Skip to content
opsnite
Changelog

What we shipped.

A running log of what landed in opsnite, version by version. New features, fixes, security improvements, performance wins. Honest about all of them.

v0.14

Continuous control testing wave

  • NEW

    Continuous control testing for AWS IAM access reviews and S3 encryption posture. Failed tests open Jira/Linear tickets directly to the owning team with control + asset context.

  • NEW

    Wiz integration GA. Cloud-posture findings flow into the unified vuln queue with EPSS + KEV-weighted prioritization.

  • NEW

    Custom framework authoring. Bring your own internal control catalog, map it to standard frameworks, run it the same way.

  • FIX

    Vendor questionnaire export to PDF was clipping multi-page tables. Fixed.

  • PERF

    Audit evidence search now hits a dedicated index. Previous P95 was 1.4s on tenants with >100k evidence records; now 130ms.

v0.13

Pen test management module

  • NEW

    Pen test engagement workspace. Scoping, findings library, retest workflow, branded report generation. HackerOne and Bugcrowd live; Cobalt in beta.

  • NEW

    Findings from pen test engagements automatically reference affected controls in the GRC graph and surface as exceptions during the next audit.

  • SECURITY

    Tightened tenant isolation on file uploads. No customer data was affected; this was a defense-in-depth improvement caught in our own quarterly threat-model review.

  • FIX

    CSV import for vendor list was failing on tenants with custom field schemas. Now respects schema overrides.

v0.12

Contract lifecycle GA + obligation extraction

  • NEW

    Contract lifecycle module GA. Authoring, redlines (track changes from Word), DocuSign + Adobe Sign signing, executed contract storage.

  • NEW

    Obligation extraction. Notice periods, audit rights, data residency, breach notification windows extracted from executed contracts and surfaced into the risk register.

  • NEW

    Salesforce + HubSpot two-way sync. Close-won opportunities trigger contract creation; signed contracts close back to the CRM.

  • FIX

    Trust page was caching control state for 24h on free tier. Now updates within 15 minutes for all tiers.

v0.11

Multi-framework cross-mapping

  • NEW

    Cross-framework mapping engine. Map a control once, satisfy the equivalent control in SOC 2, ISO 27001, HIPAA, HITRUST, NIST CSF, and 21 CFR Part 11.

  • NEW

    Gap analysis when adding a new framework. Automatic, not manual.

  • FIX

    Risk register heat map was double-counting risks tagged to multiple control families. Fixed.

  • PERF

    Trust page render cut from 2.1s to 380ms on the worst-offending tenant.

v0.10

Vendor risk module + concentration views

  • NEW

    Vendor risk module GA. Onboarding workflow, security questionnaires (CAIQ + SIG + custom), DPA tracking, continuous public-signal monitoring.

  • NEW

    Concentration risk views. Vendors ranked by transaction-flow exposure, fourth-party dependencies surfaced as nodes in the graph.

  • NEW

    Okta SCIM integration for vendor employee terminations.

Want to know what’s in the next release?

Email hello@opsnite.com with ‘roadmap’ in the subject. We will share what is coming, what we have parked, and why.