Skip to content

Devici Product Release Notes

This page contains the active, continuously updated release notes for the Devici platform.


2026

Version 2.26.0 — 10 March 2026

New features

  • Expanded Smart Attribute intelligence
    Smart Attributes can now query both custom and built-in Codex sources, improving the accuracy of attribute suggestions when applying attributes to elements.

  • AI-assisted attribute recommendations
    The AI Diagram Assistant can now recommend and apply attributes to diagram elements, helping users enrich threat models more quickly and consistently.

  • OT & IoT threat modeling methodology
    Added a new methodology designed for hardware-based threat modeling, including dedicated attributes, threats, and mitigations tailored for OT and IoT environments.

Improvements & fixes

  • Detailed report layout improvement
    Fixed an issue where longer threat model descriptions could overlap tags in the Detailed Report.

  • Improved OTM import reliability
    Enhanced the OTM import workflow to address minor parsing issues, resulting in more accurate and consistent imports of OTM files.


Version 2.25.0 — 10 February 2026

New features

  • Data flow connections to trust boundaries
    Data flows can now be connected directly to trust boundary elements, improving accuracy and expressiveness in threat model diagrams.

  • Richer AI-generated element descriptions
    Elements generated via the AI Diagram Assistant now include descriptive text, providing clearer context and reducing manual cleanup after generation.

  • Export diagrams as PNG
    Diagrams can now be exported as PNG files, making it easier to share, review, and include threat models in documentation and reports.

  • Workflow action inheritance for collections
    A new option allows workflow actions configured on a parent collection to be automatically propagated to its subcollections.

    • Simplifies workflow management across large collection hierarchies

Improvements & fixes

  • Trust boundary transparency rendering
    Fixed an issue where trust boundary background transparency was applied incorrectly on the initial render.

  • Collection settings modal stability
    Resolved an issue where the collection settings pop-up could appear multiple times.


Version 2.24.0 - 27 January 2026

New features

  • Multi-select smart attributes
    Users can now select multiple smart attributes at once when adding them to elements, eliminating the need to repeatedly search when applying several attributes.

  • Lock elements on the canvas
    Elements can now be locked in place to prevent accidental movement while reviewing or collaborating on a threat model.

  • Threat model tagging and filtering
    Threat models can now be tagged and filtered, making it easier to organize, discover, and manage models at scale.

    • Tags are also included in the Detailed Report for improved visibility and reporting
  • Admin role with scopes
    Admin roles now support scoped access, allowing you to define which objects an admin can access across Devici with specific read and write permissions.

    • Scoped admins can be issued API tokens aligned to their assigned permissions
    • Improves security and operational control for integrations and automation

Improvements & fixes

  • Threat model description length increased
    The maximum character limit for threat model descriptions has been increased from 140 to 500 characters.

  • Canvas element layering persistence
    Resolved an issue where canvas layering order was not preserved after moving elements.

  • Code Genius diagram rendering
    Fixed an issue where Trust Boundaries generated by Code Genius lacked opacity, causing edges and elements to be visually obscured.

  • Canvas selection stability
    Fixed an issue where elements could disappear from the canvas when selected and the user double-clicked selection mode.


2025

Version 2.23.0 — 25 November 2025

New features

  • API token management
    Devici now supports multiple API tokens per organization, enabling more granular access control and improved security for integrations.

    • Introduces two new roles: Owner and Superadmin
    • Existing Admins were migrated to Superadmin
    • Additional Admin-level token management improvements are planned
  • Canvas layering controls
    When elements overlap on the canvas, a new Layer icon displays all stacked elements, making it easier to select, reorder, and bring items forward.

Improvements & fixes

  • Attribute removal behavior
    Removing an attribute now automatically removes all associated threats.

    • A preview panel clearly shows which threats will be removed before confirming

Update — 20 October 2025

New features

  • Starter promo checkout flow
    The Starter plan sign-up and checkout experience now supports promo codes end-to-end, enabling smoother campaign-driven promotions and onboarding.

  • API enhancement — include_archived
    The get threat-model API endpoint now supports an include_archived parameter, allowing archived threat models to be retrieved programmatically.

Improvements & fixes

  • Custom Attributes & Codex reliability
    Resolved an issue where newly added custom attributes did not persist or properly save associated threats from the Devici Codex.

  • AI prompt history
    Navigating away from Threat Models no longer discards AI prompt history.

    • Users now receive a confirmation prompt before clearing context
  • Threat Models API
    Fixed an issue that returned data for non-existent models.

    • Responses now correctly reflect only valid threat models
  • Editing custom attributes
    Users can now save edited custom attributes without requiring a description, aligning with intended behavior.

  • Canvas / Threat Model API security
    Addressed an issue where canvas payloads unintentionally included user data.

