August 18th, 2026
New

Managing a handful of targets is easy. Managing two hundred across five teams is not. Labels let you tag targets the way your organization already thinks about them, by environment, business unit, or criticality, then filter, select, and act on them in bulk instead of working down a flat list one row at a time.
What's new
Workspace and Company Labels β Create labels scoped to a single workspace, or company-wide so every team shares the same taxonomy. Both are managed from Settings.
Two Label Types β Standalone labels stack freely, so a target can be both production and high-value. Label groups are mutually exclusive, so a target carries only one label from a group like Environment: Prod, Staging, or Dev, and nothing gets double-tagged by accident.
Assign Labels in Place β Apply or change a target's labels straight from the targets table or its settings page, without opening Settings just to tag one target.
Filter and Bulk-Select by Label β Use labels as a filter in the Target Selector or the Start Scan wizard, then Shift+Select the filtered results to scan or manage all of them together.
Give it a try and tell us what you think.
August 17th, 2026
Improved

Setting up a pentest now happens on a single page. Scan type, objective, and testing approach are all chosen before you move to target selection, replacing the multi-step flow that came before.
Improvements
All-in-One Pentest Setup β The Start Scan flow now brings scan type, objective, and authenticated or unauthenticated testing together on one setup page, ahead of target selection. What used to take several steps is a single screen.
Objective Selection β Choose an objective that matches what the pentest is for. Objective section include SOC 2, PCI DSS, ISO 27001, GDPR, WASA, and CERT-IN, alongside a custom option and No Objective when none applies.
Testing Approach β Run a pentest with login credentials as authenticated grey box testing, or without them as unauthenticated black box testing. Selecting an objective requires grey box, so the testing approach is set for you and credentials are requested before launch.
Credential-Aware Targets β Targets without saved login credentials can only run unauthenticated testing. For grey box pentests you can now add credentials directly from the scan start sheet, without leaving for another page.
August 12th, 2026
Improved

This release brings Jira two-way sync to automated scans, makes scan setup and vetting requests clearer, and fixes eight issues across pentest, vulnerability, and API scanning flows.
Jira Two-Way Sync for Automated Scans β Two-way sync now works with automated scans, not just pentests. Once it's enabled, changes made in either system carry across to the other, exactly as they already do for pentests. Reach out to support to get access.
Smarter Scan Setup Defaults β When your plan supports only one scan type or subtype, Astra preselects it instead of asking you to step through the choice.
Clearer Vetting Credits β The Request Vetting flow now labels available requests more clearly, so you can see how many you have left before you submit.
Improved Vulnerability Completion Copy β Messaging now correctly refers to marking business-acceptable findings as accept risk, instead of using misleading false-positive wording.
More Useful Astranaut Bot Replies β Customer-facing comment replies from Astranaut Bot now carry more of the detail you need.
Restarting Pentest Scans β Fixed an issue that prevented some pentests from being restarted from certain progress states.
Automated Scan Finding States β In Auto Pentests, vulnerabilities reported by Bounty Hunters or Structured Pentesters now get reported directly in Unsolved status.
Vulnerabilities Page Pagination β Changing the page number in the URL no longer opens an empty page when findings exist.
HAR File Uploads β Fixed errors that could appear while adding a new HAR file during API scanning setup.
Pentest Scan Start Failures β Fixed an internal server error that could block a pentest scan from starting.
Duplicate Jira Tickets β Fixed a regression that created Jira tickets for automated scans when users had only set them up for pentests.
Endpoint Details Layout β Fixed endpoint URL overflow in the import endpoint details sheet.
Bounty Hunter Report Status β The report widget now reflects the correct status more reliably.
June 18th, 2026
New

Hey there π
I'm Shikhil, the founder of Astra Security. I did my first pentest 15+ years ago and have been obsessed with offensive security ever since.
Over the years, we built a PTaaS platform, a DAST scanner, an API Security platform, a Cloud Vulnerability Scanner, and discovered tens of millions of vulnerabilities along the way. But one belief stayed constant through all of it: business logic vulnerabilities would never be discovered autonomously. Ever.
AI just shattered that limit. And nothing has excited me like this in 15 years of being in infosec.
So we built Astra Autonomous Pentesting. Not a smarter scanner. An army of AI agents that owns the full pentest cycle:
π Discover - Offensive agents built on insights from 5,000+ real-world pentests hunt complex, chained vulnerabilities.
π₯ Exploit - Agents chain and exploit findings to prove real-world impact, not flag theoretical risks.
β Validate - An independent validator layer drives false positives to near-zero.
π§ Fix - AI-fix agents that deliver tailored remediation right in your Cursor, Copilot, and Claude Code.
The full cycle. No handoff. No report sitting in someone's inbox. Software that heals itself.
This isn't about replacing pentesters π Let AI own the grunt work - the cookie flags, the report writing, the endless threat modeling sessions. Let pentesters do what they love: chaining complex vulnerabilities, getting deep into a system. Pentesters at Astra are central to everything we build. Now, AI is their most powerful ally, not their replacement.
We call this the era of self-healing software. And we're just getting started. Would love your questions, brutal takes, and your support today. π
Looking forward to helping you with your next Pentest!
β Shikhil, Founder & CEO, Astra Security
November 26th, 2025
New

