Deploy faster. Secure honestly. Operate with confidence.
Deploy, secure, monitor, and connect your applications from one powerful platform. Manage reverse proxies, apps, Docker, certificates, WAF, Security Center, VPN mesh, and cluster operations without stitching together ten different tools.
A complete development and production web stack that runs from any folder. No installation, no registry changes, no admin required.
Apache 2.4 reverse proxy with TLS 1.2/1.3, SNI multi-domain support, Let's Encrypt automation via bundled win-acme, self-signed cert generation with bundled OpenSSL. Auto-detects cert paths and generates vhost configs.
Start, stop, and monitor backend apps with health checks, auto-restart on crash, and multi-stage sub-processes. Run Supabase + npm dev simultaneously. Auto-accept prompts for npx/npm commands. Per-app environment variables.
Drop a .zip/.7z project onto the Dashboard and ProxyStack extracts it, detects the stack — Node.js, Bun, Python, Go, .NET, Java, Ruby, PHP, Rust, Deno, Docker Compose, or a raw Dockerfile — and dry-runs executable stacks through the Process Reputation sandbox before ever presenting a command as trustworthy. Frontend builds can deploy as a static Site instead of a long-running process. Docker Compose imports get their own managed project tab with rollback, service status, profile/service selection, and logs. Auto Build shows a build plan, env-var guidance, and failure logs before you guess at fixes. Every import's full evidence trail is logged permanently.
Full Docker container management with Compose up/down, image pull, container logs. Portable PostgreSQL with one-click auto-install and progress bar. Database console for direct SQL queries. Supabase health monitoring.
Connect to your SentinelAI dashboard for 25+ real-time security monitors, 3-stage ML threat detection (local ML → heuristics → AI), ransomware canary files, fleet management, and remote agent commands.
10 automated checks against the OWASP Top 10 2025. Security score 0–100 with pass/fail breakdown per category. Color-coded OWASP cards for A01 through A10. Export compliance reports as CSV or TXT.
14 built-in rules covering SQL injection, XSS, path traversal, command injection, SSRF, and more. Custom rule editor with regex patterns. Block-mode rules are enforced inline (real 403s, not just logging) whenever the pattern can be safely compiled into config, on both Nginx and Apache. Export as ModSecurity .conf for a separately installed ModSecurity module.
Quick Scan (11 checks) and Full Scan (18 checks) covering TLS config, headers, directory permissions, secrets exposure, network ports, containers, database security, and more. Severity breakdown: Critical, High, Medium, Low. Async scanning with progress bar. Results persisted and exportable.
DPAPI-encrypted key-value store (Windows CurrentUser scope). 8 categories: General, Database, API Key, OAuth, SSL/TLS, Cloud, Service, Internal. Reveal with 5-second auto-hide. Copy with 30-second clipboard auto-clear. One-click rotation with 32-char cryptographic random. Export as .env file. Backward compatible with legacy format.
4 frameworks: SOC2 Type II (9 controls), GDPR (6 articles), PCI-DSS v4.0 (8 requirements), HIPAA (5 safeguards). "All Frameworks" mode runs all 28 checks at once. Each check evaluates real config and provides evidence. Compliance score with pass/fail/N/A. Export as CSV or formatted TXT.
mTLS (mutual TLS) toggle with CA certificate generation (RSA 4096-bit, 10yr) and server certificate generation (RSA 2048-bit, 2yr) with auto-SAN from configured domains. Certificate-based auth policies: CN, OU, Issuer, Fingerprint, SAN match. Network segmentation zones with CIDR, port, and direction rules. Trust score 0–100. Export Apache .conf with SSLVerifyClient and SSLRequire directives.
Unified status + threat timeline across WAF, SentinelAI, Cluster, Microsoft Defender, ClamAV, and Headscale VPN. Process Reputation monitors every ProxyStack-managed app's processes in real time - deterministic risk scoring, VirusTotal hash lookup, explicitly-gated sample submission, isolated low-privilege sandbox detonation, and policy enforcement (Kill/Quarantine/Block/Isolate/Approve), manual or fully automatic.
