Version 2.115.0 updates
Major overhaul of SBOM Manager, Trust Chain digest emails, AI Risk Management, and more. Here's an overview of what we updated in GRC v2.115.0:
🤝 Trust Chain does more of the chasing for you. Send vendor invitations with a welcome message in your own words, group large evidence requests into named lists, and let automated login reminders and weekly digests keep things moving without you logging in to check.
🌐 Our external vulnerability scanner now maps a vendor's full public footprint, discovering subdomains automatically instead of checking the apex domain alone.
📋 NIST AI RMF is live. If you're building or buying AI, the framework is available now with criteria mapped to controls and ready for evidence collection.
🔌 Slack evidence collection goes deeper, collecting user group membership as evidence for access reviews. Note: we now support GitHub App auth for GitHub integrations too.
🤖 Atlas keeps getting sharper. Action items now show the full context behind a referenced resource, a collection script that fails can be regenerated without restarting the workflow, and 33 new AWS scripts joined the shared registry for everyone.
📎 The Public Evidence API now accepts direct file uploads, so external systems can push evidence straight into Strike Graph.