Changelog

What's new in SurfaceLoop.

14 September 2026

One answer to "how severe is this?" -- everywhere

Severity is now calculated one way and shown the same way on every surface: the Overview, the Threats list, the Ports and Technologies tiles, the PDF report, and alert emails. Where a finding involves a known CVE, the severity is CVE-aware rather than a generic category score. If you read HIGH in an email, you will see HIGH in the app — no more cross-referencing.

11 September 2026

Monitor whole IP ranges

You can now add an IP range (CIDR) as an asset, not just single addresses and domains. SurfaceLoop watches the range for live hosts and folds anything it finds into the same scanning and change tracking as the rest of your estate. Available by plan.

11 September 2026

Lookalike-domain watching gets sharper

The phishing protection wizard now scores how forgeable each lookalike domain is using a deterministic model, so the riskiest candidates surface first and the same domain always gets the same score. Suggestions that swap characters for visually identical ones (like rn for m, or punycode homoglyphs) are called out explicitly as deception rather than typos, and the wizard discloses the punycode form so you can see exactly what is registered.

9 September 2026

A running scan is always in view

When a scan is running, it is now one click away from every page in the app, and starting one gives unmissable feedback. New workspaces also get a clearer first-run experience: onboarding walks through the first scan and shows a proper waiting state while discovery does its initial pass.

4 September 2026

A redesigned app, end to end

SurfaceLoop has a new interface — calmer, denser, and built around the questions that matter: what do I own, what is exposed, what changed, and can I prove it is fixed. Navigation is reorganised into Surface, Exposure, Change and Prove; the Threats table gets a structured detail drawer with plain-English explanations; Assets become a grouped inventory with a full dossier per asset; and every monitoring page — Certificates, DNS and Email, Ports and Services, Discovery, Dark Loop, Phishing and Scans — is redrawn in the new system, with a command palette and keyboard shortcuts throughout.

2 September 2026 v1.0

A redesigned findings report

The downloadable PDF report has been rebuilt from scratch to be something you can hand to a director or an auditor: what we found, how severe it is, and what to fix first — readable without security expertise. It uses the same severity language as the app, so the report and the dashboard never disagree.

1 September 2026

Verify the apex, cover the subdomains

Proving you own an apex domain now covers its subdomains too. Verify example.co.uk once with a DNS record, and the subdomains discovery finds under it are authorised for scanning automatically — including ones discovered later. No repeat verification per subdomain.

31 August 2026

Scans on a dependable clock

Scan scheduling is now deterministic: a 24-hour interval means a scan every 24 hours, with each asset’s scans spread across the day rather than bunched together. Your scan cadence is visible and adjustable in Settings, with the minimum interval set by your plan.

31 August 2026

Clearer confirmations for destructive actions

Every browser-native confirm prompt in the app has been replaced with one consistent confirmation dialog, and the most destructive actions — the ones that remove data across your workspace — now ask you to type a confirmation phrase. Slower by a second, and worth it.