Real-time CPU, RAM, and disk metrics. Real request rate and error rate parsed from live Nginx access logs. Latency percentiles shown when computable, honestly reported as unavailable otherwise - see Proof Status. Custom alert thresholds with email and Slack notifications.
Multi-user RBAC with admin, editor, and viewer roles. Audit logging for all config changes. Share complete stack configs via .psxt templates (v1.1 bundles SSL certs as base64). Slack webhook notifications. Import creates missing site directories automatically.
Rate limiting per-IP and per-route (Nginx). Automated config backups with rotation. Load balancing across multiple backends. SSL certificate expiry monitoring via the Cert Expiry Notifier plugin. Remote management REST API for headless operation.
REST API v2.0 with 20 endpoints for remote management. Real plugin runtime with 6 bundled starter plugins and a hosted marketplace for more. Multi-server cluster management with config sync, plus optional VPN mesh join. VS Code extension, CLI tool, 19 service blueprints (Next.js, Django, Flask, Express, etc.).
Request/response rewriting with regex. HTTP caching layer with Redis support. API gateway with path-based versioning. Dark/light theme toggle. Auto-update system with SHA256 integrity verification and rollback. Classic UI mode via --classic flag.
One-click PostgreSQL auto-install with progress bar. Start/stop/restart from the GUI. Database list, create/drop databases, and a built-in SQL query runner. No Docker required — runs as a portable binary from the postgres/ folder.
Dedicated Certificates view for managing all SSL certs. Let's Encrypt automation via bundled win-acme (HTTP-01 validation). Self-signed cert generation via bundled OpenSSL. Auto-detect cert paths by domain name. Certificate expiry monitoring with alerts.
Real hook-based plugin runtime: 6 bundled starter plugins (Uptime Pinger, Cert Expiry Notifier, Deploy Webhook Notifier, Brute-Force IP Blocker, Config Git History, Daily Ops Digest), all disabled by default. Browse and one-click install more from the hosted marketplace, SHA256-verified, or install your own from a local ZIP.
Multi-server node management from a single dashboard. Add remote ProxyStack instances, monitor health status, and push configuration to secondary nodes. Auto-refresh every 30 seconds. Enterprise license required.
Built-in license activation on the Dashboard. Community (free), Pro, and Enterprise tiers with runtime feature gating. Stripe integration for checkout. License API (FastAPI) for validation, deactivation, and admin management. 14-day Pro trial included.
Centralized log viewer for Apache access/error logs and per-site logs. Real-time log tailing. Application settings management with theme toggle, auto-start configuration, and environment profile switching. All from dedicated Logs and Settings views.
From download to production in under 5 minutes.
Download the portable ZIP (~138 MB). Extract to any folder. No installer needed.
Run ProxyStackGUI.exe. The modern dark-themed GUI opens with 22 sidebar views ready to use.
Configure domains, backends, and SSL certs from the Sites tab. Apache vhosts are auto-generated.
One click to start Apache. Your reverse proxy is live with TLS, security headers, and WAF protection.
Click any view to see what's inside. Every feature accessible from a modern dark-themed control panel.
Unzip and run. No installation, no registry changes, no admin required. Built-in auto-updater keeps you current.
Single-binary, self-contained, no runtime needed. Docker, secure import, security scanning, backups, SentinelAI, monitoring — the portable control plane from the terminal.
All builds also available via GitHub CI/CD with automated tests
Linux Quick Start → One-liner install instructions
Cross-platform endpoint security agent — monitors processes, network, files, auth logs, cron jobs, and SSH keys. Reports to the SentinelAI dashboard with ML-powered threat detection.
macOS and ARM64 agent builds coming soon · SentinelAI Dashboard →
Every release is scanned with 70+ antivirus engines. Transparency matters.
