Changelog

What we shipped

Cipherscale ships new capabilities the moment they’re ready — sometimes daily, often weekly. Here’s what’s new.

AI-native engineering means receipts: every entry below is real shipped capability, not roadmap promise. Watch the roadmap page for what’s coming next.

Release 0.1.1

Latest

Activity logs

Every workspace now includes a searchable 90-day activity log for sign-ins, gateway events, member changes, OAuth connections, and AI chat actions. Admins can query it directly from chat, making security reviews and troubleshooting even faster.

Personal sign-ups and multi-workspace access

Cipherscale now supports personal Google and Microsoft account sign-ups, so evaluators can create independent workspaces without needing a company domain. Users can also join multiple workspaces and move between them from the same account.

Bulk profile download

Download your workspace configs as a single ZIP instead of clicking through each gateway. On WireGuard the archive holds one .conf per online gateway; on OpenVPN it holds one .ovpn covering every online gateway, which the client picks among when it connects.

Portal handles workspaces without a gateway yet

Workspaces where the admin hasn't deployed a gateway yet now show a clear 'gateway not yet deployed' state on the client portal instead of an error. Reload the portal once the first gateway is live to get your config.

Portal UX consistency pass

The client portal gets a consistent top bar across all views, the Cipherscale logo as a home anchor, and platform-aware badges showing which WireGuard or OpenVPN client to install for your device.

Multiple gateways in the same region

Admins can deploy two or more gateways in the same region (for example, us-east). Members are assigned across the co-located gateways deterministically, so load is spread at assignment time. If a gateway goes offline, members pointed at it are offered a switch to another gateway from the client portal.

Overlapping VPC CIDR support

Admins can deploy multiple gateways in the same VPC with overlapping CIDR ranges — for example, two gateways in the same 10.0.0.0/16 VPC for HA. On WireGuard each member is paired to one gateway per overlapping range deterministically, so their config's AllowedIPs stay non-overlapping. On OpenVPN the gateway pushes the routes and the client connects to one gateway at a time.

Better-match gateway suggestions in the client portal

If two or more gateways are online when you open the client portal, it re-checks every 30 seconds whether a different gateway is a better match for your location. If one is — and it stays the better choice for a full minute — the portal offers a Switch button. Switching issues you an updated config to import; it does not move a tunnel that is already running. On WireGuard the new config changes which gateway carries your internet traffic; on OpenVPN the client keeps choosing among your online gateways when it connects.

Location-based gateway selection at sign-in

When you open the client portal, Cipherscale looks up your location from your IP address and picks a gateway on your continent. On WireGuard that gateway is the one your config sends your internet traffic through; on OpenVPN your config lists every online gateway and the client picks one when it connects. Selection uses a bundled offline IP-location database, so no paid GeoIP subscription is required. If no gateway matches your continent, or your location can't be resolved, the config points at your workspace's primary gateway.

One-click gateway switch when a gateway goes offline

If the gateway your config points at stops responding, the client portal shows a banner with a Switch button that re-issues your config against another gateway, excluding the one you are on. You import the new config to reconnect.

Gateway deployment safety: CIDR overlap detection

At gateway deploy, the system warns admins via AI chat if the proposed VPC CIDR overlaps with an existing gateway in the workspace. Explicit override required to proceed — prevents silent routing collisions.

Visual polish refresh

Typography, palette, spacing, dividers, and card treatments tightened across the website. Geist webfont in two weights; cleaner visual rhythm.

One client config per workspace

You get a single config for your workspace rather than one per gateway. On WireGuard it carries a peer entry per online gateway so each gateway's own private network is reachable through it; your Internet traffic goes through one gateway. On OpenVPN it lists the online gateways as alternate endpoints and connects to one at a time. Adding a gateway takes effect when you download a fresh config.

Microsoft sign-in

Sign in with a Microsoft account — work, school, or personal — alongside Google. Single Sign in button on the homepage; pick the provider on the sign-in page.

Roadmap and changelog pages

Two new pages: /roadmap.html shows what we're planning, and /changelog.html (this page) shows what we just shipped.

Team & Members

Admins can now create invites for teammates by email address — chat returns a one-time link to send them — and manage members from there: see who's accepted, pending, or revoked, all via AI chat.

DigitalOcean gateway support

Deploy gateways on DigitalOcean alongside GCP. Pick the cloud at gateway-deploy time via admin chat; same OAuth-based deploy flow.

Website redesign for SMB

Refreshed landing page with sticky navigation, "How it works" walkthrough, and audience-targeted messaging.

Multi-cloud gateway management

Deploy GCP gateways with software updates, status monitoring, secure teardown, and internet-and-VPC egress routing — all via AI chat.

Release 0.1.0

AI chat as admin interface

The Cipherscale admin doesn't use a dashboard. Type what you want, get the result. Powered by an AI agent that knows ZTNA.

Workspace + Google sign-in

Sign in with Google, create a workspace, and you're live.

Free landing page

cipherscale.ai goes live.

Workspace creation + tenant isolation

Create a workspace and it's sealed off from every other — your members, gateways, policies, and data stay private to that workspace, enforced at every layer. The secure foundation everything else builds on.

Want to know what’s next?

Talk to our AI → See what’s coming →