Changelog22 July 2026

Privacy, OAuth and auth hardening

security

What's new

Google scopes narrowed, OAuth tokens encrypted at rest with logs scrubbed, a Google data deletion API with an owner danger zone, per-user erasure for every role, media deleted on erasure, and transcripts and embeddings purged.

Impact

Three critical authentication holes were closed: a pre-auth account takeover in the Google callback, unverified Apple identity tokens, and an unauthenticated webhook. An SSRF guard was added to workflow HTTP requests.

Upgrade

No action required. Suvi deployments are managed, so this reached your instance automatically.