Weβre excited to announce the launch of Astra Cloud Vulnerability Scanner, designed to help teams continuously detect misconfigurations, IAM risks, and compliance gaps across AWS, Azure, and GCP.
Built on Astraβs Offensive Security Engine, the Cloud Scanner gives you continuous visibility into your cloud environment, helping you find real risks faster and fix them before they impact production.
Monitor your entire cloud environment from IAM roles and exposed storage to public endpoints and policy misconfigurations. Astra automatically detects new resources and scans them in real time, so you never miss a drift or hidden risk.
Built for AWS, Azure, and GCP, the scanner runs hundreds of cloud-specific checks to identify:
AWS Inspector V2 Vulnerability Scanner Not Enabled
Secret Rotation Interval Not Configured Properly
Missing Monitoring for Network
Detect Unauthorized KMS Key
Storage Bucket Public Access Check
Cloud Storage Bucket Versioning Check
Cloud Function has Default Service Account Enabled
Outdated Python Version for web apps
Web App Client Certificate Validation Disabled
Every finding includes actionable guidance and code-level fixes. You can trigger an automated rescan instantly to verify the resolution, no waiting on pentesters, no second opinions. Your cloud team can go from detection to resolution faster than ever.
Getting started is simple: connect your cloud accounts with read-only permissions and start scanning right away. No agents, no complex deployments, and zero performance impact on your infrastructure.
The Cloud Scanner works seamlessly alongside Astraβs other solutions, DAST, API Security, and PTaaS, giving you one unified dashboard for everything from cloud posture to app vulnerabilities. Manage all your security findings, guided fixes, and validation proof from a single, easy-to-use platform.
Your cloud evolves by the minute; your security should, too. Experience a faster, clearer, and more actionable way to stay ahead of misconfigurations.
Start your 7-day trial for just $7 and see Astra in action. Learn more β
October 3rd, 2025
New

Weβve just rolled out an exciting new feature that lets you host your Trust Center pages on your own custom domain, making your Trust Center fully branded, professional, and customer-ready!
1. Step-by-Step Setup in Dashboard
Add your custom domain directly from Trust Center settings and follow guided instructions, no complex configs required.
2. Real-Time Verification
Once you add the required DNS record, trigger verification right from the dashboard and get instant feedback on your domain status.
3. Automatic Domain Activation
Verified domains go live instantly with authentication issued automaticallyβyour Trust Center is ready for customers in no time.
Fully branded customer experience, your domain, your brand.
Simple updates or domain changes, all manageable from the dashboard.
Increased trust with stakeholders by keeping everything under your own domain.
Check out the full help article here
September 30th, 2025
New

Weβre excited to announce the launch of Trust Center, a continuous, publicly accessible hub designed to help businesses showcase their live security posture and compliance status with ease.
1. Continuous Security Proof
Share real-time vulnerability scans, penetration test results, and compliance status.
Move beyond static PDFs with automatically updated security evidence.
Build trust instantly with stakeholders, customers, and partners.
2. Dynamic Trust Seal
Embed a one-click Trust Seal on your website, sales decks, or email signatures.
Redirects buyers and stakeholders to your live Trust Center for instant verification.
Strengthen credibility wherever your brand shows up.
3. Custom Branding & Controls
Customize your Trust Center with company logo, colors, and custom domain.
Manage visibility of sections like security posture, assessments, compliance, APIs, and FAQs.
4. AI-Assisted Setup
Enter your domain and AI drafts company, security, and compliance content in minutes.
Simplify onboarding with minimal manual work for startups and enterprises.
Astraβs Trust Center empowers teams to turn compliance questions into competitive advantages. With continuous verification and instant transparency, it helps companies shorten deal cycles, boost customer trust, and prove security every day.
Learn more: https://www.getastra.com/astra-trust-center
September 2nd, 2025
New
Improved
Fixed