    • Responses now exclude all PII and return only canvas-specific fields

Version 2.21.0 — 1 October 2025

New features

  • Google & GitHub SSO
    Users can now sign up and log in with Google or GitHub, providing a seamless and secure onboarding experience.

  • Quick Start modal
    A new modal guides users to start model creation immediately with clear paths.

    • Use a Template
    • Import a Diagram
    • Generate from Text (AI)
    • Build Your Own (blank canvas + tutorial)
    • Scan with CodeGenius (Enterprise feature; paywalled for Free/Pro)
  • Integrated onboarding tutorial
    An in-product guided tutorial helps first-time users get started quickly and confidently.

  • Bulk user management
    Administrators can manage users in bulk, improving efficiency for large teams.

    • Enable or disable users
    • Change roles
    • Delete user accounts

Update — 19 September 2025

New features

  • Role Catalog API endpoint (/api/v1/roles)
    Added a new endpoint that allows customers to programmatically retrieve the complete role catalog.

    • Includes Owner, Superadmin, Admin, and User roles
    • Supports versioning and ETag validation
    • Uses caching headers to reduce unnecessary API calls
  • MAESTRO Threat Framework
    Introduced the MAESTRO framework to help users identify and mitigate risks associated with agentic AI systems.


Version 2.20.0 — 28 July 2025

New features

  • Monitoring tool for canvas connections
    Introduced a tool that provides real-time feedback on connection status and data saving.

    • Notifies users when connections are active, disrupted, or successfully saved

Improvements & fixes

  • General performance improvements
  • Resolved multiple stability and reliability issues

Version 2.19.0 — 14 July 2025

Improvements

  • Updated feature matrix
    Subscription tier feature matrix updated to provide clearer comparisons across plans.

Fixes

  • Various usability and stability improvements
  • Backend performance enhancements

Version 2.18.0 — 16 June 2025

New features

  • Out-of-scope elements in threat models
    Users can now mark elements as out of scope, improving clarity and auditability.

    • Explanatory notes can be added for additional context
  • Configurable sticker editing permissions
    Authors can control whether collaborators are allowed to edit stickers.

  • Static IP address for app integrations
    All API traffic now originates from a dedicated static IP address.

    • Enables firewall and reverse-proxy allowlists

Improvements & fixes

  • Platform enhancements
  • Usability and performance improvements

Version 2.17.0 — 14 May 2025

New features

  • AI Diagram Assistant
    Generate Data Flow Diagrams (DFDs) from text descriptions and modify them in real time.

    • Save prompts and adjust layouts
    • Prompts remain private and are not stored or analyzed
  • In-app notifications
    Notifications for key events such as deadlines, new features, and account changes.

  • Administrator notifications
    Targeted notifications for API access, integrations, workflows, and audit logging.

Improvements & fixes

  • Usability improvements
  • Stability fixes

Version 2.16.0 — 17 March 2025

New features

  • Challenge Mode for threat modeling
    Enables two competing teams to model threats in parallel.

  • API enhancements
    Standard API includes CRUD support for Teams, Users, and Collections.

    • Improved access to Dashboards and Reports
  • Syslog integration
    Logs can now be securely sent to external servers via mTLS.

Improvements

  • Enhanced diagram dragging
  • Stickers contextually linked to elements
  • Codex can be used exclusively as the threat source

Fixes

  • Minor bug fixes to improve reliability

Version 2.15.0 — 23 January 2025

New features

  • Audit Log
    Customers can view and track account activity through an audit log.

  • Global Search
    A new search bar enables faster navigation across Collections and Threat Models.

Improvements

  • Mitigate Threats workflow
    Updated to provide clearer configuration of threat statuses and prioritization.

Fixes

  • Stability and performance improvements

2024

Version 2.14.0 — 12 November 2024

New features

  • Create reviews without a workflow
  • Bi-directional Azure DevOps sync for tickets
  • Drag-and-drop reordering on Collections pages
  • Control which threat sources apply to threat models
  • Mitigating Attributes tab now displays Codex attributes
  • Link Codex attributes to Devici threats
  • New Workflow Action — Alert
  • Canvas-level Dataflow management
  • Patterns for reusable model components

Fixes & improvements

  • Performance enhancements
  • Bug fixes and UI refinements

2023

Version 1.2.0 Beta — 21 December 2023

New features

  • Default collection auto-created for all accounts
  • Redesigned Collection pages
  • Added “Create” button to My Models
  • Expanded text box sizes
  • Copy/paste for Trust Boundary elements

Improvements

  • Sign-in and MFA UX improvements

Fixes

  • Checklist issues resolved
  • MFA and Okta handling improvements
  • Unicode support added for PDF exports