<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://docs.levo.ai/changelog</id>
    <title>Levo.ai Changelog</title>
    <updated>2026-05-31T00:00:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://docs.levo.ai/changelog"/>
    <subtitle>Product updates and release notes</subtitle>
    <icon>https://docs.levo.ai/img/levo-rounded.svg</icon>
    <rights>Copyright © 2026 Levo, Inc.</rights>
    <entry>
        <title type="html"><![CDATA[Release Notes — May 2026]]></title>
        <id>https://docs.levo.ai/changelog/may-2026</id>
        <link href="https://docs.levo.ai/changelog/may-2026"/>
        <updated>2026-05-31T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Release period: 2026-05-01 → 2026-05-31]]></summary>
        <content type="html"><![CDATA[<p><em>Release period: 2026-05-01 → 2026-05-31</em></p>
<p>May deepens Levo's AI security stack: a redesigned Policy Hub with identity-aware policies, a next-generation AI traffic tagger that attributes traffic to individual agents and sessions, and a full Agent Detail view. We also added Streamable HTTP transport for the MCP server, deeper API discovery from source code, and broad reliability and performance gains across the platform.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="highlights">Highlights<a href="https://docs.levo.ai/changelog/may-2026#highlights" class="hash-link" aria-label="Direct link to Highlights" title="Direct link to Highlights" translate="no">​</a></h2>
<ul>
<li class=""><strong>Policy Hub with identity-aware AI policies</strong> — The AI Policies page is now a redesigned Policy Hub with inline Monitor/Enforce toggles, server-side pagination, and a new Identity Policy type that matches principals across clouds. Default policies expanded from 16 to 36.</li>
<li class=""><strong>AI Agent Detail and per-agent attribution</strong> — A new Agent Detail page (Models, MCP, Tools, Findings, Traces) backed by a next-generation AI traffic tagger that attributes traffic to individual agents and reconstructs sessions, including AWS Bedrock AgentCore.</li>
<li class=""><strong>MCP server Streamable HTTP transport</strong> — The Levo MCP server adds Streamable HTTP transport with header-based auth and new tools, including full vulnerability detail with HTTP traces.</li>
<li class=""><strong>Enforced AI guardrails</strong> — The AI Gateway wires rate-limit policy actions to token-bucket enforcement, scans LLM response bodies, and enriches guardrail alerts with caller identity and policy lineage.</li>
<li class=""><strong>Faster, more reliable platform</strong> — Up to 7x faster app and endpoint listing, plus extensive hardening against stalls, deadlocks, and trace drops.</li>
<li class=""><strong>Discover more APIs from source</strong> — Source-code scanning now runs in parallel across entire GitHub organizations, with offline spec generation and large-repo controls, to surface APIs that may never appear in live traffic.</li>
</ul>
<p><strong>What's new at a glance.</strong> A one-page map of where May's additions land across the Levo API and AI security platform.</p>
<p><img decoding="async" loading="lazy" alt="May 2026 — What&amp;#39;s new" src="https://docs.levo.ai/assets/images/2026-05-whats-new-e32335ca7db7993f437e934f8be08bb5.png" width="2800" height="1800" class="img_ev3q"></p>
<p><em>Legend for the bullets below: 🆕 new · ⚡ enhancement · 🐞 fix</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-discovery--cataloging">API Discovery &amp; Cataloging<a href="https://docs.levo.ai/changelog/may-2026#api-discovery--cataloging" class="hash-link" aria-label="Direct link to API Discovery &amp; Cataloging" title="Direct link to API Discovery &amp; Cataloging" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Force-refresh OpenAPI spec</strong> — Manually force a refresh of an application's OpenAPI spec from the org details page.</li>
<li class="">🆕 <strong>Discover APIs from source at scale</strong> — Source-code scanning now runs in parallel across entire GitHub organizations, with include/exclude directory controls for large repositories and an offline spec-generation mode, surfacing APIs that may never appear in live traffic.</li>
<li class="">⚡ Endpoint and application reports now include tags, and applications show all source types when they have both observed traffic and imported endpoints.</li>
<li class="">⚡ Source-code scanning skips unsupported languages, classifies empty-spec outcomes, and ignores node_modules and build directories.</li>
<li class="">🐞 Fixed silent endpoint-rename failures, environment filtering for application listing, and reliable revival of soft-deleted environments.</li>
<li class="">🐞 Resolved storage-version mismatches and dependency errors in the .NET source-analysis path.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-security-testing">API Security Testing<a href="https://docs.levo.ai/changelog/may-2026#api-security-testing" class="hash-link" aria-label="Direct link to API Security Testing" title="Direct link to API Security Testing" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI-authored tests (early access)</strong> — New scaffolding and validation APIs for AI-authored tests, with a persisted plan and approval state machine, and test execution gated behind approval status.</li>
<li class="">⚡ Exported test plans now produce a runnable zip, and test results are richer with real-time streaming.</li>
<li class="">🐞 False-positive suppression and detection hardening for OS command injection and input validation, plus a fix for LFI handling of empty response bodies.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-scanning-dast">Web Application Scanning (DAST)<a href="https://docs.levo.ai/changelog/may-2026#web-application-scanning-dast" class="hash-link" aria-label="Direct link to Web Application Scanning (DAST)" title="Direct link to Web Application Scanning (DAST)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Advanced authentication strategies</strong> — DAST scans add opt-in multi-step DOM-driven login, session-transplant and storage-state strategies, and static MFA pass-through, plus an iframe-aware login resolver for Keycloak, Auth0, and Okta SSO.</li>
<li class="">🆕 <strong>Redesigned Create DAST Scan modal</strong> — A cleaner scan-creation experience, with the option to run scans on Levo Cloud or on-prem.</li>
<li class="">⚡ Time-based SQLi detection with N-sample confirmation, broad passive and active false-positive reduction (up to ~75% on some paths), and improved crawler diversity.</li>
<li class="">🐞 DAST scan creation is now correctly blocked when the feature flag is disabled.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-security">AI Security<a href="https://docs.levo.ai/changelog/may-2026#ai-security" class="hash-link" aria-label="Direct link to AI Security" title="Direct link to AI Security" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Policy Hub with Identity Policies</strong> — The AI Policies page is redesigned as a Policy Hub with an Identity Policy editor, inline Monitor/Enforce toggles, and server-side pagination. A new Identity Policy type matches principals across clouds, and default policies expanded from 16 to 36, seeded automatically for new environments.</li>
<li class="">🆕 <strong>Enforced guardrails and rate limiting</strong> — The AI Gateway wires rate-limit policy actions to token-bucket enforcement, scans LLM response bodies for output policies, and supports hot-reload policy enforcement via a new control plane.</li>
<li class="">⚡ <strong>Richer guardrail alerts</strong> — Alerts now carry caller identity (source address, IAM principal, user agent, model, upstream), policy lineage, real scanner names, and gateway-supplied titles, with enforcement mode following the originating policy.</li>
<li class="">⚡ Azure OpenAI native passthrough for transparent API-key forwarding, plus guardrail model cache pre-warming and reduced gateway memory usage.</li>
<li class="">🐞 Guardrail alerts now write to a dedicated alerts table, and duplicate scanner fires were eliminated.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-discovery">AI Discovery<a href="https://docs.levo.ai/changelog/may-2026#ai-discovery" class="hash-link" aria-label="Direct link to AI Discovery" title="Direct link to AI Discovery" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Next-generation AI traffic tagging</strong> — A new AI Traffic Tagger attributes traffic to individual agents and sessions, recognizes AWS Bedrock AgentCore runtime callers, and adds A2A discovery and comprehensive AI-provider parsers.</li>
<li class="">🆕 <strong>Function-calling tools and AgentCore identity</strong> — Discover function-calling tools alongside MCP tools, with per-agent identity from AgentCore, and support for server-less MCP tool rows.</li>
<li class="">⚡ AI and MCP trace ingestion and querying via a trace-type filter, with a Trace Type switch on the Traces page and PII type names shown inline in the Findings table.</li>
<li class="">🐞 Reliable MCP entity modeling when captured at the proxy or gateway, correct per-agent attribution, and stable agent identifiers across batches.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerabilities--findings">Vulnerabilities &amp; Findings<a href="https://docs.levo.ai/changelog/may-2026#vulnerabilities--findings" class="hash-link" aria-label="Direct link to Vulnerabilities &amp; Findings" title="Direct link to Vulnerabilities &amp; Findings" translate="no">​</a></h2>
<ul>
<li class="">⚡ <strong>Persistent filters</strong> — Vulnerability filters are retained across list and detail views.</li>
<li class="">⚡ Auto-closing a vulnerability on a flagged endpoint now includes your comment, and bulk vulnerability updates are processed reliably.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensitive-data">Sensitive Data<a href="https://docs.levo.ai/changelog/may-2026#sensitive-data" class="hash-link" aria-label="Direct link to Sensitive Data" title="Direct link to Sensitive Data" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Sensitive data findings for AI workloads</strong> — New sensitive-data finding services with entity-type awareness, and PII data pivoted to AI-aware entities so findings cover AI agents and sessions.</li>
<li class="">⚡ Entity type is now included across all sensitive-data APIs.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="runtime-protection">Runtime Protection<a href="https://docs.levo.ai/changelog/may-2026#runtime-protection" class="hash-link" aria-label="Direct link to Runtime Protection" title="Direct link to Runtime Protection" translate="no">​</a></h2>
<ul>
