Changelog
Updates from the Arbitex team — features shipped, improvements made, and what's next.
Budget caps by model and by provider
Spend caps previously applied at user and group scope only. Budgets can now be set on an individual model or an individual provider, and are enforced at request intake — a request that would exceed the cap is refused rather than recorded after the fact.
Learn more →Register your own provider endpoints
Add an OpenAI-compatible or other provider endpoint of your own and route to it through the same policy, DLP, and audit path as a built-in provider. Endpoint secrets are stored with envelope encryption and displayed only as a last-four fragment. Administrators can also exclude specific models or providers from availability for their organization.
Learn more →Monitoring dashboards on live data
Model-quality alerts, latency percentiles, Outpost fleet health, geographic traffic aggregates, and cost and budget panels now read live cross-plane data instead of showing placeholders.
Learn more →Configure your own SIEM connectors
Administrators can configure audit-stream delivery to any of the seven supported SIEM platforms from the console, each with its own connector-specific fields. Connector secrets are stored with envelope encryption and scoped to your organization.
Learn more →Per-detector actions and condition logic in policy packs
A detector placed in a policy pack now carries its own action — block, redact, log, or allow — instead of inheriting one action for its whole entity type. Each detector can also be narrowed with a condition of several pattern clauses combined with AND or OR, so a detector fires only in the contexts you intend. Cross-detector conflicts resolve under an explicit combining mode, defaulting to most-restrictive-wins.
Learn more →Search and sort across the full dataset
Search, filter, and sort on the audit log, DLP events, credentials, and user and group tables now run against the entire underlying dataset rather than only the rows currently loaded on screen. Investigations at audit scale no longer silently operate on a single page of results.
Learn more →Connect any OIDC identity provider
Single sign-on is no longer tied to a fixed list of vendors. Any standards-compliant OpenID Connect provider can be connected, with multiple providers configurable side by side for organizations consolidating more than one identity source.
Learn more →Stronger client authentication for enterprise SSO
SSO integrations can authenticate without a shared client secret — either with a mutual-TLS client certificate, or with a signed client assertion using your own key. Both are standards-based options for organizations whose policy prohibits long-lived shared secrets.
Learn more →Cost breakdown by group and provider
Cost and usage reporting adds group and provider as reporting dimensions alongside the existing per-user view, so spend can be attributed to a team or to a specific provider without exporting the raw records.
Learn more →SAML configuration and SCIM tokens in the console
Configure your SAML identity provider from the console — set the name-ID format, download service-provider metadata, and run a live connection test before switching users over. Provisioning tokens for SCIM are generated in the same place.
Learn more →Webhook delivery health and live test
View delivery health and per-attempt history for your webhooks, and send a live test delivery to confirm an endpoint is reachable. Outbound requests are checked against an egress guard so a webhook target cannot be pointed at internal infrastructure.
Learn more →Air-gap configuration bundles on physical media
A fully disconnected Outpost can now take a configuration update from physical media. The bundle carries two independent signatures and both are verified before any value is applied. A bundle containing configuration outside the scope its signature authorizes is rejected in full rather than partially applied.
Learn more →Three Enterprise deployment flavors
Enterprise customers can now deploy Arbitex three ways: shared multi-tenant SaaS, a dedicated single-customer hosted instance, or a customer-deployed air-gap Outpost. The same governance pipeline runs in every flavor — choose the isolation model that matches your requirements.
Learn more →Outpost detection parity with signed update channels
Air-gap Outpost deployments now deliver the same GPU-accelerated detection quality as the hosted service. Detection model updates ship over signed, verifiable channels — choose automatic updates, notify-and-approve, or fully offline tarball delivery for disconnected environments.
Learn more →Bring your own provider credentials
Organizations can register their own AI-provider API keys instead of routing through shared credentials. Keys are stored with envelope encryption and behave identically in the hosted service and in air-gap Outpost deployments.
Learn more →Want to see the platform in action?Book a demoand we'll walk you through the latest capabilities.