Spinnable - Notice history

All systems operational

Notice history

Jul 2026

Jun 2026

Upgrade Failures
  • Resolved
    UTC
    Resolved

    Through our monitoring, we have determined that project upgrade behavior has returned to normal across the fleet. This incident is resolved.

  • Monitoring
    UTC
    Monitoring

    We have implemented all necessary mitigations and the project upgrade rates have returned to normal across the fleet. We will continue to monitor these flows for any irregularities or recurring degradation. If you are still experiencing delayed or blocked upgrades on your Project, please contact Support.

  • Update
    UTC
    Update

    We are starting to notice improvements as a result of our mitigation efforts, and expect that project upgrades should start to become less delayed. We’ll continue monitoring and will update as we observe improvements across the fleet.

  • Update
    UTC
    Update

    We are continuing our operational and investigative work to improve upgrade flow performance and mitigate further problems.

  • Update
    UTC
    Update

    We are implementing operational mitigations to try to improve upgrade performance.

  • Update
    UTC
    Update

    We are continuing to work through a variety of options for improving upgrade performance. This includes working with our upstream provider and adjusting operational parameters.

  • Update
    UTC
    Update

    We are aware that upgrades continue to be delayed. We are exploring other factors that are contributing to the slow upgrades.

  • Identified
    UTC
    Identified

    The upgrade delays have been caused by resource capacity limits. We are taking actions to increase the appropriate resources.

  • Update
    UTC
    Update

    Upgrades are taking longer than usual, but generally will complete if allowed to proceed. We are investigating the cause of the delays.

  • Investigating
    UTC
    Investigating

    We are investigating potential upgrade issues in multiple regions. We are working to confirm impact and determine next steps.

May 2026

Issues with worker tools from upstream provider
  • Postmortem
    UTC
    Postmortem

    Composio security incident — May 21, 2026

    On May 21, 2026, Composio — one of the integration providers Spinnable uses to connect to third-party services — experienced a security incident. Composio's own analysis indicates the affected scope was small (around 0.3% of customer connections globally, concentrated in GitHub, which Spinnable does not route through Composio).

    Impact on Spinnable

    We have no indication that any Spinnable accounts have been impacted. The connections that route through Composio (Gmail, Outlook, Asana, and similar) are stored on Composio's infrastructure, not ours — so our exposure tracked theirs. Integrations Spinnable provides through other MCPs or directly are not part of this incident.

    We reviewed our access logs for activity from the attacker's known IP addresses across the incident window and found no evidence of unauthorized access to Spinnable systems.

    What we did

    Out of an abundance of caution, every affected connection in our project has been invalidated — either through Composio's own bulk-revocation effort, by per-connection revocation we ran through their API, or through direct credential rotation (X / Twitter) where Composio's revocation pathway was failing. Affected users were notified directly by email.

    Timeline (UTC)

    When

    Event

    May 21, 08:05–16:15

    Composio incident window

    May 23

    Composio published their public disclosure and began bulk revocation

    May 24

    Spinnable forensic snapshot, per-connection revocation for our project, X (Twitter) client-secret rotation

    May 26

    Post-mortem published; status page updated

    May 27

    Spinnable emailed the affected users directly

    What we've improved

    • Enabled 2FA on Spinnable's Composio dashboard account

    • Configured IP allowlisting on the Composio API key (a feature Composio rolled out as part of their incident response)

    • Reorganised our public status-page components to separate Spinnable services from subprocessors, so the same kind of upstream incident attributes correctly in future

    • Committed the response tooling (snapshot → resolve users → revoke → comms) to the Spinnable repo for faster future runs

    Looking forward

    For toolkits where token leakage would be high-impact, we're evaluating moving to bring-your-own OAuth credentials, which would give Spinnable a direct kill switch independent of subprocessor cooperation. We'll share updates as that work progresses.

    Reference

    Composio's full public disclosure: https://composio.dev/blog/composio-may-2026-security-incident

    Questions or concerns: security@spinnable.ai

  • Resolved
    UTC
    Resolved

    This incident has been resolved. All tools should be working correctly after reconnection.

    We will notify users by email in the coming day with more details about the causes and measures taken.

  • Monitoring
    UTC
    Monitoring

    We implemented a fix and are currently monitoring the result. We will email users individually to explain the actions taken and the disruption they saw with some of their connected accounts.

  • Investigating
    UTC
    Investigating

    We are currently investigating an incident with an upstream provider of tools for workers.

Network restrictions preventing read replica communication
  • Resolved
    UTC
    Resolved

    Communication between read replicas and their primaries for impacted projects has been restored. This incident is now resolved.

  • Monitoring
    UTC
    Monitoring

    We have merged the fix and are monitoring for stability.

  • Update
    UTC
    Update

    We have developed a fix and it is currently being validated. We will provide more updates soon.

  • Update
    UTC
    Update

    Our team continues to work on implementing a fix for the issue. We will provide additional updates as progress is made.

  • Update
    UTC
    Update

    Our team continues to work on implementing a fix for the issue. We are continuing to monitor the impact and will provide additional updates as progress is made.

  • Identified
    UTC
    Identified

    We have identified the cause of the issue impacting read replica communication for projects. Our team is actively working on a fix and continuing to assess the impact to affected projects.

  • Update
    UTC
    Update

    We are reviewing the impact of this issue, which is limited to projects with read replicas and network restrictions. We continue to both investigate mitigation options for the issue and identify projects that may be impacted.

  • Investigating
    UTC
    Investigating

    Network restrictions are preventing read replicas from communicating with their primaries for a limited number of customer projects. We are actively investigating this issue.

May 2026 to Jul 2026

Next