Changelog

New features, improvements, and fixes across the Odin security platform.

July 2026

Real-time attack surface, Slack assignments & live findings

Real-time attack surface insights, live findings during scans, Slack finding assignment, Azure DevOps workload identity federation, Auto Deposit improvements, and better integration error handling.

New

See attack surface in real time

Attack-surface recon in Mjolnir now shows endpoints with auth, observed status codes, and coverage state, plus a tech fingerprint and defence profile panel.

Workload identity federation for Azure DevOps

Azure DevOps service principal onboarding now includes the workload identity federation setup required to connect the integration.

Assign findings from Slack

The @Odin agent in Slack can now be used to assign findings to team members. Make sure to map your team in integrations to be able to assign to the right members.

Target-balance model for Auto Deposit

Auto Deposit now uses a target-balance model.

Improved

  • Streamed findings: findings now stream into Mjolnir runs while they are still in progress, instead of appearing only after the run ends.
  • Feedback for failing integrations: integration sync failures for a retired Linear team now show an error state and alert the team.

Assign findings, follow the updates that matter, and PR reviews that close the loop

Assign findings to your team and keep them in sync with your issue tracker, follow the findings you care about for tighter notifications, and let PR reviews update finding status automatically. Plus a snappier interface and a handful of fixes.

New

Assign findings to your team

Assign any finding to a teammate so it's always clear who owns the fix. Map your Odin users to your issue tracker's users once, and assignments stay in sync both ways with Linear, Jira, GitLab, GitHub, and Shortcut. (available to teams using issue-tracker sync)

Follow findings and get the updates that matter

Follow a finding to be notified about its status changes, comments, and mentions, and unfollow anything you'd rather tune out. Related updates are now grouped into a single notification instead of a flood, and your organisation can choose who's subscribed to new findings by default.

PR reviews connected to findings

When a pull request is reviewed, its findings now link back to the review and update on their own. They move to resolved when a fix lands and reopen if a regression shows up.

Tax details at checkout

Checkout now collects the billing address and VAT/tax ID needed for compliant invoicing, with tax calculated automatically. (for teams on business plans)

Improved

  • Snappier interface: the command palette, tables and tooltips respond faster, with lighter animation on the surfaces you use most.
  • Reduced-motion support: Odin now respects your system "reduce motion" preference and eases off animations accordingly.
  • Consistent run-page labels: the phases shown on the run page now match what's actually happening behind the scenes and in the event feed.
  • Clearer activity history: finding status changes made by connected systems, not just people, is now clearly attributed in the activity timeline.

Fixed

  • Deleting your profile picture works again.
  • The attack-surface map now shows the correct parent and child relationships between subdomains.
  • Applied a security update to address a known advisory in a third-party dependency.

Single sign-on, plus attack-surface and findings improvements

This release adds single sign-on to Business and Enterprise plans, plus Azure DevOps PR review configuration. We've also sharpened the attack-surface map, added manual PR linking to findings, included finding identifiers in synced titles, and fixed several display issues across the product.

New

Single sign-on (SSO)

Set up SSO for your organisation with verified domains and connections, then let your team sign in through your own identity provider. (available on Business and Enterprise plans)

Azure DevOps PR reviews

You can now configure PR reviews for Azure DevOps, with reviews dispatched automatically via webhooks when pull requests are opened. (for teams using PR reviews)

Improved

  • Sharper attack-surface map: the map now follows the underlying graph layout more closely for a clearer view of your attack surface.
  • Manual PR linking: you can now link a pull request to a finding directly from the UI, and the search now includes older pull requests when you do.
  • Finding identifiers in synced titles: findings synced to your issue tracker now include the finding identifier in the title, so they're easier to match up.
  • Easier changelog access: the changelog is simpler to find once you're signed in.

Fixed

  • Findings now show counts for the selected pentest rather than org-wide totals.
  • Finding activity now renders as Markdown with clearer spacing.
  • IP asset rows and the attack-surface map now show open ports.

Shortcut sync and Azure DevOps support

This release adds Shortcut as a two-way issue-tracker integration and brings Azure DevOps support to whitebox pentests and PR reviews. Findings exports now include linked issue references, integration health is more reliable, and escaped markup no longer leaks into finding text.

New

Shortcut integration

Connect Shortcut as an issue tracker and keep findings in sync both ways. Findings are created as Shortcut stories when reported, and their workflow state stays in sync as the finding progresses.

Azure DevOps support

You can now connect Azure Repos to run whitebox pentests against Azure DevOps repositories, and Azure DevOps pull requests are supported for PR reviews, including review comments, status updates, and ongoing review summaries. (for teams using pentests and PR reviews)

Improved

  • Linked issue references in exports: findings exports now include references to their connected tracker items across every format, so that you can trace a finding back to its issue.
  • More reliable integrations: Jira and Linear connections no longer show an expired token as healthy and refresh more reliably.
  • Asset notes stay in sync: notes managed in our operations tooling now sync through to the asset in Odin.

Fixed

  • Escaped Markdown and HTML sequences no longer leak into rendered finding text.

June 2026

Welcome to the Odin changelog

Welcome to the Odin changelog. This release adds in-app feedback. Submit ideas, attach files, and read our replies without leaving Odin. Plus richer findings exports, faster triage with the agent confirmation type, clearer PR reviews, and smoother onboarding.

Welcome to the Odin changelog, where we'll post what's new, improved, and fixed. You can filter by tag or search past updates to find what's relevant to you.

Here's what's new in this release.

New

Send feedback without leaving Odin

A dedicated feedback space lets you submit ideas and issues, attach files, follow the status of everything you've sent, and read replies from our team, all in the app.

Improved

  • Richer findings exports: more bulk export options and more consistent output across formats.
  • Faster triage: the findings page now surfaces the agent confirmation type, so you can prioritise at a glance.
  • Clearer PR reviews: correlated findings are now split into distinct "addressed finding" and "regression risk" sections, and you can configure PR review yourself. (for teams with PR reviews enabled)
  • Smoother onboarding: clearer owner setup and domain-join settings, plus easier access to legal documents during sign-up.
  • Expanded help docs covering current product flows, keyboard shortcuts, feedback, and API access.