ProxyStack GUI runs on Windows with .NET 8. The CLI runs on Windows and Linux with zero dependencies.
Get notified about new releases, security advisories, and tips.
Recent updates and improvements across all releases.
proxystack ai ... in the CLI, on Windows and Linux (real end-to-end WSL2 Ubuntu verification, including a real NVIDIA GPU detected through nvidia-smi passthrough).serve command had zero authentication on its mesh-join/promote/config-sync endpoints - any client that could reach the port could make the target machine join an attacker-controlled VPN mesh or overwrite its own config, with no credentials at all. Now gated by a constant-time API key check, fail-closed by default. Separately, the Classic UI's REST API toggle displayed a hardcoded "loopback-only" status while actually binding all interfaces key-less - fixed to generate/reuse a real key and show the real reachability state.ObjectDisposedException from a background update callback racing the app's own shutdown. Fixed with a defensive invoke helper across every affected call site, verified with a harness that reproduces the exact race before confirming the fix stops it. Confirmed live: closing the app via the title-bar X with no manual workaround, no crash.proxystack serve command now does too - live-verified end-to-end with a real Linux node joining a real coordinator, independently confirmed online from the coordinator's own records, not just the client's self-report.whoami /groups run from inside the sandboxed process itself, not inferred from an API success code.config/waf-apache.conf gives Apache the same real inline enforcement Nginx got in v14.7.0, via RewriteCond/RewriteRule - verified against a live sandboxed Apache instance with real requests, not just unit tests.config/waf-nginx.conf as native if (...) { return 403; } conditions - verified against a live Nginx instance with real requests, not just unit tests.logs/waf-threats.jsonl (was logs/waf.log) with every matched rule, severity, and whether the request was blocked or only detected.checks object used the literal key apache even when Nginx was active, so a Nginx user saw a confusing apache: true. Renamed to webServer, matching /api/status's existing engine-agnostic field.plugin.json manifest declares an entry script and which lifecycle hooks it subscribes to — server start/stop, config changes, or a 5-minute scheduler tick. Every run is logged per-plugin with a timeout so one broken plugin can't hang the app.openssl.cnf in release ZIPs for packaged certificate workflows.cloud deploy via SSH, cloud status remote health check, cloud setup-script for Ubuntu EC2. Full cloud-init script for automated provisioning.serve Command: Lightweight API server on port 9090 for remote cluster nodes — enables GUI health checks, config sync, and promotion across cloud instances.curl | tar xz && sudo ./install.shhttp2 on; directive for Nginx 1.25.1+Release history. We recommend always using the latest version.
| Version | Date | Highlights | Full | Lite |
|---|---|---|---|---|
| v{{VERSION}} (latest) | Jul 20, 2026 | Secure Project Import: competitive expansion. Ten more stacks recognized (Bun, Go, .NET, Java, Ruby, PHP, Rust, Deno, plus Dockerfile as a broad fallback with automatic image build/run). Docker Compose imports become managed, persisted projects with lifecycle actions, service status, profile/service selection, version history, and rollback, with published-port preflight before every up. Frontend builds can deploy as a static Site instead of a long-running process. Auto Build adds a build-plan preview, env-var guidance, and logs/fix guidance when a container does not listen. Also fixes a generated-command port mismatch for Flask/Django/Vite, a Docker Compose file-picker/refresh bug, and a live SSL cert/key mismatch incident. | Download | Download |
