Slack channel management with chat notifications, a built-in communications platform for activity logging and email dispatch, AI chat assistant, and an Electron desktop app.
Justin Leapline
changelog
Out of Beta: Settings, Reports & Billing
Redesigned settings, built-in report templates, Stripe Sync Engine for billing, and MCP server with OAuth 2.1.
Justin Leapline
craft
Strategies in a Shrinking Resource Economy: Building a Resilient Security Program
Practical strategies for security leaders to maintain impact and resilience even when budgets and resources are shrinking.
Justin Leapline
changelog
AI Gateway & Enhanced Security
Centralized AI gateway for all AI features and OTP verification for stronger account security.
Justin Leapline
ai
AI Governance and Compliance: What Every SaaS Company Needs to Know
A practical guide to AI governance for SaaS companies – covering regulatory requirements, model documentation...
ai
AI Governance and Compliance: What Every SaaS Company Needs to Know
A practical guide to AI governance for SaaS companies – covering regulatory requirements, model documentation...
news
Beyond Memorization: How episki Supports True Security Awareness Through Behavior Change
Why quizzes and policy read-throughs fall short, and how episki helps teams build real security instincts through contextual, scenario-driven awareness.
Justin Leapline
craft
Compliance in the Cloud
A practical guide for growing companies on how to approach cloud compliance with confidence, clarity, and the right tools.
Justin Leapline
craft
When PCI Compliance Goes Off Track: How to Respond and Recover with Confidence
A practical guide for security and compliance teams on how to respond when PCI DSS compliance slips—covering common pitfalls, recovery strategies, and how to regain control with confidence.
Justin Leapline
ai
Automating Evidence Collection Without Losing Control
How to automate compliance evidence collection while maintaining accuracy, audit trail integrity, and human oversight where it matters.
Justin Leapline
changelog
AI-Powered Compliance
Introducing RAG pipeline and Notion-like AI assistance for smarter compliance management.
Justin Leapline
ai
AI-Powered GRC: A Practical Guide to Automating Compliance Work
Where AI actually helps in GRC — from evidence collection and control testing to report drafting and risk scoring — and where human judgment still matters.
Justin Leapline
craft
GRC Tool Buying Guide: What to Look for in 2026
How to evaluate GRC platforms in 2026 — covering must-have features, pricing models, build-vs-buy decisions, and a migration checklist.
Justin Leapline
craft
How to Build a GRC Team: Roles, Skills, and Hiring Order
When to make your first GRC hire, what skills to prioritize, how to scale from one person to a team, and when outsourcing makes more sense than hiring.
Justin Leapline
changelog
TypeScript & Quality of Life
Full TypeScript enforcement, smarter autocomplete, and numerous usability improvements.
Justin Leapline
craft
PCI DSS 4.0.1 Compliance for Fintech and Payments
A practical guide to PCI DSS 4.0.1 compliance for fintech companies — covering key changes, CDE scoping, API security, and processor management.
Justin Leapline
craft
SOC 2 for SaaS Companies: From First Audit to Enterprise Sales
How SaaS companies use SOC 2 to unlock enterprise deals — from scoping and engineering controls to using your report as a sales accelerator.
Justin Leapline
changelog
Import/Export & Custom Statuses
Full import and export capabilities for testing procedures, plus customizable control statuses.
Justin Leapline
craft
Risk Registers Demystified: Building One That Actually Gets Used
How to build a risk register that drives real decisions — covering risk identification, scoring, treatment plans, review cadence, and board reporting.
Justin Leapline
craft
Vendor Risk Management: A Complete Guide for Lean Teams
A practical guide to vendor risk management for lean security teams — covering inventory, risk tiering, assessments, contract clauses, and ongoing monitoring.
Justin Leapline
changelog
Custom Statuses & Dark Mode Polish
Customize how you track control status and enjoy a refined dark mode experience.
Justin Leapline
craft
Control Mapping Across Multiple Frameworks: A Practical Guide to Reuse
How to map controls across SOC 2, ISO 27001, HIPAA, and PCI DSS to reduce duplicate work and build a unified compliance program.
Justin Leapline
craft
How to Prepare for a Compliance Audit: The 60-Day Countdown
A week-by-week guide to preparing for a compliance audit — from scoping and evidence review through audit week and post-audit follow-up.
Justin Leapline
craft
NIST CSF 2.0: Using the Framework to Measure and Improve Security Maturity
How to use NIST CSF 2.0 as a practical tool for measuring, communicating, and improving your organization's security maturity.
Justin Leapline
craft
HIPAA Compliance for Healthtech Startups: A Technical Guide
A practical technical guide to HIPAA compliance for healthtech startups — covering safeguards, BAAs, PHI handling, breach notification, and framework overlap.
Justin Leapline
craft
ISO 27001 Certification: A Step-by-Step Implementation Guide
A practical, step-by-step guide to ISO 27001 certification — from gap analysis and ISMS setup through Stage 1 and Stage 2 audits.
Justin Leapline
craft
Compliance Playbook for Regulated Industries: Healthcare, Fintech, and SaaS
Industry-specific compliance requirements, common pitfalls, and practical starting points for healthcare, fintech, and SaaS companies.
Justin Leapline
craft
Choosing the Right Compliance Framework: SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST CSF Compared
A practical comparison of the five major compliance frameworks to help you decide which to pursue first and how to manage multiple frameworks efficiently.
Justin Leapline
craft
The Complete Guide to GRC for Growing Companies
Everything growing companies need to know about governance, risk, and compliance — from building your first program to scaling across multiple frameworks.
Justin Leapline
craft
GRC Metrics Executives Actually Care About
Skip vanity dashboards and focus on the few signals that show risk exposure, audit readiness, and operational velocity.
Justin Leapline
craft
Build an Evidence Library That Scales With Your Company
A repeatable system for naming, ownership, and retention that turns evidence collection into a steady workflow instead of a scramble.
Justin Leapline
craft
SOC 2 Readiness in 30 Days: A Practical Roadmap
A focused four-week plan to scope your SOC 2 effort, assign control ownership, collect evidence, and run a clean pre-audit check.
Justin Leapline
craft
5 Common Mistakes in GRC and How to Avoid Them
Five common GRC pitfalls that even experienced professionals make, with practical advice on how to avoid them and keep your compliance program on track.