July 2026 Release Archive
Historical Y2 Intelligence Platform release notes from July 2026.
Historical release context
This archive preserves what changed in July 2026. Follow its links to the maintained feature and API guides for current behavior.
July 30, 2026: Privacy, product platform, and installed-app foundation
Y2 strengthens its privacy terms, simplifies product analytics and feedback, and lays the foundation for installed desktop and Android applications.
Clearer data-processing terms
- The Data Processing Agreement now defines customer and Y2 processing roles, United States service-provider restrictions, security and breach duties, deletion and audit support, and international transfer safeguards.
- New processing, subprocessor, and security schedules explain the data involved, each provider's purpose, and Y2's technical and organizational safeguards.
- Customers now receive at least 30 days' notice before a new subprocessor materially processes Customer Personal Data.
One consent-controlled product platform
- Y2 removed Statsig and UserJot and consolidated product analytics, masked session replay, surveys, and in-app Support in PostHog.
- Optional browser analytics remain consent-controlled. Session replay masks visible text and form inputs, and reviewed product events exclude user-authored report, profile, and investigation content.
- The Privacy Policy, DPA subprocessor schedule, and internal data-privacy audit now describe the same current processing.
Platform and installed-app foundation
- The web application and backend now use a shared Bun and Turborepo workspace, with common translation and desktop contracts.
- Electron and Android shells add secure renderer boundaries, scoped device permissions, update and packaging checks, and shared application behavior. Native signing and store distribution remain separate release gates.
July 24, 2026: Projects, Automations, and workspace governance
Y2 added private Project workspaces and durable Agent Y2 Automations with plan-aware access, workspace isolation, and Elite governance.
Projects on Lite, Pro, and Elite
- Projects organize chats, reports, profiles, graph boards, generated images, evidence, and private documents around one objective.
- Graph, Timeline, Situation, Evidence, Knowledge, and Overview views keep related intelligence connected without publishing Project content to Global Knowledge.
- Projects are bound to the active workspace and their owner. Switching workspaces cannot expose another workspace's Project chats, resources, evidence, or private knowledge.
- Project sharing was not included in this release; Elite members did not automatically gain access to another member's private Projects.
Follow the Projects overview or create your first Project.
Automations on Pro and Elite
- Automations run bounded Agent Y2 instructions daily, weekly, monthly, or after a selected InfoOps profile completes a report.
- Pro includes up to 10 Automation definitions and Elite includes up to 50, shared across the active workspace. Free and Lite do not include Automations.
- An Automation can write to a workspace-bound output thread or stay inside an active Project.
- Live admission checks stop stale, overlapping, cross-workspace, downgraded, or inaccessible Project runs before paid work continues.
- Run history records trigger, definition revision, output, status, and billing settlement; owners can safely pause or archive definitions after a downgrade.
See Automations and the Automation reference.
Workspace governance and language support
- Elite audit records bind material Project and Automation changes to the acting user and workspace without changing owner-private content access.
- Project and Automation navigation, plan guidance, upgrade states, forms, run history, and landing explanations are available in English and Spanish.
- Plan, workspace, report-workflow, and profile documentation reflects the same enforced entitlement boundaries.
July 21, 2026: Global coverage, Chat updates, and Pro API keys
Y2 expanded global intelligence coverage, simplified active research, and tightened API-key access.
Intelligence
- New Situation Room visitors start with all 27 map layers enabled. Existing preferences stay unchanged, and mobile markers are easier to select.
- Discover adds monthly digests for 72 cities and 39 industries. Chat and onboarding now recommend a matching public digest before creating a duplicate custom brief.
- News Terminal expands to 40 global topics across geopolitics, markets, industries, regions, AI, and crypto. High-signal items join Y2's ontology with deduplication, entity links, and source provenance.
- Incident enrichment and corroboration now run together, with automatic recovery for interrupted work and protection from stale retries.
Explore News Terminal, OSINT sources, or the News API.
Chat
- New chats default to GLM 5.2 using Zero Data Retention routing. Existing threads and saved model choices stay unchanged.
- Featured models are now Nemotron 3 Ultra, Grok 4.5, GLM 5.2, DeepSeek V4 Pro, Kimi K3, Qwen 3.6, GPT-5.6 Luna, Claude Sonnet 5, Gemini 3.6 Flash, and Mistral Small.
- Tool activity now uses a compact, auto-scrolling panel with clearer progress and failure states.
See Chat Features for model selection and privacy details.
API access
- New API keys require Pro (5 keys, 30 requests/minute, 5,000/day) or Elite (25 keys, 120 requests/minute, 50,000/day).
- Existing Lite keys keep their historical limits (10 requests/minute, 500/day) and can still be rotated or revoked. Lite cannot create more keys, and future downgrades are not grandfathered. Webhooks remain available on Lite, and x402 access is unchanged.
See API Authentication or x402 pay-per-request access.