| v14.18.0 | Jul 20, 2026 | Secure Project Import. Drag a .zip or .7z project onto the Dashboard or Apps view and ProxyStack extracts it, detects what it is (static site, Node.js, Python, or Docker Compose), and - for Node.js/Python - dry-runs it through the existing Process Reputation sandbox in two phases (install/build, then a stricter runtime smoke test) before ever presenting it as trustworthy, always against a disposable copy, never the real extracted folder. Full behavioral telemetry from both phases is captured and classified rather than filtered. Opens the existing Add Site/Add App dialog prefilled with a risk banner; nothing is ever auto-saved or auto-started. Every import writes a full evidence record to logs/deploy-imports.jsonl. | Superseded by v14.19.0 | |
| v14.17.7 | Jul 9, 2026 | Critical fix, updated same day. A real update attempt from v14.17.5 surfaced 3 more real bugs, all now fixed in this same version (no new version number - just a corrected re-release). The in-app updater's checksum check had been comparing against the wrong hash entirely, so every download failed with "Checksum mismatch" regardless of whether it was actually fine - fixed to the real, verified value. The same missing-runtime-file crash PostgreSQL had also affected Apache's httpd.exe and openssl.exe - fixed the same way. And the PostgreSQL status check could itself throw an error if a quick check took slightly too long - now handled gracefully. Also includes the original fix: bundled PostgreSQL was crashing repeatedly on fresh installs with a missing-runtime-file error, and a page was showing literal placeholder text instead of the real version number. | Superseded by v14.18.0 | |
| v14.17.6 | Jul 9, 2026 | Added a real "Contact Support" option inside the app itself (Settings) - previously the only way to file a ticket was the website. Added a Support link to the navbar on every page of the site, not just two obscure legal pages. Built a real way for us to write and send an update to newsletter subscribers, which surfaced and fixed a real email-delivery bug along the way. | Superseded by v14.17.7 | |
| v14.17.5 | Jul 9, 2026 | Critical fix. A customer testing on a genuinely clean VM hit a fatal crash on every launch of a fresh install. Reproduced it by extracting the actual shipped ZIP into total isolation - the release packaging script had only ever copied part of what .NET needs for one specific system-info package, missing a required subfolder on every release. Invisible to our own testing because we'd always tested from the full build output, never the exact narrowly-packaged ZIP a real customer downloads. Fixed, and re-verified the same way the bug was found - a fresh isolated extraction now launches correctly. | Superseded by v14.17.6 | |
| v14.17.4 | Jul 9, 2026 | GUI-only fix, CLI unaffected. Prompted by a user question about what actually happens when you click Deactivate. Found it only ever reset local state - it never told the license server to unbind this machine's hardware ID, which is the whole point of deactivating (so the same key can be used on a different machine). Fixed to call the real endpoint first, requiring an internet connection to do it rather than let you think a license is freed up when it isn't. Also added a "View Plans & Pricing" link to the License panel - previously there was no way to actually go buy a license from inside the app despite "Upgrade to unlock" messaging on locked features. | Superseded by v14.17.5 | |
| v14.17.3 | Jul 9, 2026 | GUI-only fix, CLI unaffected. User-reported via screenshot: the Dashboard's License panel had a "Refresh" button (shown next to Deactivate once a license is active) clipped to a 5px sliver, cut off by the panel's own edge - the panel was 350px wide but the button's right edge sat well beyond it. Widened the panel to fit. | Superseded by v14.17.4 | |
