FTAPI Version 4.66.0

Released 15.07.2026.

New


SecuRooms

  • Invite user groups to unencrypted datarooms: Administrators can invite entire user groups to datarooms instead of granting access to each member individually. When a group's composition changes, dataroom access is adjusted automatically: new members gain access, departing members lose it. When a user group is deleted, all dataroom access granted through that group is removed automatically. When a dataroom is permanently deleted, the group-derived access rights are fully removed as well.
  • Group selection with member count and readable group names: When inviting a group, the selection now shows the number of members per group, so dataroom owners can see how many people will receive access before sharing. System groups (e.g. administrators, employees, guests) are shown with their translated names instead of internal keys.
  • Group-based access stays under admin control: Users who have access to a dataroom through a group membership can no longer leave it on their own. This keeps group-managed access consistent with the member list maintained by the administrator.

We're already working hard on enabling you to invite user groups to encrypted datarooms soon.

SecuMail / SubmitBox

  • Set a default validity centrally in server administration: You can now define a default validity period for deliveries in the group settings. This value applies in the web client and in OWA and is preselected when creating a delivery. The functionality known from classic Outlook is now also available for web and OWA.
  • New dashboard for Intelligent Email Encryption: A new dashboard now shows administrators all emails sent via Intelligent Email Encryption. This makes it easy to track how many emails were sent, which encryption was applied, and whether an email failed and therefore requires action. Learn more.

Administration

  • Storage overview for administrators: Administrators can now see their organization's used and available storage space directly in the administration area, including the storage logs. This lets you identify early when additional storage should be booked. This view was previously available only to the root admin.

Platform

  • Log forwarding to a SIEM (syslog): Technical and security-relevant logs can now be forwarded to a SIEM via syslog, for centralized monitoring and auditing. The forwarding supports TCP, UDP, and TLS and is configured directly in the admin interface. It is disabled by default and only activates once a target server is configured.

Improved


SecuRooms

  • Redesigned invite dialog: The dialog for inviting people to a SecuRoom has been redesigned. The title now shows the name of the shared SecuRoom or folder, so it is always clear what access is being granted. Entered recipients are displayed more clearly: registered users, not-yet-registered recipients, and invalid email addresses are each marked distinctly.
  • New table and overview design: The tables for dataroom contents, the home screen, and the search results have been redesigned. Improvements include more consistent actions in the toolbar and context menu, larger icons, a larger click area for checkboxes, and calmer behavior when sorting.
  • No duplicate roles when re-inviting: Re-inviting a user or group to a dataroom or folder previously created an additional access entry instead of overwriting the existing one. Each user is now kept and displayed with only their highest role in the access dialog.
  • Allowed file types only enforced when virus scanning is active: After disabling virus scanning in SecuRooms, the configured list of allowed file types was still enforced. When virus scanning is disabled, the file-type restriction is now no longer applied either.
  • Upload notifications delivered in full even for very large uploads: For upload sessions with more than 1,000 activities, only the first 1,000 notifications were sent, leaving further recipients without one. All notifications are now delivered, regardless of the volume.
  • Clear notification for rejected files: When an uploaded file could not be approved during review, the notification email showed an internal placeholder instead of the message text. The email now shows the correctly translated text.
  • Maximum file size per upload raised to 500 GB: In SecuRooms, individual files up to 500 GB can now be uploaded; the previous limit was 100 GB.
  • Group access is preserved when restoring from trash: When files are restored from the trash whose parent folder was renamed in the meantime, the group-based access rights are now applied correctly.
  • Correct date in the trash: The trash sometimes showed "Invalid Date" instead of the actual date for entries. The date is now displayed correctly.
  • User creation works with group names containing spaces: If a group name had a leading or trailing space, no new user could be created via the web interface: the dialog window closed immediately. User creation now works reliably regardless of such spaces.
  • Direct access and group access are handled separately: When a user's individually granted access to a dataroom was revoked, their access granted through a group was previously lost as well. Both types of access are now handled separately.

SecuMail / SubmitBox

  • Deliveries via the FTAPI Trust Network are scanned for viruses: Deliveries forwarded to a partner server via the FTAPI Trust Network now additionally go through the virus scan before being forwarded. In the past, this was only the case for incoming deliveries. Administrators can therefore be even more confident that all deliveries via the Trust Network are scanned.
  • Download confirmation and tracking for Trust Network deliveries: Deliveries received via the FTAPI Trust Network now behave like regular SecuMails: the download confirmation by email, the tracking in the activity panel under "Sent", and the presentation in the reports (including Delivery Report, Monthly Delivery Report, Download Report) match the familiar standard.
  • Security levels 3 and 4 counted correctly in the monthly report: Deliveries at security levels 3 and 4 were sometimes not counted in the monthly report. The report totals now include these deliveries in full.
  • SubmitBox link removed from the confirmation email: The confirmation email after a SubmitBox submission no longer contains a link to the SubmitBox, since with personal SubmitBox links this information might not be intended for sharing by the SubmitBox owner.
  • Empty "Attachments" field removed from Level 2 SubmitBox submissions: For submissions via a Level 2 SubmitBox, an empty "Attachments/File" field was displayed. This field is now hidden.
  • Sender correctly resolved in the inbox: For deliveries received as a submission via a SubmitBox, the sender was not correctly resolved via the interface. The sender is now correctly determined and displayed.
  • No expiration date in email confirmations without a validity end: If a delivery has no expiration date, none is shown in the email confirmations anymore.
  • "Delete deliveries from inbox/outbox" now also takes effect for the inbox: The option to disable the deletion of deliveries from inbox and outbox had no effect for the inbox. Deliveries can now also no longer be deleted from the inbox.

Administration

  • Technical Trust Network users do not count as licensed: Technical users created by the FTAPI Trust Network are no longer counted as licensed users and are hidden from the User Report. The license evaluation therefore reflects the licenses actually in use.
  • Redirect to SecuForm after SSO login: After logging in via SSO, users were not redirected to the intended SecuForm. The redirect to the intended SecuForm now works correctly.
  • No version information in exported reports: When downloading reports as PDF, the metadata contained information about the PDF library used. This information is now removed from the metadata.
  • Report generation no longer overloads the server: Generating large reports could lead to server outages. Reports are now generated one after another instead of in parallel, keeping operations stable.

Platform

  • Consistent term "Legal Notice": The terms "Imprint" and "Site Notice" have been replaced consistently with "Legal Notice", including in the admin area (footer links), the user menu, and the footer notices. This makes the term unambiguous for English-speaking users too.
  • Login with forced password change and SMS 2FA: With the setting "Force new password" active in combination with SMS 2FA, an error occurred during login. Login now works without errors in this combination.
  • SMS 2FA with French language setting: Two-factor authentication via SMS did not work when the user's language was set to French. SMS delivery now also works with this language setting.
  • Alphanumeric SMS codes for two-factor authentication: When the SMS code for two-factor authentication is configured to be alphanumeric, the input field previously only accepted digits, so codes containing letters could not be entered. The field now accepts both letters and digits in line with the configured format.

 

FTAPI cloud customers do not need to take any action, the update was performed automatically. Customers can receive detailed information about the maintenance window via status.ftapi.com.

Information on On-Premises


The next On-Premises version is expected to be released in calendar week 30. We will notify you by email as soon as the version is available for download.