Blog

Discover the latest insights, tutorials, and updates from our team. Stay informed about governance trends, best practices, and innovative solutions.

Security Questionnaires, Answered From What You Have Already Said

Inbound security questionnaires land as work items and draft their answers from your trust center and an answer library of everything you have approved before. Plus trust center subscribers and updates, custom control mapping, per-scope tests, evidence-grounded PCI assessment drafting, and findings that read like findings.
Security Questionnaires, Answered From What You Have Already Said

Selling to anyone who takes security seriously ends the same way: a spreadsheet of two hundred questions, most of which you answered for the last prospect in slightly different words.

The trust module has promised AI-answered questionnaires since launch, but only the outbound direction — questionnaires you send to vendors — actually existed. This release builds the inbound side on the same foundation. Upload the sheet, check the extracted questions, and draft. The drafting order is the point: your own public words come first, because an answer that matches your trust center is one your prospect can verify. Internal policies, evidence, and controls come second and are weighted down, because they were written for insiders. Every answer cites its source, and a quote the model paraphrased is labeled as paraphrased.

When you approve a questionnaire, its answers become the library. The next prospect who asks "Do you encrypt customer data at rest?" as "Is data encrypted when stored?" gets a draft from the answer you already approved.

The trust center itself became something you run rather than something you configure. Visitors subscribe and confirm by email, you send updates by topic, and the visitor questions, access requests, and subscriber list moved out of Settings into the main app, where the work actually happens.

On the compliance side, custom control mapping is for teams who wrote their own controls and need each one tied to the several framework requirements it covers. Map it in the app or in the CSV import, and anything ambiguous is reported back instead of guessed. PCI assessment drafting now reads what is inside your evidence before it writes a response, and writes one per testing procedure.

  • Inbound security questionnaires with grounded AI drafting and an answer library
  • Trust center subscribers with double opt-in, topic-based updates, and unsubscribe
  • Trust inboxes in the main app — questions, access requests, subscribers
  • Custom control mapping and per-scope Tests
  • Evidence-grounded PCI drafting, per-procedure responses, and a full SAQ report
  • Readable findings and a weekly coverage digest
  • A security hardening pass across functions, route guards, and notification content

Azure, Loops, and an Inbox That Knows What Is On Fire

Azure cloud posture joins the connector estate with one-click role assignment, Loops turn "when X happens, do Y" into agent work you can see in Runs, the inbox ranks by urgency instead of alphabet, and evidence collapses into versioned records that stay verified without piling up.
Azure, Loops, and an Inbox That Knows What Is On Fire

Most of this release is about making the platform act without being asked — and making what it does legible.

Loops close a gap the automation model has promised since it shipped. Recurring schedules could create work on a timer, but nothing could say "when a critical finding is raised, open a remediation task and draft the ticket." Now a Loop binds a trigger and a filter to plain-language instructions, and when it fires the agent plans and executes the work through the same pipeline every other agent run uses. You see the result in Runs. Loops are edited as drafts and published deliberately, because something that acts on your workspace by itself should not change behavior while you are halfway through a thought.

Azure joins AWS, Microsoft 365, Google Workspace, and the PaaS connectors. It is a separate integration from Microsoft 365 for a reason that is not cosmetic: Entra app permissions grant nothing in Azure Resource Manager, so an Azure-only customer should never be asked for tenant-wide directory access they do not need. Setup was rebuilt around one observation — the token episki already holds carries the service principal's identity, and the tenant root group's id is the tenant id — so there is nothing to look up and nothing to paste that can fail on a permission unrelated to the task.

The inbox now answers the question an inbox exists for. It used to list everything you owned grouped by kind, so "assessment" outranked "task" whether or not anything was on fire. The Priority tab orders by urgency, shows why each item is there, and the sidebar badge finally reaches zero.

