Version 9.3.0.1
August 4, 2026- Dormant Administrator Detection: Administrator accounts with no sign-in for 90 days are flagged automatically on the Administrators list, so privileged access nobody is using surfaces in your access review instead of persisting unnoticed. A flagged account can be disabled from the same list.
- Provider-Scoped Posture Reports: A posture report can now be scoped to an entire cloud provider — every connected AWS, Azure, or Google Cloud account in one export — as well as to a single account or across your whole estate. Each report covers connected accounts, discovered assets, open findings, and the severity breakdown, as a readable report or a spreadsheet, so a request for evidence on one provider does not mean handing over the others.
Enhancements
Cloud Security- Cloud Account Removal Clears Its Findings: Removing a cloud account clears its inventory and findings with it, so your open-findings count reflects the accounts you actually run. Export that account’s posture report before you remove it if you need to retain the evidence.
- Attributable Cloud Audit Entries: Cloud audit entries now carry the account name and the provider — AWS, Azure, or Google Cloud — as columns in the audit trail, so a configuration change is attributable to the account it was made in without resolving an account identifier against the inventory first.
- Application Control Priority on Block Rules: Application control rules now show their evaluation priority for block rules as well as allow rules, so where an allow rule and a block rule cover the same application you can confirm which one wins before the policy reaches your fleet.
- Updated Classification Definitions: The current application, file, and device classification definition set extends coverage to recently released collaboration and AI assistant clients, further installer and archive file types, and additional removable-media and peripheral device classes. Adoption stays under your control — check your classification settings to confirm your organization is running the current set — and classifications you wrote yourself are never overwritten.
Security Updates
- Verified-Domain Single Sign-On: Single sign-on is restricted to your organization’s own verified domain, so only identities in that domain can authenticate into your organization. Administrators you invite directly are unaffected.
- Immediate Session Invalidation: Signing out invalidates that session immediately, and each device session holds its own token, so ending a session on one device leaves your other devices untouched.
Endpoint Detection & Response and a dedicated Identity & Access Management module are both in active development and coming soon.
Version 9.3.0.0
July 30, 2026- Insights Rebuilt as Security Analytics: Insights now carries more than thirty views across web attack, DNS, endpoint, identity, certificate, and configuration data. New views cover attack volume and attack origin over time, the most-targeted URLs and paths on your protected sites, DNS query volume split by allowed and blocked, top web categories, riskiest users, endpoint operating-system mix, multi-factor adoption, control pass rate, certificate expiry, and configuration-change activity by module — web protection, endpoint, and cloud.
- API Schema Validation: Upload an OpenAPI definition for a protected API and Osto enforces it at the edge. Requests that violate the declared paths, methods, parameter types, or required fields are rejected before they reach your service, and the API inventory flags any endpoint serving traffic outside the schema you published for it.
- Custom Protection Rules: Write your own detection rules against request paths, parameters, headers, cookies, and body content; choose block, log, or challenge; and order them against the managed ruleset. An attack pattern specific to your application is covered on your own timetable rather than on a signature release cycle.
- Log Forwarding to Your SIEM: Stream web protection, domain filtering, endpoint, secure server access, and audit events to your own SIEM or log platform, choosing the event types and minimum severity you forward. Osto remains your control plane while your existing detection pipeline keeps a complete picture.
- Newly Seen API Paths: The API inventory introduced in 9.1.2.0 now separates paths seen for the first time in the last seven days from those it has been tracking, so an endpoint that appeared this week is something you are shown rather than something you go looking for.
- Deny Rules Refuse the Connection Outright: A secure server access rule set to deny refuses the connection outright, and the attempt is recorded in your logs as a policy denial. A denial is attributable to the rule that made it, so an access review reads your policy decisions directly.
