Released
v0.1.0 · March 31, 2026

Workspace and evidence foundation

Start with the full note if you need shipped details, or jump to the roadmap and wishlist if you are comparing what to do next.

I want the release list

Go back to the index if you need to compare versions or pick another note.

I want the roadmap

Open the roadmap when the question is direction rather than a specific release.

I want to request something

Send a wishlist item if this release page surfaced a gap you want prioritized.

I want the current note

Jump to the release body and read the shipped change in full.

Release notes

What's new

Tenant workspace and authentication

Sotiras now supports multi-tenant workspaces with isolated data, clear role boundaries, and audit history. You can register an organization, sign in, and manage your workspace from /portal. Multiple people can be invited to the same workspace with different roles: Owner, Admin, Operator, Incident Responder, MSP Collaborator, Auditor, and Viewer.

Asset inventory

You can manually add and manage assets in your workspace: servers, applications, endpoints, identities, SaaS systems, networks, data, and vendors. Assets are the foundation for all risk, control, and incident tracking.

Risk register and control checklist

Findings from collectors and audits are normalized into a prioritized risk register. You can assign risks, track remediation tasks, and check controls off as you build your security posture.

Collectors and agent setup

Register collectors with scoped tokens, view heartbeat and health, and download configuration templates for syslog, fail2ban, WordPress, Next.js, nginx, Payload CMS, and Laravel agents.

Threat intelligence

Threat indicators from collector events, community signals, and assessments are tracked in the threat intelligence workspace with policy modes (monitor, assisted, proactive, strict), allowlists, block rules, and AI-assisted assessment.

Incident workspace

Incidents now have their own workspace with evidence capture, task assignment, playbook seeding, and AI summary runs. Operators can escalate, contain, and record recovery steps.

AI-assisted analysis

AI runs can be queued for risk summaries, incident analysis, audit findings, and security assessments. Results are reviewed by an operator before actions are taken. Deployments can use the configured platform model and optional second-opinion providers when tenant policy allows it.

Support documentation

Customer support docs are available at /support/docs covering setup, security operations, incident response, billing, exports, and all agent types.