<li class="">⚡ Protection module health check is now enabled by default.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensors--deployment">Sensors &amp; Deployment<a href="https://docs.levo.ai/changelog/may-2026#sensors--deployment" class="hash-link" aria-label="Direct link to Sensors &amp; Deployment" title="Direct link to Sensors &amp; Deployment" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Java agent published to a public container registry</strong> — The Java agent is now available as a published container image.</li>
<li class="">⚡ <strong>Higher-throughput, self-diagnosing capture</strong> — The Java agent adds an async dispatcher with sampling, connection-level sticky sampling, host/port filters, TCP 5-tuple recovery across Tomcat, Jetty, Netty, and Vert.x, per-endpoint rate limiting (dark-launch), and self-diagnosing capture for third-party APIs.</li>
<li class="">⚡ The eBPF sensor adds richer socket-info capture and preserves in-progress request data, with noisy health probes suppressed at the capture layer.</li>
<li class="">🐞 Fixed Java 8 silent capture-loss and over-capture bugs for more reliable instrumentation.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="integrations">Integrations<a href="https://docs.levo.ai/changelog/may-2026#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Slack notifications</strong> — Levo can now send notifications to Slack.</li>
<li class="">🐞 Fixed user organization invitations and disabled unaccepted org invites in the org picker.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting--compliance">Reporting &amp; Compliance<a href="https://docs.levo.ai/changelog/may-2026#reporting--compliance" class="hash-link" aria-label="Direct link to Reporting &amp; Compliance" title="Direct link to Reporting &amp; Compliance" translate="no">​</a></h2>
<ul>
<li class="">⚡ New reports added and page-size handling improved, with a wider Actions column to fit Preview and Download buttons.</li>
<li class="">🐞 Fixed report pagination and download issues.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mcp-server">MCP Server<a href="https://docs.levo.ai/changelog/may-2026#mcp-server" class="hash-link" aria-label="Direct link to MCP Server" title="Direct link to MCP Server" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Streamable HTTP transport</strong> — The Levo MCP server adds Streamable HTTP transport at /mcp with header-based authentication.</li>
<li class="">🆕 <strong>Full vulnerability detail tool</strong> — A new MCP tool returns full vulnerability details including the complete HTTP trace, alongside additional test-authoring tools.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="platform-administration--access">Platform, Administration &amp; Access<a href="https://docs.levo.ai/changelog/may-2026#platform-administration--access" class="hash-link" aria-label="Direct link to Platform, Administration &amp; Access" title="Direct link to Platform, Administration &amp; Access" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Polished on-prem sensor management</strong> — The Sensors page adds status pills, a Type column, search, compact layout, and contextual empty states, plus a Deployments and Configuration tab.</li>
<li class="">⚡ <strong>Faster listings</strong> — App and endpoint listing is up to 7x faster thanks to new indexes, with broad hardening against stalls, deadlocks, and trace drops for a more reliable experience.</li>
<li class="">⚡ Graceful handling of expired sessions with one-shot token refresh, and reduced noise from benign auth-page network errors.</li>
<li class="">🐞 Application name changes now reflect in filter dropdowns across modules, and stale JavaScript chunks no longer cause load failures.</li>
</ul>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="platform" term="platform"/>
        <category label="reporting" term="reporting"/>
        <category label="api-security" term="api-security"/>
        <category label="ai-security" term="ai-security"/>
        <category label="ai-governance" term="ai-governance"/>
        <category label="dast" term="dast"/>
        <category label="notifications" term="notifications"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Release Notes — April 2026]]></title>
        <id>https://docs.levo.ai/changelog/april-2026</id>
        <link href="https://docs.levo.ai/changelog/april-2026"/>
        <updated>2026-04-30T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Release period: 2026-04-01 → 2026-04-30]]></summary>
        <content type="html"><![CDATA[<p><em>Release period: 2026-04-01 → 2026-04-30</em></p>
<p>April brings AI security front and center: discovery of AI agents, models, and MCP tools from cloud providers, the first AI Policies and guardrail alerting, and a major step forward for web application scanning (DAST) with AI-driven authentication. We also expanded reporting, hardened sensors, and shipped new deployment options.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="highlights">Highlights<a href="https://docs.levo.ai/changelog/april-2026#highlights" class="hash-link" aria-label="Direct link to Highlights" title="Direct link to Highlights" translate="no">​</a></h2>
<ul>
<li class=""><strong>AI discovery for agents, models, and MCP</strong> — Levo now automatically discovers AI agents, models, and MCP servers and tools from your traffic, including AWS Bedrock and Gemini, so your AI footprint is cataloged alongside your APIs.</li>
<li class=""><strong>AI Policies and guardrail alerting (beta)</strong> — A new AI Gateway policy framework with guardrail alerts that capture prompt snippets, detection scores, model name, and MCP context, giving you visibility and control over AI usage.</li>
<li class=""><strong>DAST gets smarter authentication</strong> — Web app scans now support AI-driven login and flexible auth strategies, with deployable scan runners and improved scan depth and fidelity to reduce false positives.</li>
<li class=""><strong>Proof-based injection testing</strong> — New semantic, proof-based SQL and NoSQL injection detection delivers high-confidence findings with dramatically lower false positives.</li>
<li class=""><strong>AWS ECS Fargate deployment</strong> — One-click deploy and enhanced installation scripts for running the Satellite and PCAP sensor on AWS ECS Fargate.</li>
<li class=""><strong>Redesigned sign-in and dark mode</strong> — A refreshed authentication experience plus a new dark mode in the admin portal.</li>
</ul>
<p><strong>What's new at a glance.</strong> A one-page map of where April's additions land across the Levo API and AI security platform.</p>
<p><img decoding="async" loading="lazy" alt="April 2026 — What&amp;#39;s new" src="https://docs.levo.ai/assets/images/2026-04-whats-new-b9f4477ebe37f31d1dce5f1dc1d96456.png" width="2800" height="1800" class="img_ev3q"></p>
<p><em>Legend for the bullets below: 🆕 new · ⚡ enhancement · 🐞 fix</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-discovery--cataloging">API Discovery &amp; Cataloging<a href="https://docs.levo.ai/changelog/april-2026#api-discovery--cataloging" class="hash-link" aria-label="Direct link to API Discovery &amp; Cataloging" title="Direct link to API Discovery &amp; Cataloging" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Large and bulk Postman imports</strong> — Import large Postman collections in bulk, with normalized path segments to prevent duplicate endpoints.</li>
<li class="">🆕 <strong>Discover APIs from .NET and C# source</strong> — Source-code scanning that surfaces APIs into your inventory now supports .NET and C#, finding endpoints that may not appear in live traffic.</li>
<li class="">⚡ Filter endpoints by the time of the last trace received, and apply a global quick filter for all, external, or internal endpoints on the Auth Schemes view.</li>
<li class="">⚡ Endpoint exports now cover zombie and inactive endpoints, with sensor export pagination.</li>
<li class="">🐞 Trace-to-endpoint race conditions and duplicate endpoints from imports are now handled reliably.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-security-testing">API Security Testing<a href="https://docs.levo.ai/changelog/april-2026#api-security-testing" class="hash-link" aria-label="Direct link to API Security Testing" title="Direct link to API Security Testing" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Proof-based SQL and NoSQL injection detection</strong> — New semantic, evidence-driven detection for SQLi and NoSQLi with very low false-positive rates.</li>
<li class="">⚡ Improved assertions for CORS and injection attacks, and aggregated sub-technique assertions for mass-assignment testing.</li>
<li class="">🐞 Suppressed a SQLi union-canary false positive triggered by server input echo, and fixed a URL-parsing error.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-scanning-dast">Web Application Scanning (DAST)<a href="https://docs.levo.ai/changelog/april-2026#web-application-scanning-dast" class="hash-link" aria-label="Direct link to Web Application Scanning (DAST)" title="Direct link to Web Application Scanning (DAST)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI-driven authentication for scans</strong> — Web app scans support AI-assisted login, including extra steps for AI/LLM keys and advanced header fields; the feature is now out of beta.</li>
<li class="">🆕 <strong>Deployable DAST scan runners</strong> — Run web app scans from deployable runners, with re-run and configurable scan depth.</li>
<li class="">⚡ Endpoints are now segregated by source, with a "URLs by Source" tab, live scan metrics, and visibility into URLs pending in the queue.</li>
<li class="">⚡ Smarter scanning that is tech-stack aware, plus improved detection for command injection, file upload, and stored XSS.</li>
<li class="">⚡ "WebAppScan" is now consistently named "DAST Scan" across the product.</li>
<li class="">🐞 Significant false-positive reduction and signal-quality hardening, with graceful handling of scan timeouts so they are no longer reported as cancelled.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-security">AI Security<a href="https://docs.levo.ai/changelog/april-2026#ai-security" class="hash-link" aria-label="Direct link to AI Security" title="Direct link to AI Security" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI Policies and AI Gateway policies (beta)</strong> — A new policy framework for governing AI usage, with expanded MCP governance policies. The feature is disabled by default while in beta.</li>
<li class="">🆕 <strong>AI guardrail alerts</strong> — Guardrail alerts capture prompt snippets, detection scores, model name, and MCP context, with an alert detail drawer, export, and multi-select in the dashboard.</li>
