Skip to main content

Release Notes

Follow new updates and improvements to AquilaX AI.

Release Notes – Scan-Level Custom Security Policies

Release Date: 2026-02-09

Status: Production Ready

Overview

This release introduces scan-level custom security policies, enabling teams to override group-level security configurations on a per-scan basis. This enhancement provides greater flexibility for projects that require tailored security controls without modifying shared group policies.

Key Highlights

  • Define custom security policies per scan

  • Override group policies only when needed

  • Automatically preserve custom policies during rescans

  • Support for both form-based and JSON-based policy editing

  • Plan-based enforcement ensures all policies comply with subscription tier limits

What’s New

  • New UI to configure scan-level security policies at scan creation

  • Workers automatically prioritize custom policies over group defaults

  • Rescans inherit the original scan’s policy configuration

  • Custom policies are visible in scan metadata for transparency

Compatibility

  • Fully backward compatible

  • No breaking API changes

  • Default behavior remains unchanged if no custom policy is defined

Feature Update: Scan Comparison in AquilaX

AquilaX now supports scan comparison, allowing teams to compare two security scans (e.g., across commits or branches) and view:

  • New vulnerabilities introduced

  • Vulnerabilities resolved

  • Changes in severity distribution

  • Scanner-specific deltas

Key Benefits

  • Track security trends: Understand if security posture is improving or regressing over time.

  • Validate remediations: Confirm that fixed vulnerabilities no longer appear in later scans.

  • Detect regressions early: Identify security issues introduced by recent code changes.

  • Integrate into CI/CD: Enforce policies based on delta (e.g., block builds if new critical vulns are found).

This feature supports all scan types including SAST, SCA, Secrets, IaC, and Compliance.

Source-to-Sink analysis

AquilaX now supports Source-to-Sink analysis in both multi-tenant and single-tenant deployments for its SAST findings.

This feature allows users to trace data flow from the initial point of injection (source) all the way to the vulnerable function (sink). By following this path, developers can visualize the exact journey of potentially harmful data, making it easier to pinpoint where the vulnerability originates—and more importantly, where it can be fixed.

Earlier updates