Skip to main content

Product updates

Changelog

Each important change is clearly explained.

august 2026

5 Changes in
DORA Business Functions Register

Track DORA Critical ICT Functions in a dedicated register and link each one to the assets, third parties, and people that keep it running—via console, CLI, MCP, or n8n.

The Platform
Smarter Privacy Law Detection

Cookie consent now resolves geolocation to the state or province, so US and Canadian visitors get the privacy law banner that actually applies—not a generic country-level one.

Cookie Banner
CCPA Privacy Choices Panel

California visitors get a Your Privacy Choices panel in the cookie banner to opt out of data sale and sharing, plus a notice-only banner for regions with no consent law.

Cookie Banner
Dutch Language Support

Dutch is now supported across the console, compliance portal, and cookie banner—including documents, NDA flows, access requests, and Privacy Choices panel copy.

The Platform Portal conformitate Cookie Banner
Multiple Compliance Portals

Run multiple compliance portals from one organization—each with its own catalog of audits and documents, visitor experience, and publication controls for different products or segments.

Portal conformitate

iulie 2026

17 Changes
Log Exports for Audits

Export audit logs or SCIM events as a CSV from the console, Connect, MCP, or CLI—no more asking ZebraByte for a data dump when auditors or your SIEM need the raw history.

The Platform
Audit Start and End Dates

Audits now track a start and end date, so review windows show up as sortable columns without opening each audit to check.

Compliance Page
Bulk Document Access Requests

Portal visitors can request access to several locked documents at once instead of filing a separate request for each one.

Compliance Page
French Language Support

ZebraByte speaks French now, in the console and in the compliance portal your customers see, its first shipped language besides English.

The Platform
More Access Review Connectors

Access Reviews now cover five more platforms, from web analytics to payments infrastructure, including Google Analytics and Segment.

Revizuire acces
Employee Device Management

Admins get a full view of employee device posture in the console, and employees can self-serve enrollment confirmation without an assumed session.

The Platform
Data Subject Rights Requests

Visitors can now file GDPR and CCPA rights requests directly from the Compliance Portal and track their status without an email chain.

Portal conformitate
Webhooks Now Show What Changed

Update events now include the entity's prior state, so you can diff old vs new values without making a separate lookup call.

Integration of
More Access Review Connectors

Four new managed connectors mean fewer manual access reviews. Provider logos and ownership checks ship before a connection goes live.

Revizuire acces
Risk Assessments now has its own tab

Jump straight from a risk to its assessments without leaving the risks list, saving clicks every time you review your risk register.

The Platform
FERPA and PCI DSS Frameworks

Import FERPA and PCI DSS controls straight into your compliance program, no manual setup needed for student or payment card data.

Portal conformitate
Edit Draft Documents via n8n

The document.update node action now edits body, title, classification, and type, and creates a draft automatically when none exists.

Integration of
Document Lifecycle Webhooks

Subscribe to document created, updated, signed, and approved events instead of polling the API and diffing the result yourself.

The Platform

iunie 2026

Thirteen changes
Deeper Third-Party Vetting Reports

Third-party vetting now keeps the full structured analysis, not just a short summary, covering risk, privacy, and AI governance.

The Platform
Four More Access Review Connectors

Support, AI routing, incident response, and email marketing join the access review connector list with Pylon and three more tools.

Revizuire acces
DocuSign Signing Integration

Connect DocuSign with a full OAuth2 flow and pick which account to use, no manual API key wrangling or copy-pasting required.

The Platform
Five New Access Review Connectors

Cover banking, sales tooling, and AI infrastructure in your next access review campaign with Mercury, Apollo.io, and three more tools.

Revizuire acces
Connect AI Agents via OAuth2 (CIMD)

MCP clients like Claude and ChatGPT can now register with ZebraByte through a standard OAuth2 client metadata document instead of a pre-provisioned client ID.

MCP
Personal API Tokens

Create, list, and revoke your own bearer tokens for scripting against the ZebraByte API, without sharing a service account with your team.

IAM
Auto-Enriched Vendor Catalog

Import vendors from a shared, auto-enriched catalog instead of typing in the same third-party details your peers already found.

The Platform
5 New Access Review Connectors

Pull user access straight from five more infrastructure and observability tools: Better Stack, SigNoz, Neon, Render, and Qovery.

Revizuire acces
Nested Third-Party Relationships

Third parties can now nest to any depth, not just one level of sub-vendor, so subprocessors of subprocessors are representable.

The Platform
Risk Assessment Boundaries

Group risk assessment nodes into named, nestable boundaries so large Mermaid diagrams stay readable as your system map grows.

The Platform
Archive Documents

Archive documents you no longer need active from the row action menu — non-destructive and consistent with archiving elsewhere in ZebraByte.

The Platform
Five New Access Review Connectors

ZebraByte adds access review connectors for Zendesk, Okta, Clerk, SendGrid, and Datadog — each pulling your user list so reviewers see who has access to what.

Revizuire acces
Automatic Tracker Policy

Publishing your cookie banner now generates a tracker policy document automatically, listing every detected tracker and its vendor.