<li class="">🆕 <strong>Transparent TLS interception and MCP sidecar</strong> — The AI Gateway adds transparent TLS interception, sidecar injection (including Java sidecar support with TLS trust-store injection), and auto-configuration of TLS interception, enabling inline inspection of AI traffic.</li>
<li class="">⚡ The gateway now buffers request bodies for man-in-the-middle inspection and adds a configuration to suppress noisy HTTP methods.</li>
<li class="">🐞 Tenant isolation for guardrail alerts, plus fixes to prevent guardrail-related crash loops and alert truncation.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-discovery">AI Discovery<a href="https://docs.levo.ai/changelog/april-2026#ai-discovery" class="hash-link" aria-label="Direct link to AI Discovery" title="Direct link to AI Discovery" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Discover AI agents, models, MCP servers, and tools</strong> — Levo discovers AI agents, MCP servers, and MCP tools from AWS Bedrock tool configurations, and extracts model names from Bedrock and Gemini request paths.</li>
<li class="">⚡ AI and MCP entities are now labeled in the endpoint TYPE column, and full LLM request bodies are forwarded for accurate agent and MCP entity discovery.</li>
<li class="">🐞 Reliable AI trace ingestion for Bedrock, including base64-prefixed streaming responses, large payloads, and paths containing colons; pagination and sorting fixes for AI Models and AI Agents views.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerabilities--findings">Vulnerabilities &amp; Findings<a href="https://docs.levo.ai/changelog/april-2026#vulnerabilities--findings" class="hash-link" aria-label="Direct link to Vulnerabilities &amp; Findings" title="Direct link to Vulnerabilities &amp; Findings" translate="no">​</a></h2>
<ul>
<li class="">⚡ <strong>Jira tickets for grouped findings</strong> — Create a Jira ticket linked to multiple endpoints directly from grouped findings, and filter findings by whether they have a Jira ticket.</li>
<li class="">⚡ Merged category options in vulnerability filters and a stats API that updates as you apply findings filters.</li>
<li class="">🐞 Fixes to Jira ticket and delete icon sizing and an overlapping solution URL in Findings.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensitive-data">Sensitive Data<a href="https://docs.levo.ai/changelog/april-2026#sensitive-data" class="hash-link" aria-label="Direct link to Sensitive Data" title="Direct link to Sensitive Data" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Richer sensitive data view</strong> — New stats on the sensitive data page, plus API type, newly-added, external, and trace context for each item.</li>
<li class="">⚡ Improved PII detection using a new NER model alongside regex, and external flags surfaced in sensitive data.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="runtime-protection">Runtime Protection<a href="https://docs.levo.ai/changelog/april-2026#runtime-protection" class="hash-link" aria-label="Direct link to Runtime Protection" title="Direct link to Runtime Protection" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Replay-attack protection</strong> — Added nonce deduplication and token lifetime enforcement to defend against replay attacks.</li>
<li class="">⚡ Added a health check for the Protection module.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensors--deployment">Sensors &amp; Deployment<a href="https://docs.levo.ai/changelog/april-2026#sensors--deployment" class="hash-link" aria-label="Direct link to Sensors &amp; Deployment" title="Direct link to Sensors &amp; Deployment" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AWS ECS Fargate deployment</strong> — One-click deploy and enhanced installation scripts for the Satellite and PCAP sensor on AWS ECS Fargate, with updated task definitions.</li>
<li class="">🆕 <strong>Zero-downtime key rotation for the Satellite</strong> — A new decryption pipeline with zero-downtime key-store rotation, a filesystem key store, and pluggable decryption scripts for Satellite traffic.</li>
<li class="">⚡ eBPF sensor self-monitoring of CPU and memory, and a more efficient collector configuration with metrics export.</li>
<li class="">🐞 Fixed an eBPF sensor memory leak and improved its restart behavior; resolved a Java agent memory leak and binary payload corruption.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="integrations">Integrations<a href="https://docs.levo.ai/changelog/april-2026#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations" translate="no">​</a></h2>
<ul>
<li class="">⚡ <strong>Improved integrations page</strong> — A refreshed integrations experience in the dashboard.</li>
<li class="">⚡ Keycloak LDAP/AD user federation for on-prem installations, LDAP support for multiple AD groups, and improved Auth0 subject detection.</li>
<li class="">⚡ Chrome extension now captures application data.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting--compliance">Reporting &amp; Compliance<a href="https://docs.levo.ai/changelog/april-2026#reporting--compliance" class="hash-link" aria-label="Direct link to Reporting &amp; Compliance" title="Direct link to Reporting &amp; Compliance" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>New report types</strong> — Added AI Agents reports, a change-log and auth-schema report, an environment test report, and an RBI compliance report integrated into the UI.</li>
<li class="">⚡ Past Reports now show request metadata and offer filters; reports can be downloaded via secure links.</li>
<li class="">🐞 Report storage moved to durable object storage and a database for reliability, with corrected report numbers.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="platform-administration--access">Platform, Administration &amp; Access<a href="https://docs.levo.ai/changelog/april-2026#platform-administration--access" class="hash-link" aria-label="Direct link to Platform, Administration &amp; Access" title="Direct link to Platform, Administration &amp; Access" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Admin portal upgrades</strong> — New Environments tab, Feature Control, Session Management, org detail tabs, dark mode, and global API error handling with an error boundary page.</li>
<li class="">⚡ <strong>Modernized authentication UI</strong> — Redesigned login and signup experience, with redirect back to your original URL after login.</li>
<li class="">⚡ Sticky header rows, better empty-space handling on large screens, and the dashboard UI upgraded to a current runtime.</li>
<li class="">🐞 Filters and cache now reset correctly on organization switch, and a Test Plans page crash when sorting was fixed.</li>
</ul>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="platform" term="platform"/>
        <category label="traffic-capture" term="traffic-capture"/>
        <category label="reporting" term="reporting"/>
        <category label="api-security" term="api-security"/>
        <category label="ai-security" term="ai-security"/>
        <category label="ai-governance" term="ai-governance"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Release Notes — March 2026]]></title>
        <id>https://docs.levo.ai/changelog/march-2026</id>
        <link href="https://docs.levo.ai/changelog/march-2026"/>
        <updated>2026-03-31T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Release period: 2026-03-01 → 2026-03-31]]></summary>
        <content type="html"><![CDATA[<p><em>Release period: 2026-03-01 → 2026-03-31</em></p>
<p>March is a big month for web application scanning: our DAST engine matures with smarter crawling, scheduled and on-demand scans, AI/LLM-driven authentication, and a large round of false-positive reduction. We also unified AI Gateway policies with live guardrail enforcement, moved reporting to a faster async pipeline with a new application comparison report, and added configurable session management, sensor health notifications, and grouped threats.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="highlights">Highlights<a href="https://docs.levo.ai/changelog/march-2026#highlights" class="hash-link" aria-label="Direct link to Highlights" title="Direct link to Highlights" translate="no">​</a></h2>
<ul>
<li class=""><strong>DAST matures</strong> — Web application scans gain smart crawl depth, scheduled and re-runnable scans, deployable on-prem runners, OpenAPI spec parsing, and broad coverage of missing vulnerability categories — with a major false-positive cleanup across active and passive scanners.</li>
<li class=""><strong>Unified AI Gateway policies</strong> — A consolidated, gateway-level policy architecture with hot-reloaded policies from SaaS, a forward-proxy AI traffic governance pipeline, and live guardrail scanners now enabled in the AI Firewall.</li>
<li class=""><strong>Faster reporting with application comparison</strong> — Reports moved to an async pipeline for reliability at scale, plus a new application comparison report you can run and view in the dashboard.</li>
<li class=""><strong>Configurable session management</strong> — Set inactivity and absolute session timeouts, with a clear banner explaining why a session ended.</li>
<li class=""><strong>Sensor health notifications</strong> — Get notified when a sensor goes inactive, with configuration support so you know your traffic capture is healthy.</li>
<li class=""><strong>Grouped threats and richer findings</strong> — Threats are now grouped for easier triage, with evidence surfaced in the Threat Feed, severity sorting, more filters, and saved views across findings and scans.</li>
</ul>
<p><strong>What's new at a glance.</strong> A one-page map of where March's additions land across the Levo API and AI security platform.</p>
<p><img decoding="async" loading="lazy" alt="March 2026 — What&amp;#39;s new" src="https://docs.levo.ai/assets/images/2026-03-whats-new-529c86277a578db987a00f7ee13a2e24.png" width="2800" height="1800" class="img_ev3q"></p>
<p><em>Legend for the bullets below: 🆕 new · ⚡ enhancement · 🐞 fix</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-discovery--cataloging">API Discovery &amp; Cataloging<a href="https://docs.levo.ai/changelog/march-2026#api-discovery--cataloging" class="hash-link" aria-label="Direct link to API Discovery &amp; Cataloging" title="Direct link to API Discovery &amp; Cataloging" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Configurable ignored HTTP methods</strong> — API discovery can be configured to skip specific HTTP methods, keeping catalogs focused on the traffic that matters.</li>
<li class="">⚡ Endpoint exports now include the created date and last-trace-received date, and you can sort endpoints by when their last trace arrived.</li>
<li class="">⚡ Header parameters such as Content-Type and Accept are now parsed and populated automatically, and endpoint parameters are returned sorted by required status and name.</li>
<li class="">⚡ A new "Recently Discovered" filter at the application level, and a tooltip on Owned Domains in the API Discovery configuration.</li>
<li class="">🐞 Fixed request-parameter wrapping in API specifications and corrected masked-parameter handling in captured request paths.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-security-testing">API Security Testing<a href="https://docs.levo.ai/changelog/march-2026#api-security-testing" class="hash-link" aria-label="Direct link to API Security Testing" title="Direct link to API Security Testing" translate="no">​</a></h2>
<ul>
<li class="">⚡ More reliable parameter handling — user-set parameter values are no longer overwritten by newly derived values, and custom values are preserved in raw parameters.</li>
<li class="">⚡ Live UI log streaming per test suite for better visibility into running tests, and quieter CLI output in non-interactive mode.</li>
<li class="">🐞 Corrected test-run counts so they match between Insights and the API Scans page, and fixed author selection to use organization users.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-scanning-dast">Web Application Scanning (DAST)<a href="https://docs.levo.ai/changelog/march-2026#web-application-scanning-dast" class="hash-link" aria-label="Direct link to Web Application Scanning (DAST)" title="Direct link to Web Application Scanning (DAST)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Scheduled and re-runnable web app scans</strong> — Schedule web app scans to run automatically, re-run a previous scan, and trigger scans from CI/CD with a new DAST scan action.</li>
<li class="">🆕 <strong>Smart scan depth and crawl-only mode</strong> — Scans default to a "smart" depth mode, with a crawl-only option for discovery and configurable scan depth per scan.</li>
<li class="">🆕 <strong>AI/LLM-driven authentication</strong> — Provide cookies, local storage keys, and headers for authenticated scans, including AI-assisted login that handles SPA re-login and CAPTCHA flows.</li>
<li class="">🆕 <strong>OpenAPI spec parsing and broader coverage</strong> — The scanner parses OpenAPI specs and adds support for the remaining DAST vulnerability categories, plus soft-404 detection, tech-stack detection, and stored-XSS detection.</li>
<li class="">🆕 <strong>Deployable on-prem scan runners</strong> — Run web app scans from deployable runners with scheduled, org-isolated execution for on-prem deployments.</li>
<li class="">⚡ A redesigned create-scan flow, a search bar for URLs and endpoints in the scan details view, HTTP-method support and filtering, live crawl metrics, persistent filters, saved filter state, and the ability to switch off DAST scanning selectively.</li>
<li class="">⚡ Endpoint URL is now captured on DAST findings and vulnerabilities, with a finding "Kind" filter (Web App Scans / Traffic / All).</li>
<li class="">🐞 Large false-positive reduction across active and passive scanners — including auth-bypass, JWT, GraphQL introspection, and JSON-reflected XSS — plus more reliable crawling, static-asset filtering, soft-404 handling, scan cancellation, and a CLI startup fix.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-security">AI Security<a href="https://docs.levo.ai/changelog/march-2026#ai-security" class="hash-link" aria-label="Direct link to AI Security" title="Direct link to AI Security" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Unified AI Gateway policy architecture</strong> — A consolidated, gateway-level policy framework with a single policy engine, policy versioning, and policies hot-reloaded from SaaS so changes take effect without redeploying.</li>
<li class="">🆕 <strong>Forward-proxy AI traffic governance</strong> — A new forward-proxy mode runs AI traffic through a multi-stage governance pipeline for inline inspection.</li>
<li class="">🆕 <strong>Live guardrail scanners in the AI Firewall</strong> — Guardrail scanners are now implemented and enabled, with the AI Firewall and AI Gateway pages out of "coming soon."</li>
<li class="">⚡ The AI Gateway can now send its traffic to the Levo Satellite for full API observability alongside your other APIs, and ships latency benchmarks with inspection optimizations.</li>
<li class="">🆕 <strong>Chrome extension AI Guardrails</strong> — The browser extension (now "Levo Live") adds AI Guardrails integration with LLM interception and enforce or observe modes.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-discovery">AI Discovery<a href="https://docs.levo.ai/changelog/march-2026#ai-discovery" class="hash-link" aria-label="Direct link to AI Discovery" title="Direct link to AI Discovery" translate="no">​</a></h2>
<ul>
<li class="">⚡ <strong>AI traffic to the Satellite</strong> — The collector adds a Levo AI receiver and AI-proxy span processing, and full LLM request bodies are forwarded so AI agents and MCP entities are discovered accurately.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerabilities--findings">Vulnerabilities &amp; Findings<a href="https://docs.levo.ai/changelog/march-2026#vulnerabilities--findings" class="hash-link" aria-label="Direct link to Vulnerabilities &amp; Findings" title="Direct link to Vulnerabilities &amp; Findings" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Grouped threats and evidence</strong> — Threats are now grouped for easier triage, with evidence returned by the findings API and surfaced in the Threat Feed.</li>
<li class="">🆕 <strong>Bulk tag actions</strong> — Apply tag actions to findings in bulk, and sort findings by severity.</li>
<li class="">⚡ More filters on the Findings and Applications pages, saved filters and views on API Scans, application stats that update as you apply filters, and a stats API for consistent counts.</li>
<li class="">🐞 Fixed open-vulnerability counts that did not match between Insights and the global level, and corrected bulk actions on the vulnerability pages.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensitive-data">Sensitive Data<a href="https://docs.levo.ai/changelog/march-2026#sensitive-data" class="hash-link" aria-label="Direct link to Sensitive Data" title="Direct link to Sensitive Data" translate="no">​</a></h2>
<ul>
<li class="">⚡ <strong>Inline sample traces for PII</strong> — The PII tab now shows inline sample traces with row selection, pagination by type, and a refreshed view that updates as new sensitive data is discovered.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="runtime-protection">Runtime Protection<a href="https://docs.levo.ai/changelog/march-2026#runtime-protection" class="hash-link" aria-label="Direct link to Runtime Protection" title="Direct link to Runtime Protection" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Findings and evidence from protection rules</strong> — Protection now creates findings (including for Lua-based rules) with evidence, and deduplicates rate-limit findings to one per key per window.</li>
<li class="">🆕 <strong>Bulk rule exclusions and header-injection rules</strong> — Add bulk rule exclusions and custom header-injection rules, with configurable content types and active WAF protection.</li>
<li class="">⚡ Improved rate-limit rule configuration in the dashboard, and GraphQL protection handling.</li>
<li class="">🐞 Blocking is now disabled by default for safer rollout, with smarter routing of rule overrides and hardened Kubernetes deployment.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensors--deployment">Sensors &amp; Deployment<a href="https://docs.levo.ai/changelog/march-2026#sensors--deployment" class="hash-link" aria-label="Direct link to Sensors &amp; Deployment" title="Direct link to Sensors &amp; Deployment" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Sensor health notifications</strong> — Get notified when a sensor becomes inactive, with configuration support so you always know your traffic capture is healthy.</li>
<li class="">⚡ The Java agent now logs to file with additional diagnostics for easier troubleshooting.</li>
<li class="">🐞 Sensor Helm chart fixes addressing a customer-reported deployment issue.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="integrations">Integrations<a href="https://docs.levo.ai/changelog/march-2026#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>CI/CD DAST scan action</strong> — A new action to run web app scans directly from your CI/CD pipeline.</li>
<li class="">⚡ Auth0 tokens are now routed correctly by subject claim, and SSO-only users no longer hit a 401 on password reset.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting--compliance">Reporting &amp; Compliance<a href="https://docs.levo.ai/changelog/march-2026#reporting--compliance" class="hash-link" aria-label="Direct link to Reporting &amp; Compliance" title="Direct link to Reporting &amp; Compliance" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Application comparison report</strong> — A new report that compares applications side by side, available to run and view in the dashboard.</li>
<li class="">🆕 <strong>Async reporting pipeline</strong> — Existing reports were migrated to an async architecture for reliability at scale, with additional report types added and a new Reports page in the UI.</li>
<li class="">⚡ Reports support multiple CSV previews, and DAST scan report findings now include a solution field and detected AI endpoints.</li>
<li class="">🐞 Fixed PDF rendering in generated reports.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mcp-server">MCP Server<a href="https://docs.levo.ai/changelog/march-2026#mcp-server" class="hash-link" aria-label="Direct link to MCP Server" title="Direct link to MCP Server" translate="no">​</a></h2>
<ul>
<li class="">⚡ Reliability improvements to the MCP Server deployment.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="platform-administration--access">Platform, Administration &amp; Access<a href="https://docs.levo.ai/changelog/march-2026#platform-administration--access" class="hash-link" aria-label="Direct link to Platform, Administration &amp; Access" title="Direct link to Platform, Administration &amp; Access" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Configurable session management</strong> — Set inactivity and absolute session timeouts, with sensible defaults and a banner that explains why a session ended after inactivity or expiry.</li>
<li class="">🆕 <strong>Default "staging" environment</strong> — New organizations are created with a default "staging" environment so you can start capturing traffic immediately.</li>
<li class="">🆕 <strong>Redesigned admin portal login</strong> — A modernized admin portal sign-in, with consolidated frontend and backend deployment.</li>
<li class="">⚡ Sidebar UX improvements (peek, pin, and toggle), clicking the Levo logo returns you home, an announcements unread count, and organization list sorting with consolidated copy buttons.</li>
<li class="">🐞 Cross-organization data leakage on org switch is fixed by clearing cached state, pagination and filter state now persist correctly across navigation, dark-mode rendering issues were resolved, and several login and auto-logout bugs were fixed.</li>
</ul>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="platform" term="platform"/>
        <category label="traffic-capture" term="traffic-capture"/>
        <category label="reporting" term="reporting"/>
        <category label="api-security" term="api-security"/>
        <category label="ai-security" term="ai-security"/>
        <category label="ai-governance" term="ai-governance"/>
        <category label="dast" term="dast"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Release Notes — February 2026]]></title>
        <id>https://docs.levo.ai/changelog/february-2026</id>
        <link href="https://docs.levo.ai/changelog/february-2026"/>
        <updated>2026-02-28T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Release period: February 1 – February 28, 2026]]></summary>
        <content type="html"><![CDATA[<p><em>Release period: February 1 – February 28, 2026</em></p>
<p>February built on January's launches by making them production-ready: web application scanning (DAST) matured fast with CLI-driven scans, evidence, and DOCX reports; AI Guardrails gained a policy framework and multi-tenant, parallelized scanning; and we introduced tagging across findings and vulnerabilities, separated threats into their own feed, and shipped a new agentless API discovery CLI.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="highlights">Highlights<a href="https://docs.levo.ai/changelog/february-2026#highlights" class="hash-link" aria-label="Direct link to Highlights" title="Direct link to Highlights" translate="no">​</a></h2>
<ul>
<li class=""><strong>Findings &amp; Vulnerabilities tagging</strong> — Apply tags to findings and vulnerabilities to organize, triage, and filter at scale, with bulk delete and a redesigned Findings view.</li>
<li class=""><strong>DAST scanning matures</strong> — Launch web app scans from the CLI, capture evidence, cancel scans end to end, export DOCX reports, and discover far more endpoints with new JS-aware crawling.</li>
<li class=""><strong>AI Guardrail Policies</strong> — A new policy framework for AI Guardrails with multi-tenant enforcement and parallel scanning for 3–5x faster checks.</li>
<li class=""><strong>Threats, separated from findings</strong> — Runtime threats now have their own dedicated feed, distinct from security findings.</li>
<li class=""><strong>Agentless API discovery CLI</strong> — A new command-line tool to discover APIs with multiple scan modes, no sensor required.</li>
<li class=""><strong>End-to-end audit logging</strong> — A rebuilt audit log with readable entity names, user-activity tracking, and before/after state on changes.</li>
</ul>
<p><strong>What's new at a glance.</strong> A map of where February's new capabilities fit across the Levo API &amp; AI security platform.</p>
<p><img decoding="async" loading="lazy" alt="February 2026 — What&amp;#39;s new" src="https://docs.levo.ai/assets/images/2026-02-whats-new-4d79403f839e53c5f126d1eca0175922.png" width="2800" height="1800" class="img_ev3q"></p>
<p><em>Legend for the bullets below: 🆕 new · ⚡ enhancement · 🐞 fix</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerabilities--findings">Vulnerabilities &amp; Findings<a href="https://docs.levo.ai/changelog/february-2026#vulnerabilities--findings" class="hash-link" aria-label="Direct link to Vulnerabilities &amp; Findings" title="Direct link to Vulnerabilities &amp; Findings" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Tagging for findings and vulnerabilities</strong> — Apply and search by tags across findings and vulnerabilities to organize and triage at scale.</li>
<li class="">🆕 <strong>Bulk delete for findings</strong> — Select and remove multiple findings in one action.</li>
<li class="">🆕 <strong>Redesigned Findings page</strong> — A new Findings view with clearer layout and additional row controls.</li>
<li class="">⚡ Search for multiple issue names at once across the Findings and Grouped Findings screens.</li>
<li class="">⚡ New KIND filter for findings and vulnerabilities, plus improved field filtering.</li>
<li class="">🐞 Fixed null values on the Grouped Findings page, a vulnerability detail page that would not open for certain filters, and an application-to-endpoints count mismatch.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-scanning-dast">Web Application Scanning (DAST)<a href="https://docs.levo.ai/changelog/february-2026#web-application-scanning-dast" class="hash-link" aria-label="Direct link to Web Application Scanning (DAST)" title="Direct link to Web Application Scanning (DAST)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Launch scans from the CLI</strong> — Kick off web application scans directly from the command line.</li>
<li class="">🆕 <strong>Evidence capture</strong> — DAST scans now record supporting evidence for each finding, viewable in the UI.</li>
<li class="">🆕 <strong>DOCX scan reports</strong> — Export web application scan results as DOCX, alongside an improved report export experience.</li>
<li class="">🆕 <strong>Scan cancellation</strong> — Cancel a running web app scan end to end.</li>
<li class="">🆕 <strong>AI-assisted login</strong> — Provide a prompt and credentials for AI-driven authentication during a scan.</li>
<li class="">⚡ <strong>Smarter crawling and discovery</strong> — AI-driven crawler and prompt improvements, framework-agnostic URL discovery, and JS endpoint discovery that finds 80–99% more endpoints.</li>
<li class="">⚡ Separate passive (Scanner) and active (Probe) interfaces, advanced rules in active scans, and new active-scan test categories including a SQL injection filter in the UI.</li>
<li class="">⚡ Standard crawl mode is now the default when creating a scan, with a refreshed scan details page, metrics, and URLs tab.</li>
<li class="">🐞 Fixed scan log cleanup, LLM provider selection, and assorted scan stability issues.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-security">AI Security<a href="https://docs.levo.ai/changelog/february-2026#ai-security" class="hash-link" aria-label="Direct link to AI Security" title="Direct link to AI Security" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI Guardrail Policies</strong> — A new policy framework to configure AI Guardrails, with an expandable policy screen and per-scanner action and alert settings.</li>
<li class="">🆕 <strong>Guardrail alert management API</strong> — New API endpoints to manage and route guardrail alerts.</li>
<li class="">🆕 <strong>Standalone Scan API</strong> — Dedicated request and response scan endpoints for integrating guardrail checks directly.</li>
<li class="">⚡ <strong>Multi-tenant guardrails</strong> — Multi-tenant guardrail management with per-tenant alert routing and OAuth2 token rotation.</li>
<li class="">⚡ <strong>Faster guardrail scanning</strong> — Parallel scanner execution for 3–5x faster checks, plus a global model cache that cuts cold-start model load from ~40s to ~1s.</li>
<li class="">⚡ Configurable alert webhooks and periodic scanner-configuration polling, with SaaS configuration enabled by default.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-discovery">AI Discovery<a href="https://docs.levo.ai/changelog/february-2026#ai-discovery" class="hash-link" aria-label="Direct link to AI Discovery" title="Direct link to AI Discovery" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Local MCP and coding-agent discovery</strong> — Levo now discovers local MCP servers and coding agents, including those launched from the Claude CLI, and captures their enabled tools and permissions.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-discovery--cataloging">API Discovery &amp; Cataloging<a href="https://docs.levo.ai/changelog/february-2026#api-discovery--cataloging" class="hash-link" aria-label="Direct link to API Discovery &amp; Cataloging" title="Direct link to API Discovery &amp; Cataloging" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Agentless API discovery CLI</strong> — A new command-line tool to discover APIs with multiple scan modes, without deploying a sensor.</li>
<li class="">🆕 <strong>Auth scheme refresh</strong> — A new system capability to refresh authentication schemes for endpoints by replaying recent traffic.</li>
<li class="">⚡ Configure API discovery to ignore specific HTTP methods, reducing noise in generated specs.</li>
<li class="">⚡ Application-name support across discovery so endpoints are attributed to the right app, with faster API-visibility retrieval.</li>
<li class="">🐞 Imported Postman collections are now persisted reliably, and optional path lists are handled correctly during discovery.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="runtime-protection">Runtime Protection<a href="https://docs.levo.ai/changelog/february-2026#runtime-protection" class="hash-link" aria-label="Direct link to Runtime Protection" title="Direct link to Runtime Protection" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Dedicated threat feed</strong> — Runtime threats are now separated from security findings into their own feed and UI, with new threat-ingestion endpoints.</li>
<li class="">⚡ Production reliability, memory-safety, and client-identification improvements across the protection engine.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensitive-data">Sensitive Data<a href="https://docs.levo.ai/changelog/february-2026#sensitive-data" class="hash-link" aria-label="Direct link to Sensitive Data" title="Direct link to Sensitive Data" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Sensitive-data masking in trace collection</strong> — Trace collection can now mask sensitive values, with data-type-based masking applied during processing.</li>
<li class="">⚡ Improved Sensitive Data page for both traces and endpoints, with Authentication and PII details separated on the endpoint detail page.</li>
