Skip to main content
CHANGELOG

What's New

May 2026In development

Mendicant AI — built into every tool

The Mendicant AI analyst is now embedded across all eleven Sandworm tools. It explains alerts, drafts queries, summarizes investigations, and recommends response actions — grounded in each tool's real data, with evidence cited inline. Running on frontier models today; a sovereign, precision-AI engine purpose-built for security is in development.

May – Jun 2026In development

Enterprise-depth upgrade across all eleven tools

Every Sandworm tool was brought to a common enterprise depth: organized navigation, richer dashboards with charts and drill-downs, expanded Settings, and in-product Help. The upgrade surfaced substantially more real capability across detection, response, cloud security, network, endpoint, identity, supply-chain, AI security, threat intelligence, and SOAR. All eleven tools ship as native desktop applications for Windows, macOS, and Linux.

May 2026In development

300+ connector fabric

A connector fabric spanning 300+ vendors across 23 services, with every event normalized to OCSF 1.3. Each connector catalog entry is Ed25519-signed so you can verify the exact version of every integration your deployment is running.

May 2026In development

Autonomous alert triage

An autonomous triage analyst that works alerts from every product using bounded AI tool-loops. Evidence citation is mandatory — the analyst cannot close an alert without linking the specific findings that support its verdict. Triage decisions are captured in signed monthly attestations. Opt-in auto-close is gated behind hard safety rules and a tunable confidence threshold you control.

May 2026In development

Multi-region federation and federated intelligence

Region-pinned tenancy in US-East and EU-West, with federated threat intelligence and federated user-behavior baselines that pool signal across fleets under a formally validated differential-privacy guarantee. No raw customer data leaves its assigned region.

v1.0.0Coming Q4 2026

Initial Release

The first public release of the Sandworm Security platform — eleven security tools plus the unified portal and the Mendicant AI analyst. Desktop applications for Windows, macOS, and Linux.