Cookie Banner
Filter and Identify Trackers by Vendor

See the vendor behind each tracker on the banner trackers page, and filter the entire list by third party to audit everything a given vendor places.

Cookie Banner

mai 2026

14 Changes
Seven New Access Review Connectors

Seven new access review connectors land in ZebraByte, plus HTTP Basic auth support and automatic signature request cancellation.

Revizuire acces
Archive Users

Deactivate a user with the new archiveUser operation — removed from active workflows but kept in the org for audit trail purposes.

The Platform
Link Measures to Third Parties

Measures and third parties can now be linked many-to-many, third parties support self-referential relations, and measure state moves to a header badge.

The Platform
Kubernetes Helm architecture milestone

Historical platform-lineage note: the earlier self-managed architecture gained an official Helm deployment path. ZebraByte Cloud preserves the product capabilities without exposing this as a customer installation method.

Architecture
Risk Assessment in n8n

The riskAssessment resource is live in n8n, covering the entire risk assessment hierarchy with full CRUD operations for automation.

Automated
Vendors Are Now Third Parties

Vendor is now Third Party across the API, CLI, webhooks, and console — a breaking rename that better matches compliance terminology.

The Platform
Microsoft 365 in Access Reviews

Run access reviews against your Microsoft 365 users and groups directly from ZebraByte, pulling decisions straight from Entra ID.

Revizuire acces
Microsoft 365 SCIM Bridge

Sync users and groups from Microsoft Entra ID into ZebraByte automatically, closing the identity sync gap for Microsoft 365 shops.

IAM
SCIM via MCP and CLI

ZebraByte's SCIM management is now reachable from your AI agent and the terminal, so you can script provisioning without the console.

MCP CLI
Cookie Banner

Build, theme, translate, and ship a GDPR-ready cookie banner from ZebraByte, with consent signals, auto-detection, CLI, and MCP support baked in.

The Platform MCP CLI

aprilie 2026

Twelve changes
CMMI Maturity Levels on Controls

Controls now carry a real CMMI maturity score instead of a binary implemented flag, showing how mature each control actually is.

Portal conformitate
SOA as a Publishable Document

The Statement of Applicability is now a full document you can edit, publish, version, and send for approval and signature.

Portal conformitate
Inline Document Details

Document properties like classification, owner, and version are now visible directly on the page instead of hidden in a drawer.

The Platform
Statement of Applicability

The SOA section is now correctly named Statement of Applicability, matching the exact term auditors actually use for it.

Portal conformitate
Markdown Copy-Paste in the Editor

Paste markdown into the rich text editor and it renders automatically, tables, headers, lists, and code blocks included.

The Platform
Measure-Document Linking

Link documents directly to measures for better evidence mapping, so auditors can see the supporting policies at a glance.

Portal conformitate
Access Reviews

Run periodic access reviews to verify who still has access to what, tracking evidence in ZebraByte instead of a spreadsheet.

Revizuire acces
In-Progress State for Tasks

Tasks now have an in-progress state alongside open and done, making your task board genuinely useful for tracking active work.

The Platform
Rich Text Editor for Documents

Write and edit documents directly in ZebraByte with tables, links, diagrams, and slash commands, in a proper WYSIWYG editor built on TipTap.

The Platform

martie 2026

Thirteen changes
Document Classification Filter

Filter your document library by classification to quickly narrow a long list down to just your public policies or internal procedures.

The Platform
Major.Minor Document Versioning

Minor version updates no longer require everyone to sign the document again, saving re-signatures for changes that actually matter.

The Platform
Document Approval Workflow

Documents now go through a proper review and approval process before publishing, tracking who signed off and when for auditors.

The Platform
Task Priority

Set priority levels, urgent, high, medium, or low, on tasks so your team always knows what to tackle first during a busy sprint.

The Platform
Automatic Evidence Descriptions

Upload evidence and ZebraByte automatically analyzes the file and generates a plain-language description of exactly what it contains.

The Platform
Access Logs

Get full visibility into every action in your organization with SIEM-ready audit logs auditors expect during SOC 2 and ISO 27001 reviews.

The Platform
Google and Microsoft SSO

Sign in to ZebraByte with your Google Workspace or Microsoft Entra ID enterprise account, no new password or magic link required.

IAM
Skip Mailing List Confirmation Emails

Add subscribers to your compliance page mailing list without a confirmation email, ideal for contacts who already signed a DPA or NDA.

The Platform
Drag-and-Drop Audit Reports

Upload audit report PDFs by dragging and dropping them directly onto your audit list, no more digging through attachment menus.

The Platform
Cross-Origin CSRF Protection

New cross-origin request forgery (CSRF) defenses stop malicious sites from making unauthorized requests while you're logged into ZebraByte.

IAM
Full-Text Search for Measures

Find any measure instantly by searching across titles, descriptions, and details instead of scrolling through long lists.

The Platform
Unified Findings

Track audit findings with shared severity levels across the web app, MCP, and CLI, so nothing gets lost switching between tools.

The Platform MCP CLI
ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert