Changelog
Complete version history and features of SecuryBlack. We release updates regularly.
Comprehensive Backup Management with TitanVault v0.1.2, Multi-Cloud Storage & Nexus Agent v0.2.15
Introducing the end-to-end backup and disaster recovery management suite powered by TitanVault, our new native Rust agent for memory-streaming backups without consuming intermediate disk space. Configure multi-cloud storage targets (Cloudflare R2, Hetzner Storage Box, Google Drive, or local storage), schedule backup sources for PostgreSQL databases, Docker volumes, or file paths, and trigger on-demand snapshots or instant restores with a single click.
- Zero-Intermediate-Disk Backup Streaming: direct memory streaming of databases and files with zstd compression and source-level ChaCha20-Poly1305 encryption to remote targets
- Multi-Cloud Storage Targets: intuitive UI modal to configure and validate credentials for Cloudflare R2, Hetzner Storage Box, Google Drive, or local paths with automatic connection health checks
- Modular Backup Sources: define targets to safeguard (PostgreSQL databases, Docker container volumes, and host directories) with custom retention policies
- On-Demand Snapshots & 1-Click Restore: inspect full snapshot history across targets with exact file sizes and status indicators, or trigger manual backups directly from server details
- Nexus Agent v0.2.15: automatic local discovery, lifecycle management, and unattended 1-click installation for both TitanVault and CromoForge
- Expanded Remote Agent Updates: on-demand manual update triggers now extended to TitanVault and CupraFlow from the dashboard
- Mobile-Optimized Backups & Databases: horizontally scrollable tab bars, responsive server resource cards, and fluid modals tailored for mobile screens
PostgreSQL Administration & Performance Suite, Lock Buster & CromoForge v0.1.4
Introducing the new PostgreSQL database administration and performance suite for host servers and Docker containers with zero ports exposed to the internet. Monitor and terminate blocking queries with Lock Buster, recover storage with 1-click Vacuum and Reindex, audit obsolete indexes with Index Doctor, and tune memory allocation with the Hardware-aware PGTune Advisor.
- Zero-Port PostgreSQL Administration: 100% internal telemetry and command execution via persistent gRPC tunnel and CromoForge, keeping database ports unexposed to public networks
- Lock Buster & Live Query Monitor: real-time inspection of pg_stat_activity with live duration tracking, client IPs, transaction states, and wait events
- Process Termination Actions: cancel long-running queries (pg_cancel_backend) or terminate locked connections (pg_terminate_backend) with a single click
- Table Bloat & Maintenance: detect table bloat with one-click actions to run VACUUM (ANALYZE) and concurrent REINDEX without write downtime
- Unused Index Doctor: automatically detect indexes over 1 MB with zero scans (idx_scan = 0) wasting memory and disk I/O, with copyable DROP INDEX CONCURRENTLY commands
- Database Tuning Advisor (PGTune): calculate optimal postgresql.conf memory parameters (shared_buffers, effective_cache_size, work_mem, maintenance_work_mem, wal_buffers) based on host RAM compared to current settings
- 1-Click Extension Manager: discover, inspect version compatibility, and install popular extensions (pg_stat_statements, pgcrypto, vector, timescaledb, citext, etc.) without manual SSH
- CromoForge v0.1.4: new agent release delivering database metrics collection and safe maintenance task execution
- Full Mobile Support: dedicated Databases navigation tab on the mobile bottom bar to manage and unblock database instances on the go
Comprehensive Fail2ban & CrowdSec Management, Attack Insights & Remote Log Streaming
Expanded edge defense capabilities with dedicated management panels for Fail2ban and CrowdSec. Control IP bans, monitor live attack insights and service logs, and tune security configurations directly from the SecuryBlack dashboard.
