Squash updates
Customer-facing product, security, and service updates for Squash AI, Inc.
Last updated June 20, 2026
Key points
- Release channel
- This page records public updates that customers and prospects can use to track meaningful changes.
- Customer impact
- Entries call out whether customer action is needed, whether availability changed, and which service area changed.
- Support path
- Questions about an update can be sent to support@squash.ai or security@squash.ai, depending on the topic.
June 21, 2026 - Anonymous reporting channel
Release type: compliance operations.
Squash published an anonymous whistleblower reporting channel for good-faith ethics, compliance, security, privacy, retaliation, or workplace concerns.
Customer impact: no customer action required. The channel supports anonymous submission without account login, required identity fields, marketing analytics, ad tracking, lead-tracking scripts, or IP/browser details in the report payload.
Anonymous channel
The anonymous reporting channel is available at squash.ai/anonymous-reporting.
Confidential review
Reports are routed for confidential review by the limited people needed to assess, investigate, and respond.
June 21, 2026 - Vulnerability disclosure program
Release type: security and compliance operations.
Squash published a public vulnerability disclosure program and security.txt file so security researchers have a clear contact path, scope, safe-harbor expectations, and report format for suspected vulnerabilities.
Customer impact: no customer action required. This update improves public security-reporting transparency and supports ongoing security review.
Disclosure policy
The public disclosure program is available at squash.ai/vulnerability-disclosure.
security.txt
The machine-readable security contact file is available at squash.ai/.well-known/security.txt.
June 20, 2026 - Public website security headers
Release type: security improvement.
Squash updated the public website response headers for squash.ai, including an expanded content security policy, frame-ancestor controls, cross-origin isolation headers, permissions policy, referrer policy, content-type sniffing protection, and removal of the default framework powered-by response header.
Customer impact: no customer action required and no planned downtime. This update improves the public website security baseline and supports ongoing security review.
Service area
Public Squash website at squash.ai.
Validation
The updated headers were verified on the live public website after deployment.
June 20, 2026 - Recurring security evidence automation
Release type: security and compliance operations.
Squash added recurring report-only security evidence automation for the public website, including static application security testing, dependency security auditing, and OWASP ZAP baseline dynamic application security testing.
Customer impact: no customer action required. These evidence runs are scheduled or manual and do not block normal product releases or emergency fixes.
Coverage
The workflow records SAST, SCA, and DAST artifacts for review and audit evidence.
Release safety
The security evidence workflow is separate from normal pull request and deployment checks.
June 18, 2026 - Status and documentation access pages
Release type: customer support and service transparency.
Squash added a public system status page and a documentation access page so customers and prospects have clearer paths for service status, support escalation, and authenticated documentation access.
Customer impact: no customer action required. Customers can use the public status page for current service summary and support routing.
Status page
The public status summary is available at squash.ai/status.
Documentation access
The documentation entry point is available at squash.ai/docs for authorized documentation access.
Questions about an update?
For product or service questions, contact support@squash.ai. For security review questions, contact security@squash.ai.