{"version":"https://jsonfeed.org/version/1.1","title":"Driftlock Changelog","home_page_url":"https://tideline-5xcqop.polsia.app/changelog","feed_url":"https://tideline-5xcqop.polsia.app/changelog.json","items":[{"id":"launch-changelog-2026-08-03","date":"2026-08-03","updatedAt":"2026-08-03T00:00:00Z","title":"Public changelog is live","body":"Every Monday this page picks up a new Driftlock engineering update — what shipped, what changed, what we paused — with a deep link back to the source commit, doc, or architecture diagram. Each entry is reverse-chronological and permalinkable so a trial cohort can drop the link straight into Slack, and the title itself is the link to the live surface it describes.","href":"/changelog","url":"https://tideline-5xcqop.polsia.app/changelog","surface":"meta","tags":["meta"]},{"id":"pricing-roi-table-2026-07-27","date":"2026-07-27","updatedAt":"2026-07-27T00:00:00Z","title":"Pricing ROI table — what manual overnight triage actually costs in labour","body":"The pricing page now ships a side-by-side labour table that puts a real cost against the overnight Dependabot, RustSec, and TypeScript advisory diffs a regulated monorepo absorbs in a quarter. Each row has a stated unit — staff-engineer hours, SBOM re-emissions, audit-trail fields stitched by hand — so a platform-security lead reading the page alongside a finance buyer lands on the same number, not a marketing estimate.","href":"/pricing#cost-comparison","url":"https://tideline-5xcqop.polsia.app/pricing#cost-comparison","surface":"pricing","tags":["pricing"]},{"id":"vs-pages-cursor-claude-bots-2026-07-20","date":"2026-07-20","updatedAt":"2026-07-20T00:00:00Z","title":"Comparison pages for Cursor, Claude Code, and internal bot frameworks","body":"Three new comparison pages landed this week — /vs/cursor, /vs/claude-code, and /vs/internal-bot-frameworks — each running the same six-row ask a regulated platform lead opens an evaluation with: where the audit-trail row lives, who holds the signing key, whether the SBOM survives a key rotation, and which sign off on the overnight diff. The Cursor and Claude Code pages name the in-IDE pattern directly; the internal-bot-framework page is for the team running their own OpenHands-style runner in a VPC and wondering where the gap shows up in a SOC 2 evidence pack.","href":"/vs/cursor","url":"https://tideline-5xcqop.polsia.app/vs/cursor","surface":"comparisons","tags":["comparisons"]},{"id":"governance-expanded-2026-07-13","date":"2026-07-13","updatedAt":"2026-07-13T00:00:00Z","title":"Audit-trail / RBAC / SBOM / signing reference expanded on /governance","body":"The /governance explainer now walks the seven-column audit-trail row end to end and adds a row-by-row owner column — the watcher, the sandbox, the signing controller, and the SBOM signer each have a single column and a single retention tier. RBAC, SBOM, and signing references sit in the same table, in the vocabulary a SOC 2 / PCI reviewer actually reads, so a regulator replays the page the same way the platform team replays a PR.","href":"/governance","url":"https://tideline-5xcqop.polsia.app/governance","surface":"governance","tags":["governance","security"]},{"id":"self-host-runbook-2026-07-06","date":"2026-07-06","updatedAt":"2026-07-06T00:00:00Z","title":"Self-host runbook published","body":"A self-host runbook now lives at /docs/self-host: the Helm + Terraform deployment, the egress policy that keeps the sandbox reachable only to the customer artifact registry and the customer KMS, the Rekor claim payload the signing controller writes, and the customer KMS-resident cosign key onboarding on day one. The runbook is the same shape the trial cohort walks during a ten-day scoped engagement, so a buyer can read it before the call and start the deployment from the same page.","href":"/docs/self-host","url":"https://tideline-5xcqop.polsia.app/docs/self-host","surface":"docs","tags":["docs","self-host"]},{"id":"sandbox-config-reference-2026-06-29","date":"2026-06-29","updatedAt":"2026-06-29T00:00:00Z","title":"Sandbox configuration reference at /docs/sandbox-config","body":"A new /docs/sandbox-config page enumerates every knob the Driftlock sandbox exposes — the hermetic-build hash, the bounded VPC egress, the Bazel cache mount, and the toolchain identity — and maps each one to the audit-trail column it feeds and the SBOM field it signs. The page is the reference a platform-security lead reads once and then keeps open during a SOC 2 walk-through.","href":"/docs/sandbox-config","url":"https://tideline-5xcqop.polsia.app/docs/sandbox-config","surface":"docs","tags":["docs","monorepo"]},{"id":"webhook-payload-schemas-2026-06-22","date":"2026-06-22","updatedAt":"2026-06-22T00:00:00Z","title":"Webhook payload schemas published at /docs/webhooks","body":"The webhook payload schema pages now publish per-source shapes — Dependabot, RustSec, OSV / GHSA, and the on-call pager integration — with the exact JSON the watcher expects on each delivery and the audit-trail column the watcher writes back. A platform team wiring Driftlock into