Changelog

Releases, in full transparency.

Every update to the protection and the dashboard is documented here.

10 septembre 2026

Plateforme web · Dashboard · Middleware
New

The feature formerly called “Low Internet Page” is now “Native error pages”. It can show a browser-inspired error rendering instead of the classic Shugoi page.

Fixes

The dashboard, API, guard and server bundle now use the same configuration name, with temporary compatibility for older integrations.

Security

Systemd publications use versioned, verifiable releases so the previous release can be restored if a post-deployment check fails.

Security

A multi-browser campaign measures continuity-signal stability and collisions. No additional signal is enabled for blocking until false-positive rates are established.

23 août 2026

SDK Node · Sécurité
Security

The verification bootstrap is served by the central guard and can evolve without republishing the SDK. Browser signals remain manipulable and are not proof of identity.

Security

Render and authorization decisions are checked server-side with grants bound to the site, context and expiry. Signal changes can be flagged, without promising spoof-proof detection.

Security

Attempts to tamper with network exchanges can be flagged; the authorization decision remains verified server-side.

Fixes

Signals are compared across available contexts to flag identity changes; browser-side signals can still be manipulated.

14 août 2026

Plateforme web · Shugoi 0.4.34
New

The Shugoi platform now uses Shugoi 0.4.34, with synchronized and verified production builds.

Security

Render grants remain valid when the network address changes, while staying bound to the site, machine, token and expiry.

Fixes

The Shugoi middleware is compatible with Express 4 and Express 5 applications under strict TypeScript.

Fixes

The Shugoi service is now managed by systemd with versioned releases and post-deployment checks.

13 août 2026

Plateforme web · CI · sécurité serveur
Security

Bypass tests now cover missing, forged, expired, future-dated and cross-site replayed grants.

New

The threat model, server authorization boundary and build metrics are now documented.

Fixes

CI now uses the renamed SDK path, and production smoke tests are configurable for the allowlisted beta.

12 août 2026

Plateforme web · SDK Node · sécurité serveur
Security

Dashboard routes now require a verified server session before their handlers execute.

Security

Authenticated mutations apply a same-site origin check, and telemetry from unknown sites is rejected.

Fixes

Node SDK patch releases 0.4.31 through 0.4.34 hardened render grants and Express TypeScript compatibility.

New

Client, SSR and server builds, browser tests, dependency audit and smoke tests were validated before release.

11 août 2026

Plateforme web · bêta privée
Security

Runtime persistence is now normalized in SQLite: accounts, sessions, sites, events, fingerprints, quotas and tokens use typed columns and relation tables, with no KV or business JSON files.

Fixes

A storage verification check now blocks the accidental return of payload columns, runtime JSON files and interpolated SQL queries.

Security

The public calibration route was removed and public journeys are checked against one route registry.

New

Enterprise, Data Rights and Abuse Reporting pages complete trust, sales and support journeys.

Fixes

Deployments retain already-served assets while publishing new ones, preventing load errors between site versions.

Fixes

Backup, deployment and verification scripts are checked in continuous integration alongside unit, type and browser tests.

Fixes

Legal, support and authentication pages now use a centered container at every screen size.

Security

Site persistence now uses SQLite with a versioned migration and a blocking check if a legacy file reappears.

10 août 2026

Plateforme web · bêta privée
Security

The Node.js, Next.js, Ruby and PHP modules no longer use dynamic JavaScript evaluation; the security policy no longer allows unsafe-eval.

New

The protection bootstrap is 75% smaller uncompressed and 31.6% smaller after gzip compression.

New

Initial site JavaScript has been reduced by 27.7%, and the server-rendering bundle by 25.3%.

New

A selection guide, trust centre and live service check complete the preparation journeys. Commercial launch remains subject to the readiness gates.

New

Account owners can export their data and consult the OpenAPI description of documented public endpoints.

Fixes

Cross-browser recognition and data-location claims now reflect actual limitations and subprocessors.

UI & accessibility

Action and label colours now meet WCAG AA contrast on the tested commercial pages.

Fixes

Access-list updates now use one shared watcher instead of polling disk for every connection.

Fixes

Unused dependencies, uncalled legacy paths and persistent timers were removed before acceptance testing.

New

The private Starter beta is now available to authorised existing accounts, with login preserving the requested page.

Fixes

The beta pricing flow uses a concise label and signup works without a hidden payment validation step.

New

The fictional demo page was removed in favour of documentation, and a Trademark and press resources page was added.

New

Trademark resources now show downloadable previews of the logo, mark and Open Graph image.

New

Sales Contact and Acceptable Use pages complete the public SaaS foundation.

Fixes

The full footer is now available in the dashboard and old internal documentation routes were removed.

Fixes

Documentation frameworks now use official Simple Icons SVG paths.

09 août 2026

npm 0.4.30 · PHP 0.4.6 · Ruby 0.4.6
New

Resource usage has been reduced under heavy load, particularly for analytics and long-running processes.

New

Demo processes use 45% less memory after removing unnecessary intermediate launchers.

New

The initial site download is more than twice as light; pages are then loaded only when visited.

Security

Content isolation between protected sites has been strengthened during server-side rendering.

Fixes

Node.js and Ruby storage remains reliable and responsive during traffic spikes.

New

Stable signals can associate browsers on the same machine; network data remains a separate security control.

Fixes

Clock drift is now a separate anti-impersonation signal: a VPN or different network path no longer changes the universal identity.

New

A Node/CDP probe automatically compares Chrome, Edge, Brave and Opera (WebGL, fonts, codecs, audio, WebRTC and clock) in a JSON report.

Security

Stronger identity verification: attempts to impersonate another machine are blocked.

New

Sharing previews (Discord, Facebook, X, LinkedIn) display correctly, with protection enabled.

Fixes

The machineId is more stable between visits on the same machine, while staying distinct between different machines.

UI & accessibility

Landing rewritten: more direct tone, concrete numbers, and a clearer “What Shugoi doesn't do” section.

04 août 2026

npm 0.4.19 · Ruby 0.4.4 · PHP 0.4.4
Security

Single-use proof of work with a per-request randomised salt: an already-consumed proof is rejected, including from another IP.

Security

Session cookie bound to IP and browser: stealing a cookie no longer grants access.

Security

Per-request verification signature and logging of refusal reasons (pow, mid, allowlist).

New

Two-factor authentication (TOTP) enabled from settings, with recovery codes.

New

Guided onboarding: free Starter in the private allowlisted beta, then billing when the product opens.

New

Documentation built into the dashboard: Express, Fastify, Next.js, Ruby, PHP and Laravel, with Install / Configure / Test tabs.

New

Real-time analytics: blocks by reason, passes, live stream.

Fixes

Copy aligned with facts: “detected out of the box” replaces over-absolute promises.

Fixes

Removed outdated mentions (self-host, versions) from the documentation.

UI & accessibility

Global visible focus, WCAG contrast, touch targets ≥ 44 px.

UI & accessibility

Rebuilt navigation: fixed bar, cleaner sidebar, tighter dashboard.

Full technical details live in the commit history of the public repositories.