<li class="">🐞 Fixed a persistent PII filter issue in saved views.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting--compliance">Reporting &amp; Compliance<a href="https://docs.levo.ai/changelog/february-2026#reporting--compliance" class="hash-link" aria-label="Direct link to Reporting &amp; Compliance" title="Direct link to Reporting &amp; Compliance" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>DOCX report generation</strong> — Generate DAST reports in DOCX format for sharing and offline review.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensors--deployment">Sensors &amp; Deployment<a href="https://docs.levo.ai/changelog/february-2026#sensors--deployment" class="hash-link" aria-label="Direct link to Sensors &amp; Deployment" title="Direct link to Sensors &amp; Deployment" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Sensor health reporting</strong> — eBPF and PCAP sensors now capture health and component details and report them to the Satellite.</li>
<li class="">⚡ eBPF sensor CPU optimizations and PCAP multitenant traffic support.</li>
<li class="">⚡ New fallback handling so traffic is captured reliably across PCAP and other sensors.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-security-testing">API Security Testing<a href="https://docs.levo.ai/changelog/february-2026#api-security-testing" class="hash-link" aria-label="Direct link to API Security Testing" title="Direct link to API Security Testing" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Per-test error-code configuration</strong> — Define expected error codes for security tests to reduce false positives.</li>
<li class="">⚡ Automatic baseline retry when authentication expires mid-run, for more reliable test results.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="integrations">Integrations<a href="https://docs.levo.ai/changelog/february-2026#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations" translate="no">​</a></h2>
<ul>
<li class="">🐞 Burp extension now omits default ports (80 for HTTP, 443 for HTTPS) from the Host header, per RFC 7230.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="platform-administration--access">Platform, Administration &amp; Access<a href="https://docs.levo.ai/changelog/february-2026#platform-administration--access" class="hash-link" aria-label="Direct link to Platform, Administration &amp; Access" title="Direct link to Platform, Administration &amp; Access" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>End-to-end audit logging</strong> — A rebuilt audit log that resolves entity IDs to readable names, tracks user activities, captures before/after state on changes, and supports querying by organization.</li>
<li class="">⚡ <strong>POC workspace limits</strong> — Proof-of-concept workspaces are now capped at five applications via tier tagging, with a clear in-app banner.</li>
<li class="">⚡ Standardized service-to-service communication and environment-scoped requests for more consistent, isolated multi-environment behavior, with improved connection stability at scale.</li>
<li class="">⚡ Faster endpoint and application loading, database-level pagination, and page numbers retained when switching environments.</li>
<li class="">⚡ Skeleton loaders, category titles in navigation, clearer severity colors, and assorted dashboard UI/UX fixes.</li>
<li class="">🐞 Fixed a caching issue when switching organizations and a more intuitive wrong-password sign-in experience.</li>
</ul>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="traffic-capture" term="traffic-capture"/>
        <category label="reporting" term="reporting"/>
        <category label="api-security" term="api-security"/>
        <category label="ai-security" term="ai-security"/>
        <category label="ai-governance" term="ai-governance"/>
        <category label="dast" term="dast"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Release Notes — January 2026]]></title>
        <id>https://docs.levo.ai/changelog/january-2026</id>
        <link href="https://docs.levo.ai/changelog/january-2026"/>
        <updated>2026-01-31T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Release period: January 1 – January 31, 2026]]></summary>
        <content type="html"><![CDATA[<p><em>Release period: January 1 – January 31, 2026</em></p>
<p>January was a big month for AI security. We shipped Vigil, our AI-native firewall for AI apps and MCP servers, launched our new web application scanning (DAST) and external attack surface management capabilities, and made AI guardrails and AI discovery work end to end — alongside dozens of improvements to findings, sensitive data, reporting, and the dashboard.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="highlights">Highlights<a href="https://docs.levo.ai/changelog/january-2026#highlights" class="hash-link" aria-label="Direct link to Highlights" title="Direct link to Highlights" translate="no">​</a></h2>
<ul>
<li class=""><strong>Vigil — AI-native firewall</strong> — New runtime protection purpose-built for AI applications and MCP servers, with upstream route configuration and live policy enforcement.</li>
<li class=""><strong>AI Guardrails, end to end</strong> — Guardrail violations now generate real-time alerts, backed by both ML-based and regex-based scanners for request and response content.</li>
<li class=""><strong>Web Application Scanning (DAST)</strong> — First release of our DAST engine (ShadowNet), including AI-driven and hybrid crawling and a crawl-only mode.</li>
<li class=""><strong>External Attack Surface Management (EASM)</strong> — New product to discover and scan your internet-facing API attack surface.</li>
<li class=""><strong>AI discovery in your traffic</strong> — Levo now tags and classifies AI, API, and MCP traffic, including AI PII, so you can see what your AI apps are exposing.</li>
<li class=""><strong>Findings export &amp; faster dashboard</strong> — Export findings to CSV and PDF, server-side sorting on the Findings screen, and broad UI performance improvements.</li>
</ul>
<p><strong>What's new at a glance.</strong> A map of where January's new capabilities fit across the Levo API &amp; AI security platform.</p>
<p><img decoding="async" loading="lazy" alt="January 2026 — What&amp;#39;s new" src="https://docs.levo.ai/assets/images/2026-01-whats-new-43d07d568b47936efaeef721f724454c.png" width="2800" height="1800" class="img_ev3q"></p>
<p><em>Legend for the bullets below: 🆕 new · ⚡ enhancement · 🐞 fix</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-security">AI Security<a href="https://docs.levo.ai/changelog/january-2026#ai-security" class="hash-link" aria-label="Direct link to AI Security" title="Direct link to AI Security" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Vigil — AI-native firewall</strong> — A new firewall built for AI apps and MCP servers, with upstream route configuration and runtime enforcement.</li>
<li class="">🆕 <strong>AI Gateway &amp; firewall configuration</strong> — Configure your AI Gateway and firewall policies directly, including a forward-proxy mode and the ability to forward AI traces to a remote endpoint.</li>
<li class="">🆕 <strong>Guardrails with ML and regex scanning</strong> — AI Guardrails now scan both requests and responses using ML-based and regex-based detectors.</li>
<li class="">🆕 <strong>Guardrail violation alerting</strong> — End-to-end alerting fires when a guardrail is violated, surfaced in a new AI Guardrails alert screen in the dashboard.</li>
<li class="">🆕 <strong>MCP server scanning</strong> — New tooling to scan MCP servers for security issues, with discovered findings published back to the platform.</li>
<li class="">⚡ ML models for AI security can now be deployed with persistent storage for faster, more reliable startup.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-discovery">AI Discovery<a href="https://docs.levo.ai/changelog/january-2026#ai-discovery" class="hash-link" aria-label="Direct link to AI Discovery" title="Direct link to AI Discovery" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI traffic classification</strong> — Traffic is now tagged by module type (API, AI, MCP) so AI activity is identified and cataloged automatically.</li>
<li class="">🆕 <strong>AI PII discovery</strong> — Levo now detects and surfaces personally identifiable information flowing through your AI applications.</li>
<li class="">⚡ New observability receivers for Portkey AI Gateway, LiteLLM, and Agent Gateway broaden the AI sources Levo can ingest.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-scanning-dast">Web Application Scanning (DAST)<a href="https://docs.levo.ai/changelog/january-2026#web-application-scanning-dast" class="hash-link" aria-label="Direct link to Web Application Scanning (DAST)" title="Direct link to Web Application Scanning (DAST)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>DAST module (ShadowNet)</strong> — First release of Levo's web application scanning engine.</li>
<li class="">🆕 <strong>AI-driven and hybrid crawling</strong> — New crawler support including a crawl-only mode for mapping an application before scanning.</li>
<li class="">⚡ Scan results now include a findings summary and clearer scan logs.</li>
<li class="">⚡ Web app scan details can now ignore unknown items to reduce noise.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="external-attack-surface-management">External Attack Surface Management<a href="https://docs.levo.ai/changelog/january-2026#external-attack-surface-management" class="hash-link" aria-label="Direct link to External Attack Surface Management" title="Direct link to External Attack Surface Management" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>EASM product</strong> — A new capability to discover and scan your external, internet-facing API attack surface, with multiple scanner improvements in this first release.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-security-testing">API Security Testing<a href="https://docs.levo.ai/changelog/january-2026#api-security-testing" class="hash-link" aria-label="Direct link to API Security Testing" title="Direct link to API Security Testing" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Local File Inclusion (LFI) test</strong> — New test category to detect local file inclusion vulnerabilities.</li>
<li class="">🆕 <strong>Input Validation test category</strong> — New test category covering input validation weaknesses.</li>
<li class="">⚡ Filter test runs by the user who started them.</li>
