<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>episki</title>
    <link>https://episki.com/now</link>
    <description>GRC platform updates, changelog, and insights</description>
    <language>en</language>
    <lastBuildDate>Mon, 02 Mar 2026 06:24:59 GMT</lastBuildDate>
    <atom:link href="https://episki.com/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title><![CDATA[What to Do If PCI Compliance Goes Off Track: A Practical PCI DSS Remediation Plan]]></title>
      <link>https://episki.com/blog/2026-02-23-slack-comms-desktop</link>
      <guid>https://episki.com/blog/2026-02-23-slack-comms-desktop</guid>
      <description><![CDATA[Failed a PCI audit or missed a PCI DSS requirement? Learn how to build a structured remediation plan, use compensating controls, and recover from PCI non-compliance with confidence.]]></description>
      <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Out of Beta: Settings, Reports & Billing]]></title>
      <link>https://episki.com/changelog/2026-02-11-settings-reports-billing</link>
      <guid>https://episki.com/changelog/2026-02-11-settings-reports-billing</guid>
      <description><![CDATA[Redesigned settings, built-in report templates, Stripe Sync Engine for billing, and MCP server with OAuth 2.1.]]></description>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <category>changelog</category>
    </item>
    <item>
      <title><![CDATA[Strategies in a Shrinking Resource Economy: Building a Resilient Security Program]]></title>
      <link>https://episki.com/blog/security-shrinking-resources</link>
      <guid>https://episki.com/blog/security-shrinking-resources</guid>
      <description><![CDATA[Practical strategies for security leaders to maintain impact and resilience even when budgets and resources are shrinking.]]></description>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[AI Gateway & Enhanced Security]]></title>
      <link>https://episki.com/changelog/2026-01-22-ai-gateway-security</link>
      <guid>https://episki.com/changelog/2026-01-22-ai-gateway-security</guid>
      <description><![CDATA[Centralized AI gateway for all AI features and OTP verification for stronger account security.]]></description>
      <pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate>
      <category>changelog</category>
    </item>
    <item>
      <title><![CDATA[AI Governance and Compliance: What Every SaaS Company Needs to Know]]></title>
      <link>https://episki.com/blog/ai-governance-compliance</link>
      <guid>https://episki.com/blog/ai-governance-compliance</guid>
      <description><![CDATA[A practical guide to AI governance for SaaS companies – covering regulatory requirements, model documentation...]]></description>
      <pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate>
      <category>ai</category>
    </item>
    <item>
      <title><![CDATA[AI Governance and Compliance: What Every SaaS Company Needs to Know]]></title>
      <link>https://episki.com/blog/launch</link>
      <guid>https://episki.com/blog/launch</guid>
      <description><![CDATA[A practical guide to AI governance for SaaS companies – covering regulatory requirements, model documentation...]]></description>
      <pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate>
      <category>ai</category>
    </item>
    <item>
      <title><![CDATA[Beyond Memorization: How episki Supports True Security Awareness Through Behavior Change]]></title>
      <link>https://episki.com/blog/beyond-memorization</link>
      <guid>https://episki.com/blog/beyond-memorization</guid>
      <description><![CDATA[Why quizzes and policy read-throughs fall short, and how episki helps teams build real security instincts through contextual, scenario-driven awareness.]]></description>
      <pubDate>Fri, 09 Jan 2026 00:00:00 GMT</pubDate>
      <category>news</category>
    </item>
    <item>
      <title><![CDATA[Compliance in the Cloud]]></title>
      <link>https://episki.com/blog/compliance-in-the-cloud</link>
      <guid>https://episki.com/blog/compliance-in-the-cloud</guid>
      <description><![CDATA[A practical guide for growing companies on how to approach cloud compliance with confidence, clarity, and the right tools.]]></description>
      <pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[When PCI Compliance Goes Off Track: How to Respond and Recover with Confidence]]></title>
      <link>https://episki.com/blog/when-compliance-goes-off-track</link>
      <guid>https://episki.com/blog/when-compliance-goes-off-track</guid>
      <description><![CDATA[A practical guide for security and compliance teams on how to respond when PCI DSS compliance slips—covering common pitfalls, recovery strategies, and how to regain control with confidence.]]></description>
      <pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Automating Evidence Collection Without Losing Control]]></title>
      <link>https://episki.com/blog/automating-evidence-collection</link>
      <guid>https://episki.com/blog/automating-evidence-collection</guid>
      <description><![CDATA[How to automate compliance evidence collection while maintaining accuracy, audit trail integrity, and human oversight where it matters.]]></description>
      <pubDate>Fri, 02 Jan 2026 00:00:00 GMT</pubDate>
      <category>ai</category>
    </item>
    <item>
      <title><![CDATA[AI-Powered Compliance]]></title>
