Privacy, OAuth and auth hardening
security
What's new
Google scopes narrowed, OAuth tokens encrypted at rest with logs scrubbed, a Google data deletion API with an owner danger zone, per-user erasure for every role, media deleted on erasure, and transcripts and embeddings purged.
Impact
Three critical authentication holes were closed: a pre-auth account takeover in the Google callback, unverified Apple identity tokens, and an unauthenticated webhook. An SSRF guard was added to workflow HTTP requests.
Upgrade
No action required. Suvi deployments are managed, so this reached your instance automatically.