- Interactive Fail2ban Dashboard: inspect service status, active jails, total banned IPs counter, and trusted whitelists at a glance
- 1-Click IP Ban & Whitelist Actions: ban or unban IPs manually and keep trusted ranges synchronized without logging into SSH
- Fail2ban Log Streaming & Attack Ranking: analyze real-time service logs and identify top targeted jails and aggressive attacker IPs with quick-action ban buttons
- Dynamic Fail2ban Configuration: view and update bantime, findtime, and maxretry with instant reload on the server
- CrowdSec Management Suite: brand-new management dashboard supporting active decisions, installed bouncers, and perimeter security metrics
- CrowdSec Scenario Alerts: stream blocked attacks, triggered security scenarios, and attacker reputation in real time
- Unattended Installation & Collections: install Fail2ban or CrowdSec and deploy additional security collections with a single click
- FerroSentry v0.2.25: new security agent release with complete command intake and secure streaming handlers for Fail2ban and CrowdSec
Active Docker Manager, CromoForge v0.1.1 and Real-Time Live Log Viewer
Introducing active Docker container management directly from the SecuryBlack dashboard. Start, stop, and restart containers with Sudo Mode biometric elevation, and troubleshoot incidents instantly with the all-new real-time Live Log Viewer.
- Container Lifecycle Management: Start, stop, or restart any Docker container directly from the server dashboard with clear impact confirmation dialogs
- Sudo Mode & Passkey Protection: Container stop and restart operations require FIDO2 biometric authentication to prevent accidental downtime or unauthorized disruption
- Real-Time Live Log Viewer: Brand-new monospace dark terminal drawer with continuous streaming (3s auto-refresh) to diagnose service crashes without SSH
- Tail Lines & Timestamps Selector: Choose between 100, 200, 500, or 1000 lines and toggle ISO timestamps column to match your inspection preference
- Interactive Search & Log Download: Filter log lines by keyword in real time, copy output to clipboard, or download full .log files with a single click
- CromoForge v0.1.1: New release of the deployment & container agent with optimized execution and chronological interleaving of stdout and stderr
- 1-Second Edge Gateway: Accelerated command poller delivering container operations and log queries through the persistent gRPC tunnel in sub-second time
Full Server Hardware Specifications, OxiPulse v0.3.13 & One-Click Security Remediation
Expanded system monitoring with full hardware specification discovery for each server (vCPUs, CPU model, total RAM, storage, OS distribution, kernel version, and uptime). In addition, introduced one-click automated security remediations backed by biometric Passkey Sudo Mode for SSH hardening, unattended upgrades, and intrusion prevention.
- Real-time server hardware specifications: new technical overview card showcasing processor (model & vCPUs), RAM & Swap, total storage, OS, kernel version, and uptime
- Dynamic server header subtitle: instant glance of OS distribution, vCPUs, total RAM, and total disk storage right in the server header
- Detailed resource metrics: CPU and RAM resource bars enhanced with exact CPU model and Gigabytes usage breakdown (used / total)
- OxiPulse v0.3.13: new Rust agent release automatically discovering and streaming host hardware attributes to the OTLP gateway
- One-click security remediation: resolve security findings directly from the dashboard (SSH hardening, unattended upgrades, and fail2ban setup)
- Instant port blocking: automatically add DENY firewall rules to UFW with a single click from exposed port findings
- Biometric protection with Sudo Mode: critical server remediations require step-up biometric Passkey authentication with assisted onboarding
Interactive Changelog Notifications in Sidebar & Integrated Updates Modal
Introduced an in-app product updates notification system directly inside the dashboard. Discover what is new without leaving your workspace, dismiss notifications per-version across all your devices, and configure badge visibility from account preferences.
