Changelog
Product updates and platform changes from the sference team.
2026-08-20
Security & compliance hardening
- SecurityEnabled Amazon GuardDuty threat detection with findings forwarded to on-call, and multi-region CloudTrail audit logging.
- SecurityVPC Flow Logs enabled on all networks; log retention standardized to 365 days.
- SecurityExtended monitoring: load-balancer health/latency, database, and server alarm coverage.
- PlatformDatabase audit logging (pgaudit) configured for the production Postgres fleet.
2026-08-10
Encryption & access controls
- SecurityAll S3 storage now enforces HTTPS-only access via bucket policy.
- SecurityEmployee AWS access consolidated to SSO with MFA; standing console accounts removed.
- PlatformPoint-in-time recovery enabled for infrastructure state.
- PlatformBranch protection now enforced on all repositories: required reviews and status checks.
2026-08-04
Dependency security updates
- SecurityPatched high-severity vulnerabilities in cryptography (CVE-2026-69247) and httplib2 (CVE-2026-59939) — same-day turnaround.