Changelog¶
All notable changes to this project are documented here. The format is based on Keep a Changelog, and the project aims to follow Semantic Versioning once it reaches 1.0.
This project is pre-1.0: any change to detection thresholds, the asset manifest, or public result shapes may be breaking for downstream users, and is called out explicitly below.
[0.1.3] - 2026-08-11¶
Added¶
- Added public post-prediction hooks for filtering non-actionable credential and local-path evidence while retaining model predictions for diagnostics.
- Added precision-first, real-corpus calibration data and a local sweep tool for general Dynamic PII labels, plus benchmark coverage for names, dates of birth, cities, and countries.
Changed¶
- Expanded the default and document-aware Dynamic PII label sets with calibrated
first_name,last_name,date_of_birth,city, andcountryentities, and recalibrateddate.
Fixed¶
- Reduced false-positive DLP and MCP findings for template
.envcopies, empty or placeholder secret assignments, and low-entropy credential values. - Suppressed
personevidence when a detected name is only a username inside a local filesystem path. - Rejected loopback, multicast, unspecified, and truncated IPv6 candidates as PII, and rejected terminal metadata words and invalid zero postal codes as German postal addresses.
Breaking¶
- Dynamic PII findings and native PII/DLP/MCP decisions can change because label sets, thresholds, evidence filtering, and native validators were updated.
[0.1.2] - 2026-07-26¶
Added¶
- Added compact
.mmbpetokenizer generation for compatible mmBERT byte-fallback BPE tokenizers during verified downloads and cached warmup. The originaltokenizer.jsonremains the canonical fallback. - Added German imperative variants to the native
instruction_overrideL1 detector.
Changed¶
- Added the structured
decisionenvelope to model-backed classifier results. The envelope exposes the final Ark verdict, the canonical policy candidate, all typed L2/L3/Union candidates, Ark's calibrated recommendation, terminality, and minimal provenance. - Restricted
decisionto terminal authoritative classifier results. Early L2 results withl3_pending, provisional events, and result-preview events now leavedecisionunset so downstream policy consumers can key onresult.decision.is_some(). - Extended compact tokenizer asset preparation beyond Granite
.kitgeneration so supported mmBERT L2/L3 bundles can reuse hash- and version-invalidated generated artifacts. - Changed classifier default arbitration to preserve a calibrated default-class confidence when
the producing model exposes one, instead of always forcing
0.0.
Fixed¶
- Fixed promoted NTDB L2 fallback results so the final-decision threshold profile is still applied before publishing the fallback class.
- Fixed L2-only classifier arbitration so accepted candidates are selected from model label scores instead of the already defaulted top-level result.
- Fixed persistent
redbcache handling to recreate a missing or externally deleted database file while still surfacing corrupt databases and active second-writer conflicts as errors.
Breaking¶
- Removed the redundant NTDB L2
details.raw_class_nameanddetails.raw_confidencefields. Consumers should readdecision.decision_candidateanddecision.candidates[]instead. - Candidate arbitration data is no longer exposed as public
layers[].details.arbitration_*fields. The public contract is the top-leveldecisionenvelope.
[0.1.1] - 2026-07-26¶
Added¶
- Added bundled NTDB final-decision thresholds for L2, L3, and weighted L2/L3 union arbitration across classifier pipelines.
- Added request-local
enqueue(..., ntdb_operating_point=...)support for overriding the final-decision threshold profile on queued scans. - Added
threatvalidation samples to the built-in local benchmark.
Changed¶
- Changed classifier final arbitration to accept L3 first, then a weighted L2/L3 union, then L2, and otherwise return the pipeline default class.
- Changed Python's
ntdb_operating_pointmeaning to select the final-decision threshold profile; L2 promotion continues to use the NTDB package promote operating point and is not changed by that Python setting. - Changed the default final-decision threshold profile to
best_f1.
Removed¶
- Removed
tool_classvalidation samples from the built-in local benchmark fixture set.
Breaking¶
- Classifier result decisions can change because calibrated final-decision thresholds now apply to L2, L3, and union arbitration.
- Benchmark comparisons against previous local runs are not one-to-one for
tool_class, because the packaged benchmark fixture was removed andthreatwas added.
Added¶
- Added
normalize_text(text, configs={})as a pure text-normalization API for applyingcanonical_security_text_v1before scanning or for direct caller use.
Fixed¶
- Added a separate macOS Intel wheel build that pins
ortto2.0.0-rc.10, which still provides prebuilt ONNX Runtime binaries forx86_64-apple-darwin. - Kept macOS arm64, Linux, and Windows wheel builds on
ort2.0.0-rc.12.
[0.1.0] - 2026-07-24¶
Initial public release of Patronus Ark.
Added¶
- Hybrid Rust/Python security scanning library published as the
patronus-arkRust crate and Python package. SecurityGatewayfor synchronous scans and queued request processing.- Scan categories for prompt injection, DLP, PII, dynamic PII, sensitive documents, tool classification, tool actions, tool tags, routing, and threat detection.
- Layered scanning with native L1 detectors, NTDB L2 model packages, and promoted L3 ONNX models.
- Configurable model asset download and cache management.
- Configurable execution gates, L3 scheduling policy, L3 strategy selection, and ONNX backend options.
- Hot and persistent result caching.
- Built-in local benchmark runner with packaged benchmark fixtures.
- Rust and Python examples plus documentation for installation, quickstart, configuration, assets, result schema, and release/testing workflows.
Notes¶
This is the first public changelogged release. Future releases will record Added / Changed / Deprecated / Removed / Fixed / Security sections here.