Changelog

Tighter security checks between our services

We ran a full security review across the Forbidden Finance codebase and shipped everything it turned up. The changes tighten how our internal services authenticate to one another, so every request between them is verified rather than trusted, and they harden the checks on our email notification endpoints so those fail safely instead of quietly relaxing if they were ever misconfigured. We also moved a networking library up to its patched release.

Alongside one-off reviews like this one, we continuously scan our codebase with third-party security tooling and monitor the software the app is built on for newly disclosed vulnerabilities, patching them as they are identified.

None of this affected customer data, and there is nothing you need to do.