- Cookie Security Exemptions: You can now name specific cookies to exclude from cookie-security enforcement, so third-party or legacy cookies that must keep their original attributes keep working while every other cookie on the site stays hardened. Exemptions are written per site in the advanced policy editor and listed with the rest of that site’s policy, so a deliberate exception stays visible rather than becoming an unexplained gap.
Enhancements
- Certificate Validation Before a Site Goes Live: Duplicate and expired certificates are flagged before you attach one to a site, so a site does not go live behind a certificate that is already invalid.
With API schema validation, custom protection rules, and log forwarding, this release closes the loop: Osto enforces what your APIs declare, lets you write the rules only you could write, and hands every event to the pipeline you already run.
Version 9.2.2.0
June 30, 2026- Expanded Cloud Posture Check Coverage: Twenty-six new posture checks across AWS, Azure, and Google Cloud: over-permissive roles, access keys past their rotation age, and unused privileged identities; storage containers, database endpoints, and network rules reachable from the internet; and unencrypted volumes, snapshots, and managed database instances. The new checks are evaluated on your next scheduled scan and appear in your findings and posture reports alongside the rest.
- Expanded Data Classification Patterns: The classification library behind data loss prevention gained new built-in patterns — payment card and bank account numbers, national and tax identifiers across additional regions, health record identifiers, and credentials such as private keys and provider access tokens carried in files. Any App File Access policy already scoped to a classification picks up the wider coverage without an edit.
- Device Posture Checks Before Access: A secure server access policy can now require the connecting device to meet your endpoint standard — agent present, disk encryption enabled, screen lock enforced — before a session is established, so an access decision accounts for the state of the machine and not only the identity behind it.
- On-Demand Cloud Posture Scans: Re-scan a connected cloud account whenever you need with a Scan now action rather than waiting for the next scheduled run, so you can confirm a misconfiguration is genuinely closed at the moment you remediate it.
- Configurable Origin Response Timeout per Website: Set how long Osto waits for your origin to respond, per protected website, from that website’s settings, and lift the limit entirely for long-running endpoints. A report builder, a bulk export, or any other slow path stays behind full inspection while it runs.
Enhancements
- Access Logs at Full Traffic Volume: Access log paging and export return the complete record set at any traffic volume, so an export doing evidentiary work — an incident timeline, or the sample an auditor asked for — carries every matching record.
- Google Cloud Connection Diagnostics: A failed Google Cloud connection names the exact permission or service to enable, and the connection test succeeds for projects that run no compute instances, so a project built on storage, functions, or managed databases can be brought under posture scanning.
Access decisions now weigh the device as well as the identity — an unencrypted or unmanaged machine can be kept out of your infrastructure even when the credentials are perfectly valid.
Version 9.2.1.1
May 29, 2026- One-Click Bypass Rules for False Positives: When a legitimate request is blocked, click Bypass directly on that log entry and Osto writes a precise exception — for that one rule, on that one URL, query-string or request-body parameter, header, cookie, or source address, and for that origin alone. Every bypass rule is listed, reviewable, and removable, so a tuning decision made months ago is still visible to whoever reviews your policy next. Policy exceptions written under 9.2.0.0 keep working alongside them; review yours and retire any that a narrower bypass rule now covers.
- Account-Wide Bot and Denial-of-Service Protection: Bot and denial-of-service protection are now set once for your whole account rather than site by site, so your posture is uniform across every protected site and a site you add tomorrow inherits it rather than starting from its own configuration.
- Time-Based Policy Windows: Application control and data protection policies can now be scoped to a date range and to specific days and times of the week, so a control applies during working hours, a contractor engagement, or a change freeze rather than permanently.
Enhancements
- Path Rewrite and Per-Rule Protection for Routing Rules: Custom routing rules can now rewrite the request path before it reaches your origin, and each rule carries its own web protection switch — so you can exempt a single callback route from inspection without loosening the policy covering the rest of the domain.
- Screen Lock and Disk Encryption in One Device Policy: Automatic screen lock and enforced full-disk encryption are set together in a single device policy per user group, so the two controls cannot drift apart across the same set of devices.