| v14.17.2 | Jul 9, 2026 | A customer reported a real, live 403 Forbidden on two production sites, reachable from one specific device only - not a VM/network issue as first suspected. Root cause: the WAF's built-in SSRF rule blocked on the substring "0.0.0.0", and modern Chrome's frozen browser-version suffix ("Chrome/150.0.0.0") spells that out whenever the version number ends in 0 - silently blocking roughly 1 in 10 Chrome visitors on every install with default WAF rules. Fixed without weakening real SSRF detection (verified live); existing installs self-heal automatically. Also closed a CLI onboarding gap found in the same investigation: a fresh CLI download had no way to create its own config from nothing, leaving a new user stuck on the very first command - now bootstraps automatically, matching how the GUI has always worked on first launch. | Superseded by v14.17.3 | |
| v14.17.1 | Jul 8, 2026 | Trust/polish/consistency pass - no new major features. Re-verifying Cluster mesh join against a real second Windows machine found and fixed 3 more real bugs: the REST API server only listened on "localhost" (rejecting even the machine's own real LAN IP - now fixed and reachable from other machines), the modern GUI had no way to turn the REST API on at all (previously only the old classic interface could), and installing the VPN client silently reported success even when it actually failed for lack of admin rights (now verified for real, with a proper admin-permission prompt). Also fixed a fake "Restore" button that opened a file picker and then did nothing, email alerts that silently failed even when configured correctly, and a wide sweep of outdated documentation and website claims. | Superseded by v14.17.2 | |
| v14.17.0 | Jul 8, 2026 | Real per-country geo-blocking (free ipdeny.com CIDR data, genuinely enforced on Nginx + Apache, replacing a checkbox that did nothing). Cluster VPN mesh join now works from Linux/macOS too, not just the Windows GUI - live-verified with a real node joining a real coordinator. Found and fixed 3 real bugs along the way, including a coordinator config that only listened on localhost. VM Sandbox network detection now watches continuously instead of checking once at the end, and a new "Test Sandbox" button verifies all 6 setup steps in one run. Added a live demo and an honest per-feature Proof Status page. | Superseded by v14.17.1 | |
| v14.16.0 | Jul 8, 2026 | Added the VM-isolation sandbox tier - samples now run inside a genuinely separate OS (a customer-provisioned VirtualBox guest VM), not on the host at reduced integrity. ProxyStack never bundles or licenses the guest OS, only orchestrates it; falls back automatically to the existing low-integrity tier if not configured. Found and fixed two real bugs via live testing: a Windows command-line quoting issue that silently corrupted VirtualBox commands, and Windows Memory Integrity (HVCI) silently breaking VM startup if enabled. Verified live end-to-end including the snapshot-restore revert cycle itself. | Superseded by v14.17.0 | |
| v14.15.0 | Jul 7, 2026 | Added ProxyStackVPN, a first-party-branded client for the existing Headscale mesh (self-compiled from Tailscale's open-source daemon, Windows service/adapter renamed from "Tailscale" - zero changes to the Headscale server itself). Added NetBird as a second, independently-toggleable VPN Mesh backend - client-only by design, since NetBird's own server is AGPL-3.0 licensed; you run your own NetBird server, same relationship ProxyStack already has with Docker. Also live-verified a previously-unconfirmed Headscale node mapping using a real WSL2 Linux peer. | Superseded by v14.16.0 | |
| v14.14.1 | Jul 7, 2026 | Closed the last known gap in the token-unlock fix - a customer who never had any Pro/Enterprise/Trial license had no license_key at all, so a feature unlock purchased via tokens still couldn't reach their desktop install. Redeeming a feature unlock now mints a Community-tier "identity anchor" license the first time (no expiry, grants no tier upgrade by itself), returned so the user knows to activate it. Verified live with a fresh test account that had zero license history before the test. | Superseded by v14.16.0 | |
