Week of March 30: runtime hardening and SaaS controls

Stabilized SQL-backed runtime views, added SaaS paywalls, and improved upload and identity controls.
securityplatformbug fixesperformance

Platform

  • Stabilized SQL-backed dashboards and chat runtime sync.
  • Added SaaS paywalls, pricing upsells, social login flags, and profile-based egress allowlists.
  • Improved packet-stats runtime surfaces, admin diagnostics, and upload audit logging.

Security

  • Hardened container egress with host approval requirements and adopted uv-managed runtime Python package installation.
  • Expanded enterprise auth controls, on-prem proxy flow hardening, and egress allowlist coverage.
  • Removed a stale Zeek update path and documented the supply-chain policy.

Analyzer

  • Added permission-aware PCAP duplicate detection, optimistic PCAP deletion, compact security summaries, and compact PacketStats summaries.
  • Improved memory items and telecom summaries in Agent-facing analysis.

Bug fixes

  • Fixed workspace navigation routes for captures and rules.
  • Tightened network topology label coverage and PacketStats regression behavior.