Support Hub, care corner, and Guardian — ask for help, finish setup, and get unstuck in-product, with dark and light screenshots.
What we shipped
The releases that changed what customers can do — product launches, new surfaces, methodology publications. Reverse-chronological.
2026 · Q4
2 releasesFour views (Scope, Coverage, Continuity, Today) that answer the questions you actually ask on an audit, in the order you ask them. One framework per assessment, every requirement graded against its own text, the whole observation window on one screen.
2026 · Q3
5 releasesNew suppliers enroll in your review queue on their own, and the GO / CONDITIONAL / NO GO decision is written back onto the supplier record where procurement already works.
The integrity layer under the platform is now licensable on its own: every consequential action becomes a record a third party can re-derive without trusting us, our model provider, or our cloud.
Discovery reads your vendors’ published disclosures and extracts their AI posture with a citation on every claim. Nothing becomes the record until your team confirms it.
A 20-minute pre-investment red-flag scan, term-sheet covenants auto-drafted from the findings, and a one-page LP-letter cyber section that gets easier every quarter.
Compliance agents working end-to-end, with cryptographically signed actions, reasoning traces you can read, and freshness-verified evidence.
2026 · Q2
6 releasesScenarios auto-generated from live platform signals rather than a pre-built library, in three layers: board appetite, risk, deficiency.
For regional security VARs, GRC implementers, and small MSPs. Sliding-scale recurring margin up to 30% on Enterprise; operator-track white-label lands Q4 2026.
Refraction, Keystone, and Continuous Indicators under one roof, so a tripped indicator raises the scenario and the vendor alert together.
Per-engagement diligence returning a single Cyber Cost of Deal figure across five defensible pillars, priced against the acquirer’s valuation model.
Ask your compliance program anything from Claude, GPT, or your own agent, and get evidence-backed answers with the citations attached.
Someone Else’s Debt: how to translate cyber risk into a dollar figure a deal team can act on — the methodology behind our diligence surface.
2026 · Q1
11 releasesLoss exceedance curves from live percentiles, per-finding exposure and remediation cost, and findings that flow into the operating program instead of a shelved report.
10,000 runs per scenario with FAIR-shaped decomposition. Every dollar figure downstream is live simulation, not a lookup table.
Verifiable deletion certificates, a viewer that keeps raw document bytes out of the reader’s browser, and watermarking that identifies a leaked page’s reader.
Canonical IDs and alias resolution in a shared module, so every service reads frameworks from the same place.
Credential stuffing is the top attack vector against SaaS, so we removed the class: magic link plus mandatory TOTP, across every external portal too.
Per-resource authorization instead of role checks, and metered consumption between the platform and billing. Every tier-gated feature since inherits both.
Versioned, cross-linked articles that sit inside the surfaces they explain, starting with business controls, overrides, testing, and questionnaires.
Pipeline, bottleneck, and assignment views across services; the standards tab rewritten as a queue driven by deadlines, gaps, and evidence freshness.
Scoped external-reader access with view analytics and time-bound links — for every founder assembling a Drive folder the night before a term-sheet call.
Engagement-scoped, tenant-isolated rooms with ephemeral storage and deletion certificates as first-class artifacts.
Three mandatory steps for business context, progressive disclosure for depth, and a persistent checklist for first-value actions.
Shipping since Jan 2026 · Press releases · RSS