- End-to-End Request Tracing in Web Protection Logs: Web protection logs now carry the client user agent, request identifier, connection scheme, and rule tags — enough to follow a single request from the edge to the control that acted on it, and to line it up against your own application logs.
- Protection Mode and Policy Changes in the Audit Trail: The audit trail now records protection mode switches with their before and after values, user group membership changes, and device policy edits, so any change in enforcement posture is attributable to a person and a time.
Version 9.2.1.0
May 4, 2026 Code Security- Repository, Dependency, Secret, and Infrastructure Scanning: Connect a GitHub, GitLab, or Bitbucket account — cloud or self-hosted — and Osto scans every repository for insecure code, vulnerable open-source dependencies, hard-coded secrets in both working code and commit history, and misconfigured infrastructure definitions. Browse findings by repository, branch, language, and severity.
- Software Bill of Materials per Repository: Every scanned repository produces a bill of materials listing the open-source components you ship and the license attached to each, so a license question or a newly disclosed component vulnerability is answered by lookup rather than by investigation.
- Osto Risk Score: Every finding carries a single 0-100 value that blends technical severity with real-world exploit likelihood, whether the flaw appears on the public catalog of actively exploited vulnerabilities, and whether the vulnerable code is reachable from your running application. A list of a thousand alerts collapses to the few dozen that warrant action.
- Scanning Inside the Development Workflow: Scans run on every push and on every pull request, commenting inline on the exact changed lines. Results are split into new, pre-existing, and fixed against the merge target, so a pull request is judged only on what it introduces. Scheduled scans cover everything else, with findings emailed to the recipients you name.
- Triage with Expiring Suppressions: Mute a finding or accept a false positive against an expiry date, so nothing is dismissed permanently by accident and every suppression returns for review.
- Validated Secret Findings: A detected secret is verified against the service it belongs to, so a finding tells you whether the credential is still live and needs rotating today or was already revoked — the difference between an incident and a backlog item.
- SOC 2 with Automated Evidence Collection: Enable SOC 2 and Osto builds the program — the full control library, a task list with owners and due dates, and a readiness dashboard showing which requirements are satisfied, partially satisfied, or outstanding. Evidence is drawn continuously from the rest of your Osto estate: web application protection, data loss prevention, domain filtering, endpoint device policy, cloud posture, sign-in records, and audit trails. Control status therefore reflects your live configuration rather than a screenshot taken once. You can still upload your own evidence, add custom controls, and create your own tasks.
- Policy Library with Enforced Approval Separation: More than twenty ready-written policies cover the ground auditors ask about, including information security, access control, incident response, and vendor management. Each is pre-filled with your company details, editable in the browser, and versioned with a change summary. Every policy routes through a formal approval step in which an author cannot approve their own document, then publishes as a branded PDF and goes out to staff for acknowledgment.
- Security Awareness Training with Recurring Assignment: Build training programs from reusable modules with knowledge-check quizzes and assign them to individuals or groups. Osto re-assigns a program automatically before the previous completion expires, so coverage never lapses unnoticed. Acknowledgment and completion records feed your compliance evidence directly.
- Enforced Full-Disk Encryption with Recovery Credentials: Require full-disk encryption on managed devices as part of a device policy. Recovery credentials are made available to the administrators you nominate, so an encrypted machine is always recoverable by someone named in advance.
- Software Inventory Across Managed Devices: Managed devices report the applications installed on them — publisher, version, architecture, install date, and signature status — and the inventory refreshes as software is installed or removed. It is searchable and filterable, so “which of our machines still run that version” has an answer during an incident rather than after one.
Enhancements
Web Protection- Scheduled Security Reports: Osto sends your administrators a recurring web protection summary as an HTML or PDF attachment covering request volumes, top threats broken down by severity, policy violations, and how the period compares with the one before it. Choose the reporting window and the severities you want included.