      <link>https://episki.com/changelog/2025-12-23-ai-features</link>
      <guid>https://episki.com/changelog/2025-12-23-ai-features</guid>
      <description><![CDATA[Introducing RAG pipeline and Notion-like AI assistance for smarter compliance management.]]></description>
      <pubDate>Tue, 23 Dec 2025 00:00:00 GMT</pubDate>
      <category>changelog</category>
    </item>
    <item>
      <title><![CDATA[AI-Powered GRC: A Practical Guide to Automating Compliance Work]]></title>
      <link>https://episki.com/blog/ai-powered-grc-guide</link>
      <guid>https://episki.com/blog/ai-powered-grc-guide</guid>
      <description><![CDATA[Where AI actually helps in GRC — from evidence collection and control testing to report drafting and risk scoring — and where human judgment still matters.]]></description>
      <pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate>
      <category>ai</category>
    </item>
    <item>
      <title><![CDATA[GRC Tool Buying Guide: What to Look for in 2026]]></title>
      <link>https://episki.com/blog/grc-tool-buying-guide</link>
      <guid>https://episki.com/blog/grc-tool-buying-guide</guid>
      <description><![CDATA[How to evaluate GRC platforms in 2026 — covering must-have features, pricing models, build-vs-buy decisions, and a migration checklist.]]></description>
      <pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[How to Build a GRC Team: Roles, Skills, and Hiring Order]]></title>
      <link>https://episki.com/blog/building-a-grc-team</link>
      <guid>https://episki.com/blog/building-a-grc-team</guid>
      <description><![CDATA[When to make your first GRC hire, what skills to prioritize, how to scale from one person to a team, and when outsourcing makes more sense than hiring.]]></description>
      <pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[TypeScript & Quality of Life]]></title>
      <link>https://episki.com/changelog/2025-11-10-typescript-qol</link>
      <guid>https://episki.com/changelog/2025-11-10-typescript-qol</guid>
      <description><![CDATA[Full TypeScript enforcement, smarter autocomplete, and numerous usability improvements.]]></description>
      <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
      <category>changelog</category>
    </item>
    <item>
      <title><![CDATA[PCI DSS 4.0.1 Compliance for Fintech and Payments]]></title>
      <link>https://episki.com/blog/pci-dss-fintech</link>
      <guid>https://episki.com/blog/pci-dss-fintech</guid>
      <description><![CDATA[A practical guide to PCI DSS 4.0.1 compliance for fintech companies — covering key changes, CDE scoping, API security, and processor management.]]></description>
      <pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[SOC 2 for SaaS Companies: From First Audit to Enterprise Sales]]></title>
      <link>https://episki.com/blog/soc2-for-saas</link>
      <guid>https://episki.com/blog/soc2-for-saas</guid>
      <description><![CDATA[How SaaS companies use SOC 2 to unlock enterprise deals — from scoping and engineering controls to using your report as a sales accelerator.]]></description>
      <pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Import/Export & Custom Statuses]]></title>
      <link>https://episki.com/changelog/2025-10-09-import-export</link>
      <guid>https://episki.com/changelog/2025-10-09-import-export</guid>
      <description><![CDATA[Full import and export capabilities for testing procedures, plus customizable control statuses.]]></description>
      <pubDate>Thu, 09 Oct 2025 00:00:00 GMT</pubDate>
      <category>changelog</category>
    </item>
    <item>
      <title><![CDATA[Risk Registers Demystified: Building One That Actually Gets Used]]></title>
      <link>https://episki.com/blog/risk-register-guide</link>
      <guid>https://episki.com/blog/risk-register-guide</guid>
      <description><![CDATA[How to build a risk register that drives real decisions — covering risk identification, scoring, treatment plans, review cadence, and board reporting.]]></description>
      <pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Vendor Risk Management: A Complete Guide for Lean Teams]]></title>
      <link>https://episki.com/blog/vendor-risk-management</link>
      <guid>https://episki.com/blog/vendor-risk-management</guid>
      <description><![CDATA[A practical guide to vendor risk management for lean security teams — covering inventory, risk tiering, assessments, contract clauses, and ongoing monitoring.]]></description>
      <pubDate>Thu, 25 Sep 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Custom Statuses & Dark Mode Polish]]></title>
      <link>https://episki.com/changelog/2025-09-23-custom-statuses-dark-mode</link>
      <guid>https://episki.com/changelog/2025-09-23-custom-statuses-dark-mode</guid>
      <description><![CDATA[Customize how you track control status and enjoy a refined dark mode experience.]]></description>
      <pubDate>Tue, 23 Sep 2025 00:00:00 GMT</pubDate>
      <category>changelog</category>
    </item>
    <item>
      <title><![CDATA[Control Mapping Across Multiple Frameworks: A Practical Guide to Reuse]]></title>
      <link>https://episki.com/blog/control-mapping-frameworks</link>
      <guid>https://episki.com/blog/control-mapping-frameworks</guid>
      <description><![CDATA[How to map controls across SOC 2, ISO 27001, HIPAA, and PCI DSS to reduce duplicate work and build a unified compliance program.]]></description>