  • Loops — event- and schedule-driven agent automation, capability-gated, with draft and publish
  • Azure cloud posture with one-click role assignment
  • Priority inbox ranked by urgency, with per-member signal choices
  • Versioned evidence — one record per stream, re-verified on every collection, no duplicate rows
  • Command sees attached images
  • Per-channel notification settings and a badge that counts what matters

Cloud Evidence That Actually Evaluates

Multi-account AWS, Supabase, Vercel, Netlify, and GitHub connectors now write real control verdicts — and a failing check raises a finding instead of quietly passing. Plus agent skills, approved exceptions that satisfy a check, per-boundary program reporting, and a desktop app with tabs.
Cloud Evidence That Actually Evaluates

Collecting evidence was never the hard part. Producing a verdict you can defend is.

This release connects the last link in that chain. Every integration operation now decodes its own response, evaluates its assertions, and writes a real verdict against the control — and the failure modes that used to resolve silently in your favor no longer do. An AccessDenied used to arrive as evidence with zero records, which made a "no critical Security Hub findings" check pass. XML from IAM, EC2, and S3 was never decoded, so those checks were reading an empty array. A relative-date predicate compared ISO strings against the literal text CUTOFF_PLACEHOLDER. Each of those failed by attesting a control rather than by erroring, which is the only kind of bug that matters here.

Now an undecodable response fails its region, empty evidence returns inconclusive and attests nothing, an incomplete sync run is excluded from coverage, and every failing check raises a finding with the evidence attached.

The connector estate grew to match. AWS sync spans multiple accounts, multiple regions, and AWS Organizations — fanning out with per-account failure isolation, stamping every record with its account and region, and offering chained role access for estates that will not run StackSets. Supabase, Vercel, Netlify, and GitHub cover the teams whose production footprint is a PaaS stack, where hosting, database, and deploy pipeline previously produced no automated evidence at all.

  • Approved exceptions can satisfy a check — pointed at specific records, requiring a real approver, and expiring on their own, so an accepted risk is not a permanent carve-out
  • Agent skills bundle instructions, tools, and when-to-use guidance, loading on demand instead of on every turn, with provenance-aware approvals and asynchronous sub-agents
  • Programs report against individual boundaries, with account and region scope rules that finally make the PCI CDE case reachable
  • Assessments scoped to a program inherit its controls and every piece of evidence already on file
  • A desktop app with tabs, persisted per workspace and reorderable by drag
  • AI spend attributed by surface and operation, with a usage report that reconciles itself
  • CSP enforced, privileged RPCs behind the service role, and a security pass that closed every advisor finding

Open Signup, PCI DSS, and Agent-Run Vendor Reviews

The waitlist is gone — anyone can sign up. Plus full-fidelity PCI DSS ROC & SAQ assessments, an agent that runs the vendor evidence lifecycle over email, trust centers served at your own domain root, and an evidence-backed assurance dashboard.
Open Signup, PCI DSS, and Agent-Run Vendor Reviews

The waitlist is gone. Anyone can sign up and start a workspace — no invite, no waiting.

This release also puts the agent runtime from June to work on the most tedious loop in GRC: vendor reviews. Every workspace gets its own agent email address. Send a questionnaire or evidence request from a vendor's Communications tab, and when the vendor replies, the agent triages the attachment, links it to the vendor with recorded provenance, and threads a conversational response. Accept the evidence and the review cadence advances on its own. CAIQ v4.1 and CCM Lite questionnaires join the catalog, alongside ISO 27001 and pen-test evidence playbooks.

PCI DSS lands as a first-class framework: full-fidelity ROC and SAQ assessments with an in-app report, a summary matrix, and export. And the dashboard now shows evidence-backed assurance — scores derived from the actual evidence behind each control, with drill-downs and an attention card for what needs action.

