Changelog
Product updates, new features, and improvements.
September 2026
- NEWVisitor identifiers are issued server-side, and each response states where the identifier came from: presented by the browser, recovered from storage, or newly minted.
- IMPROVEDProof of identity now survives cookie clearing together with the identifier itself; a returning Brave visitor is recognised noticeably faster.
- NEWAccount Takeover coverage panel in the dashboard shows how many of your accounts have enough history to be judged at all, and declines to name a risk level when the data is thin.
- NEWgpu — the visitor's video adapter model, normalised to a readable name — in the dashboard, the Data API and webhook v2 (Pro and above).
- NEWnetwork.proxyDetected: the visit's page traffic and its raw network path leave through different networks — a proxy or VPN sits in front of the browser. Two addresses of the same provider do not count (Pro and above).
- NEWnetwork.realIp — the public address observed behind the proxy or VPN, with its country and ISP, in the Data API and webhook v2 (Business and above).
- IMPROVEDThe early identification response now arrives several times faster.
- IMPROVEDThe browser agent no longer carries its detection map; the bundle is about 6% smaller.
- IMPROVEDDashboard on a phone: search in the drawer, readable tiles, a scrollable usage table, direct links to profile and account.
- NEWStripe promo codes for 3, 6 and 12 free months.
- IMPROVEDSignal identifiers travel the wire as opaque codes; an observer of your page's traffic no longer sees a list of what is collected. Request bodies are about 9% smaller.
- NEWEnvironment settings show whether account bindings arrived with a valid signature in the last 7 days.
- IMPROVEDNotifications moved to the sidebar; the feed is split into Today and Earlier; on mobile the panel opens full width.
- NEWUnread indicator: a grey dot for unread, red for critical; repeated alerts collapse into one line; read state syncs between tabs instantly.
- IMPROVEDPlatform spoofing now raises risk gradually: one confirmed inconsistency adds 20 of 100, two add 70, further ones climb to a ceiling of 80 — below the weight of a caught bot. The verdict itself is unchanged: the fact and the score are shown, you decide.
August 2026
- NEWFour server-side integrity checks on each visit: the presented session token against the issued one, internal timing consistency, the payload echo against the recorded body, and agreement across storage layers.
- IMPROVEDThirteen new collection signals.
- IMPROVEDBrowser extensions pass four trust gates before they are shown — the same rules in the dashboard, the Data API and webhooks. Two registry rules that reported a non-existent extension are disabled.
- NEWFraud reports you file appear immediately with their status; when spoofing is proven, the visitor header shows the measured OS next to the claimed one (Business and above).
- FIXEDVisitor cards no longer show extensions that were never installed: an environment that “finds” each probe now betrays itself and the whole batch is discarded.
- IMPROVEDClaimed platform is cross-checked against measured traits — fonts, GPU driver limits, speech engine, TLS. A desktop presenting itself as an iPhone no longer passes as a clean visitor; device class, browser and OS are named by the server, not by the visitor's own string.
- IMPROVEDSession and visitor detail pages moved to two columns; “what was spoofed” and “why this verdict” live in one Security card.
- FIXEDData collection restored on paid plans: a server-side check the agent could not satisfy was dropping events.
- NEWFraud Rings is now a single section with a server-built graph of each ring: click an edge to see what links the accounts, with the confidence of the link.
- NEWFraud Rings as a workplace: filters by country, OS, evidence, risk and status; search and sorting; ring triage with a status and a note; CSV export; Report fraud.
- NEWSend your accounts' human-readable names and emails via the Data API and see them in place of raw identifiers (Pro and above).
- IMPROVEDBehaviour scoring recalibrated on live traffic: one broken rule withdrawn, three rules retuned; 29 windows out of 20,000 changed verdict, all of them toward “human”.
- NEWEvents carry the page address — login, checkout, form — with query strings and fragments stripped, so analytics and behaviour can be broken down by page.
- IMPROVEDDifferent people on identical mass-market phones and typical PCs no longer merge into one visitor; accumulated merged histories were split apart.
- IMPROVEDIncognito and anti-fingerprinting browsers get a stable identifier immediately, not after 15 minutes.
- IMPROVEDVisitors from the US and Asia are served from Europe; collection speed for them is back to European levels.
- IMPROVEDThe identifier and verdict arrive first; heavy hardware measurements follow in a second wave or come from the browser cache. Time to first response roughly halved on slow machines.
- IMPROVEDEnvironment mode, limits and custom-host changes take effect on the next request, not within five and a half minutes.
- IMPROVEDLosing a storage node no longer costs a visitor their identity, quota counters or visit history.
- IMPROVEDThe agent no longer blocks the page's main thread for long; the first event leaves sooner. Same signals, same values.
- NEWThe real operating system is read from the network layer again, so a spoofed User-Agent is caught.
Want to suggest a feature?
We ship based on user feedback. Tell us what matters to you.