July 17, 2026: Y2 Affiliate program
Every Y2 user can review the Affiliate Program in Settings → Referrals. A personal FirstPromoter referral link is created and displayed only after the user explicitly accepts the current program terms. The enrolled dashboard keeps provider credentials and raw customer details server-side.
- The default Y2 Affiliate Program offers 15% recurring commission on eligible paid Lite and Pro subscription revenue.
- Referral attribution converts only after a new customer completes a verified non-zero Lite or Pro payment; a signup, 7-day trial, Free or Elite purchase, or fully discounted invoice does not create a commissionable referral.
- A promoter must maintain an active paid Lite, Pro, or Elite workspace and keep their own Y2 payments current throughout commission eligibility, review, and payout.
- Pending commissions remain subject to the 60-day payment, refund, fraud, and eligibility review.
See the Affiliate Program guide for enrollment, attribution, payout, and troubleshooting details.
July 10, 2026: Privacy-first Chat and connected intelligence
Y2 makes model selection clearer, keeps provider routing privacy-first, and connects Situation Room signals to the wider intelligence workspace.
What changed
Privacy-first Chat
- Y2 Chat and Agent Y2 route model requests through Zero Data Retention (ZDR) endpoints, with provider data collection disabled. See Chat Features and the Agent Y2 API guide.
- The model picker now shows readable names, provider filters, and search.
- GPT-5.6 Luna and NVIDIA Nemotron 3 Ultra are featured chat options, subject to current provider availability.
Situation Room and connected intelligence
- The map now groups orbital and satellite layers, surveillance sources, live media, and expanded infrastructure and military overlays in shared layer controls and a source catalog.
- The monitor tool rail places Intel Findings, Network Intel, ontology Search, and API Query beside the map and loads each tool on demand.
- Live malware monitoring now includes relationship graphs for indicators, malware families, and related entities.
- Search the Y2 ontology directly from the Situation Room to explore entities and their live relationships.
- Map marker graphs now show richer source, confidence, time-range, and report context, with a direct link to the related historical report when available.
- Monitor controls and data panels now adapt to smaller screens and simplify navigation.
Reliable scheduled reports
- Scheduled report generation now detects interrupted runs, queues bounded recovery attempts, and keeps the profile active instead of delivering incomplete reports.
- Profile status and retry state are clearer when a report needs another attempt. See Scheduling.
Clearer plan guidance
- Plan and branding documentation now matches current access: the full Situation Room is available on Lite, Pro, and Elite, while reusable report branding is available on Pro and Elite. See Whitelabel Branding.
July 8, 2026: Agent Y2 API, OpenAI-compatible Chat, and MCP
Y2 now exposes Agent Y2 through API-key authenticated streaming, an OpenAI-compatible chat-completions route, a standalone MCP server for agent clients, and refreshed OpenAPI, client-integration, and endpoint documentation.
What changed
Agent Y2 API and OpenAI-compatible Chat
- Agent Y2 is now available through API-key authenticated streaming at
POST /api/v1/agent-y2/chat/stream; see the Agent Y2 API guide and generated Agent Y2 reference. - The OpenAI-compatible
POST /api/v1/chat/completionsroute supportsmodel: "y2-agent"for streaming clients that already consume OpenAI-style chat completion chunks. - Both routes require the
agent:y2API-key scope, use workspace-aware entitlements and chat credit budgets, and attribute usage back to the correct workspace, thread, endpoint, and API key. - Agent Y2 API access is intentionally API-key only in this release, with a shared
5/min,100/dayper-key throttle and a10/min,250/dayworkspace/user throttle across both Agent Y2 API routes. - OpenAI-compatible stateless chat calls preserve caller-provided transcript context when no Y2 thread is attached, while threaded calls validate ownership before reserving chat credits.
MCP, OpenAPI, and client documentation
Separate MCP package
@y2-intel/mcp is distributed separately from this platform repository. The maintained
MCP guide explains that boundary and shows how to inspect the capabilities of
the installed package version.
- New Y2 MCP docs cover the standalone
@y2-intel/mcpstdio server for Claude, Codex, Claude Desktop, and other MCP-compatible clients. - The MCP server exposes Y2 docs and OpenAPI resources, bounded report and news tools, an
operation lookup tool, and
y2_ask_agentfor Agent Y2 access. - The OpenAPI specification, Endpoint Reference,
and client guides now reflect the canonical Agent Y2 routes,
agent:y2scope, request schemas, response codes, generated examples, and rate-limit headers. - The API Workbench and docs navigation received sidebar, category, route, theme-state, and 404 handling improvements for the expanded API surface.
Agent reliability and synthesis safety
- The shared Agent Y2 executor now powers both app-authenticated and API-key routes, keeping the fixed Agent Y2 system prompt protected from caller override.
- Agent Y2 API responses hide internal reasoning chunks and align SDK examples to the
canonical
POST /api/v1/chat/completionspath. - Degraded Y2 synthesis now fails closed instead of completing reports from low-confidence output, with debugging documentation added for report-generation degradation triage.