Two new modules land together: Code Security, which secures your codebase before it ships, and Compliance Automation, which turns SOC 2 from a screenshot exercise into evidence your platform collects for you.
Version 9.2.0.0
April 21, 2026- Rebuilt Web Application Threat Detection Engine: The engine that inspects traffic to your protected domains has been rebuilt, with a refreshed detection ruleset covering SQL and command injection, cross-site scripting, path traversal, request smuggling, and insecure deserialization. Set it to Blocking or Detection-Only, choose how much audit detail each match records, and apply that choice globally or to an individual origin. Mode and ruleset changes take effect without dropping traffic.
- False-Positive Tuning with Policy Exceptions: When a legitimate request is blocked, raise the matching exception in one step directly from the traffic log. Exceptions can also be written by hand against a URL, a query-string or request-body parameter, a header, a cookie, or a source address, each with accept, skip, or drop behavior, and an existing exception can be edited in place rather than deleted and recreated.
- App File Access Data Loss Prevention: A new policy type controls which applications may — or may not — open which classes of files on managed devices. Pick the file classifications, pick the application groups, choose block or allow, and apply the rule to individual people or whole groups, optionally limited to a schedule. Osto ships ready-made classifications and you can add your own.
- Custom Routing Rules for Protected Domains: Shape traffic per domain without touching your own infrastructure. Match requests by path prefix, exact path, or pattern; route them to a chosen backend or issue a redirect with the status code you want; rewrite the host or path; force HTTPS; and order rules by priority. A rule can also exclude its route from threat inspection where an origin requires requests to arrive unmodified.
- AI Security Questionnaires: Upload a customer or vendor security questionnaire, or paste it in as text, and Osto drafts each answer from your own published policies and your declared security stack. Edit any answer, regenerate it with extra context, mark it reviewed, and export the completed questionnaire.
Enhancements
- Individually Switchable Advanced Protections: Sensitive-data leak prevention, response cloaking, parameter protection, and cookie security can each be turned on or off per domain from the Advanced Policy page, so a domain that needs one of them relaxed does not lose the other three.
- Dedicated Rate Limiting: Rate limiting is now separate from general request limits, so you can hold a strict request rate without also constraining request size, and tune the two against different thresholds.
- Status Code, Rule Tag, and Matched Sample in Every Log: Traffic, error, and policy violation logs gained status code, rule tag, and matched-sample columns, and log filters now support contains and contains-any matching — so you can pull back every request that tripped one named rule.
- Global Device Policy: Device-wide settings are managed from a single Global Policy page, starting with enforced automatic screen lock, applied to individuals or user groups with per-group overrides.
Detection-Only mode is the safe way to trial the new threat detection engine — every request is evaluated and everything that would have been blocked is recorded, without affecting live traffic.
Version 9.1.2.4
March 19, 2026- Access Revocation Reaches Live Sessions: A change to your secure server access rules — including removing a person and removing a server — is pushed to connected clients as you make it, so it reaches sessions that are already open. When you cut someone off during an offboarding or pull a server out mid-incident, the change applies to live connections.
- Versioned Classification Definitions You Choose to Adopt: The built-in file, application, and device classifications behind data loss prevention, application control, and device control are now versioned. You can see whether your organization is running the current definition set, choose when to adopt a new one rather than having it applied to your fleet unannounced, and rely on any classification you wrote yourself never being overwritten by an update. New organizations start on the current version.
- Certificate Renewal Alerts and Standalone Upload: You are now emailed on both outcomes — when a certificate renews and when a renewal fails — so a lapse is something you are told about rather than something your users discover. You can also upload a certificate on its own without attaching it to a site first: Osto reads the covered domain out of the certificate itself, so a certificate is filed against the domain it actually covers rather than the one someone typed.
Enhancements
- Refreshed Web Protection Rulesets: The detection rulesets behind web application and API protection were updated with current signatures for request smuggling and desync, server-side template injection, insecure deserialization, and server-side request forgery.
