July 28 customer-ready lab validation release
Start with the full note if you need shipped details, or jump to the roadmap and wishlist if you are comparing what to do next.
I want the release list
Go back to the index if you need to compare versions or pick another note.
I want the roadmap
Open the roadmap when the question is direction rather than a specific release.
I want to request something
Send a wishlist item if this release page surfaced a gap you want prioritized.
I want the current note
Jump to the release body and read the shipped change in full.
Release notes
Product notice
Sotiras is preparing a controlled, operator-assisted customer-ready lab validation release for July 28, 2026. This release focuses on customer-readable proof: live evidence, reviewed AI output, governed action, known limitations, support ownership, realistic Collector Lab/ProtectTheBox validation, and clear next steps.
This is not a self-service offensive-testing launch, a fully autonomous security operations center, or a mature breach-detection claim. Collector Lab, ProtectTheBox, and authorized penetration-test planning are customer-ready only as controlled, operator-assisted validation until their authorization, safety checks, results, rollback, and support runbooks are complete.
What's new
Customer-release proof packet
The reports workspace now leads the release packet from /portal/reports#customer-release-proof. The packet separates real Sotiras platform proof, real production customer proof, Collector Lab and ProtectTheBox validation, clean-host breach-progression learning, and fixture/demo fallback, so you can tell which evidence is live and which is illustrative.
July 28 lab validation readiness
Reports now include a readiness section for ProtectTheBox and Collector Lab that shows, in plain terms, whether each validation scenario has been authorized, safety-checked, run, and is ready for a rollback if something goes wrong. Nothing in this area is presented as available until that readiness check is complete.
Sotiras protects its own platform
Sotiras runs its own production environment on Sotiras. That means the evidence quality, AI review, action governance, source health, and reporting you see in the product are proven against a real environment we operate every day, not only against demo data.
Real customer proof
Beyond our own platform, an early production customer's live telemetry is used to prove the same evidence-to-action workflow end to end: current source evidence, AI review, recommended action, outcome proof, and customer-readable reporting.
Collector maturity levels
Collectors are now classified by how thoroughly they've been proven: proven on a real customer, proven on the Sotiras platform, qualified in the Collector Lab, qualified in ProtectTheBox, Preview/support-assisted, or not yet supported. This keeps the release honest about which collector families are fully proven versus still maturing.
Cleaner action tracking
Failed enforcement attempts and anything that blocks your visibility after an action are now always raised as a review alert. Expired temporary bans and actions that completed successfully move into Actions Taken or the audit trail instead of sitting in your Action Needed queue.
AI review governance
AI review behavior now follows a documented, versioned protocol: results are reviewed before they're acted on, model routing and consent settings are explicit, and sensitive data handling follows your redaction policy. AI can keep improving its analysis over time, but changes to what data it uses or what it's allowed to do on its own still ship as a normal product release, not a silent AI update.
Release and support status
This first customer release is Stable, operator-assisted: every capability's support status, escalation path, review cadence, and upgrade path is documented. Long-term-support guarantees are not promised yet — that follows once migration and end-of-life tooling is in place.
Known limitations
- No fully autonomous response promise.
- No self-service attack testing.
- No zero-day protection claim.
- No install-once-never-upgrade promise.
- No AI replacement for product releases.
- No mature breach-detection claim without observe-only progression, containment, recovery, and reviewed AI label evidence.