Connect your social profiles so the Launchpad analytics page shows live numbers instead of demo data.
Security
Dated remediation log for the current Henshu release. This tab appears in Settings for the platform super administrator.
✓ Current release status
Source-code remediation status for the current release. Dependency audit status is verified during release checks; this page also records outstanding non-code governance work and is not a substitute for incident monitoring or access reviews.
2026-08-02 — security remediation
2026-08-02 — credentials and realtime authentication Reusable session tokens were removed from application URLs. API requests use Authorization headers and realtime authentication happens in the first WebSocket message. Browser-native previews, downloads, and OAuth pop-ups use a protected same-site cookie instead. The release invalidates sessions issued before this change, so everyone signs in again once.
2026-08-02 — outbound automations and request limits Automation webhooks are HTTPS-only and block private/reserved destinations, URL credentials, and unsafe redirects. Public review comments and data-deletion requests now have targeted rate limits; ordinary JSON requests are capped at 16 MB while streamed file uploads remain available.
2026-08-02 — Home load reliability Concurrent browser calls for My Tasks now share one in-flight request, reducing duplicate scans and queueing on the single production instance. Release automation runs security, authentication, billing, performance, loading-state, and comment-rendering checks before deployment.
Stored cross-site scripting: profiles Profile images and banners now accept only HTTPS or Henshu upload URLs. Existing invalid stored image values are cleared on read, and avatar rendering escapes attributes or builds image nodes directly.
Stored cross-site scripting: card descriptions Rich descriptions are sanitized at every board write and read, including item templates. Real-time description relays receive the same server-side sanitization before other users can render them.
Workspace isolation Board access is now enforced by authentication itself, so new authenticated routes cannot omit tenant checks. Access guards fail closed, and the legacy “all root users” fallback was removed: cross-workspace staff access requires an explicit Team Access membership.
Outbound link previews Link-title lookups are restricted to supported HTTPS providers. Redirects are handled manually and every destination is checked again, preventing the endpoint from fetching arbitrary internal addresses.
Dependency maintenance Production dependencies were updated, including Express 4.22.2, ws 8.21.1, and Nodemailer 9.0.3. The release verification command reports zero production dependency vulnerabilities.
Request attribution and reliability Proxy trust is limited to a configurable hop count instead of all forwarded headers, which protects IP-based rate limits. The Google Drive card-rename path now preserves the old title before invoking Drive sync.
Ongoing controls
Review each workspace’s Team Access list before granting staff access; an empty list grants no cross-workspace access.
Keep the production dependency audit at zero before release and update this dated log when security behavior changes.
Henshu is not SOC 2 certified from this release alone. Certification requires operating controls and audit evidence, including access reviews, vendor management, incident response, backup/restore testing, and an independent audit.
Privacy and retention work remains: complete the data map and end-to-end deletion/retention process across boards, comments, files, integrations, analytics, backups, and subprocessors before making a complete compliance claim. Legal review is required for notices, terms, a DPA, and jurisdiction-specific obligations.
The production data bucket’s legacy project-level object-reader convenience role needs a separately approved least-privilege IAM change after dependency verification. It is an internal access-control cleanup, not a public-bucket finding.
Danger Zone
Irreversible actions. Everything here asks twice.
Restart Everything
Restarts the Henshu server, public website, and Cloudflare tunnel. Site will be briefly unavailable.
Templates
Manage the board templates used when creating new client workspaces. Pick the default onboarding template here, then open any template workspace to edit its actual board structure.
Templates live here in Workspace Settings and feed the onboarding template dropdown.
Board Templates0
Name
Workspace
Users
Status
Actions
New client workspaces are cloned from whichever board template you choose during onboarding. Template names, default selection, and activation live here. Template content is edited by opening the template workspace itself.
Dashboard Layout Templates
Save and apply dashboard widget layouts across workspaces.
No templates yet. Save your current layout to get started.
Personal Settings
Manage your account profile and preferences.
Name
—
Email
—
Role
—
Theme
Notifications
No notifications yet
Members
0 selected
0 selected
Add Widget
Add Automation
IF
,THEN
Upload Emotes
Drop images here or browse
PNG, GIF, WebP, APNG — max 4MB each
ESC
🐍 SNAKESCORE: 0BEST: 0
Press SPACE or ENTER to start
WASD / Arrow Keys to move · ESC to close · R to restart