- DNS Settings Delivered to Linux Endpoints: Linux clients now receive their DNS settings as part of connecting, so private service names resolve and your domain filtering policy applies from the moment the tunnel comes up, instead of depending on how the machine happens to be configured locally.
Security Updates
- Least-Privilege Read-Only Administrators: Administrators holding a read-only role are shown only the actions that role permits, so an access review of your read-only administrators reflects real capability rather than what the console offers.
Version 9.1.2.3
March 5, 2026- Cloud Posture Reporting and Grouped Findings: Export your cloud posture as a formatted report or a spreadsheet covering connected accounts, discovered assets, open findings, and a breakdown by severity — for your whole estate or scoped to a single cloud account, so you can hand an auditor or an account owner exactly the scope they asked for. Findings can now be grouped by severity, cloud account, service, or check rather than read as one flat list, and each connected account reports live scan progress. A scan that cannot complete states why — expired credentials, missing permissions — so a gap in coverage is never mistaken for a clean result.
- Scheduled Web Vulnerability Scanning: Web application scanning now runs on a cadence you set — daily, weekly, or monthly — alongside on-demand scans, so an internet-facing application is re-tested on a fixed schedule rather than whenever someone remembers to start one. The dashboard follows each scan through its real states — not started, in progress, completed, report ready — so a completed scan is never mistaken for a stalled one.
- Authenticated Web Scanning: A scan can now sign in to your application before it tests, using credentials or a session you supply, so the pages behind your login — where the business logic and the sensitive data actually live — are covered rather than stopping at the front door.
- Reusable Scan Profiles: Save a scan configuration as a profile — scope, crawl depth, excluded paths, and credentials — and apply it to any site, so every application in a class is tested the same way every time.
Enhancements
- Expanded Web and App Scanner Checks: Forty new scanner checks, including weak TLS versions and cipher configuration, missing Content-Security-Policy and HSTS response headers, session fixation, insecure direct object reference, and server-side request forgery.
- Bypass Rules Across Multiple Posture Checks: A single posture bypass rule can now cover several checks at once, so a documented exception that spans a group of related checks is written and reviewed as one rule rather than repeated per check.
- Audit Coverage for Administrative and Access Changes: The audit trail now records administrative and access-control changes with a before-and-after snapshot of exactly what changed, so a review shows the previous value beside the new one instead of recording only that something was edited. Log columns have also been standardized across views, so the same field means the same thing on every page and a filter expression you build on one log carries to the next.
An unauthenticated scan tests your front door. Authenticated scanning tests the rooms behind it — where your business logic and your customer data actually are.
Version 9.1.2.2
February 25, 2026- Bypass Rules for Cloud Posture Checks: Cloud posture results can now be tuned to your environment. A bypass rule marks an individual finding — or an entire check, everywhere it applies — as passed, skipped, or failed, with the reason recorded against it. Accepted risks and known exceptions stop resurfacing on every scan, the recorded reason makes each exception reviewable later rather than a decision someone has to recall, and what remains in your findings list is what still needs action.
Enhancements
- Classification Changes Reach Devices on the Next Check-In: A new or changed application or file classification now reaches managed devices on their next agent check-in rather than waiting for a rebuild, so a control you publish is enforced across the fleet the same day you write it.
- Log Times Normalized on Ingest: Event times from the audit trail, authentication, device control, secure server, domain filtering, and web protection logs are normalized to a single format as they arrive, so an incident timeline assembled from several log types lines up rather than drifting between them, and sorting, filtering, and cross-referencing agree across views.
- CIS Benchmark Mapping on Posture Checks: Every cloud posture check now carries the CIS Benchmark control it maps to, so a finding is traceable to the published benchmark behind it and your posture results speak the language your auditors already recognize.
- Granular Removable Media and Peripheral Control: Device control now treats removable storage, mobile devices, and imaging and printing peripherals as separate classes, so you can block mass storage outright while leaving the peripherals your teams work with connected.