| v14.14.0 | Jul 7, 2026 | Fixed a real monetization bug - token-purchased feature unlocks (Docker, Plugins, Security Center, etc.) had zero effect on the desktop app for any customer, ever. Fixed end-to-end: license validation now returns and applies active unlocks, with a new Dashboard "Refresh" button so a purchase doesn't sit invisible for up to 7 days. Also fixed: Security Center was missing from the purchasable list; "+1wk Trial Extension" was also a no-op (now server-backed); "Cloud Backup" was sold with no real feature behind it (rebuilt into real Scheduled & Automated Backups with an actual timer and retention cleanup). | Superseded by v14.16.0 | |
| v14.13.1 | Jul 7, 2026 | Fixed Security Center provider cards overlapping/cutting off text (a real rendering bug in the shared status-tile control, found via a user screenshot). Added a manual "Update Signatures Now" button for ClamAV, so an "ActionNeeded - run an update" status has an on-demand fix instead of only an unattended 24-hour background timer. Refreshed the front page hero copy to "The Portable DevSecOps Control Plane for Modern Web Apps", with matching meta/OG/Twitter/JSON-LD updates. | Superseded by v14.16.0 | |
| v14.13.0 | Jul 7, 2026 | Real Windows Low-integrity sandboxing - the sandbox detonation feature now actually launches the sample at Windows Low Mandatory Integrity Level (confirmed via whoami /groups from inside it), not just inside a scoped temp directory. Found and fixed two real bugs along the way (a privilege requirement in the first approach, and a .NET Process quirk). Also fixed real front-page gaps: added a missing Security Center card and corrected stale "21 views"/"18 endpoints" text throughout, and filled in missing ClamAV/Headscale FAQ entries. |
Superseded by v14.16.0 | |
| v14.12.0 | Jul 6, 2026 | Automatic sandbox detonation for Process Reputation (opt-in) - a flagged-but-unresolved process now gets a real isolated-sandbox run automatically, not just via the manual button. Verified the two Administrator-gated Phase 5 actions (real-time block watcher, network isolation) at full elevated strength. Corrected Windows Home edition virtualization docs (Hyper-V role/Windows Sandbox are blocked, but the underlying hypervisor tech that powers WSL2 isn't, and third-party hypervisors like VirtualBox work fine) and added an honest comparison to AVG CyberCapture. | Superseded by v14.16.0 | |
| v14.11.0 | Jul 6, 2026 | Process Reputation: all 5 phases of the SentinelAI Detonation Engine are real. Real Windows process-tree monitoring with deterministic risk scoring (Phase 1), pluggable hash reputation lookup including VirusTotal (Phase 2), explicitly-gated sample submission with a privacy warning (Phase 3), real isolated-process sandbox detonation (Phase 4), and real policy enforcement - Kill/Quarantine/Block/Isolate-network/Require-approval, manual or fully automatic once explicitly enabled (Phase 5). Detect/warn only by default. | Superseded by v14.16.0 | |
| v14.10.0 | Jul 6, 2026 | ClamAV and Headscale VPN went from honest stubs to real: bundled/PGP-verified ClamAV with real scans/quarantine (Full edition), Headscale compiled from source with an opt-in local VPN mesh coordinator (Full edition). Lite gets both via a real in-app "Download & Install" instead of bundling them. Cluster can join a node to the VPN mesh when adding it. | Superseded by v14.16.0 | |
| v14.9.0 | Jul 5, 2026 | Security Center: a new provider-based framework unifying WAF, SentinelAI, Cluster, and new antivirus/VPN providers into one status view and threat timeline. Real Microsoft Defender integration (scans, remediation, exclusions, live-verified). ClamAV and Headscale VPN shipped as honest detection-only stubs at the time. Enterprise tier. | Superseded by v14.16.0 | |
| v14.8.0 | Jul 5, 2026 | Apache reaches WAF inline-blocking parity with Nginx (config/waf-apache.conf) - verified against a live sandboxed Apache instance. Fixed two real Apache escaping bugs found via live testing and a WAF-009 (XXE) encoding bug affecting both engines. | Superseded by v14.16.0 | |
