Release notes

What changed in Avalon.

Product, reliability, and integration updates across Avalon.

Protected-data security foundation

Avalon now explains its protected-data model as layered security: database encryption at rest, per-tenant application encryption for sensitive data, private passphrase unlocks, and tenant-aware KMS key wrapping.

  • Private passphrase boundary — Protected mailbox content stays unreadable while locked; unlocked AI automation is called out as the explicit, narrow processing exception.
  • Tenant-aware KMS wrapping — Security copy now describes KMS wrapping as an application-layer boundary rather than relying only on database-level logical separation.
  • Honest assurance wording — The public security page avoids overstating SOC 2, pentest, or end-to-end encryption claims before external evidence exists.