Security Changelog

What we've actually shipped on security

A dated, public log of security-relevant changes to CloudGuard. We'd rather show you the real history than ask you to take our word for it.

How to read this: every entry below corresponds to a real, dated change in our codebase. This page is not a marketing summary, it's an ongoing record. See our Trust Center for the current state of our controls, and security.txt for how to report a vulnerability.

Mandatory two-factor authentication and session timeout controls

  • Email-based 2FA added to every login: a 6-digit one-time code is required in addition to password, with a 5-minute expiry and a 5-codes-per-hour per-account send limit to prevent abuse.
  • Session hardening: JWTs now carry and enforce an explicit type claim, so a refresh token or a pending-2FA token can never be replayed as a full access token.
  • Absolute session limit: sessions now expire after 12 hours regardless of activity.
  • Idle timeout: sessions are also terminated server-side after 60 minutes of genuine user inactivity, tracked independently of background polling so it reflects real idle time.

Public Trust Center and gated document requests

  • Published a full Trust Center (Overview, Documents, Controls, Sub-processors) detailing our infrastructure, access model, encryption, and compliance framework coverage.
  • Added a reviewed document-request flow for sensitive materials (security questionnaire, named sub-processor list), replacing an open email link with a logged, rate-limited request process.

Bot protection and authentication flow hardening

  • Added Cloudflare Turnstile CAPTCHA to login and registration to prevent automated abuse.
  • Hardened the authentication refresh flow and published our Privacy Policy and Terms of Use.