This is a SaaS-only update
Release date: Dec 16, 2024
Back end version: v7.113.0
Front end version: v2.126.3
Scanner version: ???
Workflows version: v1.13.0
Keycloak v25.0.2
CalypsoAI SDK ??? > 2.14.0
Admin Export/Import Version 6
Red team early access
We’re thrilled to announce the alpha release of our new CalypsoAI Red Team product. This groundbreaking product allows organizations to launch adversarial attacks against AI models and applications with the click of a button. It combines automated, scalable assessments with over 10,500 static prompts and advanced agentic and operational attacks, including customizable scenarios, to generate actionable vulnerability reports.
CalypsoAI Red Team is available now via an early access program and will be generally available on March 31. For more information, contact our sales team.
Features
OpenAI-compliant APIs
We’ve released a powerful new addition to our product: support for OpenAI-compatible APIs. This feature allows you to seamlessly connect and leverage AI models that adhere to the OpenAI API standard, expanding your options beyond OpenAI's offerings.
Key benefits:
Increased flexibility: Integrate with a wider range of AI models and providers, including agentic models.
Familiar interface: Use the same tools and workflows you're accustomed to with OpenAI.
Enhanced customization: Choose models that best fit your specific needs and budget.
Future-proof: Stay compatible with the growing ecosystem of OpenAI-compliant tools and services.
Updates to logs UI
We’ve added more filtering options to our Prompt History logs UI to make it easier to find exactly what you’re looking for. You can now:
Multi-select filter by groups.
Multi-select filter by providers.
Show only prompts that were sent via CalypsoAI’s Playground.
Enhanced Security: Multi-Factor Authentication and SAML 2.0 Support
We’ve made two major security enhancements to our product: Multi-Factor Authentication (MFA) and SAML 2.0 support. These additions significantly boost your account security and streamline enterprise-level access management.
Multi-factor authentication
MFA adds an extra layer of security to your account by requiring a second form of verification in addition to your password. To enable MFA in your SaaS or on-premises deployment:
Navigate to Settings > Organization
Toggle on MFA
Super admins can also reset MFA for individual users who’ve been locked out or lost their token.
SAML 2.0 support
SAML 2.0 integration allows enterprise customers to use their existing identity provider for single sign-on (SSO), simplifying user management and enhancing security. Benefits:
Centralized user authentication
Reduced password fatigue
Improved compliance with security policies
To get SAML 2.0 set up for your organization, please contact support. You’ll need to provide:
The login URL for your IDP
An X509 signing certificate
Your email domain or domains (if more than one).
Bugs
Blank user column for scans. The user column for scans was previously blank but now it will show the name of the API token used
Chat should still be disabled after clicking New Chat. If no providers are configured, we show a banner in the chat view stating this and prevent the user from sending a prompt until a provider is chosen. Previously, the user could click New Chat
to get around this and end up in a broken state. Now, clicking New Chat
will still display the banner, but disable the chat until a provider is chosen.
Show error log for custom providers. Our new error log display in Model Configurations was only showing for our set providers. Now it will also show if there is an error when creating a custom provider.
Improvements to Keycloak MFA.Users that previously had MFA enabled will have it disabled if the setting is turned off across the organization.
Expired badge still shows after generating new invite link. Previously, when an “Invite” link was expired, clicking Generate Invite Link
would generate a new valid link, but the “Expired” badge would still be shown in the table. Now it reverts back to the “Invite” badge.
Broken page when navigating to the groups tab of Model Configurations. If no groups were set up and you navigated to the Groups tab of the Model Configuration screen, the page would enter an error state. This has been fixed.
Record Prompts. Toggling off the Prompt Logs
switch on the Logs screen will now stop the recording of prompts across the organization.
Sunset features: Disclosures
We’ve sunsetted the “Disclosures” feature from Chat settings, due to lack of adoption
Known issues
Users with admin privileges (those who have
Basic Role
but areAdmin of a Group
) are able to see Global logs. They should only see the logs of the groups they are admin of.They are also given an
Insufficient permissions
error when trying to click retain logs. (They either should have ability to do so for only their groups, or not see the functionality at all - aka missing permission handling for Admins in Logs view)Red team reports can have an error state, but the system does not currently provide information about the type or source of the error, or how to fix it.
Group admins can see Reports & Campaigns in the nav, but only in orgs that have blue and red team enabled.