| v14.7.1 | Jul 5, 2026 | Self-updater reliability fixes: it now actually stops Nginx before applying an update (was missing from the process list entirely), a failed update relaunches the GUI so services come back up instead of staying down, truncated downloads are detected instead of silently corrupting the install, and SHA256 verification is actually invoked. | Superseded by v14.16.0 | |
| v14.7.0 | Jul 5, 2026 | Real WAF engine - Nginx now actually blocks matching requests inline (config/waf-nginx.conf), not just logs them, via a shared rule engine also used by the runtime monitor and a new Test WAF Rule tool. Apache remains detection-only by design. 2 new built-in rules (14 total). | Superseded by v14.16.0 | |
| v14.6.2 | Jul 4, 2026 | Fixed a misleading /api/health field name, ran a full documentation accuracy pass (JWT/HMAC, plugin system rewrite, removed WAF/geo-blocking overclaiming), and fixed a widespread source-file encoding corruption | Superseded by v14.7.0 | |
| v14.6.1 | Jul 4, 2026 | Apache mTLS Parity + Certificate Auth Policies + Network Segmentation + Real WAF Detection - Apache installs get the same mTLS enforcement Nginx got in v14.6.0; auth policies and network segmentation zones are now enforced; WAF threat log now populated by a real access-log detection engine | Superseded by v14.6.2 | |
| v14.6.0 | Jul 4, 2026 | Real mTLS Enforcement + Opt-In RBAC - Zero Trust mTLS and security headers now actually applied to Nginx config; Team tab RBAC enforcement; cluster promotion fix | Superseded by v14.6.1 | |
| v14.5.2 | Jul 4, 2026 | Real Alert Monitoring + Rich Discord Embeds - Settings alerts now actually monitor server state instead of test-only; Restart fires hooks/alerts; rich embed cards | Superseded by v14.6.0 | |
| v14.5.1 | Jul 4, 2026 | 3 More Starter Plugins - Brute-Force IP Blocker, Config Version History (git-backed), Daily Ops Digest; 6 starter plugins total | Superseded by v14.6.0 | |
| v14.5.0 | Jul 4, 2026 | Real Plugin Runtime + Hosted Marketplace - plugins execute on real lifecycle hooks, SHA256-verified one-click install, 3 bundled starter plugins | Superseded by v14.6.0 | |
| v14.4.0 | Jul 4, 2026 | Discord Alerts + SentinelAI Agent Fix - Discord webhooks alongside Slack, fixed agent false positives on legitimate Windows processes | Superseded by v14.6.0 | |
| v14.3.9 | Jul 4, 2026 | REST API Security Hardening - mandatory API keys on mutating endpoints, real observability metrics, removed placeholder plugin catalog | Superseded by v14.6.0 | |
| v14.3.8 | Jul 4, 2026 | Config Safety + Nginx Process Fix - fixed config clobbering and duplicate nginx processes | Superseded by v14.6.0 | |
| v14.3.7 | May 31, 2026 | Windows Agent Launch Fix - bundled agent launches without requiring Python, Trivy scanner included | Superseded by v14.6.0 | |
| v14.3.6 | Apr 15, 2026 | Certificate Packaging Fix - bundled OpenSSL config, fixed packaged cert generation, updater metadata refresh | Superseded by v14.6.0 | |
| v14.3.3 | Mar 12, 2026 | Update & Versioning Fixes - v14.3.3 links, app version sync, startup reliability improvements | Superseded by v14.6.0 | |
| v14.3.2 | Feb 22, 2026 | Stability & SSL Fixes - CertsView freeze fix, GameSense proxy, Sentinel agent improvements | Superseded by v14.6.0 | |
| v14.3.1 | Feb 15, 2026 | Phase 22.5: UX Polish & Safety - prune previews, search boxes, context menus, enhanced confirmations, bug fixes | Superseded by v14.6.0 | |
| v14.2.1 | Feb 12, 2026 | Token Rewards & Admin: referral system, token wallet, 30-day feature unlocks, admin roles, HTTP/2 fix | Superseded by v14.6.0 | |
| v14.1.0 | Feb 12, 2026 | Full Nginx support - rate limiting, caching, load balancing, HTTP/2, access control, Reload button | Superseded by v14.6.0 | |
| v14.0.0 | Feb 12, 2026 | Plugin Marketplace (20 plugins), REST API v2.0, Cluster Management, 21 views | Superseded by v14.6.0 | |
| v11.6.1 | Feb 11, 2026 | Monetization & Licensing — Stripe, License API, PostgreSQL view | Superseded by v14.6.0 | |