an existing PagerDuty webhook reads the schema off the same page the regulator replays the row from.","href":"/docs/webhooks","url":"https://tideline-5xcqop.polsia.app/docs/webhooks","surface":"docs","tags":["docs","integrations"]},{"id":"carebridge-health-customer-story-2026-06-15","date":"2026-06-15","updatedAt":"2026-06-15T00:00:00Z","title":"Healthcare seed customer story — CareBridge Health","body":"A third seed customer story landed this week, written in the same posture as the regulated fintech narratives on /customers. CareBridge Health runs a TypeScript and Go monorepo through a single protected main branch and a single GitHub App identity, and the per-PR audit row the page describes is the row a HIPAA-leaning auditor replays against the run id — including a sandbox test result, an approver chain, and a cosign signature over the SBOM hash.","href":"/customers/carebridge-health","url":"https://tideline-5xcqop.polsia.app/customers/carebridge-health","surface":"customers","tags":["customers","healthcare"]},{"id":"architecture-signing-section-2026-05-25","date":"2026-05-25","updatedAt":"2026-05-25T00:00:00Z","title":"Architecture page exposes the signing section in full","body":"The architecture page now breaks out the signing controller as its own labelled section — the cosign key it expects on the customer KMS, the Rekor claim payload it posts on every merged PR, and the verification command a security reviewer runs on the SBOM hash. The section sits next to the sandbox and triage diagrams so a platform-security lead reading top-to-bottom sees the custody chain end to end.","href":"/architecture#architecture-signing","url":"https://tideline-5xcqop.polsia.app/architecture#architecture-signing","surface":"architecture","tags":["architecture"]},{"id":"security-data-handling-rows-2026-05-18","date":"2026-05-18","updatedAt":"2026-05-18T00:00:00Z","title":"Custody and retention rows land on /security","body":"The /security data-handling section now ships two new rows: the per-tenant custody boundary (sandbox egress reaches only the customer artifact registry and the customer KMS) and the retention tier (180 days hot, 7 years cold, signed-verifiable on read). Both rows map to the same vocabulary the /docs/compliance reference uses, so a SOC 2 reviewer reading the narrative and the regulator reading the reference land on identical text.","href":"/security#data-handling","url":"https://tideline-5xcqop.polsia.app/security#data-handling","surface":"security","tags":["security"]},{"id":"acme-platform-customer-story-2026-05-11","date":"2026-05-11","updatedAt":"2026-05-11T00:00:00Z","title":"Acme Platform customer story published","body":"A new customer story shipped at /customers/acme-platform — the first Series-B fintech narrative in the seed set, covering the migration off an in-house Renovate runner, the per-PR audit trail the SOC 2 evidence pack stitches against, and the SBOM re-emission cost the new nightly desk replaces. The page reads in the same posture as the rest of the customer voices — audit-linked, permalinkable, and written for a regulated platform-security lead skimming it the night before a procurement call.","href":"/customers/acme-platform","url":"https://tideline-5xcqop.polsia.app/customers/acme-platform","surface":"customers","tags":["customers"]},{"id":"install-page-helm-2026-05-04","date":"2026-05-04","updatedAt":"2026-05-04T00:00:00Z","title":"/docs/install page published with the Helm chart","body":"The /docs/install page is now the home of the Driftlock Helm chart, the values.yaml knobs the platform team overrides on day one (image pull policy, registry mirror, customer KMS endpoint, egress firewall), and the smoke-test pipeline that runs after the chart apply. It sits beside the self-host runbook so the deploy-and-onboard path is one bookmark chain.","href":"/docs/install","url":"https://tideline-5xcqop.polsia.app/docs/install","surface":"docs","tags":["docs"]},{"id":"compliance-audit-immutability-2026-04-27","date":"2026-04-27","updatedAt":"2026-04-27T00:00:00Z","title":"Audit-trail immutability row added to the compliance deep-dive","body":"The /docs/compliance reference now publishes the audit-trail immutability row directly under the merge-audit-trail section: rows are written once, signed once, and append-only — there is no UPDATE or DELETE path any Driftlock component exposes. The same row ships alongside the SOC 2 controls table so a compliance reviewer cross-references the two on the same call.","href":"/docs/compliance#audit-immutability","url":"https://tideline-5xcqop.polsia.app/docs/compliance#audit-immutability","surface":"security","tags":["security","compliance"]},{"id":"compliance-reference-page-2026-04-20","date":"2026-04-20","updatedAt":"2026-04-20T00:00:00Z","title":"/docs/compliance reference published","body":"A new /docs/compliance reference page replaces the regulatory-as-marketing slide deck with the four-section record a platform-security lead actually replays against: the RBAC matrix with config snippet, the seven-column audit-trail row, the SPDX document