← Security & Trust
SECURITY CHANGELOG

Security changelog

A running log of security improvements we ship. We publish fixes, not exploits. Entries are append-only and stay published permanently.

2026-10-09Latest
Session security hardening
  • Instant server-side revocation: a per-user revocation epoch now invalidates previously issued tokens the moment a password is changed or reset, or the user chooses "Sign out of every device" — no waiting for token expiry.
  • Shorter token lifetimes: access tokens reduced from 24 hours to 15 minutes, with refresh-token rotation and reuse detection (a reused copied token revokes the whole chain).
  • Logout hardens the session: a normal logout now forces a refresh-token rotation, so a previously captured refresh token becomes useless.
  • Automatic sign-out on rejection: clients immediately sign out when a session is rejected server-side.
  • First-party authentication domain: sign-in and sign-out now run on auth.usezn.com instead of exposing the underlying identity-provider tenant.
  • Branded error handling: identity errors now show a usezn-branded page, and expired sessions land on the login page with a clear "session expired" notice instead of a broken redirect.

Thanks to the independent researchers credited in our Security Hall of Fame — reports like theirs are how these improvements happen. Found something? Contact security@usezn.com.