Track DORA Critical ICT Functions in a dedicated register and link each one to the assets, third parties, and people that keep it running—via console, CLI, MCP, or n8n.
Product updates
Changelog
Each important change is clearly explained.
august 2026
5 Changes inCookie consent now resolves geolocation to the state or province, so US and Canadian visitors get the privacy law banner that actually applies—not a generic country-level one.
California visitors get a Your Privacy Choices panel in the cookie banner to opt out of data sale and sharing, plus a notice-only banner for regions with no consent law.
Dutch is now supported across the console, compliance portal, and cookie banner—including documents, NDA flows, access requests, and Privacy Choices panel copy.
Run multiple compliance portals from one organization—each with its own catalog of audits and documents, visitor experience, and publication controls for different products or segments.
iulie 2026
17 ChangesExport audit logs or SCIM events as a CSV from the console, Connect, MCP, or CLI—no more asking ZebraByte for a data dump when auditors or your SIEM need the raw history.
Audits now track a start and end date, so review windows show up as sortable columns without opening each audit to check.
Portal visitors can request access to several locked documents at once instead of filing a separate request for each one.
ZebraByte speaks French now, in the console and in the compliance portal your customers see, its first shipped language besides English.
Access Reviews now cover five more platforms, from web analytics to payments infrastructure, including Google Analytics and Segment.
Admins get a full view of employee device posture in the console, and employees can self-serve enrollment confirmation without an assumed session.
Visitors can now browse your compliance portal updates as a real feed, and subscribe by email to hear about changes automatically.
Visitors can now narrow down your subprocessor list by facet instead of scrolling through everything on the public trust page.
Trust Center is now the Compliance Portal, live in production with its own branded sign-in, custom domain, and document library.
Visitors can now file GDPR and CCPA rights requests directly from the Compliance Portal and track their status without an email chain.
Update events now include the entity's prior state, so you can diff old vs new values without making a separate lookup call.
Four new managed connectors mean fewer manual access reviews. Provider logos and ownership checks ship before a connection goes live.
Jump straight from a risk to its assessments without leaving the risks list, saving clicks every time you review your risk register.
Import FERPA and PCI DSS controls straight into your compliance program, no manual setup needed for student or payment card data.
The document.update node action now edits body, title, classification, and type, and creates a draft automatically when none exists.
Subscribe to document created, updated, signed, and approved events instead of polling the API and diffing the result yourself.
A new ZebraByte Trigger node starts your n8n workflow the moment a document event happens, with HMAC verification and no polling node.
iunie 2026
Thirteen changesThird-party vetting now keeps the full structured analysis, not just a short summary, covering risk, privacy, and AI governance.
Support, AI routing, incident response, and email marketing join the access review connector list with Pylon and three more tools.
Connect DocuSign with a full OAuth2 flow and pick which account to use, no manual API key wrangling or copy-pasting required.
Cover banking, sales tooling, and AI infrastructure in your next access review campaign with Mercury, Apollo.io, and three more tools.
Give Compliance Portal pages a memorable custom URL slug instead of a generated ID, perfect for links in a sales deck or email.
MCP clients like Claude and ChatGPT can now register with ZebraByte through a standard OAuth2 client metadata document instead of a pre-provisioned client ID.
Create, list, and revoke your own bearer tokens for scripting against the ZebraByte API, without sharing a service account with your team.
Employee document signings now generate a real signed PDF and an esign record, the same way document approvals already did.
Import vendors from a shared, auto-enriched catalog instead of typing in the same third-party details your peers already found.
Pull user access straight from five more infrastructure and observability tools: Better Stack, SigNoz, Neon, Render, and Qovery.
Third parties can now nest to any depth, not just one level of sub-vendor, so subprocessors of subprocessors are representable.
Group risk assessment nodes into named, nestable boundaries so large Mermaid diagrams stay readable as your system map grows.
The ZebraByte cookie consent banner adds 9 languages — bringing the total to 13 — and adapts to a visitor's browser language with no extra configuration.
Archive documents you no longer need active from the row action menu — non-destructive and consistent with archiving elsewhere in ZebraByte.
ZebraByte adds access review connectors for Zendesk, Okta, Clerk, SendGrid, and Datadog — each pulling your user list so reviewers see who has access to what.
The ZebraByte cookie-banner SDK 0.8.0 exposes trackerType on every CookieItem, so the headless cookie list and themed banner can render what kind of tracker each entry is.
Publishing your cookie banner now generates a tracker policy document automatically, listing every detected tracker and its vendor.
