Security changelog

Security changes you can review

Review material changes to ZipPigeon security controls, release integrity, persistence durability, and browser hardening.

August 11, 2026 — Release and recovery integrity

Standalone installers now verify Sigstore identity and provenance, release publication fails closed on incomplete evidence, and disaster-recovery tooling reconciles encrypted object inventory without decrypting customer files.

August 11, 2026 — Browser transport hardening

Production Content Security Policy now upgrades insecure subresource requests while retaining the existing narrow connection allowlist, browser isolation headers, and WebAssembly requirement for client-side encryption.

Verification boundary

This changelog describes implemented product controls and regression coverage. It is not an independent audit, certification, or guarantee that every deployment has completed its external CDN, storage, backup, and restore evidence checks.

Send the file. Keep control of the link.

Use ZipPigeon when a file needs to reach the right person without becoming another attachment or shared folder to clean up later.

Open signed-in sender