The product you bought keeps getting better. Here's what shipped.
A running record of what's new in PK Protect, updated each quarter.
July 2026 Release
v20.6Agent v20.60 · PK M365 v1.60 · PK Secure Office v1.7
See where quantum risk lives in your data. Years before it matters.
A new Encryption Discovery view surfaces post-quantum cryptography risk across the data you have already discovered, so you can see which encrypted data will need to move to quantum-safe algorithms.
A PQC Progress Report page in the Admin UI tracks migration status as you work through it, and the underlying cryptographic libraries have been updated to enable post-quantum algorithms.
Ask your account team about the betaScan by sensitivity label. Not just by location.
Cloud Agent scans now filter on Microsoft Purview sensitivity labels across SharePoint, OneDrive, and Exchange, so you can scope actions to the classification your business already trusts. Unlabeled files can pick up a default Purview label.
Coverage widened at the same time: policies can target SharePoint subsites and OneDrive subfolders, and in-place archive mailboxes are scanned by default.
Large cloud scans finish cleaner.
Cloud scanning gets adaptive concurrency, per-scan token caching, and better error behavior, plus fixes for stalled scan slots, idle targets and label resolution. Original filenames are now preserved in encrypted output.
Patch and you are current on this quarter's advisories.
The release delivers quarterly package and security updates across PK Protect components, covering both product hardening and third-party dependency remediations found through dependency audits and security review.
Every fix is included in the base release, so there is nothing extra to license or enable. The specifics ship with the release notes.
See advisory detailsDecide exactly where in an email sensitive content gets remediated.
The Outlook Add-In adds per-location control over email content remediation, with content-location selection inside email rules and a filter-bundle scoping toggle on the email policy page. Global email settings have moved to the policy level, so control is finer grained.
Dark Mode styling and better handling of unsupported-file errors round out the release.
Version 21 groundwork you can try before it ships.
These arrive in 20.6 as opt-in, pre-release features at no extra cost. Use them for evaluation, testing, and training, and ask your account team if you'd like any of them turned on for your environment.
A rebuilt virtual appliance, ready ahead of version 21.
The new v3 appliance runs on a modern operating system and software stack, including Ubuntu 26.04 LTS, .NET 10, and PostgreSQL. A migration checklist and more tolerant schema migration make the move to it easier.
Ask your account team to try itMore of the Admin UI is now the modern UI.
This release converts additional administrator pages to the modern React interface, including the Events pages for levels, log, and configuration. Navigation has been reorganized into a simpler layout, and data tables keep gaining capability: column visibility, per-column search, and dropdown filtering.
The entitlement is off by default and available at no cost. SaaS customers have it enabled already.
Ask your account team to enableApril 2026 Release
v20.5Agent v20.50 · PK M365 v1.50
Moving to SaaS used to mean a Professional Services engagement. Now it's a wizard.
The new SaaS Migration Tool walks you through migrating an entire on-prem PK Protect instance to PKWARE-hosted SaaS. End to end. From inside the admin console.
When the migration completes, the source server flips into redirect mode and endpoints reconnect automatically.
See migration documentationProtect a single SharePoint subsite. Not the whole tenant.
Stop over-applying policy across a whole tenant to cover one department. Protection now scopes to specific subsites and OneDrive subfolders.
Deploy the Windows Agent the way you deploy everything else.
The Windows Agent now ships as a standard MSI. SCCM, Intune, and the rest of your endpoint tooling handle it without PKWARE-specific workarounds.
Patch and you're covered for several disclosed CVEs.
Including a critical OpenSSL CMS fix and a multi-version cluster API fix. The cluster API fix is backported to every supported server version (20.0 through 20.5), so you don't have to upgrade to get it.
See advisory detailsOpt-in features customers can ask their account team to enable.
These ship in 20.5 as opt-in entitlements. No extra cost. Ask your account team if you'd like any of them turned on for your environment.
The modern Admin UI keeps growing.
New Global Search, revised navigation, and a redesigned Target Results page. Data tables now support column show/hide, per-column search, dropdown filters, and async loading on large lists.
Ask your account team to enableFind sensitive data hiding in your company's email.
Discovery now reaches into Microsoft Exchange Online, scanning subject lines, email bodies, and attachments. In-Place Archive is supported.
Ask your account team to enableProtect files even when they can't be scanned.
Discovery Fallback Remediation now runs on the Cloud Agent. Build remediation policies that safeguard files whether they're unsupported types, encrypted, or simply can't be scanned for any other reason. Target Status reporting shows which files were caught by the fallback.
Ask your account team to enableAlready a customer? Most of this is included.
If you're not sure whether you're on the latest version, or you want the new UI entitlement enabled, your account team can sort it in a day.