Skip to main content

Version 2.115.0 updates

Major overhaul of SBOM Manager, Trust Chain digest emails, AI Risk Management, and more. Here's an overview of what we updated in GRC v2.115.0:

🤝 Trust Chain does more of the chasing for you. Send vendor invitations with a welcome message in your own words, group large evidence requests into named lists, and let automated login reminders and weekly digests keep things moving without you logging in to check.

🌐 Our external vulnerability scanner now maps a vendor's full public footprint, discovering subdomains automatically instead of checking the apex domain alone.

📋 NIST AI RMF is live. If you're building or buying AI, the framework is available now with criteria mapped to controls and ready for evidence collection.

🔌 Slack evidence collection goes deeper, collecting user group membership as evidence for access reviews. Note: we now support GitHub App auth for GitHub integrations too.

🤖 Atlas keeps getting sharper. Action items now show the full context behind a referenced resource, a collection script that fails can be regenerated without restarting the workflow, and 33 new AWS scripts joined the shared registry for everyone.

📎 The Public Evidence API now accepts direct file uploads, so external systems can push evidence straight into Strike Graph.