Devici Product Release Notes
This page contains the active, continuously updated release notes for the Devici platform.
2026
Version 2.26.0 — 10 March 2026
New features
-
Expanded Smart Attribute intelligence
Smart Attributes can now query both custom and built-in Codex sources, improving the accuracy of attribute suggestions when applying attributes to elements. -
AI-assisted attribute recommendations
The AI Diagram Assistant can now recommend and apply attributes to diagram elements, helping users enrich threat models more quickly and consistently. -
OT & IoT threat modeling methodology
Added a new methodology designed for hardware-based threat modeling, including dedicated attributes, threats, and mitigations tailored for OT and IoT environments.
Improvements & fixes
-
Detailed report layout improvement
Fixed an issue where longer threat model descriptions could overlap tags in the Detailed Report. -
Improved OTM import reliability
Enhanced the OTM import workflow to address minor parsing issues, resulting in more accurate and consistent imports of OTM files.
Version 2.25.0 — 10 February 2026
New features
-
Data flow connections to trust boundaries
Data flows can now be connected directly to trust boundary elements, improving accuracy and expressiveness in threat model diagrams. -
Richer AI-generated element descriptions
Elements generated via the AI Diagram Assistant now include descriptive text, providing clearer context and reducing manual cleanup after generation. -
Export diagrams as PNG
Diagrams can now be exported as PNG files, making it easier to share, review, and include threat models in documentation and reports. -
Workflow action inheritance for collections
A new option allows workflow actions configured on a parent collection to be automatically propagated to its subcollections.- Simplifies workflow management across large collection hierarchies
Improvements & fixes
-
Trust boundary transparency rendering
Fixed an issue where trust boundary background transparency was applied incorrectly on the initial render. -
Collection settings modal stability
Resolved an issue where the collection settings pop-up could appear multiple times.
Version 2.24.0 - 27 January 2026
New features
-
Multi-select smart attributes
Users can now select multiple smart attributes at once when adding them to elements, eliminating the need to repeatedly search when applying several attributes. -
Lock elements on the canvas
Elements can now be locked in place to prevent accidental movement while reviewing or collaborating on a threat model. -
Threat model tagging and filtering
Threat models can now be tagged and filtered, making it easier to organize, discover, and manage models at scale.- Tags are also included in the Detailed Report for improved visibility and reporting
-
Admin role with scopes
Admin roles now support scoped access, allowing you to define which objects an admin can access across Devici with specific read and write permissions.- Scoped admins can be issued API tokens aligned to their assigned permissions
- Improves security and operational control for integrations and automation
Improvements & fixes
-
Threat model description length increased
The maximum character limit for threat model descriptions has been increased from 140 to 500 characters. -
Canvas element layering persistence
Resolved an issue where canvas layering order was not preserved after moving elements. -
Code Genius diagram rendering
Fixed an issue where Trust Boundaries generated by Code Genius lacked opacity, causing edges and elements to be visually obscured. -
Canvas selection stability
Fixed an issue where elements could disappear from the canvas when selected and the user double-clicked selection mode.
2025
Version 2.23.0 — 25 November 2025
New features
-
API token management
Devici now supports multiple API tokens per organization, enabling more granular access control and improved security for integrations.- Introduces two new roles: Owner and Superadmin
- Existing Admins were migrated to Superadmin
- Additional Admin-level token management improvements are planned
-
Canvas layering controls
When elements overlap on the canvas, a new Layer icon displays all stacked elements, making it easier to select, reorder, and bring items forward.
Improvements & fixes
-
Attribute removal behavior
Removing an attribute now automatically removes all associated threats.- A preview panel clearly shows which threats will be removed before confirming
Update — 20 October 2025
New features
-
Starter promo checkout flow
The Starter plan sign-up and checkout experience now supports promo codes end-to-end, enabling smoother campaign-driven promotions and onboarding. -
API enhancement —
include_archived
Theget threat-modelAPI endpoint now supports aninclude_archivedparameter, allowing archived threat models to be retrieved programmatically.
