March 18, 2026
Security hardening & platform improvements
- SQL injection fixes across GCP provider and reporting service
- 2FA rate limiting and backup code race condition fixes
- TOTP setup flow for mandatory 2FA organizations
- Account lockout after failed login attempts
- Refresh token IP binding
- Invitation token hashing
- CSV formula injection prevention
- Network policy enforcement in Kubernetes
- Pod security contexts across all deployments