<li class="">🐞 Authenticator logs now appear correctly in the UI, and unauthenticated endpoints now use the target URL from the manifest.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerabilities--findings">Vulnerabilities &amp; Findings<a href="https://docs.levo.ai/changelog/january-2026#vulnerabilities--findings" class="hash-link" aria-label="Direct link to Vulnerabilities &amp; Findings" title="Direct link to Vulnerabilities &amp; Findings" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Export findings to CSV and PDF</strong> — Export your findings for sharing and offline review.</li>
<li class="">⚡ Server-side sorting on the Findings screen for faster, more consistent results.</li>
<li class="">⚡ Vulnerability alignment in test runs and an improved diff view in the test-case log page.</li>
<li class="">🐞 Findings are now created even when the originating endpoint is no longer present.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensitive-data">Sensitive Data<a href="https://docs.levo.ai/changelog/january-2026#sensitive-data" class="hash-link" aria-label="Direct link to Sensitive Data" title="Direct link to Sensitive Data" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI prompt sensitive-data view</strong> — New screen to review sensitive data detected in AI prompts.</li>
<li class="">⚡ More filters and saved views in the sensitive data tab.</li>
<li class="">⚡ PII masking applied to trace collection shown on the dashboard.</li>
<li class="">🐞 Corrected PII endpoint filter behavior, including the "does not contain PII" and null-value cases.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="runtime-protection">Runtime Protection<a href="https://docs.levo.ai/changelog/january-2026#runtime-protection" class="hash-link" aria-label="Direct link to Runtime Protection" title="Direct link to Runtime Protection" translate="no">​</a></h2>
<ul>
<li class="">🆕 Threat feed and prompt sensitive-data permissions added for runtime protection.</li>
<li class="">⚡ Protection configuration moved into a dedicated API &amp; Web App Protection Rules section for easier management.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensors--deployment">Sensors &amp; Deployment<a href="https://docs.levo.ai/changelog/january-2026#sensors--deployment" class="hash-link" aria-label="Direct link to Sensors &amp; Deployment" title="Direct link to Sensors &amp; Deployment" translate="no">​</a></h2>
<ul>
<li class="">🆕 Java agent diagnostics script and Java 8 compatibility.</li>
<li class="">⚡ <strong>Traffic capture improvements</strong> — New trace collection strategy with support for masked traces.</li>
<li class="">⚡ PCAP sensor now parses form-urlencoded bodies wrapped in data URIs (RFC 2397).</li>
<li class="">🐞 PCAP sensor now handles self-signed certificates correctly.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="integrations">Integrations<a href="https://docs.levo.ai/changelog/january-2026#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>QRadar integration</strong> — Added to the integrations catalog for SIEM forwarding.</li>
<li class="">⚡ Refreshed integrations page with new connectors and clearer "new" indicators.</li>
<li class="">⚡ Documentation added for the Chrome extension, IDE plugin, and Jenkins.</li>
<li class="">🐞 Fixed Azure AD SSO user attribute mapping.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting--compliance">Reporting &amp; Compliance<a href="https://docs.levo.ai/changelog/january-2026#reporting--compliance" class="hash-link" aria-label="Direct link to Reporting &amp; Compliance" title="Direct link to Reporting &amp; Compliance" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Export findings to CSV / PDF</strong> — Generate findings reports in CSV and PDF formats from the dashboard.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="mcp-server">MCP Server<a href="https://docs.levo.ai/changelog/january-2026#mcp-server" class="hash-link" aria-label="Direct link to MCP Server" title="Direct link to MCP Server" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Dedicated MCP Server section</strong> — Levo's MCP Server now has its own navigation and page in the dashboard.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="platform-administration--access">Platform, Administration &amp; Access<a href="https://docs.levo.ai/changelog/january-2026#platform-administration--access" class="hash-link" aria-label="Direct link to Platform, Administration &amp; Access" title="Direct link to Platform, Administration &amp; Access" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Audit logs</strong> — End-to-end audit logging across the platform, with a dedicated UI, permissions, and broad endpoint coverage.</li>
<li class="">🆕 <strong>Keycloak authentication</strong> — Added Keycloak as a supported authentication provider.</li>
<li class="">🆕 <strong>Licensing visibility</strong> — Organizations now show their license expiry date, with new org licensing storage and retrieval.</li>
<li class="">⚡ <strong>Admin portal enhancements</strong> — Time-based sorting of organizations, multi-org workspace lookups, and clean organization deletion.</li>
<li class="">⚡ Dedicated pages for Satellites, Sensors, and Test runs, an auto-expandable menu, and grouped settings navigation.</li>
<li class="">⚡ Consistent application display names across all pages and clearer status-code and HTTP filtering.</li>
<li class="">⚡ Dashboard performance improvements across multiple screens.</li>
<li class="">🐞 Several dark mode fixes, including hard-refresh, test plans, and the org-selection screen.</li>
</ul>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="platform" term="platform"/>
        <category label="traffic-capture" term="traffic-capture"/>
        <category label="reporting" term="reporting"/>
        <category label="api-security" term="api-security"/>
        <category label="ai-security" term="ai-security"/>
        <category label="ai-governance" term="ai-governance"/>
        <category label="dast" term="dast"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Release Notes — Q4 2025]]></title>
        <id>https://docs.levo.ai/changelog/q4-2025</id>
        <link href="https://docs.levo.ai/changelog/q4-2025"/>
        <updated>2025-12-31T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Release period: October 1 – December 31, 2025]]></summary>
        <content type="html"><![CDATA[<p><em>Release period: October 1 – December 31, 2025</em></p>
<p>This release brings a refreshed dashboard experience, a completely rebuilt notification system, and the first wave of web application scanning and AI security capabilities. We also expanded API discovery, security testing, and administrative controls to make Levo easier to operate at enterprise scale.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="highlights">Highlights<a href="https://docs.levo.ai/changelog/q4-2025#highlights" class="hash-link" aria-label="Direct link to Highlights" title="Direct link to Highlights" translate="no">​</a></h2>
<ul>
<li class=""><strong>New Light/Dark theme</strong> across the entire dashboard, with smoother loading states and a polished interface.</li>
<li class=""><strong>Unified notifications</strong> — all alerts now flow through a single, more readable notification service, with richer Slack notifications and scheduled-report digests.</li>
<li class=""><strong>Web Application Scanning (early access)</strong> — a new dynamic scanning capability to test deployed web apps, available alongside API security testing.</li>
<li class=""><strong>AI visibility foundation</strong> — Levo now discovers and catalogs AI Models, AI Agents, and MCP servers and tools, with dedicated dashboard views and permissions.</li>
<li class=""><strong>Stronger vulnerability governance</strong> — mandatory closure comments, single-finding export with reproducible commands, and severity context on every alert.</li>
</ul>
<p><strong>What's new at a glance.</strong> This map shows where this quarter's additions fit across the Levo platform: from traffic capture, through Discover → Test &amp; Scan → Detect/Alert/Report, to the dashboard and your downstream tools. New or expanded areas are marked <strong>NEW</strong>.</p>
<p><img decoding="async" loading="lazy" alt="Q4 2025 — What&amp;#39;s new" src="https://docs.levo.ai/assets/images/2025-q4-whats-new-d18403516e35175f5bc3e61d75dd7ca1.png" width="2800" height="1800" class="img_ev3q"></p>
<p><em>Legend for the bullets below: 🆕 new · ⚡ enhancement · 🐞 fix</em></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-discovery--cataloging">API Discovery &amp; Cataloging<a href="https://docs.levo.ai/changelog/q4-2025#api-discovery--cataloging" class="hash-link" aria-label="Direct link to API Discovery &amp; Cataloging" title="Direct link to API Discovery &amp; Cataloging" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Postman collection import</strong> — bring API definitions into Levo directly from Postman collections, including adding endpoints to existing applications and converting collections to OpenAPI. Large collections (up to 50 MB) are supported.</li>
<li class="">🆕 <strong>Source type visibility</strong> — endpoints now show where they were observed from, so you can distinguish traffic-discovered, imported, and other sources at a glance.</li>
<li class="">🆕 <strong>Diversity-based clustering</strong> — an improved discovery option that produces cleaner, more representative API catalogs.</li>
<li class="">⚡ Larger OpenAPI specifications (over 4 MB) can now be uploaded and exported reliably.</li>
<li class="">⚡ Application and endpoint catalogs now always reflect the latest observed traffic on refresh.</li>
<li class="">⚡ Added a default saved filter to hide noisy <code>OPTIONS</code> and <code>HEAD</code> endpoints, plus filtering by query or path parameters.</li>
<li class="">⚡ Bulk tag updates are now supported when application or method details change.</li>
<li class="">⚡ OpenAPI specifications can be cleaned automatically to remove invalid parameters.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-security-testing">API Security Testing<a href="https://docs.levo.ai/changelog/q4-2025#api-security-testing" class="hash-link" aria-label="Direct link to API Security Testing" title="Direct link to API Security Testing" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Mass Assignment test category</strong> — added to Levo's security test suite to catch a common and high-impact API vulnerability class.</li>
<li class="">🆕 <strong>Multi-user testing</strong> — run security tests across multiple user identities to validate authorization behavior.</li>
<li class="">🆕 <strong>Test plan hooks</strong> — inject parameters and authenticated calls into test plans for more accurate, real-world test execution.</li>
<li class="">🆕 <strong>Remote test runs from the CLI</strong> — launch a test run remotely, with Jenkins integration support.</li>
