Product
Changelog
Last updated October 8, 2026
What changed in Vulnix, newest first. Changes to the API are recorded separately in the API changelog.
Stricter browser security in the dashboard
- The dashboard now allows only scripts that carry a one-time key issued for each page load, so a script injected into a page does not run.
- app.vulnix.dev opens straight to your dashboard, or to sign-in when you are signed out.
Vulnix now runs on Google Cloud in Frankfurt
- The platform moved to Google Cloud in Frankfurt, Germany. Your data stays in the EU, as before.
- Product analytics, which you can decline in the cookie banner, now go to PostHog's EU region.
Vulnix MCP: run pentests from your AI apps
- Connect Claude, ChatGPT, Cursor or any MCP client to https://api.vulnix.dev/mcp and sign in with your Vulnix account.
- Start and watch pentests, triage findings, check a fix and manage domains, scopes and knowledge in plain language.
- You choose what each connection may do at sign-in. Actions that spend credits are never pre-selected, and owners and admins can turn AI apps off or cap their permissions.
- Connections are listed and revocable under API, MCP.
- A light and dark theme switch is now in the client and staff portals.
Chat reads Arabic and goes deeper on a finding
- Arabic and other mixed-direction text now renders correctly in chat.
- Ask the agent to go deeper on a finding and it treats that as real testing work, with the finding's detail and its log in front of it.
Self-contained finding reports
- Each finding's report now carries the engine's full detail, so it can be read and shared on its own.
Test accounts, plans and a new top bar
- A test account is checked as soon as you save it, and the evidence of the login attempt is kept with it.
- A domain can hold up to three test users, and every test account needs a valid login URL.
- Compare plans side by side and change your plan from one picker.
- Your account menu, notifications and a link to the docs sit in a top bar on every page.
More ways to sign in, and to test behind a login
- Sign in or sign up with Google first, with email and password one click away.
- Give the agent a test account that signs in with Google, a username and password with a one-time code, or a magic link.
- Connect GitHub and your DNS provider while you set up, without leaving onboarding.
The dashboard moves to app.vulnix.dev
- Sign in at app.vulnix.dev. The website stays on vulnix.dev, and links to the old addresses redirect.
- You were signed out once during the move.