  • Trust centers serve at your own domain root — trust.acme.com, clean URLs, no redirect — with versioned resources and expiry reminders
  • Integrations map evidence to control coverage, with scoping, one-click AWS connect, and per-assertion sync outcomes
  • Crosswalk any two frameworks through the SCF hub, with a controlled mapping vocabulary and provenance
  • Global command palette, unified activity-and-comments feed, rich-text descriptions, and tabbed list views
  • Workspace scoping enforced at the database layer, plus a security and reliability hardening pass from a full codebase review

episki, rebuilt around agents

The biggest release in episki's history — a ground-up, agent-first rewrite. Agents plan, execute, and surface work for approval across a unified compliance platform, with new Risk, TPRM, Trust, and AI Governance modules.
episki, rebuilt around agents

This is the largest release in episki's history: a ground-up rewrite around a single idea — the platform should run the compliance lifecycle, and humans should gate the decisions that matter.

Every workflow now runs on an agent runtime. Ask an agent to do something and it proposes a plan, executes it as discrete, observable step-runs, and stops for your approval on anything sensitive. Evidence pulls run as deterministic recipes — plain, inspectable code, not model output — so auditors can read exactly how each artifact was gathered. Bring your own tools over MCP, and set runtime safety floors that the agent cannot exceed.

On top of that runtime, the Compliance Platform unifies frameworks, controls, evidence, policies, programs, assessments, and reporting in one workspace — and four modules extend it: Risk, Third-Party Risk, Trust, and AI Governance.

  • Agents plan, run step-runs, and request approval — with deterministic recipes, MCP support, and safety floors
  • SCF framework import, evidence lineage, versioned policies, scopes, obligations, and live auditor-ready reports
  • Full risk register with qualitative and quantitative scoring, acceptance decisions, threats, and treatments
  • Unlimited-vendor TPRM, a branded Trust Center on your domain, and AI Governance for the AI your org uses
  • Native AWS / Google / Microsoft / Jira / Slack integrations, semantic search, a unified inbox, and an immutable audit trail

For the thinking behind the rewrite, read Autonomous GRC and the new shape of the compliance program.

Risk Management, My Focus, and Bulk Assignment

A full risk management module with exceptions and module-based billing, a personalized My Focus view, and bulk control assignment with shared prev/next navigation.
Risk Management, My Focus, and Bulk Assignment

This release adds a full risk management module, a personalized My Focus view, and bulk assignment across the app.

Risk management ships as the first premium add-on module. Define risks and threats, map them to controls, run treatment and approval workflows, and track posture over time with the new attention queue and heatmap. Documented exceptions handle carve-outs from controls and policies with multi-approver sign-off, auto-rolling status, and expiry reminders. The SCF threats catalog is integrated out of the box.

My Focus is a new personalized page showing what's on your plate today — your tasks, issues, risks needing attention, and acceptances expiring within 60 days — with an all-caught-up empty state and a live count badge in the sidebar.

Bulk assignment lands as a single generic framework across assessment controls, tasks, issues, risks, and recurring tasks. Pick rows, set owner and due date, and recipients get one rolled-up notification per entity instead of a flood of per-row messages. Assessment controls now have a dedicated state hub with row-selection, an Assignees column, an Assignee filter, and a right-sidebar owner picker with realtime updates.

  • Module-based billing lets workspaces add risk as a paid add-on on top of the base compliance subscription
  • Risk Posture widget and new stat tiles (Open Risks, Acceptances Expiring) on the workspace dashboard when the risk module is active
  • AI chat now has conversation history with search and archive, plus new tools to create notes, navigate, update tasks in bulk, and suggest next steps
  • Shared prev/next navigation with w/x keyboard shortcuts across risks, threats, exceptions, tasks, and issues
  • Compliance scoring view and docs-as-code groundwork for in-app documentation

Program Scopes & Assurance Tracking

Per-scope assurance tracking with control degradation measurement, assurance overrides with attestation, confidence snapshots, and billing overrides.
Program Scopes & Assurance Tracking

Programs now support scopes — a major upgrade to how you track and measure control effectiveness.