Version 9.1.2.1
January 22, 2026- Bot and Denial-of-Service Rule Library: The full rule library behind bot and denial-of-service protection is now visible in the dashboard, organized into named categories such as slow-connection attacks, content-management resource exhaustion, fake search-engine crawlers, and credential-stuffing bots. Open any rule to read what it matches and how often it has fired, and switch protection on or off at category, group, or individual rule level. A single rule can be put into log-only mode so it keeps reporting while everything around it keeps blocking.
- True Client Address in Logs and Policy Matching: Web protection records and matches on the originating client address, so country blocking, rate limiting, and source-address exceptions evaluate the address a request came from even when it arrives through a load balancer or upstream proxy, and your logs attribute traffic to the client itself.
- Origin Load Balancing, Health Checks, and Re-Encryption: Put several origin servers behind a protected domain and distribute traffic across them by round-robin, least-connections, or hash, with per-server weights, connection limits, and timeouts. Origins that fail their health check are taken out of rotation automatically and returned when they recover, and traffic from Osto to your origin is re-encrypted using only the TLS versions you allow.
Enhancements
- Deeper Fields in Web Protection Logs: Policy violation logs now carry the incident type, the request method, and the request headers, so you can reconstruct exactly which control fired and on what request. Access logs carry the client user agent alongside them.
- Log Search Operators: Log search now supports contains, does-not-contain, starts-with, ends-with, in, not-in, and between, with grouping and sorting across far more fields than before, so you can isolate a single source address, path, or rule tag without exporting the log first. A dedicated error log view has also been added.
- Timestamps in Your Own Time Zone: Every log timestamp displays in your own time zone, down to the second, so a web protection incident, an endpoint event, and an audit entry line up on a single timeline when you reconstruct what happened.
Version 9.1.2.0
January 6, 2026- A Complete, Editable Protection Policy Set for Every Site: Every protected site now carries the full policy set, and each control is created, edited, and deleted per site from the dashboard rather than raised as a request: country-based blocking, sensitive-data leak prevention, error-page cloaking, JSON payload limits, request parameter validation, URL and file-upload protection with cross-site request forgery and evasion detection, cookie hardening, and request rate and size limits. Bot and denial-of-service protection are on from the moment a site goes live.
- API Discovery and Inventory: Osto now catalogs every API endpoint called across your protected sites without you declaring any of them, recording host, method, path, client address and country, response and origin timings, payload sizes, content type, and user agent across JSON, XML, and Protocol Buffers traffic. This is how you find the APIs nobody documented — forgotten test routes, versions you believed were retired, and paths that never reached your inventory.
- Automatic TLS Certificate Issuance and Installation: A trusted certificate is obtained and installed for every protected domain automatically, covering both the root domain and its www form, and renewed on its own so a lapse can never come down to a missed calendar entry. If you have your own certificate, you can supply it instead.
- Secure Server Access Provisioning and Access Rules: Secure Server Access is provisioned with private addressing, encrypted tunnels to your infrastructure, and firewall rules generated from your access model. Every organization starts with a library of common service definitions and a default access rule, and the rule set is regenerated whenever users are added or removed, so access follows your user list instead of drifting away from it.
- Endpoint Protection Baselines and Their Catalogs: Endpoint threat protection, application control, and device control each start from a working baseline policy, backed by the application catalog and device catalog they match against and an always-on schedule. Policies apply to individual people or whole user groups.
- Industry-Aligned Domain Filtering: Domain filtering starts with the site categories most organizations in your industry block already selected and enforced on managed devices — malware, phishing, anonymizers, adult content, and gambling among them — so browsing is filtered from the first day. Categories can be added or removed at any time, and the change applies to every policy that references them.
- Data Residency: Choose where your protection runs and where its data is processed and stored — India (Mumbai) or United States (Virginia), or both. Your web protection and server-access protection are provisioned only into the regions you pick, so you can answer the residency question your auditors and your own customers ask.
