All postsPrivatta

Privatta Beta 2: Better Tamper Protection on the Access Log, Plus Unattended Hosts

July 23, 20262 min readRoyal Softworks
privattachangelogrelease-notes

TL;DR — Privatta Beta 2 improves tamper protection on the access log so edits or deletions are detectable, adds unattended host mode (auto-start plus launch-at-login), makes the MAC-address check optional and LAN-only with automatic detection.

Beta 2 is out. Here's what changed, pulled from the last few commits.

The access log has better tamper protection

Privatta's access log records who accessed what, from where, and whether it was permitted. In Beta 2, that log gets meaningfully harder to quietly alter after the fact: entries are cryptographically chained to the one before them, with a checkpoint tracked outside the log itself. Edit a row, delete one from the middle, reorder entries, or truncate the tail, and that's now detectable rather than invisible — the next time the Access Log dialog is opened, Privatta replays the chain and surfaces an "Access Log Tampered" warning if anything doesn't line up. Entries written before this upgrade are treated as unverifiable-by-design, not flagged as tampering — the protection simply applies going forward.

Unattended host mode

Two new toggles under Settings:

  • Auto-start the local server when Privatta opens — skips clicking "Start Server" every time.
  • Launch Privatta when I log into this computer — an OS-level login item, applied the moment you flip it rather than deferred to the Save button.

Combined, they turn a machine into an always-on host that comes back up on its own after a reboot with no one at the keyboard.

Simpler device binding

A MAC-address whitelist on a user account is no longer a mandatory authentication factor — it's now an optional, local-network-only check an administrator can layer on top of username and password. When it's set, Privatta detects and presents the connecting machine's own MAC automatically, so there's nothing for the person on the other end to type or configure.

Also in this release

  • Local network scan respects the real subnet mask. Device discovery previously assumed every LAN was a /24; it now reads the OS-reported CIDR, so /16, /20, and /23 networks scan correctly too.

That's Beta 2: v1.0 BETA 2 - 230726, up from BETA 1 - 190726. You can download the updated version from the Download page. Questions or feedback are always welcome at office@royalsoftworks.com.

Frequently asked questions

What's new in Privatta Beta 2?

Stronger tamper protection on the access log, an unattended host mode (auto-start plus launch-at-login), an optional rather than mandatory MAC-address check for LAN accounts.

Is the MAC-address check still required for user accounts?

No — it's now optional and local-network-only. An administrator can still lock a LAN account to a specific device's MAC address as a second factor, but it's no longer mandatory, and Privatta now detects and presents the connecting machine's own MAC automatically.

What does improved tamper protection mean for the access log?

Log entries are now cryptographically chained to each other, with a checkpoint tracked outside the log itself. If a row is edited, deleted, reordered, or the log is truncated, that becomes detectable instead of silently altering the history — the app surfaces an 'Access Log Tampered' warning.

Are Virtual Folders included in every Privatta tier?

No — Virtual Folders are an ENTERPRISE feature, alongside Group management and the access log.

Related posts

See what we're building

Private, on-premise AI and software that runs entirely on your own infrastructure — no cloud, no subscriptions, no data leaving your hardware.