- Sidebar updates badge: dynamic notification card above the account menu that lights up automatically with every new release
- In-app Changelog modal: read full release notes, features and security fixes without navigating away
- Permanent account menu shortcut: quick access to Product Updates from your user profile dropdown
- Cross-device database sync: dismissing an update notification persists across all your browsers and devices
- User preference toggle: easily enable or disable sidebar update notifications in Account Settings
- Public Changelog API: edge-cached public API endpoint delivering releases data in real time
Passkeys (WebAuthn/FIDO2), UFW firewall management and Docker containers with CromoForge
Added next-generation biometric authentication with Passkeys for seamless passwordless login and hardened account protection. Shipped remote UFW firewall management with anti-lockout protection and Docker bypass detection, alongside a brand new Docker containers tab powered by CromoForge.
- Passkeys (WebAuthn / FIDO2): biometric credentials support (Face ID, Touch ID, Windows Hello, physical hardware keys) and passwordless login
- Sudo Mode (Step-Up Authentication): secure elevation with biometric Passkey or password (15-minute grace window) protecting UFW firewall modifications and sensitive infrastructure actions
- Passkeys management: dedicated settings section to review, label, register and delete linked WebAuthn authenticators
- Remote UFW firewall management: inspect active firewall rules, create new rules (port, protocol, allow/deny, source IP) and delete existing rules remotely
- Anti-lockout protection: safeguards against accidental disconnection or blocking of active SSH administrative access
- Docker UFW bypass detection: automated audit detection and warning when Docker bindings circumvent UFW rules
- Docker containers: new dedicated tab in server details to monitor containers, inspect mapped ports and trigger container restarts with CromoForge
- Database caching for Firewall and Containers: instant loading (< 20 ms) via Stale-While-Revalidate pattern, background synchronization and reactive PostgreSQL triggers
- Mobile & UX enhancements: responsive tab navigation on small viewports and hardened internal proxy redirect handling
One-click remote agent updates, process auto-resolution and tunnel resilience
Expanded remote agent management with one-click updates directly from the dashboard and visual badge alerts. FerroSentry v0.2.15 brings executable-based finding consolidation to prevent duplicate alerts and automated resolution for terminated processes. In addition, the bidirectional gRPC tunnel is hardened with active HTTP/2 keep-alives and persistent retry queues across reconnections.
- Agent updates: one-click update button next to each agent with update indicator badges in Config and Security tabs
- FerroSentry v0.2.15: smart finding consolidation by executable path in Process Sentinel, scan cache reset, and elimination of test mock events
- FerroSentry: instant auto-resolution when a suspicious or flagged process terminates on the server
- Hardened gRPC tunnel: active HTTP/2 keep-alive pings in Nexus Agent and Edge Gateway preventing 60-second idle timeouts
- Persistent bridging: Nexus Agent queues command responses and progress across stream reconnections without losing messages
- Windows Server 2019 compatibility: updated PowerShell installers with forced TLS 1.2+ and static CRT runtime on Windows
Infrastructure map: per-type agent cards and a tighter layout
The infrastructure map now shows different information depending on agent type instead of the same generic charts for everyone: FerroSentry shows open vulnerabilities and pending OS updates, and Nexus Agent shows whether it's communicating with SecuryBlack and with the server. We also tightened the layout to remove empty space between servers and services, added a zoom indicator with a one-click reset, and fixed an intermittent error when loading the map.
- Infrastructure map: agent cards now adapt to agent type — FerroSentry shows vulnerabilities and pending updates, Nexus Agent shows connectivity with SecuryBlack and with the server
- Infrastructure map: servers now size their width to the number of services they contain, and spacing between cards and servers was reduced
- Infrastructure map: new zoom indicator, defaulting to 100% on load with a one-click reset
- Fixed: intermittent error loading the infrastructure map and other authenticated views
Remote OS updates, an SSL certificate watchdog, and agent reliability
Added a button to update your servers' operating system remotely, showing the real list of pending packages and live progress. FerroSentry now auto-closes findings once the condition that triggered them clears, and we launched an SSL certificate watchdog that warns before certs expire or if they become invalid. We also improved agent installation, notification read-state, and several views across the app.
