- Added dynamic secret integrations (Fold, Tailscale, proxied services) and HMAC key support in KMS; enhanced PAM SSH logging, Unix discovery, and gateway Helm properties.
- Improved security workflow: prevent self‑approval of signing requests, support hardware security keys on FIPS, send email notifications to approvers, and disable public signups on self‑hosted after admin setup.
- Updated documentation with static secret examples, network architecture diagram, Docker CLI quickstart, and moved HSM integration info to self‑host section.