Skip to main content

Changelog

Follow new updates and improvements to Strike Graph.

Version 2.116.0 update:

Stay on top of evidence collection with these updates to the evidence repository, Trust Chain vendor alerts, attachment metadata, and more:

📅 Evidence now keeps a fixed collection date for audit integrity while the effective date stays editable. New filters also let you sort the Evidence Repository by Verify AI status and narrow the Control Library to criteria currently in scope.

✅ You can now require a manager to sign off on evidence attachments before an item counts as complete, a clear human checkpoint that works with or without Verify AI.

🤝 Trust Chain keeps vendors on track with a refreshed invite email, due date and expiration reminders, and alerts when a Verify AI review is ready.

🤖 Atlas (beta) got a round of polish and short feature videos to help your team get up to speed. Security Assistant changes and self-assessment score resets now show up in the Activity Log, and bulk owner changes send notifications just like single updates.

🔐 Admins can now set a session inactivity timeout for their organization.

🛠️ We also improved reliability across evidence collection, notifications, self-assessment scoring, and custom framework imports.

Version 2.115.0 updates

Major overhaul of SBOM Manager, Trust Chain digest emails, AI Risk Management, and more. Here's an overview of what we updated in GRC v2.115.0:

🤝 Trust Chain does more of the chasing for you. Send vendor invitations with a welcome message in your own words, group large evidence requests into named lists, and let automated login reminders and weekly digests keep things moving without you logging in to check.

🌐 Our external vulnerability scanner now maps a vendor's full public footprint, discovering subdomains automatically instead of checking the apex domain alone.

📋 NIST AI RMF is live. If you're building or buying AI, the framework is available now with criteria mapped to controls and ready for evidence collection.

🔌 Slack evidence collection goes deeper, collecting user group membership as evidence for access reviews. Note: we now support GitHub App auth for GitHub integrations too.

🤖 Atlas keeps getting sharper. Action items now show the full context behind a referenced resource, a collection script that fails can be regenerated without restarting the workflow, and 33 new AWS scripts joined the shared registry for everyone.

📎 The Public Evidence API now accepts direct file uploads, so external systems can push evidence straight into Strike Graph.

Version 2.114.0 updates

Three new integrations just landed in Strike Graph, along with a more transparent Atlas AI and a simpler vendor experience.

🔌 New integrations: Slack, KnowBe4, and Okta
You can now connect Slack in a couple of clicks through a standard “Add to Slack” flow, choose a channel, and let evidence collect itself. KnowBe4 and Okta join the integrations catalog too, each with its own guided setup so you can pull evidence straight from the tools you already use.

🤖 Atlas shows its work (beta)
Our AI Compliance Advisor gained another skill: recommending integrations and automated collection code. When Atlas identifies evidence being collected by hand, it will try to not only recommend an integration to configure for automated collection, but even help you write it with integration scripts and one-click applies.

🛡️ Sharper vulnerability detection
We expanded our vulnerability scanner’s check coverage after benchmarking it against industry tools, closing gaps and catching more of what matters. We also touched up vulnerability notification emails so critical and high severity findings from SBOM scans reach your inbox reliably.

🤝 A cleaner vendor view
We removed the Compliance Dashboard tab from the vendor-facing view, keeping vendors focused on the information that’s actually relevant to their role.

🔊 Updates, right in the app
A new in-app Updates panel and feedback widget make it easy to see what’s new and tell us what you think, without leaving Strike Graph.

Earlier updates