- Servers: button to update the operating system remotely, with the real list of pending packages and live progress
- Agents: manual "Update now" button next to each agent's version, extended to OxiPulse and Nexus Agent
- Agent install: resumable flow for servers that never finished connecting
- FerroSentry: security findings now auto-close as soon as the condition that raised them clears
- New: SSL certificate watchdog on web monitors, warning 30/7/1 days before expiry and on any invalid certificate
- Web monitor: per-region latency map on the monitor detail page, and settings now editable directly in the Settings tab
- Notifications: read/unread state is now persisted server-side instead of only in the browser, plus a redesigned Notifications page
- Navigation: collapsible sidebar with an icon-only mode
- Infrastructure map: resource charts redesigned as bars, a live status indicator, and layout overlap fixes
Hetzner Providers, Cost Optimization, and a Full Visual Redesign
We launched the Providers section to connect your Hetzner Cloud account, discover and import existing servers or provision new ones without leaving SecuryBlack. We also shipped the public savings calculator and assisted migration flow, a complete visual redesign of the app, and an overhaul of notifications and mobile navigation.
- Providers: connect your Hetzner Cloud account, discover existing servers and import or link them to one you already monitor
- Providers: provision a brand-new server directly on Hetzner from SecuryBlack, no need to leave the app
- Providers: syncing now removes servers from the list once you've deleted them on the provider's side
- Cost Optimization: public savings calculator (/ahorro) and assisted migration flow
- Cost Optimization: assign each server's provider and plan to calculate its potential savings
- Visual Redesign: new flatter, more minimal design language applied across the whole app
- Notifications: replaced the bell with an unread-count badge, and added mark-as-read (individually or all at once)
- Mobile Navigation: bottom tab bar as the sole navigation menu, with direct access to Providers
- Reliability: automatic retry for session refresh on transient network failures
FerroSentry Security Posture, Outage Charts in Latency, and Access Audit
We launched the Security Posture (FerroSentry) section in server details, interactive outage visualization directly on network latency charts, user last activity tracking, and enhanced agent installer compatibility.
- Security Posture Suite (FerroSentry v0.2.0): complete suite of 7 security sensors (SSH Auditor, File Integrity Monitor FIM with SHA-256 hashes, Permission Auditor SUID/SGID, Persistence Hunter for crons, Process Sentinel for /tmp executions, Firewall Auditor, and SSL/TLS Auditor)
- Security Posture (FerroSentry): new server details section with findings table and security audits
- Outage & Downtime Visualization: graphical representation of downtime periods directly on network latency charts
- Uptime Threshold Tuning: status palette refinement and accuracy adjustments in availability history
- User Access Audit (last_used_at): tracking and display of last user activity in profile settings
- Agent Compatibility: PowerShell 5.1 installers with forced TLS 1.2 for OxiPulse and FerroSentry
- Agent Auto-Update: reduced initial update check delay to 1 minute in OxiPulse
- Version Metadata: integrated autogenerated build version metadata in footer and about app page
Google Sign-In, Simplified Onboarding, Network Metrics, and Interactive Showcases
We introduced Google Sign-In and simplified signup friction, launched an interactive onboarding wizard, and added a network latency metric card. On the homepage, we featured interactive showcases of our Rust agents with real-time simulated terminals, and made Pro and Team plans free during the beta phase.
- Google Sign-In: integrated Google Sign-In SDK on login and registration screens
- Simplified Registration: removed redundant inputs (country, company, phone) to reduce signup friction
- Onboarding Wizard: post-login setup assistant unified into 2 simple steps
- Account Settings: new linked accounts (Google) section in the settings tab
- 60-Day Uptime History: new daily status tracking component and unified tracker UI
- Network Latency Metric: visual card to monitor server response times in real time on the dashboard
- Interactive Showcases: dedicated homepage sections for OxiPulse, FerroSentry, and CupraFlow with animated terminals
- Free Beta Subscriptions: Pro and Team plans marked as free with highlighted badges and crossed-out pricing
- UI Consistency: unified all buttons to pill shapes (rounded-full) per the design system guidelines
Server Redesign, Dynamic Metrics, and Port Scanner
We launched a deep overhaul of the server interface in Railway style, integrating support for dynamic multi-disk metrics and real-time telemetry with OxiPulse. Additionally, FerroSentry debuts its cross-platform port scanning engine, and the control panel is restructured into a high-impact grid.