per merged PR, and the four cosign verifier commands. The page lives at its own path so the /security narrative and the regulator-facing record stay independent.","href":"/docs/compliance","url":"https://tideline-5xcqop.polsia.app/docs/compliance","surface":"docs","tags":["docs","compliance"]},{"id":"compliance-soc2-controls-2026-04-13","date":"2026-04-13","updatedAt":"2026-04-13T00:00:00Z","title":"SOC 2 controls table added to the compliance reference","body":"The /docs/compliance reference now carries a SOC 2 controls table that maps each Common Criterion (CC1–CC9) to the Driftlock component responsible and the audit-trail column a reviewer replays on. The same table underpins the SOC 2 evidence pack the platform-security lead downloads under NDA, so the public reference reads in the same vocabulary as the pack itself.","href":"/docs/compliance#soc2-controls","url":"https://tideline-5xcqop.polsia.app/docs/compliance#soc2-controls","surface":"docs","tags":["docs","soc2"]},{"id":"architecture-triage-column-2026-04-06","date":"2026-04-06","updatedAt":"2026-04-06T00:00:00Z","title":"Architecture triage column published","body":"The architect triage path is now its own labelled section on /architecture: how the system clock-locks a Dependabot advisory against the running repo, how the triage pass assigns confidence and severity, and how the rejected diff is bubbled into the audit-trail column rather than dropped. The section closes the gap between the watcher fan-in and the eventual sandbox run.","href":"/architecture#architecture-triage","url":"https://tideline-5xcqop.polsia.app/architecture#architecture-triage","surface":"architecture","tags":["architecture"]},{"id":"verification-commands-2026-03-30","date":"2026-03-30","updatedAt":"2026-03-30T00:00:00Z","title":"Cosign verification commands published in the compliance reference","body":"The four cosign verification commands a security reviewer runs against an SBOM hash are now published at /docs/compliance, with the Rekor log URL, the cert subject expectation, and the failure modes a reviewer should expect to see. Each command prints the same line a SOC 2 reviewer reads out of the evidence pack, so an audit-team replay matches a live PR replay.","href":"/docs/compliance#verification-commands","url":"https://tideline-5xcqop.polsia.app/docs/compliance#verification-commands","surface":"security","tags":["security","compliance"]},{"id":"quickstart-page-2026-03-23","date":"2026-03-23","updatedAt":"2026-03-23T00:00:00Z","title":"Quickstart page published","body":"The Driftlock quickstart page is now live at /docs/quickstart — the ten-minute path from a sandbox GitHub App install to the first signed PR delivered against an open Dependabot advisory. The page is the front door the trial cohort enters from after the procurement call: same vocabulary as /docs/install, same audit-trail shape as /docs/compliance, but no prerequisite reading.","href":"/docs/quickstart","url":"https://tideline-5xcqop.polsia.app/docs/quickstart","surface":"docs","tags":["docs"]},{"id":"architecture-audit-write-2026-03-16","date":"2026-03-16","updatedAt":"2026-03-16T00:00:00Z","title":"Audit-write step in the architecture pipeline","body":"The /architecture pipeline now shows the audit-write step in full — what columns receive a write, what hash the row is signed under, and what Rekor claim payload the signing controller posts. The step sits between the sandbox run and the SBOM emit so a reader following the diagram top-down sees the custody path complete before the diff is presented for human review.","href":"/architecture#pipeline-audit-write","url":"https://tideline-5xcqop.polsia.app/architecture#pipeline-audit-write","surface":"governance","tags":["architecture","governance"]},{"id":"governance-page-published-2026-03-09","date":"2026-03-09","updatedAt":"2026-03-09T00:00:00Z","title":"/governance audit-trail explainer published","body":"A new /governance explainer page is live — the seven-column audit-trail row, the four owners (watcher / sandbox / signing / SBOM), and the two reference pages (/security and /docs/compliance) it sits between. The page reads in the vocabulary a SOC 2 / PCI reviewer scans first, so the regulator audience lands on a familiar frame rather than a marketing one.","href":"/governance","url":"https://tideline-5xcqop.polsia.app/governance","surface":"governance","tags":["governance"]},{"id":"v0-3-launch-2026-03-02","date":"2026-03-02","updatedAt":"2026-03-02T00:00:00Z","title":"Driftlock v0.3 — the dependency desk goes live","body":"Driftlock v0.3 ships this week — the first self-hosted nightly desk a regulated monorepo can run for an open Dependabot advisory stream, end to end, with one human approver at the end of the pipeline. The launch lands on /get-started and is described in the same posture as the rest of the seed set: audit-linked, permalinkable, and built for a trial cohort evaluating the audit-trail bar Driftlock sets.","href":"/get-started","url":"https://tideline-5xcqop.polsia.app/get-started","surface":"meta","tags":["meta","launch"]}]}