Release notes
Changelog for the PentestOps platform and the on-premise pentest agent. Check back here each release cycle to see what changed, or subscribe to the RSS feed.
This page covers notable releases rather than every build. The platform is SaaS and ships smaller patch and maintenance updates continuously between the versions listed here, so version numbers may jump. Your environment always runs the current release; the version in use is shown in the footer.
Platform
v2.6.8
2026-07-21
stable
- MSP / reseller self-service: per-tenant provisioning, custom domains with automated SSL, reseller pricing and a TOTP-secured console
- Security hardening: multi-factor authentication (available to all users, required for administrators), first-login password rotation, session token-version revocation and idle logout
- Advanced exploitation gated behind a self-service e-signed authorization agreement (bruteforce / RCE / credential-extraction / destructive)
- Operator-controlled one-click scanner upgrades with zero-downtime canary rollout
Delivered automatically - the PentestOps SaaS updates server-side, no action required.
v2.2.3
2026-06-01
stable
- Fleet-wide marketing counters on the public site - real scan / finding totals aggregated across every tenant (counts only, full tenant isolation preserved)
- Scanner spin-down now removes every workload it created, leaving no orphaned resources and no errors after teardown
- Platform credentials are injected from a dedicated secrets vault at runtime rather than held in configuration
- Hardening: refresh-token rotation, timeouts on long-running internal operations, and improved background-job resilience
Delivered automatically - the PentestOps SaaS updates server-side, no action required.
v2.2.0
2026-05-19
stable
- AI Remediation + Exploitation audit pass - per-tenant LLM budget gate, fair-use limits, and scope re-verification on every generate
- Exploitation pipeline is kind-aware (Audit / Validation / Exploit) with accurate per-run status callbacks
- External-scan findings default to command suggestions - no SSH playbook path to internet-facing targets
Delivered automatically - the PentestOps SaaS updates server-side, no action required.
v2.1.0
2026-05-07
stable
- Remediation workflow production-ready - approve loading states, SSE reconnect, retry + verify actions, editable playbooks
- Rescan-to-confirm endpoint closes the loop - re-run the exact finding to verify a fix landed
- Stale-task janitors keep the operator dashboard accurate across pod restarts
Delivered automatically - the PentestOps SaaS updates server-side, no action required.
v2.0.0
2026-04-20
stable
- Asset Inventory (8 phases) - bulk import, AI classification, agent-based LAN discovery, cloud sync, re-verification lifecycle, drift detection
- Rules-of-Engagement enforcement - legal scope + asset verification + freshness gate + audit log on every scan
- MSP multi-tenancy (Path B) - per-MSP namespace isolation, GitOps onboarding, 3-tier pricing
Delivered automatically - the PentestOps SaaS updates server-side, no action required.
Pentest agent
v3.3.86
latest
The current pentest agent release. Provisioning, installation and updates are handled from your PentestOps dashboard - there is nothing to pull or configure by hand.