Changelog

New features, improvements, and fixes across the Odin security platform.

July 2026

Assign findings, follow the updates that matter, and PR reviews that close the loop

Assign findings to your team and keep them in sync with your issue tracker, follow the findings you care about for tighter notifications, and let PR reviews update finding status automatically. Plus a snappier interface and a handful of fixes.

New

Assign findings to your team

Assign any finding to a teammate so it's always clear who owns the fix. Map your Odin users to your issue tracker's users once, and assignments stay in sync both ways with Linear, Jira, GitLab, GitHub, and Shortcut. (available to teams using issue-tracker sync)

Follow findings and get the updates that matter

Follow a finding to be notified about its status changes, comments, and mentions, and unfollow anything you'd rather tune out. Related updates are now grouped into a single notification instead of a flood, and your organisation can choose who's subscribed to new findings by default.

PR reviews connected to findings

When a pull request is reviewed, its findings now link back to the review and update on their own. They move to resolved when a fix lands and reopen if a regression shows up.

Tax details at checkout

Checkout now collects the billing address and VAT/tax ID needed for compliant invoicing, with tax calculated automatically. (for teams on business plans)

Improved

  • Snappier interface: the command palette, tables and tooltips respond faster, with lighter animation on the surfaces you use most.
  • Reduced-motion support: Odin now respects your system "reduce motion" preference and eases off animations accordingly.
  • Consistent run-page labels: the phases shown on the run page now match what's actually happening behind the scenes and in the event feed.
  • Clearer activity history: finding status changes made by connected systems, not just people, is now clearly attributed in the activity timeline.

Fixed

  • Deleting your profile picture works again.
  • The attack-surface map now shows the correct parent and child relationships between subdomains.
  • Applied a security update to address a known advisory in a third-party dependency.

Single sign-on, plus attack-surface and findings improvements

This release adds single sign-on to Business and Enterprise plans, plus Azure DevOps PR review configuration. We've also sharpened the attack-surface map, added manual PR linking to findings, included finding identifiers in synced titles, and fixed several display issues across the product.

New

Single sign-on (SSO)

Set up SSO for your organisation with verified domains and connections, then let your team sign in through your own identity provider. (available on Business and Enterprise plans)

Azure DevOps PR reviews

You can now configure PR reviews for Azure DevOps, with reviews dispatched automatically via webhooks when pull requests are opened. (for teams using PR reviews)

Improved

  • Sharper attack-surface map: the map now follows the underlying graph layout more closely for a clearer view of your attack surface.
  • Manual PR linking: you can now link a pull request to a finding directly from the UI, and the search now includes older pull requests when you do.
  • Finding identifiers in synced titles: findings synced to your issue tracker now include the finding identifier in the title, so they're easier to match up.
  • Easier changelog access: the changelog is simpler to find once you're signed in.

Fixed

  • Findings now show counts for the selected pentest rather than org-wide totals.
  • Finding activity now renders as Markdown with clearer spacing.
  • IP asset rows and the attack-surface map now show open ports.

Shortcut sync and Azure DevOps support

This release adds Shortcut as a two-way issue-tracker integration and brings Azure DevOps support to whitebox pentests and PR reviews. Findings exports now include linked issue references, integration health is more reliable, and escaped markup no longer leaks into finding text.

New

Shortcut integration

Connect Shortcut as an issue tracker and keep findings in sync both ways. Findings are created as Shortcut stories when reported, and their workflow state stays in sync as the finding progresses.

Azure DevOps support

You can now connect Azure Repos to run whitebox pentests against Azure DevOps repositories, and Azure DevOps pull requests are supported for PR reviews, including review comments, status updates, and ongoing review summaries. (for teams using pentests and PR reviews)

Improved

  • Linked issue references in exports: findings exports now include references to their connected tracker items across every format, so that you can trace a finding back to its issue.
  • More reliable integrations: Jira and Linear connections no longer show an expired token as healthy and refresh more reliably.
  • Asset notes stay in sync: notes managed in our operations tooling now sync through to the asset in Odin.

Fixed

  • Escaped Markdown and HTML sequences no longer leak into rendered finding text.