{
  "summary": "Traffic can now be classified into business-data categories (PII, FIN, IP, customer data, CRM) using YARA rules, DLP pattern rules, and checksum detectors together, with the result recorded on each event and pushed to Allod VRM so a vendor's actual observed data handling can be compared against what it's approved for. Underpinning this is a new pure-Go YARA detection engine wired into the full proxy pipeline, including QUIC, with no CGO/libyara dependency, hot-reloadable rule sources, and an admin API for managing rules. CASB Processes and Extensions views are now sorted by percentage of fleet affected rather than raw connection count and are paginated instead of rendering every group in a single unbounded response, making shadow-IT signals easier to read on large fleets - also faster to compute after fixing a key-derivation caching gap in the underlying aggregation. Also fixes a release-artifact signing configuration issue and a secrets-migration edge case on Postgres-backed HA installs."
}
