Changelog
Releases, in full transparency.
Every update to the protection and the dashboard is documented here.
10 septembre 2026
Plateforme web · Dashboard · MiddlewareThe feature formerly called “Low Internet Page” is now “Native error pages”. It can show a browser-inspired error rendering instead of the classic Shugoi page.
The dashboard, API, guard and server bundle now use the same configuration name, with temporary compatibility for older integrations.
Systemd publications use versioned, verifiable releases so the previous release can be restored if a post-deployment check fails.
A multi-browser campaign measures continuity-signal stability and collisions. No additional signal is enabled for blocking until false-positive rates are established.
23 août 2026
SDK Node · SécuritéThe verification bootstrap is served by the central guard and can evolve without republishing the SDK. Browser signals remain manipulable and are not proof of identity.
Render and authorization decisions are checked server-side with grants bound to the site, context and expiry. Signal changes can be flagged, without promising spoof-proof detection.
Attempts to tamper with network exchanges can be flagged; the authorization decision remains verified server-side.
Signals are compared across available contexts to flag identity changes; browser-side signals can still be manipulated.
14 août 2026
Plateforme web · Shugoi 0.4.34The Shugoi platform now uses Shugoi 0.4.34, with synchronized and verified production builds.
Render grants remain valid when the network address changes, while staying bound to the site, machine, token and expiry.
The Shugoi middleware is compatible with Express 4 and Express 5 applications under strict TypeScript.
The Shugoi service is now managed by systemd with versioned releases and post-deployment checks.
13 août 2026
Plateforme web · CI · sécurité serveurBypass tests now cover missing, forged, expired, future-dated and cross-site replayed grants.
The threat model, server authorization boundary and build metrics are now documented.
CI now uses the renamed SDK path, and production smoke tests are configurable for the allowlisted beta.
12 août 2026
Plateforme web · SDK Node · sécurité serveurDashboard routes now require a verified server session before their handlers execute.
Authenticated mutations apply a same-site origin check, and telemetry from unknown sites is rejected.
Node SDK patch releases 0.4.31 through 0.4.34 hardened render grants and Express TypeScript compatibility.
Client, SSR and server builds, browser tests, dependency audit and smoke tests were validated before release.
11 août 2026
Plateforme web · bêta privéeRuntime persistence is now normalized in SQLite: accounts, sessions, sites, events, fingerprints, quotas and tokens use typed columns and relation tables, with no KV or business JSON files.
A storage verification check now blocks the accidental return of payload columns, runtime JSON files and interpolated SQL queries.
The public calibration route was removed and public journeys are checked against one route registry.
Enterprise, Data Rights and Abuse Reporting pages complete trust, sales and support journeys.
Deployments retain already-served assets while publishing new ones, preventing load errors between site versions.
Backup, deployment and verification scripts are checked in continuous integration alongside unit, type and browser tests.
Legal, support and authentication pages now use a centered container at every screen size.
Site persistence now uses SQLite with a versioned migration and a blocking check if a legacy file reappears.
10 août 2026
Plateforme web · bêta privéeThe Node.js, Next.js, Ruby and PHP modules no longer use dynamic JavaScript evaluation; the security policy no longer allows unsafe-eval.
The protection bootstrap is 75% smaller uncompressed and 31.6% smaller after gzip compression.
Initial site JavaScript has been reduced by 27.7%, and the server-rendering bundle by 25.3%.
A selection guide, trust centre and live service check complete the preparation journeys. Commercial launch remains subject to the readiness gates.
Account owners can export their data and consult the OpenAPI description of documented public endpoints.
Cross-browser recognition and data-location claims now reflect actual limitations and subprocessors.
Action and label colours now meet WCAG AA contrast on the tested commercial pages.
Access-list updates now use one shared watcher instead of polling disk for every connection.
Unused dependencies, uncalled legacy paths and persistent timers were removed before acceptance testing.
The private Starter beta is now available to authorised existing accounts, with login preserving the requested page.
The beta pricing flow uses a concise label and signup works without a hidden payment validation step.
The fictional demo page was removed in favour of documentation, and a Trademark and press resources page was added.
Trademark resources now show downloadable previews of the logo, mark and Open Graph image.
Sales Contact and Acceptable Use pages complete the public SaaS foundation.
The full footer is now available in the dashboard and old internal documentation routes were removed.
Documentation frameworks now use official Simple Icons SVG paths.
09 août 2026
npm 0.4.30 · PHP 0.4.6 · Ruby 0.4.6Resource usage has been reduced under heavy load, particularly for analytics and long-running processes.
Demo processes use 45% less memory after removing unnecessary intermediate launchers.
The initial site download is more than twice as light; pages are then loaded only when visited.
Content isolation between protected sites has been strengthened during server-side rendering.
Node.js and Ruby storage remains reliable and responsive during traffic spikes.
Stable signals can associate browsers on the same machine; network data remains a separate security control.
Clock drift is now a separate anti-impersonation signal: a VPN or different network path no longer changes the universal identity.
A Node/CDP probe automatically compares Chrome, Edge, Brave and Opera (WebGL, fonts, codecs, audio, WebRTC and clock) in a JSON report.
Stronger identity verification: attempts to impersonate another machine are blocked.
Sharing previews (Discord, Facebook, X, LinkedIn) display correctly, with protection enabled.
The machineId is more stable between visits on the same machine, while staying distinct between different machines.
Landing rewritten: more direct tone, concrete numbers, and a clearer “What Shugoi doesn't do” section.
04 août 2026
npm 0.4.19 · Ruby 0.4.4 · PHP 0.4.4Single-use proof of work with a per-request randomised salt: an already-consumed proof is rejected, including from another IP.
Session cookie bound to IP and browser: stealing a cookie no longer grants access.
Per-request verification signature and logging of refusal reasons (pow, mid, allowlist).
Two-factor authentication (TOTP) enabled from settings, with recovery codes.
Guided onboarding: free Starter in the private allowlisted beta, then billing when the product opens.
Documentation built into the dashboard: Express, Fastify, Next.js, Ruby, PHP and Laravel, with Install / Configure / Test tabs.
Real-time analytics: blocks by reason, passes, live stream.
Copy aligned with facts: “detected out of the box” replaces over-absolute promises.
Removed outdated mentions (self-host, versions) from the documentation.
Global visible focus, WCAG contrast, touch targets ≥ 44 px.
Rebuilt navigation: fixed bar, cleaner sidebar, tighter dashboard.
Full technical details live in the commit history of the public repositories.