Version 9.1.1.9
December 18, 2025- Updated Web Protection Rulesets: The detection rulesets behind web application and API protection were refreshed with current signatures for SQL and command injection, cross-site scripting, path traversal, automated scanning, and credential-stuffing traffic. The refresh reaches every protected site without any policy change on your side.
- Rapid Coverage for Newly Disclosed Vulnerabilities: When a widely exploited vulnerability is disclosed against a common web framework or component, a matching signature is published to the managed ruleset and applied across every protected site, so your applications are covered at the edge while you schedule your own patching window.
- Refreshed Web Scanner Checks: Scanner check definitions were updated alongside the protection rulesets, so a scheduled scan tests for the same newly disclosed issues your protection is already blocking.
- Expanded Endpoint Classification Definitions: Endpoint agents received updated application, device, and file classification definitions across Windows and macOS. Coverage now extends to recently released business and collaboration applications, additional archive and container file types, and further removable-media device classes, so application control, device control, and file-based data loss prevention rules match what your people actually install and plug in.
- Expanded Domain and URL Category Intelligence: The domain and URL categorization catalog gained newly classified domains and subdomains, extending category coverage into newly registered and recently active sites. The new classifications feed straight into the domain filtering policies you already have in place.
Version 9.1.1.8
December 1, 2025- Cloud Security (GCP Support): Posture Management now includes full Google Cloud Platform coverage with automated periodic discovery of key GCP services, enriched cloud asset metadata, and built-in security checks to detect misconfigurations across supported GCP resources.
- Multi-Cloud Posture Visibility: The Cloud Security module now offers unified visibility and posture evaluations across Azure, AWS, and GCP projects, enabling complete multi-cloud analysis in a single consolidated inventory.
Enhancements
Cloud Security Experience- Visual Refinements: The Cloud Security interface has been updated with a cleaner layout that improves clarity and creates a more consistent multi-cloud viewing experience.
With this release, the Cloud Security module now supports Azure, AWS, and GCP — enabling complete visibility and posture analysis across all major cloud providers.
Version 9.1.1.7
November 25, 2025- Cloud Security (AWS): Full support for AWS environments with automated periodic discovery of key resource types, including EC2, EBS, VPCs, Subnets, Security Groups, S3 Buckets, RDS Instances, IAM Identities, Lambda Functions, EKS Clusters, and more.
- Comprehensive Asset Inventory: Includes enriched configuration, networking, identity, and encryption metadata for complete visibility across all discovered AWS assets.
- Built-in Security Checks: Get automatic findings for misconfigurations, exposure risks, and security-critical issues, enabling quick detection and faster remediation.
We are now supporting AWS along with Microsoft Azure, with GCP coming soon.
Version 9.1.1.6
November 19, 2025- Posture Management: New capability to continuously discover, map, and monitor your infrastructure’s security posture.
- Cloud Security (Azure): Full support for Microsoft Azure with automated periodic discovery of 35+ resource types, including VMs, Disks, NSGs, VNets/Subnets, SQL Servers, Cosmos DB, Storage Accounts, Key Vaults, App Services, Functions, and AKS clusters.
- Comprehensive Asset Inventory: Includes configuration, networking, identity, and encryption metadata for complete visibility.
- Actionable Security Insights: Get findings and step-by-step remediation guidance powered by near real-time posture evaluation.
Support for AWS and GCP is already in development and coming soon.
Version 9.1.1.5
October 31, 2025- Audit Logs: Gain deeper visibility into administrative activities with enhanced tracking of all changes and actions, providing stronger transparency and compliance oversight.
- WAF Custom Domain Proxy Support: Seamlessly connect your static sites (like Bettermode or GitBook) to your custom domain with a one-step proxy setup and automatic SSL management.
