v3.2.4
Released September 12, 2026
This release lets an entire tenant be marked CUI‑Authorized for single sign‑on and hardens how the CUI gate is applied to chat‑history masking.
✨ New
- Tenant‑wide CUI‑Authorized SSO. CUI‑Authorized single sign‑on can now be enabled at the deployment (tenant) level, applying the setting across your whole tenant so that signing in with SSO — or a hardware security key — can satisfy multi‑factor authentication for CUI access.
🔧 Improvements & fixes
- Chat‑history masking now fully respects the CUI gate. Chat‑history masking now uses the same full CUI authorization check as datasets and workbooks, so authorized users see their own history consistently while controlled content stays masked for everyone else.
🔒 Security & platform
Ask Sage services are delivered as FIPS‑hardened, digest‑pinned, and cosign‑signed images within the FedRAMP Class D authorization boundary, and are continuously rebuilt against the latest patched base images as part of Ask Sage’s continuous‑monitoring commitment.