The dashboard experience has been consolidated to provide a more consistent and streamlined way to access and review organizational metrics.
Introduced a Key Risk Indicator system to help organizations monitor important risk metrics, identify threshold breaches, and track risk conditions over time.
The FedRAMP POA&M export has been updated to align with the current Rev. 5 format and now uses the Export Builder framework for improved consistency and maintainability.
Added support for Army-specific Test Results and POA&M export requirements.
Added a profile to support Army framework imports and simplify configuration for Army compliance requirements.
Added support for manually importing and converting crosswalk information from supported compliance sources.
Added support for automatically backfilling embeddings for SSPs, Control Implementations, Policies, Evidence, and Components when Retrieval-Augmented Generation (RAG) capabilities are enabled.
Security Plans can now be routed through the appropriate re-approval process when substantive modifications are made.
Approval history is now recorded for Security Plans when approval workflows are initiated by triggers, including configurations where the SSP Approval Workflow feature is disabled.
Improved Evidence file version management, including support for renumbering cycle versions to provide clearer version history.
Improved the Security Plan Bulk Editor experience, including more consistent placement of drag handles in accordance with application UI conventions.
Improved catalog navigation by selecting the Catalog module by default when appropriate.
Added support for overriding categorization values where applicable.
Improved file selection controls in AI SSP Author, including more reliable Select All and Deselect All functionality.
Improved bulk selection in RegML Author so that Select All respects the currently active control-family filter.
Improved accessibility across several areas of the application, including command palette controls, dashboard controls, theme colors, target sizes, and permission-related messaging.
Added documentation describing how GitHub releases correlate with Jira release versions to improve release tracking and traceability.
Corrected Tasks terminology and navigation across the main Actions module and its record-level subsystem.
Resolved an issue where file version increments could occur unpredictably and unrelated files could incorrectly be marked as superseded.
Resolved an issue preventing External Service entries from being changed to Cancelled status.
Fixed issues that prevented the Planned Implementation Date from being saved or persisted for controls, including Control Builder v2.
Removed obsolete Inherited and Remote Inheritance Instance fields.
Fixed an issue where a Related Policy selection did not correctly display or link to the associated policy in the Policy module.
Improved questionnaire completion calculations to provide more reliable completion status and a clear path to submission.
Resolved issues that prevented some Components from being attached to Security Plans.
Fixed the Control Implementation list so that the associated Security Plan title is displayed correctly.
Resolved several export-related issues, including:
- Diagram field placeholders not being replaced correctly in DOCX templates.
- Export names incorrectly displaying "template."
- FedRAMP POA&M exports returning errors.
- Incorrect formatting of the FedRAMP POA&M export dialog.
- Raw template tokens appearing in FedRAMP Rev. 5 SSP DOCX exports.
- eMASS SSP exports failing for larger Security Plans.
- Incorrect MIME type being used for Excel downloads.
Corrected the ISO 27001 catalog information displayed in the Compliance Hygiene Dashboard.
Fixed chart scaling that could display values outside the expected 0–100 range.
Resolved issues affecting the Evidence and Files experience, including:
- Incorrect Evidence badge counts.
- Evidence cycle toggle alignment.
- Evidence upload styling.
- Evidence file version numbering.
- Hard-deleted Evidence records continuing to appear in module lists.
Fixed the SSP Inventory Workspace so vulnerability and issue counts display correctly.
Resolved issues affecting POA&M Status Board record pages and dashboard analytics, including secondary Baseball Cards that could not be selected for drill-down.
Fixed filtering and time-bucketing issues that could cause errors, incorrect filter behavior, or unexpected handling of dates.
Improved XCCDF import processing to correctly handle valid Boolean values and resolved issues where imported benchmarks could not subsequently be accessed.
Corrected authorization controls for Questionnaire endpoints to ensure appropriate permission checks are applied.
Strengthened authorization and tenant-isolation protections across several API operations to prevent unauthorized access to data across application or tenant boundaries.
Corrected API responses so permission failures return the appropriate 403 Forbidden response instead of 401 Unauthorized.
Resolved several issues affecting Issues, including:
- Facility fields appearing when they should be inactive.
- Deviation Summary appearing when configured as inactive.
- Issues becoming unsavable after automation populated Date First Detected.
- Due Dates being unexpectedly replaced by SLA dates.
- Blank Date First Detected values being incorrectly populated with the current date and time.
Fixed an issue preventing authorization boundary diagrams from being attached or linked within the system authorization boundary description.
Resolved an issue where the workflow template designer could fail to load due to invalid automatically saved steps.
Fixed workflow tooltips and history displays that incorrectly showed Assigned to: None for Manager-type workflow steps.
Resolved an issue where starting a Policy custom workflow could incorrectly activate the Evidence workflow.
Fixed the Lightning Assessment action in Scheduled Audits so that it opens within the appropriate audit context instead of navigating away.
Corrected the display of control descriptions in Lightning Assessments so that raw HTML is no longer displayed.
Resolved an issue preventing multiple Requirement Assessments from being created from the Assess Requirements workspace.
Fixed intermittent errors that could occur when creating or renaming Security Plans.
Fixed an issue where Controls did not refresh correctly when navigating from a Component to its parent Security Plan using breadcrumbs.
Corrected Control behavior requiring an Implementation Statement when the Control is configured as Fully Inherited.
Fixed an issue where duplicating a field did not create the corresponding custom form field.
Resolved issues affecting deletion and record cleanup, including records remaining visible after deletion and problems with changes and interconnect deletion workflows.
Fixed catalog import failures that could occur when users did not have a workspace or application in scope.
Improved catalog synchronization and external mapping updates to ensure changes are correctly tracked and existing mapping data is preserved.
Fixed an issue where dashboard drill-down operations could continue retrying indefinitely when underlying module data failed to load.
Resolved concurrency issues that could cause application deletion or creation operations to become blocked or take several minutes to complete.
Improved dashboard control sizing to meet accessibility requirements for interactive target sizes.
Restored appropriate accessibility semantics for the command palette and its decorative elements.
Resolved intermittent errors during Security Plan creation when newly created records could not immediately be retrieved within the request scope.
Improved migration resilience so migration circuit-breaker state persists across container restarts.
Fixed paging behavior that could cause records to be duplicated or omitted when queries did not have consistent ordering.
Resolved an issue preventing the KRI grid Save control from displaying correctly.
Fixed an issue where subsequent KRI threshold breaches could create duplicate Issues instead of updating the existing open Issue.
Corrected request logging so the logged response status accurately reflects the status returned to the client.
Resolved an issue where requests without an application identifier could receive an invalid application context, causing subsequent operations to fail.
Improved cascade-delete processing to prevent database deadlocks when multiple test suites or delete operations execute concurrently.
Removed unnecessary build tooling from the production application image to reduce the deployed runtime footprint.
Removed an obsolete plaintext-token service account purpose associated with the retired Automation Manager functionality.
Fixed an issue where risks associated with a Control Implementation were not displayed correctly.
Additional security and reliability improvements were made across the platform, including stronger tenant isolation, authorization enforcement, audit handling, error responses, and protection against unintended information disclosure.