Define scope targets, link controls to specific scopes, and track assurance at the scope level. Control assurance overrides with attestation support let you document and justify deviations from expected assurance levels, while confidence snapshots capture point-in-time program health so you can measure control degradation over time.

  • Per-scope health and risk views let you drill into scope-level control effectiveness directly from the program dashboard
  • New scope module with dedicated management pages for scope targets and control linking
  • Billing overrides support trial extensions, grace periods, and free access for workspace management
  • End-to-end tests with Playwright and automated RLS testing in CI for stronger reliability

Out of Beta: Settings, Reports & Billing

Redesigned settings, built-in report templates, Stripe Sync Engine for billing, and MCP server with OAuth 2.1.
Out of Beta: Settings, Reports & Billing

episki is officially out of beta. This release brings a redesigned settings experience, built-in report templates, and a complete billing overhaul.

Settings pages now have their own dedicated sidebar with grouped navigation across personal, workspace, and configuration sections, giving you a cleaner, more focused experience when managing your workspace.

  • Built-in report templates ready to use for PCI DSS 4.0.1 ROC, status reports, and final reports
  • Global system status groups for PCI DSS and NIST CSF Maturity out of the box
  • Stripe Sync Engine replaces manual webhooks for reliable billing data
  • MCP server with OAuth 2.1 enables third-party integrations
  • Drag-and-drop image uploads stored securely in Supabase with RLS

AI Gateway & Enhanced Security

Centralized AI gateway for all AI features and OTP verification for stronger account security.
AI Gateway & Enhanced Security

Starting the year strong with a centralized AI gateway and enhanced security features to protect your compliance data.

All AI features now route through our unified AI gateway, providing centralized management, audit logging, and improved performance for document analysis.

  • Centralized management for all AI interactions
  • Rate limiting for fair usage across all users
  • Audit logging to track AI interactions for compliance
  • Model selection to choose the right AI for each task
  • Faster RAG processing for document analysis

AI-Powered Compliance

Introducing RAG pipeline and Notion-like AI assistance for smarter compliance management.
AI-Powered Compliance

AI is here to supercharge your compliance workflow. We're introducing intelligent assistance powered by our new RAG pipeline.

Our Retrieval-Augmented Generation pipeline understands your compliance context, automatically analyzes documents, and builds organizational knowledge over time.

  • Context-aware responses that understand your frameworks and controls
  • Automatic document analysis for uploaded artifacts
  • Evidence suggestions for satisfying controls
  • Knowledge base that grows with your organization

TypeScript & Quality of Life

Full TypeScript enforcement, smarter autocomplete, and numerous usability improvements.
TypeScript & Quality of Life

This release focuses on platform stability and everyday usability with full TypeScript enforcement and quality of life improvements.

We've resolved all TypeScript errors and enabled strict checking in CI, resulting in better IDE support, improved autocomplete, and a more maintainable codebase.

  • Catch errors before they reach production
  • Improved autocomplete and error detection in your IDE
  • More maintainable and reliable codebase

Import/Export & Custom Statuses

Full import and export capabilities for testing procedures, plus customizable control statuses.
Import/Export & Custom Statuses

Move your data freely with full import/export support and customize how you track control status.

Transfer testing procedures and data between systems with full import/export support. Move your data freely with CSV and JSON format support and automatic validation during import.

  • Export testing procedures for backup or sharing
  • Bulk import from spreadsheets or other GRC tools
  • CSV and JSON formats supported
  • Automatic validation during import to catch errors

Custom Statuses & Dark Mode Polish

Customize how you track control status and enjoy a refined dark mode experience.
Custom Statuses & Dark Mode Polish

Every organization tracks compliance differently. This release lets you customize control statuses and brings a polished dark mode experience.

Define statuses that match your workflow with custom labels, color-coding, and flexible transition rules.

  • Create status labels that make sense for your team
  • Color-code statuses for quick visual identification
  • Configure which statuses can transition to which