Changelog

Product updates and platform changes from the sference team.

2026-08-20

Security & compliance hardening

  • SecurityEnabled Amazon GuardDuty threat detection with findings forwarded to on-call, and multi-region CloudTrail audit logging.
  • SecurityVPC Flow Logs enabled on all networks; log retention standardized to 365 days.
  • SecurityExtended monitoring: load-balancer health/latency, database, and server alarm coverage.
  • PlatformDatabase audit logging (pgaudit) configured for the production Postgres fleet.

2026-08-10

Encryption & access controls

  • SecurityAll S3 storage now enforces HTTPS-only access via bucket policy.
  • SecurityEmployee AWS access consolidated to SSO with MFA; standing console accounts removed.
  • PlatformPoint-in-time recovery enabled for infrastructure state.
  • PlatformBranch protection now enforced on all repositories: required reviews and status checks.

2026-08-04

Dependency security updates

  • SecurityPatched high-severity vulnerabilities in cryptography (CVE-2026-69247) and httplib2 (CVE-2026-59939) — same-day turnaround.