Osto 9.3.1.0 is live for every customer. More compliance coverage, deeper code security and faster endpoint protection, with nothing for you to install or migrate.
TL;DR
Three things changed for you in this release. Container image scanning now checks the images you ship, not only the repository they were built from. Compliance runs SOC 2 Type II, ISO 27001 and HIPAA at once, sharing one control library and one risk register, so your second framework costs a fraction of the first. Endpoint policies enforce the moment you save them, follow each device’s own timezone, and recognise 386 more applications. Released 19 August 2026 and already active on your account.
You do not need to upgrade anything. Everything below is already running on your account. Activate the pieces you want from the dashboard when you are ready.
On this page
Container image scanning
Osto Code Security now scans your container images alongside your source code, reporting vulnerable operating-system packages and application dependencies in the layers you actually ship. The image you deploy is assessed on the same terms as the repository it was built from, base-image packages included.
Container image scanning groups findings by base image, which changes the shape of the work. Twelve services sharing one outdated base is not twelve tickets. It is one, repeated, and the grouping shows you that before anyone starts filing them.
Container image scanning runs on the same schedule as your existing repository scans. Alongside it, findings and generated reports can now be scoped to a specific branch. A feature branch is assessed on its own rather than against your default branch, which makes static analysis, dependency scanning and container image scanning usable as a merge gate instead of a weekly report nobody opens.
ISO 27001 and HIPAA alongside SOC 2
Compliance now runs several frameworks at once. If you are already on SOC 2 Type II, you can add ISO 27001 or HIPAA without standing up a second programme beside the first.
| Framework | How you will find it laid out |
|---|---|
| SOC 2 Type II | Trust services criteria with controls, evidence and tasks tracked through your observation window. |
| ISO 27001 | Laid out the way an auditor expects: management-system clauses grouped as parent sections, with the Annex A control set kept separate. |
| HIPAA | Organised by administrative, physical and technical safeguards. |
Activate a framework and its full requirement and control library loads, with starter policy templates already in place, so you are not writing from a blank page.
Your second framework costs less than your first
Every control carries a badge for each framework it satisfies, and tasks filter by framework. A control that serves both SOC 2 and ISO 27001 is satisfied once and counted in both places. Adding a second framework becomes a fraction of the work of the first rather than a parallel programme.
Shared controls and the risk register
Compliance now includes a formal risk register, shared across every framework you run. Record a risk with its description, category and owner. Rate it for likelihood and impact to get an inherent score. Choose a treatment: mitigate, accept, transfer or avoid. Then link the controls that address it and re-rate to a residual score.
Risks track to closure and export with the rest of your evidence. One register answers the risk-assessment requirement in SOC 2, ISO 27001 and HIPAA alike, instead of being rebuilt for each audit.
Endpoint enforcement and coverage
Two changes here are worth knowing about on the day you next edit a policy.
| Change | What you will notice |
|---|---|
| Immediate domain filtering enforcement | A change to a domain filtering policy reaches managed devices as you save it. A category you block or allow takes effect across the fleet right away rather than at the next check-in. |
| Timezone-aware scheduling | Scheduled endpoint and domain filtering policies follow each device’s own local timezone, detected automatically. A working-hours policy applies during the user’s working hours, wherever they are. |
Application Control also gained 386 new signatures across Windows, Linux and macOS, covering development tools, AI assistant clients, cloud storage, video conferencing, social media, remote access, email clients and office software. Your policies now recognise far more of what your teams actually run.
Smaller improvements
| Area | Improvement |
|---|---|
| Endpoint | One Linux agent build now covers Ubuntu 22, 24 and 26, so a mixed fleet is a single package rather than one per release. |
| Endpoint | Protection stays active when a device boots into safe or minimal mode, including with network support. A restart into safe mode is no longer a gap in coverage. |
| Endpoint | Devices running an unsupported operating-system version report that state explicitly, so an unprotected machine is visible in your fleet rather than silently absent. |
| Endpoint | Notifications share one format and tone across Windows, Linux and macOS. |
| Threat intelligence | Domain filtering draws on a broadened feed combining reputation and geolocation sources, which also powers the automatic timezone detection above. |
| Code Security | Findings and reports can be scoped to a specific branch. |
What this means for you
The default position for most teams is that source code gets scanned and the shipped artifact does not. That gap is where inherited operating-system packages sit, unowned, until something in them is disclosed. Container image scanning removes it, and because the image is assessed under the same finding, severity and risk model as the repository, you get one queue and one definition of critical rather than two of each.
On compliance, the case for a purpose-built platform is that evidence should come from the systems doing the security work. Three frameworks against one control library and one risk register is that case made concrete. Add cloud posture, VAPT and correlated logging from the same platform and your next gap analysis stops being an archaeology project.
Nothing here requires action from you. Container image scanning is live in Code Security today, and new frameworks activate from your compliance program whenever you want them. If you want a second pair of eyes on what to turn on first, container image scanning is the one most teams should look at before anything else.
Book a walkthrough
Want a tour of what is new?
We will walk you through container image scanning, the risk register and the new frameworks against your own setup, and help you decide what to turn on first.
Book a platform walkthroughAvailable now · No upgrade steps · One platform, everything
Frequently asked questions
Do I need to do anything to get release 9.3.1.0?
No. The release went out on 19 August 2026 and is already active on your account. Container image scanning appears in Code Security, and new compliance frameworks are activated from your compliance program when you want them.
What is container image scanning?
Container image scanning inspects the layers of a built container image for vulnerable operating-system packages and application dependencies, rather than only the source repository the image was built from. It assesses the artifact that will actually run in production.
How is container image scanning different from repository scanning?
Repository scanning covers source code, declared dependencies, secrets and infrastructure definitions written by your team. Container image scanning covers everything baked into the image, including base-image packages nobody on your team wrote. Both feed the same finding, severity and risk model, so results land in the queue you already work from.
Can I run SOC 2, ISO 27001 and HIPAA at the same time?
Yes. All three run together against a shared control library. A control mapped to more than one framework is satisfied once and counted in each, and tasks filter by framework. Osto prepares your controls and evidence; the audit itself is performed by an accredited external auditor.
Does the risk register export for auditors?
Yes. Risks, owners, likelihood and impact scores, treatment decisions, linked controls and residual scores export alongside the rest of your compliance evidence. The same register answers the risk-assessment requirement across all three frameworks.
Which operating systems does the endpoint agent cover?
Application Control covers Windows, Linux and macOS. One Linux build now serves Ubuntu 22, 24 and 26. Devices running versions outside the supported range report that status, so coverage gaps are visible rather than silent.