      <pubDate>Thu, 11 Sep 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[How to Prepare for a Compliance Audit: The 60-Day Countdown]]></title>
      <link>https://episki.com/blog/compliance-audit-preparation</link>
      <guid>https://episki.com/blog/compliance-audit-preparation</guid>
      <description><![CDATA[A week-by-week guide to preparing for a compliance audit — from scoping and evidence review through audit week and post-audit follow-up.]]></description>
      <pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[NIST CSF 2.0: Using the Framework to Measure and Improve Security Maturity]]></title>
      <link>https://episki.com/blog/nist-csf-security-maturity</link>
      <guid>https://episki.com/blog/nist-csf-security-maturity</guid>
      <description><![CDATA[How to use NIST CSF 2.0 as a practical tool for measuring, communicating, and improving your organization's security maturity.]]></description>
      <pubDate>Thu, 14 Aug 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[HIPAA Compliance for Healthtech Startups: A Technical Guide]]></title>
      <link>https://episki.com/blog/hipaa-compliance-healthtech</link>
      <guid>https://episki.com/blog/hipaa-compliance-healthtech</guid>
      <description><![CDATA[A practical technical guide to HIPAA compliance for healthtech startups — covering safeguards, BAAs, PHI handling, breach notification, and framework overlap.]]></description>
      <pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[ISO 27001 Certification: A Step-by-Step Implementation Guide]]></title>
      <link>https://episki.com/blog/iso27001-implementation-guide</link>
      <guid>https://episki.com/blog/iso27001-implementation-guide</guid>
      <description><![CDATA[A practical, step-by-step guide to ISO 27001 certification — from gap analysis and ISMS setup through Stage 1 and Stage 2 audits.]]></description>
      <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Compliance Playbook for Regulated Industries: Healthcare, Fintech, and SaaS]]></title>
      <link>https://episki.com/blog/compliance-playbook-regulated-industries</link>
      <guid>https://episki.com/blog/compliance-playbook-regulated-industries</guid>
      <description><![CDATA[Industry-specific compliance requirements, common pitfalls, and practical starting points for healthcare, fintech, and SaaS companies.]]></description>
      <pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Choosing the Right Compliance Framework: SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST CSF Compared]]></title>
      <link>https://episki.com/blog/compliance-framework-comparison</link>
      <guid>https://episki.com/blog/compliance-framework-comparison</guid>
      <description><![CDATA[A practical comparison of the five major compliance frameworks to help you decide which to pursue first and how to manage multiple frameworks efficiently.]]></description>
      <pubDate>Thu, 19 Jun 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[The Complete Guide to GRC for Growing Companies]]></title>
      <link>https://episki.com/blog/grc-guide-growing-companies</link>
      <guid>https://episki.com/blog/grc-guide-growing-companies</guid>
      <description><![CDATA[Everything growing companies need to know about governance, risk, and compliance — from building your first program to scaling across multiple frameworks.]]></description>
      <pubDate>Thu, 05 Jun 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[GRC Metrics Executives Actually Care About]]></title>
      <link>https://episki.com/blog/grc-metrics-execs-care-about</link>
      <guid>https://episki.com/blog/grc-metrics-execs-care-about</guid>
      <description><![CDATA[Skip vanity dashboards and focus on the few signals that show risk exposure, audit readiness, and operational velocity.]]></description>
      <pubDate>Thu, 22 May 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[Build an Evidence Library That Scales With Your Company]]></title>
      <link>https://episki.com/blog/evidence-library-that-scales</link>
      <guid>https://episki.com/blog/evidence-library-that-scales</guid>
      <description><![CDATA[A repeatable system for naming, ownership, and retention that turns evidence collection into a steady workflow instead of a scramble.]]></description>
      <pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[SOC 2 Readiness in 30 Days: A Practical Roadmap]]></title>
      <link>https://episki.com/blog/soc2-readiness-roadmap</link>
      <guid>https://episki.com/blog/soc2-readiness-roadmap</guid>
      <description><![CDATA[A focused four-week plan to scope your SOC 2 effort, assign control ownership, collect evidence, and run a clean pre-audit check.]]></description>
      <pubDate>Thu, 08 May 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
    <item>
      <title><![CDATA[5 Common Mistakes in GRC and How to Avoid Them]]></title>
      <link>https://episki.com/blog/grc-common-mistakes</link>
      <guid>https://episki.com/blog/grc-common-mistakes</guid>
      <description><![CDATA[Five common GRC pitfalls that even experienced professionals make, with practical advice on how to avoid them and keep your compliance program on track.]]></description>
      <pubDate>Thu, 01 May 2025 00:00:00 GMT</pubDate>
      <category>craft</category>
    </item>
  </channel>
</rss>