Skip to main content

Version 2.113.0 updates

This week’s release brings a rebuilt Risk Register, new capability for AI Atlas, a new integration with SmartSheet, and a more self-sufficient experience for vendors in Trust Chain.

📊 A more flexible Risk Register

Inherent and residual scores now live side by side as two clearly labelled stages, so you can see at a glance how your mitigating controls move the needle on a risk. Both are filterable in the register list and broken out as separate columns in your audit export. Teams can also customize their risk scoring methodologies by renaming likelihood and consequence labels, define their own risk banding names and colors, and set the thresholds that determine where each risk lands.

🤖 Atlas gets more proactive (public beta)

Atlas, our AI Compliance Advisor, now runs new plans on an automatic schedule, so insights arrive without manual intervention. We also added a new Automation Opportunities goal, where Atlas spots evidence you are still collecting by hand and recommends the exact integration or script that could take it off your plate. Each suggestion comes with a clear review step, so nothing changes until you accept it. We also sharpened how Atlas weighs coverage gaps and taught it to better recognize your own company’s aliases rather than flagging you as an unreviewed vendor.

🔍 Smarter evidence review

Verify AI now does real computation on tabular evidence like access reviews and asset inventories, running row counts, aggregations, and set comparisons against the actual data rather than a flattened version of the sheet. The same upgrade applies to Security Assistant and questionnaire responses, so a question like "how many vendors are high risk?" gets answered straight from the source.

🔌 New and improved integrations

We shipped a full SmartSheet integration, including a guided connection flow and SmartSheet support inside Script Runner for custom evidence pulls. Jira also picked up two new collection modes: Population Collection, which runs a JQL query and saves the complete result set as a CSV; and System Overview, which produces a dated artifact evidencing that a ticketing and workflow tool is in active use. The Integration Manager now includes a self-serve card for connecting to Strike Graph's MCP endpoint, and Certify customers now receive access to Script Runner for AWS, GCP, and Azure RM. We also touched up Google Drive authorization, improved Azure RM collection reliability, gave Script Runner more room for longer-running scripts, and added better error handling throughout.

🤝 A better experience for your TPRM vendors

When using Trust Chain for TPRM, your vendors now land directly on the Evidence Request Overview at login and have a single centralized view of every document access request across all of their customers, so managing access no longer means clicking into each request one at a time. They can also review their own external vulnerability scan results, see the full set of checks including the ones that passed, and kick off a re-scan themselves.

📬 Reporting and notifications

Owners assigned to a control, risk, or evidence record at creation now get more consistent email notification, matching what already happened for ownership changes on existing records. In the Trust Asset Library, Security Certifications is now Security Certifications & Attestations, and the visibility toggle reads Publicly Shareable. We also added resiliency to audit exports so they complete and report status reliably.