<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>TRUSTIVAN changelog</title><description>What shipped in TRUSTIVAN, when, and what it changed.</description><link>https://trustivan.com/</link><item><title>2026.09 — Private registries, retention, a second factor, and a database that enforces the tenant boundary</title><link>https://trustivan.com/changelog/#2026-09/</link><guid isPermaLink="true">https://trustivan.com/changelog/#2026-09/</guid><description>Registries requiring authentication are now scannable, retention windows are enforced, TOTP two-factor arrived, and PostgreSQL row-level security backs the tenant boundary the application already enforced.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate></item><item><title>2026.08 — Policy engine, verdicts and webhooks</title><link>https://trustivan.com/changelog/#2026-08/</link><guid isPermaLink="true">https://trustivan.com/changelog/#2026-08/</guid><description>Policies became a first-class object with immutable versions, scans can be graded into a recorded verdict, and three events are now delivered as signed webhooks.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate></item><item><title>2026.07 — Finding lifecycle, scheduled rescans and the machine API</title><link>https://trustivan.com/changelog/#2026-07/</link><guid isPermaLink="true">https://trustivan.com/changelog/#2026-07/</guid><description>Findings gained a five-state lifecycle with an audit timeline, images can be rescanned on a schedule, and the platform API became drivable by a scoped credential.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>