Skip to main content
CloudArq
changelog · what’s new

What’s new

Continuous AWS security, cost & compliance auditing. We ship often — here’s what changed.

latest
v1.2.0
releases
7
cadence
continuous
v1.2.0Latest
July 20, 2026

Amazon Bedrock AgentCore security, new compliance & cost pillars, and better email deliverability.

  • NewAmazon Bedrock AgentCore security coverage — six new read-only checks over AgentCore’s control plane: memory, gateway, and runtime encryption without a customer-managed key; over-privileged gateway and runtime execution roles; a runtime reachable over the public network; and an unencrypted token vault. The AI Workload lens now covers both Bedrock Agents and AgentCore, so you’re ready before Bedrock Agents Classic closes to new customers on July 30, 2026 (existing agents keep running).
  • NewA much bigger library of guidance: a dedicated AWS cost-optimization page, framework pages for HIPAA, PCI DSS, ISO 27001, NIST 800-53, AWS Well-Architected, and GDPR (joining SOC 2 and CIS), an AWS CSPM overview, and a new Guides hub with step-by-step how-tos — auditing public S3 access, rotating stale IAM keys, setting up Bedrock guardrails and logging, and cutting AWS cost waste. Every figure is pulled from the product, never hardcoded.
  • ImprovedEmail deliverability — every account email (invites, setup links, alerts) now sends a plain-text alternative alongside the HTML, which helps inbox placement with providers like Microsoft 365 and Gmail. The docs FAQ now explains how to allowlist our sender if a message is quarantined.
  • ImprovedThe AI Workload lens now catalogs twenty checks (up from fourteen with AgentCore), and its findings map into your compliance frameworks so an AI-workload gap reads as a specific control gap.
v1.1.0
June 30, 2026

AI Workload Security — the security and cost risk in your AI workloads, as a lens over your audit.

  • NewAI Workload lens — six read-only checks built for AI on AWS: an over-privileged Bedrock agent’s IAM blast radius, AI data that can route across regions, a RAG vector store overpaying, missing Bedrock guardrail protection, Bedrock cost levers, and runaway-agent loops. It’s a view over your existing audit — each finding still counts toward its real Security or Cost pillar, never a separate scanner.
  • NewA dedicated AI Workload tab on every connection — always visible, it explains the six checks, shows that connection’s AI-workload findings (or a clean state), and links to AI-spend monitoring. A violet AI badge and filter also surface AI findings across your audits, the findings inbox, and your dashboard.
  • ImprovedWhen a check can’t complete because your IAM role is missing a read-only permission, you now see exactly that — with a one-click “update your role” action — instead of a vague “we’re investigating.”
  • FixedResource counts are floor-clamped: a scan that times out mid-count can no longer lower a previously-complete count, and a partial count is now labeled “approximate, as of {date}.”
v1.0.4
June 17, 2026

The Audit Assistant, one click away from anywhere.

  • ImprovedAudit Assistant launcher (Max) — open the assistant from a floating button on any page, ask a grounded question about your findings across your connections, then expand to the full assistant workspace when you want the whole conversation history. Same private, audit-grounded answers — now one click from wherever you are.
v1.0.3
June 16, 2026

Workflow integrations, a public trust badge, an AI audit assistant, and sharper scan accuracy.

  • NewMoney Found — your dashboard now leads with the ROI of your scan: estimated monthly savings found vs. your plan price, labeled “estimated from scan findings” with an as-of date.
  • NewEmbeddable Trust Badge (Max) — drop a live, always-current security-posture badge on your own site; its score matches your Trust Center page exactly.
  • NewJira & GitHub — open a ticket from any finding (automatically on new findings, or on demand) and keep its status in sync. A closed ticket notifies you; it never auto-marks a security finding fixed.
  • NewMicrosoft Teams notifications — send audit summaries to a Teams channel via an incoming webhook.
  • NewAsk about this audit (Max) — ask plain-English questions about your findings (“what should I fix before SOC 2?”) and get answers grounded only in your own audit.
  • NewNew least-privilege check — flags IAM roles and users granted AWS services they have never actually used, via IAM Access Advisor (now 193 automated checks).
  • ImprovedSharper severities — four checks refined so they stop over-escalating benign or by-design conditions (AWS default network ACLs, a total budget that already covers AI spend, an intentionally-public single file), with no loss of real-issue coverage.
  • FixedThe weekly-digest unsubscribe link now reliably stops the weekly email.
v1.0.2
May 31, 2026

Cost Intelligence — real AWS + AI spend, spike & LLMjacking detection.

  • NewCost tab — real Cost Explorer billed spend (this-month + projected month-end), a by-service treemap, and a 90-day spend trend.
  • NewAI / Bedrock spend insights — AWS-billed AI spend by model incl. Marketplace-billed Claude, with spend-spike and possible-LLMjacking detection.
  • NewAI spend-spike & LLMjacking alerts on every scan (Max).
  • NewSet up cost controls — generate ready-to-apply Terraform & CloudFormation for AWS Budgets and a billing alarm, with thresholds templated from your actual spend. Budgets alert you early; they don’t hard-cap.
  • NewExport all cost fixes — download the infrastructure-as-code fix for every cost finding on a connection as one bundle.
  • NewNew Cost Intelligence checks — idle SageMaker endpoints, idle ElastiCache clusters, idle load balancers, gp2→gp3 EBS upgrades, and an owner / cost-allocation tag check (now 193 automated checks).
  • NewWays to cut spend — the Cost tab now ranks every savings opportunity by estimated monthly $, each tagged low / medium / high effort, with a one-click "quick wins" filter and category facets (idle, rightsizing, commitments, AI spend, data transfer).
  • NewCost Intelligence over the REST API (Max) — pull a connection’s spend, projected month-end, savings, and AI/Bedrock spend programmatically with your API key.
  • ImprovedSafer cleanup recommendations — CloudArq now checks dependencies before suggesting a delete (a snapshot backing an AMI, a volume that may hold data, a database with read replicas) and always leads with the reversible step.
  • ImprovedCost alerts now include the dollar figure — Slack, PagerDuty, and webhook alerts show the estimated monthly cost for cost findings (e.g. “Idle RDS — ~$240/mo”).
  • ImprovedCost findings show estimated monthly savings and a ranked list — including correct Multi-AZ pricing on RDS rightsizing recommendations.
v1.0.1
May 30, 2026

Onboarding, scheduling, alerts, and full remediation coverage.

  • NewOne-click AWS onboarding. Connect an account through a single CloudFormation launch — with clearer guidance when the role isn’t ready yet.
  • NewPer-connection scan schedules. Choose on-demand, monthly, weekly, or daily auditing for each AWS connection.
  • NewAlert rules. Route specific events — new, reopened, or resolved findings and posture-score drops — to Slack, PagerDuty, or a webhook, filtered by severity, framework, and account.
  • NewMax overage. Scan past your plan’s resource cap with transparent per-resource billing.
  • ImprovedFull IaC remediation coverage. Every check now ships a copy-paste fix — AWS CLI, Terraform, and CloudFormation.
  • ImprovedFaster AI remediation. Generating a fix for a finding is now noticeably quicker.
  • ImprovedInvoice PDFs. Download past invoices straight from the billing page.
  • FixedStability, security, and accessibility improvements across the app.
v1.0.0
May 1, 2026

CloudArq launches.

  • NewContinuous AWS auditing. 193 automated checks across the six Well-Architected pillars, mapped to 8 compliance frameworks, with per-finding remediation. Read-only and agentless.