Changelog

What's new in AISEC

Every release, every fix, every improvement — documented with context so you know exactly what changed and why.

NewImprovedFixedSecurityPerformance

v1.5.0

Latest

April 28, 2025

AI governance tools, supply chain risk management, and executive reporting — the platform's most ambitious release.

New

AI-BOM (AI Bill of Materials) — auto-generate a machine-readable inventory of all AI systems, models, and data sources with ISO 42001 mappings

New

Supply Chain Risk module — vendor inventory with 5-level risk tiers, ISO 27001 A.5.19–22 control mapping, and AI-assisted supplier questionnaires

New

Executive Dashboard (Board View) — single-screen KPI summary for leadership: framework scores, open risks, audit status, evidence health

New

Competitive Benchmarking — compare your compliance posture against 3 peer anonymised datasets across any supported framework

New

Threat Intelligence Hub — live feed aggregation from MITRE ATT&CK, CISA advisories, and NVD; AI-summarised relevance scoring per control

Improved

Status page redesigned with real-time service health polling every 30 seconds and colour-coded latency indicators

Improved

Policy Library now includes 38 community templates across ISO 27001, SOC 2, GDPR, NIS2, NIST CSF, and DORA

Security

Immutable Audit Trail — every create/update/delete event is cryptographically anchored and cannot be altered by any user role

Performance

Evidence quality scoring pipeline runs asynchronously — no longer blocks the evidence upload UI

v1.4.0

Stable

March 14, 2025

Compliance drift detection, advanced monitoring, and a redesigned gap analysis engine powered by Claude.

New

Compliance Drift Detection — automated daily comparison of control implementation status against baseline; alerts when coverage drops below threshold

New

AI-powered Gap Analysis — submit your current control posture and receive a prioritised remediation plan with effort estimates and template links

New

Evidence Quality Scoring — each piece of evidence is scored 0–100 for completeness, recency, specificity, and framework relevance

New

Monitoring service expanded with drift alert history, snapshot timeline, and 90-day trend graphs

Improved

Risk Register filtering redesigned: filter by likelihood × impact matrix, owner, or treatment status simultaneously

Improved

AI Assistant now supports multi-turn conversations with full control and policy context injected per session

Fixed

Fixed policy generation TypeError when AI content was returned as a dict instead of a string

Fixed

Resolved compliance-scores 500 error caused by NestJS route collision between /compliance-scores and /:id wildcard

Security

All API responses now include Cache-Control: no-store to prevent sensitive compliance data appearing in CDN caches

v1.3.0

February 5, 2025

Open ecosystem launch: public Policy Library, developer SDKs, GitHub Actions plugin, and OIDC federation.

New

Open Policy Library — 38+ community-maintained templates, filterable by framework, sector, and control family; one-click import into any tenant

New

TypeScript SDK — npm-published client with full type coverage for policies, risks, evidence, controls, and audit endpoints

New

Python SDK — pip-installable async client for FastAPI and Django use cases

New

GitHub Actions plugin — YAML action that triggers evidence collection, runs gap analysis, and fails PRs when drift exceeds threshold

New

OIDC federation — connect Okta, Auth0, Azure AD, or Google Workspace for SSO without SAML overhead

New

Slack Evidence Connector — automatically collect change-management evidence from Slack channel archives and pinned messages

Improved

Tenant onboarding wizard reduced from 9 steps to 5 with smart defaults based on chosen framework

Fixed

Monitoring drift-alert and snapshot routes returned 404 — Go binary now rebuilt into Docker image before deployment

Performance

Policy Library loads 38 templates in under 200ms using server-side pre-rendering and edge caching

v1.2.0

January 9, 2025

API-first platform with GraphQL, Webhooks, Terraform provider, and granular RBAC permissions.

New

GraphQL API — full schema covering all entities (policies, risks, controls, evidence, audits) with nested resolvers and DataLoader batching

New

Terraform Provider — manage tenants, policies, and user roles as infrastructure-as-code; published to Terraform Registry

New

Webhook system — subscribe to policy.approved, risk.created, audit.completed, and 14 other event types with retry and signature verification

New

API Keys — create scoped keys with expiry dates and per-endpoint permission grants from the Settings → API Keys panel

New

Custom RBAC Roles — define roles with granular read/write/admin permissions per resource type; assign to users or teams

New

Bulk Policy Import — upload CSV or JSON to create or update up to 500 policies in a single operation

Fixed

impl_status enum validation now correctly rejects in_progress and not_started — valid values documented in API reference

Security

API key secrets are shown exactly once at creation; stored as bcrypt hashes — cannot be retrieved after modal is closed

v1.1.0

December 2, 2024

AI Assistant, Evidence Collector integrations, and expanded SOC 2 Type II control mapping.

New

AI Assistant Chat — conversational interface grounded in your policies, risks, and control library; suggests next actions and explains compliance gaps

New

Evidence Collector — integration framework supporting AWS Config, GitHub audit logs, Jira, Confluence, and manual uploads

New

SOC 2 Type II control mapping — 64 trust service criteria mapped to the AISEC control library with gap indicators

New

Audit Programmes — create and manage internal and external audit cycles with finding tracking and corrective action plans

Improved

Risk scoring now uses a configurable 5×5 likelihood/impact matrix instead of a fixed 3-band model

Fixed

Evidence upload failed silently when file size exceeded 10 MB — now shows a clear error message with size limit

Performance

Dashboard KPI cards reduced initial load time from 2.3s to 340ms by batching compliance-score queries

v1.0.0

LTS

November 1, 2024

Initial public release — multi-tenant AI security compliance platform with ISO 27001:2022 as the primary framework.

New

Multi-tenant SaaS architecture with row-level security — complete data isolation between organisations at the database layer

New

Policy lifecycle management — draft, generate with AI, review, approve, and publish policies with version history

New

Risk Register — create, score, assign, and track risks with full treatment workflow (accept / mitigate / transfer / avoid)

New

Control library pre-loaded with ISO 27001:2022 Annex A — 93 controls across 4 themes, all mappable to your policies and evidence

New

AI policy generation using Claude — describe your requirement and receive a draft policy aligned to your chosen framework in under 2 minutes

New

RBAC — Owner, Admin, Editor, Viewer roles with team-based access; invite users by email with configurable expiry

New

Monitoring service — real-time compliance health scores, alert rules, and 30-day trend tracking

Security

All communications over TLS 1.3 minimum; httpOnly cookie session tokens; bcrypt password hashing with cost factor 12

Stay current with every release

Follow the roadmap to see what's planned next.