This release introduces troubleshooting for connectivity check failures, giving you clear insights and self-serve resolution steps. Alongside this, weβve expanded pentest scheduling to cover more asset types, improved scanning workflows, and delivered key bug fixes to ensure a smoother, more reliable experience.
New Feature:
Connectivity Check Failure
Weβve enhanced the way connectivity check failures are communicated on the Astra OrbitX Platform. Instead of just showing a failure message, you will now see actionable insights and easy troubleshooting tips to help resolve issues faster. With this update, you can now:
Understand the reason behind a failed connectivity check
Receive guided troubleshooting steps
Quickly identify whether the issue requires configuration changes on your end
Save time by resolving common connectivity problems without external support
Improvements:
Pentest Scheduling for Other Assets: You can now schedule Manual Pentests for iOS, Android, and βOtherβ asset types from the Start Scan flow, while automated scans remain disabled for these assets.
Shift + Click Support: Added Shift + Click support in the target selector to quickly select multiple targets at once.
Force-Start Crawl Scan: Added an option to force-start a crawl scan when needed.
Bug Fixes:
OpenAPI File Upload Error: Fixed an issue in API target setup where uploading a valid OpenAPI YAML spec incorrectly threw an βinvalid formatβ error
Access Revoked Error: Fixed an issue where users sometimes continued seeing a Forbidden message even after their access was removed. Now, revoked access is reflected instantly without leaving error screens.
Integrations Page Stability: Resolved a recurring loading problem on the Integrations page so it works without cache clears or hard refreshes.
UI Overlap: Fixed a layout issue where a popover overlapped the side sheet on the Integrations page.
Scan Type Filter: The Scan Type filter now works correctly in the Web DAST Scans list view.
Compliance Vulnerabilities Page: Resolved a page loading issue so the Compliance vulnerabilities view opens reliably.
Findings Loading Issue: Fixed an issue where findings failed to load for some customers in the vulnerability details sheet.
Asset Type Filter: Corrected the asset type filter behavior in the Start Scan sheet. It is now working seamlessly.
Persistent Error Page: Fixed cases where an error page persisted even after cache refresh and data clearing.
Endpoints Page Counter: Corrected the Unauthenticated endpoints counter so it displays the accurate count.
August 27th, 2025
New
Improved
Fixed

This release brings expanded support for custom login flows in web scansβhelping you cover more complex authentication scenarios with ease along with OpenTelemetry SDK integrations to give you more flexibility in capturing and analyzing API traffic.
Apart from these, weβve also made improvements that simplify target management, provide clearer visibility into subscriptions, and ensure a smoother overall product experience
New Features:
Custom Login Support for Web Scans: Weβre excited to introduce support for custom login scripts in the Astra OrbitX Platform, this ensures more of your application is covered during automated scans, unlocking deeper insights and stronger security with less manual effort.
With this update, our scanner can reliably handle complex login methods such as:
Multi-factor authentication (including TOTP-based)
Email-based verification and magic links
Pop-up or modal-based logins
And many more unique authentication setups
OpenTelemetry SDK Instrumentation: We're excited to announce OpenTelemetry SDK Instrumentation Integrations in the Astra API Security Platform, giving you more flexibility to capture and analyze API traffic across your applications.
Ingest API traffic directly from OpenTelemetry collectors.
Seamlessly integrate with existing observability pipelines
Capture traces from popular SDKs such as Python, Node.js, Go, and Java.
Automatically collect request and response data without complex setup.
Improvements
Consistent Progress Display: The progress section now has a stable, consistent width, making it easier to track progress without layout shifts.
Clearer Checkout Details: When selecting a collapsed plan card in checkout, its line items automatically expand β no need to click βShow Featuresβ again.
Pentest Completion Guidance: A new banner appears when a pentest finishes early, helping you clearly understand the next steps.
Bug Fixes
More Helpful Error Messages: When a request is blocked, youβll now see a clear explanation instead of a generic error, helping you troubleshoot faster.
Resize Progress Bars Issue: Fixed an issue where progress bars resized unpredictably β progress indicators now remain consistent across the platform.
Save Changes Button Fixed: In the login recording section, the Save Changes button now works properly β updates like session length are saved as expected.
Subscription Card Fixed: The Show More button in subscription cards now works reliably, ensuring you can view all subscription details.
Reported Vulnerabilities Visibility: Fixed an issue where reported vulnerabilities werenβt showing up on the dashboard β all reported issues are now visible.
August 19th, 2025
Improved
Fixed

This release focuses on creating a smoother experience across the platformβstandardizing UI elements, making subscription details easier to reach, and resolving issues affecting navigation and role assignments.
Subscription Link in Target Settings β Each target now displays its active plan in the info row. Clicking on it takes you directly to the subscription page, automatically filtered to that subscription so you donβt have to dig around to find the right subscription.
Consistent UI Styling β Updated the scan details header UI for better alignment and styling consistency across the platform.
Subscription Status Tooltips β Paused, cancelled, or deleted subscriptions now display clear tooltip messages for better feedback.
Sidebar Scroll Issue β Fixed a scrolling issue in the main sidebar for smoother navigation.
Invite Member Role Assignment β Resolved an issue where invited members werenβt being assigned the correct roles.