monitoring health, and team training evidence.
  • NewRole-aware views — compliance leads see the full program picture, engineers see the security posture in their personal dashboard, and auditors/viewers get a read-only overview worth showing in an audit.
  • FixedContinuous (hourly) vulnerability monitoring on the Enterprise plan could fail to enable due to a database constraint from an earlier release — fixed.

1.2.0

The free CRA checker, public advisories and a stronger technical file

  • NewA free, public CRA classification checker at /cra-checker — answer a few questions and see your product's classification, conformity route and key deadlines in minutes, in all 8 languages. Results are shareable by link.
  • NewSecurity advisories marked Public now actually publish — on your public security page, each with a stable link and a machine-readable feed. Private advisories remain strictly private.
  • NewThe technical file now records how your support period was determined, as Annex VII requires — with guidance when a period under five years needs justification. The Annex VII coverage check only turns green when it's documented.
  • ImprovedBilling integrity: your billing currency is determined by your company's country, which is now required before checkout and verified against the billing details confirmed with our payment provider.
  • FixedClearer wording throughout on the 5-year support period rule — it is a default tied to expected product use time, not an absolute minimum.

1.1.6

A security check you can actually see

  • FixedThe "I'm a human" security check is now always visible on the contact, newsletter and security-report forms. It previously ran invisibly — and visitors who were asked to complete a challenge could be left unable to submit, with no explanation.
  • ImprovedIf the security check cannot be completed, forms now show a clear message with what to do instead of failing silently.

1.1.5

A faster Seentrix, a sharper copilot and airtight legal pages

  • ImprovedSignificantly faster page loads everywhere — pages now ship up to 80% less JavaScript, and dozens of database access paths were tuned for speed as your data grows.
  • FixedThe AI copilot no longer gets stuck on 'Thinking…' — slow answers recover automatically or offer a clear retry. We also fixed an issue where the copilot could answer without consulting the Seentrix knowledge base; it now always grounds its answers in it, or tells you it can't.
  • NewNewsletter signups now use double opt-in, and every newsletter email includes a one-click unsubscribe link.
  • ImprovedOur legal pages — privacy policy, terms, data processing agreement, cookie policy and imprint — were comprehensively reviewed and updated for accuracy and completeness.
  • FixedAssorted polish, including checkmark icons that previously didn't render on a few pages.

1.1.4

Incident notice delivery, exactly-once reports and a fresher site

  • NewIncident user notifications (CRA Article 14(8)) can now be emailed to your affected users directly from Seentrix — with per-recipient delivery tracking shown on the incident, automatic retry of failed deliveries, and duplicate-proof sending.
  • ImprovedWeekly digest and monthly report emails are now delivered exactly once per period, even if a run is interrupted and retried — no duplicates, no organizations skipped.
  • SecurityHardened outbound webhook delivery against network-level redirection, and tightened the integrity guarantees around finalizing a Declaration of Conformity so it can only be issued through the assessed conformity route.
  • ImprovedA clearer 'Compare plans' table, a roomier support chat window, a redesigned CRA-deadline timeline showing what has passed and what's next, and five new blog articles.
  • FixedCorrected the staged CRA deadline descriptions on our website, aligned support hours (Mon–Fri 9:00–18:00 CET), fixed blog tables not rendering, and quieted a background error from the contact-page security check.
  • ImprovedThe in-app user manual and the AI copilot's knowledge base now cover every shipped feature, in all supported languages.

1.1.3

Billing and reminder reliability

  • FixedPayment events are now processed even more reliably — if a rare interruption occurs while a billing update is being handled, it is automatically retried until it completes instead of being skipped.
  • FixedTrial 'ending soon' reminders are now sent exactly once per trial — no duplicate emails if a background run is retried, and no missed reminders after a delayed run.

1.1.2

Reliability polish

  • ImprovedMore resilient background jobs — vulnerability monitoring, weekly digests and deadline reminders now handle interruptions gracefully and avoid duplicate emails if a run is retried.
  • ImprovedYour plan now updates immediately on the billing page right after checkout, instead of waiting for confirmation to sync.
  • ImprovedReadability and layout polish on this What's new page.

1.1.1

Security hardening and reliability improvements

  • SecurityPlatform-wide access-control hardening: stronger enforcement of two-factor authentication, single sign-on, plan entitlements, and data isolation between organizations.
  • FixedBilling subscription changes now reconcile more reliably, so an out-of-sequence payment event can no longer affect the wrong subscription.
  • FixedAccount data-erasure requests now remove all associated personal data, including feedback submissions.
  • ImprovedCleaner, wider 'What's new' page with a consistent layout.

1.1.0

Security hardening, PDF language fixes and signup consent

  • SecurityTwo-factor authentication is now enforced end-to-end: every API request, data export and document download requires a fully verified (TOTP) session — not just the app pages.
  • SecuritySingle sign-on provisioning re-checks your plan's SSO entitlement and seat limit before admitting a new user, and organization profile changes require an admin role.
  • SecurityJira API tokens are now stored encrypted at rest (AES-256-GCM), the same way webhook secrets already were.
  • SecurityStricter server-side validation for SBOM ingestion and file uploads (size, type and content limits).
  • FixedGenerated PDF documents now render every supported European language correctly — Polish characters were previously missing from Declarations of Conformity and reports.
  • FixedTranslated 30+ interface strings that silently fell back to English (Academy lessons, SSO sign-in, API keys, team settings and more), and the dashboard profile banner no longer shows raw labels.
  • NewSignup now records your explicit Terms & Privacy acceptance, with a separate optional opt-in for product updates.
  • NewVersion number and this public update history.
  • ImprovedThe getting-started view now uses the full dashboard width — greeting and progress side by side, with the six onboarding steps as a numbered card grid.
  • ImprovedFriendlier error pages across the product, and clearer, more precise data-hosting wording on the website and legal pages.
  • ImprovedUpgraded the underlying web framework to the latest patch release.

1.0.0

Seentrix 1.0 — initial production release

  • NewThe CRA compliance workspace goes live: product classification, SBOM and vulnerability monitoring, the conformity workflow with Declarations of Conformity, Article 14 incident reporting, technical file, Academy training, AI Copilot, REST API + SCIM, SSO, and support for 8 languages.
  • SecurityMandatory two-factor authentication with backup recovery codes for every account.