Improvements & fixes
-
Custom Attributes & Codex reliability
Resolved an issue where newly added custom attributes did not persist or properly save associated threats from the Devici Codex. -
AI prompt history
Navigating away from Threat Models no longer discards AI prompt history.- Users now receive a confirmation prompt before clearing context
-
Threat Models API
Fixed an issue that returned data for non-existent models.- Responses now correctly reflect only valid threat models
-
Editing custom attributes
Users can now save edited custom attributes without requiring a description, aligning with intended behavior. -
Canvas / Threat Model API security
Addressed an issue where canvas payloads unintentionally included user data.- Responses now exclude all PII and return only canvas-specific fields
Version 2.21.0 — 1 October 2025
New features
-
Google & GitHub SSO
Users can now sign up and log in with Google or GitHub, providing a seamless and secure onboarding experience. -
Quick Start modal
A new modal guides users to start model creation immediately with clear paths.- Use a Template
- Import a Diagram
- Generate from Text (AI)
- Build Your Own (blank canvas + tutorial)
- Scan with CodeGenius (Enterprise feature; paywalled for Free/Pro)
-
Integrated onboarding tutorial
An in-product guided tutorial helps first-time users get started quickly and confidently. -
Bulk user management
Administrators can manage users in bulk, improving efficiency for large teams.- Enable or disable users
- Change roles
- Delete user accounts
Update — 19 September 2025
New features
-
Role Catalog API endpoint (
/api/v1/roles)
Added a new endpoint that allows customers to programmatically retrieve the complete role catalog.- Includes Owner, Superadmin, Admin, and User roles
- Supports versioning and ETag validation
- Uses caching headers to reduce unnecessary API calls
-
MAESTRO Threat Framework
Introduced the MAESTRO framework to help users identify and mitigate risks associated with agentic AI systems.
Version 2.20.0 — 28 July 2025
New features
-
Monitoring tool for canvas connections
Introduced a tool that provides real-time feedback on connection status and data saving.- Notifies users when connections are active, disrupted, or successfully saved
Improvements & fixes
- General performance improvements
- Resolved multiple stability and reliability issues
Version 2.19.0 — 14 July 2025
Improvements
- Updated feature matrix
Subscription tier feature matrix updated to provide clearer comparisons across plans.
Fixes
- Various usability and stability improvements
- Backend performance enhancements
Version 2.18.0 — 16 June 2025
New features
-
Out-of-scope elements in threat models
Users can now mark elements as out of scope, improving clarity and auditability.- Explanatory notes can be added for additional context
-
Configurable sticker editing permissions
Authors can control whether collaborators are allowed to edit stickers. -
Static IP address for app integrations
All API traffic now originates from a dedicated static IP address.- Enables firewall and reverse-proxy allowlists
Improvements & fixes
- Platform enhancements
- Usability and performance improvements
Version 2.17.0 — 14 May 2025
New features
-
AI Diagram Assistant
Generate Data Flow Diagrams (DFDs) from text descriptions and modify them in real time.- Save prompts and adjust layouts
- Prompts remain private and are not stored or analyzed
-
In-app notifications
Notifications for key events such as deadlines, new features, and account changes. -
Administrator notifications
Targeted notifications for API access, integrations, workflows, and audit logging.
Improvements & fixes
- Usability improvements
- Stability fixes
Version 2.16.0 — 17 March 2025
New features
-
Challenge Mode for threat modeling
Enables two competing teams to model threats in parallel. -
API enhancements
Standard API includes CRUD support for Teams, Users, and Collections.- Improved access to Dashboards and Reports
-
Syslog integration
Logs can now be securely sent to external servers via mTLS.
Improvements
- Enhanced diagram dragging
- Stickers contextually linked to elements
- Codex can be used exclusively as the threat source
Fixes
- Minor bug fixes to improve reliability
Version 2.15.0 — 23 January 2025
New features
-
Audit Log
Customers can view and track account activity through an audit log. -
Global Search
A new search bar enables faster navigation across Collections and Threat Models.
Improvements
- Mitigate Threats workflow
Updated to provide clearer configuration of threat statuses and prioritization.
Fixes
- Stability and performance improvements
2024
Version 2.14.0 — 12 November 2024
New features
- Create reviews without a workflow
- Bi-directional Azure DevOps sync for tickets
- Drag-and-drop reordering on Collections pages
- Control which threat sources apply to threat models
- Mitigating Attributes tab now displays Codex attributes
- Link Codex attributes to Devici threats
- New Workflow Action — Alert
- Canvas-level Dataflow management
- Patterns for reusable model components
Fixes & improvements
- Performance enhancements
- Bug fixes and UI refinements
2023
Version 1.2.0 Beta — 21 December 2023
New features
- Default collection auto-created for all accounts
- Redesigned Collection pages
- Added “Create” button to My Models
- Expanded text box sizes
- Copy/paste for Trust Boundary elements
Improvements
- Sign-in and MFA UX improvements
Fixes
- Checklist issues resolved
- MFA and Okta handling improvements
- Unicode support added for PDF exports