<li class="">⚡ Test runs now clearly indicate their trigger method (on-premises vs. cloud) and link back to the schedule that started them.</li>
<li class="">⚡ Introduced test runner groups for organizing and targeting runners.</li>
<li class="">⚡ Custom schedules can now be created for tracers and scheduled test runs, with the ability to enable or disable individual schedules.</li>
<li class="">⚡ Added the ability to run tests directly from selected traces, including replaying traces to a hosted target.</li>
<li class="">⚡ Reports can now show or download skipped-endpoint details for a test run.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-scanning-early-access">Web Application Scanning (Early Access)<a href="https://docs.levo.ai/changelog/q4-2025#web-application-scanning-early-access" class="hash-link" aria-label="Direct link to Web Application Scanning (Early Access)" title="Direct link to Web Application Scanning (Early Access)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Web App Scan</strong> — a new dynamic application scanning capability (powered by Levo's ShadowNet engine) to test running web applications, with GraphQL support, domain exclusions, and scan logging.</li>
<li class="">⚡ Web App Scan now supports multitenant satellite deployments and reports scan status and logs back to the dashboard.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="ai-security-foundation">AI Security (Foundation)<a href="https://docs.levo.ai/changelog/q4-2025#ai-security-foundation" class="hash-link" aria-label="Direct link to AI Security (Foundation)" title="Direct link to AI Security (Foundation)" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>AI asset discovery</strong> — Levo now discovers and catalogs AI Models and AI Agents, with create/read/update/delete management and dedicated dashboard visibility.</li>
<li class="">🆕 <strong>MCP server and tool cataloging</strong> — import, index, and manage MCP (Model Context Protocol) servers and tools, with environment-aware imports.</li>
<li class="">🆕 <strong>AI permissions and roles</strong> — a new AI section in the navigation with dedicated access controls.</li>
<li class="">⚡ Added a new API type to capture and classify AI spans in discovery.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerabilities--findings">Vulnerabilities &amp; Findings<a href="https://docs.levo.ai/changelog/q4-2025#vulnerabilities--findings" class="hash-link" aria-label="Direct link to Vulnerabilities &amp; Findings" title="Direct link to Vulnerabilities &amp; Findings" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Single-vulnerability export with reproducible commands</strong> — export an individual finding along with the commands needed to reproduce it.</li>
<li class="">🆕 <strong>Bulk actions</strong> on the vulnerabilities pages for faster triage.</li>
<li class="">🆕 <strong>Mandatory closure comments</strong> — closing a vulnerability manually now requires a comment (minimum 80 characters) to preserve an audit trail.</li>
<li class="">⚡ Added more filter conditions, including by endpoint method, on the vulnerabilities screen.</li>
<li class="">⚡ Export endpoints and vulnerabilities to PDF and CSV, with filters.</li>
<li class="">🐞 Resolved an issue where deleting a single finding removed all findings.</li>
<li class="">🐞 Fixed missing Jira ticket URLs in findings after ticket creation.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensitive-data">Sensitive Data<a href="https://docs.levo.ai/changelog/q4-2025#sensitive-data" class="hash-link" aria-label="Direct link to Sensitive Data" title="Direct link to Sensitive Data" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Category-level sensitive data export</strong> — export sensitive data for selected categories, and generate per-application PII reports in PDF or CSV.</li>
<li class="">🆕 <strong>Application-level data exposure view</strong> — see the top users with data at the application level.</li>
<li class="">🐞 Corrected duplicate endpoint entries that appeared for each sensitive data type in the endpoint list.</li>
<li class="">🐞 Fixed endpoint counts that changed between pages in the sensitive data views.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="reporting--notifications">Reporting &amp; Notifications<a href="https://docs.levo.ai/changelog/q4-2025#reporting--notifications" class="hash-link" aria-label="Direct link to Reporting &amp; Notifications" title="Direct link to Reporting &amp; Notifications" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Unified notification service</strong> — all notifications were consolidated into a single service for consistency and reliability.</li>
<li class="">🆕 <strong>Digest reports</strong> — added scheduled digest report building and delivery, including API changelog digests.</li>
<li class="">🆕 <strong>Endpoints/Vulnerabilities PDF export</strong> with copilot comments.</li>
<li class="">⚡ Vulnerability and changelog notifications are now more readable and include severity and direct links to the affected item.</li>
<li class="">⚡ Slack notifications were improved, including authenticated/external status on endpoint alerts.</li>
<li class="">⚡ Digest report timestamps now include the time of generation.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="sensors--deployment">Sensors &amp; Deployment<a href="https://docs.levo.ai/changelog/q4-2025#sensors--deployment" class="hash-link" aria-label="Direct link to Sensors &amp; Deployment" title="Direct link to Sensors &amp; Deployment" translate="no">​</a></h2>
<ul>
<li class="">⚡ <strong>Broader traffic capture</strong> — the eBPF sensor now supports capturing GnuTLS-based API traffic.</li>
<li class="">⚡ Sensor status now reflects recent activity windows (last 10 minutes / 24 hours / last activity) for clearer health visibility.</li>
<li class="">⚡ Improved reliability of sensor and satellite metrics reporting, and ordering of sensors and satellites in the Deployments view.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="integrations">Integrations<a href="https://docs.levo.ai/changelog/q4-2025#integrations" class="hash-link" aria-label="Direct link to Integrations" title="Direct link to Integrations" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Azure AD SSO support</strong> — sign in with Azure Active Directory.</li>
<li class="">🆕 <strong>Checkmarx integration improvements</strong> — auto-refresh for Checkmarx apps, scheduling fixes, and UI improvements.</li>
<li class="">⚡ Descope SSO configuration errors are now handled gracefully with improved error logging.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="platform-administration--access">Platform, Administration &amp; Access<a href="https://docs.levo.ai/changelog/q4-2025#platform-administration--access" class="hash-link" aria-label="Direct link to Platform, Administration &amp; Access" title="Direct link to Platform, Administration &amp; Access" translate="no">​</a></h2>
<ul>
<li class="">🆕 <strong>Light/Dark theme switch</strong> across the dashboard.</li>
<li class="">🆕 <strong>Organization ownership controls</strong> — transfer or change the organization owner, and delete an organization completely from the admin portal.</li>
<li class="">🆕 <strong>Role enable/disable controls</strong> at the organization level.</li>
<li class="">⚡ Completed the end-to-end user onboarding flow for adding users to an organization, with case-insensitive email handling.</li>
<li class="">⚡ Added the ability to verify unverified users from the admin portal.</li>
<li class="">⚡ Applications can now be marked as external or internal.</li>
<li class="">⚡ Added skeleton loaders and refined styling for a smoother dashboard experience.</li>
<li class="">🐞 Resolved an issue that prevented deleting invited users.</li>
<li class="">🐞 Fixed user authenticator credential inputs to trim stray whitespace from keys and values.</li>
</ul>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="platform" term="platform"/>
        <category label="traffic-capture" term="traffic-capture"/>
        <category label="reporting" term="reporting"/>
        <category label="api-security" term="api-security"/>
        <category label="ai-security" term="ai-security"/>
        <category label="dast" term="dast"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Release Notes — September 2025]]></title>
        <id>https://docs.levo.ai/changelog/september-2025</id>
        <link href="https://docs.levo.ai/changelog/september-2025"/>
        <updated>2025-09-30T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Levo.ai API Security Platform Updates ✨]]></summary>
        <content type="html"><![CDATA[<p><strong>Levo.ai API Security Platform Updates</strong> ✨</p>
<p>The Levo team is excited to bring you powerful features to secure your entire API ecosystem more efficiently!</p>
<p>💻 <strong>Levo's MCP Server</strong> exposes structured, real-time, and governed access to your security intelligence — enabling agents and humans to act without relying on dashboards, tickets, or tribal knowledge. Accelerate velocity, security coverage, and AI-assisted workflows without consuming more of the already scarce developer and security bandwidth.</p>
<p><img decoding="async" loading="lazy" alt="Levo MCP Server" src="https://docs.levo.ai/assets/images/2025-09-mcp-server-e99253ce230302eeb7b0302e175ef058.png" width="2696" height="1396" class="img_ev3q"></p>
<p>📑 <strong>Levo's API Inventory Portal</strong> is now enhanced to be a cloud-hosted, authenticated hub that transforms API management into a collaborative, dynamic process. Hosted on Levo's secure cloud, this portal eliminates silos, providing a single source of truth for API catalogs, sensitive data flows, and trace-linked payloads.</p>
<p>⛔️ <strong>Levo's new detection, protection, and blocking module</strong> has been rolled out. At its core, the new module transforms Levo's passive monitoring into a proactive, inline protection system. This means traffic can be received directly from end users, inspected for threats, and blocked in real-time if necessary — supporting IP blocking and rate limiting.</p>
<p>📣 <strong>Stay tuned!</strong> We're continuously enhancing API security and simplifying workflows. More exciting updates are on the way!</p>]]></content>
        <author>
            <name>Levo Team</name>
            <uri>https://www.levo.ai</uri>
        </author>
        <category label="release-notes" term="release-notes"/>
        <category label="mcp" term="mcp"/>
        <category label="api-inventory" term="api-inventory"/>
        <category label="protection" term="protection"/>
    </entry>
</feed>