← Security & Trust
SECURITY CHANGELOG
Security changelog
A running log of security improvements we ship. We publish fixes, not exploits. Entries are append-only and stay published permanently.
2026-10-09Latest
Session security hardening- Instant server-side revocation: a per-user revocation epoch now invalidates previously issued tokens the moment a password is changed or reset, or the user chooses "Sign out of every device" — no waiting for token expiry.
- Shorter token lifetimes: access tokens reduced from 24 hours to 15 minutes, with refresh-token rotation and reuse detection (a reused copied token revokes the whole chain).
- Logout hardens the session: a normal logout now forces a refresh-token rotation, so a previously captured refresh token becomes useless.
- Automatic sign-out on rejection: clients immediately sign out when a session is rejected server-side.
- First-party authentication domain: sign-in and sign-out now run on auth.usezn.com instead of exposing the underlying identity-provider tenant.
- Branded error handling: identity errors now show a usezn-branded page, and expired sessions land on the login page with a clear "session expired" notice instead of a broken redirect.
Thanks to the independent researchers credited in our Security Hall of Fame — reports like theirs are how these improvements happen. Found something? Contact security@usezn.com.