What shipped
The theme running through this release cycle is control at the boundary. Three larger pieces of work landed together, and they turn out to reinforce each other: you can now classify data by sensitivity, restrict where it can be reached from, and recover it when someone removes it by mistake.
Restore Center
Deleted does not have to mean gone
Vaults, tables, files, and individual file versions that are deleted now move into a Restore Center rather than disappearing. You can browse everything currently recoverable, filter by resource type, and restore items individually or several at once with multi-select.
Each recoverable item shows a countdown to permanent deletion, so there is no ambiguity about how long you have. Deleted items are also visible in context from the Vaults, Files, and Tables pages, and the type filter is deep-linkable, which means you can send a colleague a link straight to the deleted tables view rather than describing where to click.
Restoring a file brings its version history back with it, including versions nested several levels deep in a promotion chain.
IP Access Control Center
Decide where your data can be reached from
Organisations can now define access rules based on network origin and have the platform enforce them, not just report on them. Rules are scoped in two tiers - a category and then a specific target - so you can apply a rule broadly across a resource class or narrowly to one vault.
A traffic view shows attempts against your rules, marked simply as allowed or blocked, so you can see the effect of a rule before and after you enable it. Rules can be toggled individually without waiting on the rest of the list.
This is the control most often requested by organisations with a data residency obligation, and it pairs directly with the classification work below.
Data Classification
Sensitivity labels the platform can act on
Vaults and files now carry a data classification level. New files inherit the classification of the vault they land in, so the label follows the data without anyone having to remember to apply it.
Classification is not decorative. Access rules can now be enforced by classification level, so a vault marked at a higher sensitivity behaves differently from one marked lower. Vaults at the most restricted level require a fresh multi-factor step-up before access, and organisations can define a country allowlist that applies specifically to sensitive and restricted vaults.
Classification also appears as a real field in vault-level and organisation-level compliance reports, which means the sensitivity of the data is now part of the evidence you hand to an auditor rather than something you assert separately. Changes to a vault's classification are recorded in the audit trail and cascade to the files inside it.
Smaller improvements worth knowing about
- Organisation-wide file validation by hash: check whether a file is known to your organisation without needing a Trust Page for it first
- Validation results now show a validity percentage alongside a count of detected changes, so partial matches are readable at a glance
- File detail pages have a dedicated tab surfacing the compliance reports associated with that file
- Country Intelligence lets you drill into everything that happened from a given country in one view
- Compliance reports can be filtered by file and by vault address
- New accounts can complete onboarding before creating an organisation, with a grace period and a visible countdown on email verification
Everything above is live now. If you have an account, the Restore Center and the IP Access Control Center are in the main navigation. If you do not, you can create one and try the classification workflow on a single vault.
For context on why classification and access enforcement matter for regulated organisations, the CISO's guide to regulatory compliance in 2026 covers the obligations these features are built against.
Recebe insights de ciber-resiliência no teu email
Orientação prática e pronta para auditoria sobre integridade de dados, conformidade e continuidade - à medida que publicamos.