- WAF Upstream Health Alerts: Stay informed with real-time alerts when upstream servers go down — ensuring you’re informed immediately and can act before your users notice.
Enhancements
- Web Vulnerability Scanner Performance Upgrade: Our AI-assisted Web Scanner has been optimized for higher performance — offering 2x faster scan execution, improved detection accuracy, and smoother reporting.
- User Policy Toggle: Policies can now be easily toggled between individual users and user groups, streamlining policy management and reducing administrative effort.
- WhatsApp Notifications for Agent Installation: Users will now receive WhatsApp alerts when they are added or reminded for agent installation, ensuring seamless setup and onboarding awareness.
- Enhanced Block Page Design: The domain filtering block page has been visually refined for a cleaner look and improved user experience.
Version 9.1.1.4
September 26, 2025- Agent Install Message Copy Option: A new option on the Users page allows admins to easily copy installation messages, which can then be shared on their official communication platforms to ensure smooth agent deployment across the organization. Multiple pre-built message templates are also available for added convenience.
Enhancements
- Authentication Logs: Improved authentication log tracking with richer details and better visibility, helping admins monitor login activity more effectively.
- Cloaking Pages: Added new cloaking page templates to strengthen web app protection, making it easier to mask sensitive details and reduce exposure during reconnaissance attempts.
Version 9.1.1.3
September 16, 2025- Admin Management: Super Admins can now add multiple Admins and assign tailored permissions for better control and governance.
- Authentication Logs: Enhanced tracking of authentication activities for improved transparency and security oversight.
Enhancements
Web Application Firewall:- Easy Certificate Setup: Just add a CNAME record — the certificate will be issued within minutes and automatically renewed, with no manual steps required.
- Flexible Configuration: Osto Web App & API Protection Module supports IPv4, IPv6, and domain name configurations.
- Automatic SAN Certificates: If your website uses the “www” subdomain, Osto WAF will automatically detect it and issue a certificate that covers both the root domain and the “www” subdomain.
- Improved Domain Filtering Performance: Optimized traffic processing to reduce latency during high traffic loads — resulting in faster and more reliable domain filtering.
- Domain Filtering Insights: Get helpful descriptions for domain categories within the policy settings.
Version 9.1.1.2
July 2, 2025- MacOS Support: The macOS Agent is now compatible with macOS versions 14 and 15.
- AI-Driven Adaptive Web Protection Profiling: Automatically detect, monitor, and intelligently profile website and API traffic using AI.
- WebChat Support: Get help when you need it — now live inside the admin dashboard.
- TLS Version Configuration: Configure which TLS versions are allowed under Website advanced settings.
- MFA for Secure Server Access: Multi-factor authentication for accessing critical infrastructure.
- Endpoint Incident Enhancement: Enhanced user-level visibility for more precise detection and investigation of endpoint activities.
Enhancements
- Onboarding Flow Optimization: Cleaner, faster, and smarter — improved DNS handling, more intuitive TLS settings, and optimized onboarding journey.
- Expanded Dashboard Insights: New insights: Shadow APIs, Top 5 Accessed Servers, Top 5 Risky Users.
- User Asset Management: View which users have (or haven’t) installed the Agent App; bulk notify users missing the app.
- Domain Category Intelligence (Powered by AI): Searchable and explainable domain categories with tooltip guidance; automatically uncover related or secure subdomains via AI-driven discovery.
- One-Click Recommended Policies: AI-curated best-practice security policies with zero guesswork.
- Revamped DAST Web Scanner UI: Cleaner formatting, improved scan report readability, and scheduled email report delivery.
- Osto Captcha Page UI Revamp: Smarter and more visually refined captcha page.
Security Updates
- Enforced MFA for Server Access: Multi-factor authentication can now be enforced for all Secure Server and Secure Gateway connections.
- Granular TLS Version Management: Fine-grained control over supported protocol versions.
- AI-Powered Web Categorization: Our engine now categorizes over 100M+ domains across 60+ categories.

