Product updates
Changelog
Product updates and fixes. Dates are UTC.
Clearer reviews, saved work and lighter loading
- Custos review engine
- Cyberscan uses Custos to examine source code, check potential vulnerabilities and assemble the report. The updated engine adds checks for transaction finality, dependencies and injection alongside value flows, cryptography, protocols and access control.
- Code relationships
- When requested, code-relationship analysis for PHP, C# and Razor supports reviews of how connected parts of the code interact. This source analysis does not run your application.
- Finding verification
- Updated duplicate detection and verification of surrounding guards and consistency. Findings retain explicit verification outcomes; an unfinished check is not treated as a cleared vulnerability.
- Optional proof checks
- When requested, isolated proof checks test eligible C# and Razor findings within fixed resource and usage limits. Reports distinguish proved, disproved, inconclusive, not run and sandbox errors. A finding is not labelled proved just because source review found it.
- Unreadable model output
- Custos can request a corrected audit response up to twice, within the existing request and credit limits. If it still cannot read the response, the review stays incomplete and compatible saved work remains available.
- Review results
- Reports put the outcome, findings and next action first. Expand Scan details for the model, elapsed time, tokens, cost and saved progress. Partial and interrupted reviews keep their specific explanations.
- Findings by review
- Use the Scan run filter to see findings from one review, alongside repository, status and text filters.
- Feedback and drafts
- Decision controls explain when a reason is required and whether your changes are saved. Feedback drafts survive refreshes and filtering. Shared reviews separate decisions from discussion comments.
- Small screens
- Fixed clipped branch and commit inputs when choosing source on narrow screens. Shared-review headers and long status messages now fit smaller and zoomed viewports.
- Saved review work
- Updated the review engine and recovery handling to preserve compatible saved checks and verification results. Incomplete results stay marked incomplete, with available findings and saved progress retained.
- Verification on continuation
- Continuations reserve verification work for findings discovered during recovery. Invalid or unreadable verification responses remain unfinished instead of being counted as completed checks. Earlier interrupted reviews are not automatically restarted.
- Review summaries first
- The workspace loads review summaries first. Finding details load when you open Findings or export results.
- Focused updates
- Background refreshes focus on active reviews and the review you have open. Brief connection failures retry automatically.
- Opening a review
- A loading message appears as soon as you open a review. Switching reviews keeps late responses from replacing the review you selected.
Stripe invoices and billing details
- Invoices for new purchases
- New credit purchases are configured to generate paid invoices in Stripe. This does not create invoices for earlier payments.
- Billing details & invoices
- Open Billing details & invoices on Credits to manage your billing details and retrieve available invoices in Stripe. Return directly to Credits when you are done.
- Business details at checkout
- Stripe collects your name and billing address, with optional business name and tax ID where supported. Details stay in Stripe and are reused for future purchases, with no separate Cyberscan onboarding form.
- Earlier invoices
- When an account has eligible earlier billing records, Earlier invoices opens their Stripe billing portal. Invoice availability depends on what was issued for those purchases.
Report fixes
- Saving results
- Fixed report rejections caused by empty finding fields or inconsistent severity and confidence values.
- Proof results
- Fixed missing proof outcome codes in saved results. These fixes do not automatically resume earlier failed runs.
Shared reviews and finding feedback
Updates released since 27 August.
- Share a review
- All users can share a completed run. Choose Share review to create a link. Anyone with the link can view its findings and leave feedback without an account. Keep it within your team; account and billing details are excluded.
- Copy an existing link
- Reopen Share review to copy, replace, or revoke an active link. Older one-time links need replacing before you can copy them again. Replacement disables the old URL and keeps its feedback.
- Finding feedback
- Decisions, reasons, and comments have a saved history. Shared feedback appears on the original finding without overwriting the owner's decision. Conflicting edits are flagged.
- Findings page
- Filter by repository and search findings. Feedback and history sections collapse. You can edit a reason without changing its decision.
- MCP feedback
- Coding agents can read feedback, update finding decisions, and add comments through MCP. Writing feedback requires permission on the access token and access to the repository.
- Parallel checks
- Independent audit and verification work can run in parallel. Completion time still depends on the repository, model, and provider.
- Continue saved work
- Continuations use the latest compatible checkpoint, including progress from earlier attempts. Report-only recovery reuses saved results without new model calls. Incomplete verification still needs to finish.
- Run details
- Completed, partial, and interrupted reviews have distinct statuses. Coverage and limitations appear alongside findings. Zero findings does not mean a repository is vulnerability-free.
- Controls and errors
- Updated report, sharing, and feedback controls. Errors now name the action that failed instead of blaming the scan.
- Workspace loading
- Fixed stale database connections that could block the workspace after a restart.
GLM 5.3 Flash is now available
- Balanced model
- Balanced reviews now use GLM 5.3 Flash. Choose Fast, Balanced, Pro, or Frontier before starting a review.
Return to saved reviews and scan PHP
- Saved work
- Accepted checkpoints no longer expire with age. Continuing requires a compatible repository, commit, and review format.
- Continue verification
- When audit checks are complete, Continue reuses them and resumes unfinished verification. Saved verdicts are reused too.
- PHP source review
- Added first-party PHP source review, excluding common dependency, generated, and test paths. Cyberscan reads the source; it does not run the PHP application.
Support and clearer credit use
- Support chat
- Added chat to signed-in pages. Include your account email, repository and run ID when reporting a problem.
- Credits page
- See your available balance, credit reserved for active runs, and settled charges. Add credit before starting or continuing a review.
- Failed-run charges
- If a failed review returns neither a result nor reusable progress, its reserved credit is returned.
Continue interrupted reviews
- Continue a review
- After a credit-limit stop, add credit and choose Continue. Cyberscan reuses the last compatible checkpoint and runs unfinished checks.
- Saved progress
- The Runs page shows whether an interrupted review has saved work available to continue. Fixed failures when saving large checkpoints and returning results.