The thirdParty vet operation is now available in the ZebraByte n8n node, queueing a vetting job that runs asynchronously without blocking your workflow.
See the vendor behind each tracker on the banner trackers page, and filter the entire list by third party to audit everything a given vendor places.
mai 2026
14 ChangesThree new capabilities land in the n8n node: archive users, link measures to third parties, and model self-referential third-party relations.
Seven new access review connectors land in ZebraByte, plus HTTP Basic auth support and automatic signature request cancellation.
Deactivate a user with the new archiveUser operation — removed from active workflows but kept in the org for audit trail purposes.
Measures and third parties can now be linked many-to-many, third parties support self-referential relations, and measure state moves to a header badge.
Sync errors from the SCIM bridge are now exposed in the API and surfaced on the Google Workspace and Microsoft 365 connector cards in the console.
Historical platform-lineage note: the earlier self-managed architecture gained an official Helm deployment path. ZebraByte Cloud preserves the product capabilities without exposing this as a customer installation method.
The riskAssessment resource is live in n8n, covering the entire risk assessment hierarchy with full CRUD operations for automation.
Vendor is now Third Party across the API, CLI, webhooks, and console — a breaking rename that better matches compliance terminology.
Every cookie banner interaction is mapped to country and privacy regulation automatically — consent records, APIs, and the banner UI stay aligned.
The SCIM bridge syncs Google Cloud Identity directories the same way as Google Workspace — automate provisioning without a Workspace license.
Run access reviews against your Microsoft 365 users and groups directly from ZebraByte, pulling decisions straight from Entra ID.
Sync users and groups from Microsoft Entra ID into ZebraByte automatically, closing the identity sync gap for Microsoft 365 shops.
ZebraByte's SCIM management is now reachable from your AI agent and the terminal, so you can script provisioning without the console.
Build, theme, translate, and ship a GDPR-ready cookie banner from ZebraByte, with consent signals, auto-detection, CLI, and MCP support baked in.
aprilie 2026
Twelve changesControls now carry a real CMMI maturity score instead of a binary implemented flag, showing how mature each control actually is.
Data and asset registry exports are gone. Both registries now publish, version, and get signed like any other compliance document.
ZebraByte now speaks OAuth2 and OpenID Connect — anyone can build integrations that plug straight into your compliance stack.
The Statement of Applicability is now a full document you can edit, publish, version, and send for approval and signature.
People with ended contracts no longer appear in the signature request dialog, so former employees don't clutter the list.
Document properties like classification, owner, and version are now visible directly on the page instead of hidden in a drawer.
The SOA section is now correctly named Statement of Applicability, matching the exact term auditors actually use for it.
Paste markdown into the rich text editor and it renders automatically, tables, headers, lists, and code blocks included.
Link documents directly to measures for better evidence mapping, so auditors can see the supporting policies at a glance.
Run periodic access reviews to verify who still has access to what, tracking evidence in ZebraByte instead of a spreadsheet.
Tasks now have an in-progress state alongside open and done, making your task board genuinely useful for tracking active work.
Write and edit documents directly in ZebraByte with tables, links, diagrams, and slash commands, in a proper WYSIWYG editor built on TipTap.
martie 2026
Thirteen changesFilter your document library by classification to quickly narrow a long list down to just your public policies or internal procedures.
Minor version updates no longer require everyone to sign the document again, saving re-signatures for changes that actually matter.
Documents now go through a proper review and approval process before publishing, tracking who signed off and when for auditors.
Set priority levels, urgent, high, medium, or low, on tasks so your team always knows what to tackle first during a busy sprint.
Upload evidence and ZebraByte automatically analyzes the file and generates a plain-language description of exactly what it contains.
Let search engines index your compliance page so prospects can find it on Google when they search your company plus "security".
Get full visibility into every action in your organization with SIEM-ready audit logs auditors expect during SOC 2 and ISO 27001 reviews.
Sign in to ZebraByte with your Google Workspace or Microsoft Entra ID enterprise account, no new password or magic link required.
Add subscribers to your compliance page mailing list without a confirmation email, ideal for contacts who already signed a DPA or NDA.
Upload audit report PDFs by dragging and dropping them directly onto your audit list, no more digging through attachment menus.
New cross-origin request forgery (CSRF) defenses stop malicious sites from making unauthorized requests while you're logged into ZebraByte.
Find any measure instantly by searching across titles, descriptions, and details instead of scrolling through long lists.
Track audit findings with shared severity levels across the web app, MCP, and CLI, so nothing gets lost switching between tools.
There are no updates in this category.