- Server Redesign: new server card interface inspired by Railway.app
- Dynamic Metrics: multi-disk support and graphs with per-disk capacity bars
- Full Renaming: unified migration from the concept of 'Agents' to 'Servers' across the entire UI
- Telemetry Optimization: precise dynamic summation and scaling of storage and network rates in real time
- OxiPulse v0.3.0: support for mount-point primary disk labels and short Linux device names
- FerroSentry: active Phase 1 cross-platform port scanner (Windows netstat and Linux /proc/net/tcp)
- Uptimes & Heartbeats: added pagination to ping history on detail pages
- Dashboard: new 2x2 grid layout for enhanced clarity and resource visualization
- App Version Page: new /about section with auto-generated build version information
Internationalization, unified notifications, and UX improvements
We launched full Spanish and English support across the entire app. Redesigned the notification system with unified channels, improved the experience with cron presets in heartbeats, and added an interactive infrastructure map. OxiPulse receives more frequent automatic updates and better Windows support.
- Full internationalization: interface available in Spanish and English
- Unified notification channels: email, Discord, Telegram, and Slack in one place
- Cron expressions in heartbeats with presets (every hour, every day, etc.)
- 90-day uptime history visualized in monitor detail
- Improved identity verification flow in breaches
- Interactive infrastructure map with deletable edges
- Agent version visible on details page
- OxiPulse: update check every 5 minutes
- OxiPulse: better auto-update support on Windows
- Opt-in telemetry in OxiPulse with remote configuration
Server monitoring & OxiPulse
We launched server monitoring and with it OxiPulse was born, our open source agent written in Rust. OxiPulse installs with a single command on any Linux server and starts sending CPU, RAM, disk, and network metrics to the SecuryBlack dashboard in real time. No vendor lock-in.
- OxiPulse: open source monitoring agent written in Rust
- One-command installation for any Linux server
- Real-time metrics: CPU, RAM, disk usage, and network traffic
- View of all servers on the main dashboard
- Email alerts when configurable CPU or RAM thresholds are exceeded
- Public repository available on GitHub
Heartbeats
We added the heartbeats system to verify that your cronjobs, backups, and scheduled scripts run correctly. A heartbeat is an HTTP signal that your script sends to SecuryBlack when finished; if that signal doesn't arrive within the configured interval, you receive an immediate alert.
- Heartbeats with configurable time window (minutes, hours, or days)
- Email alerts when the pulse doesn't arrive within the expected time
- Integration with cronjobs and scripts via a single curl line
- Status of all heartbeats visible on the main dashboard
- Execution history to detect failure patterns
Uptime monitoring
We launched the availability monitoring system for HTTP and TCP services. We automatically check every 5 minutes if your service responds correctly, record historical latency, and send immediate alerts when something goes down.
- Automatic HTTP and TCP checks every 5 minutes
- Latency history for the last 50 checks per monitor
- Main dashboard with status view of all monitors
- Email alerts on downtime and service recovery
- Uptime percentage calculated for 24h, 7d, and 30d periods
MVP — Breach scanner
First functional version of SecuryBlack. The breach scanner periodically checks if your email addresses appear in known data breach databases. When it detects a match, it sends an immediate alert with breach details.
- Email scanning against known data breach databases
- Immediate email alerts when new data breaches are detected
- Email verification by confirmation to prevent abuse
- Full detail of each breach: exposed data, date, and severity
- Free registration without credit card
Want to receive updates by email? Sign up for free