Product roadmap · Updated regularly

Where we're headed.

A live view of what we're building, what's next, and what's on the horizon. Items are updated as work progresses.

What we're building

Now · Next · Later.

A simple view across the areas we're investing in — security, compliance, platform, integrations and user experience.

Now 3
Platform

Configurable risk approval workflow

Customer administrators tailor the risk approval workflow to their organisational hierarchy — selecting who approves which type of risk, at what severity, and how many approval stages each severity warrants.

30% complete
Compliance

Per-control evidence on Statement of Applicability and Risk Assessment

Each Annex A control and each risk decision can carry attached evidence — documents, owner attestations, freshness indicators — that travel inside every immutable Statement of Applicability and Risk Assessment snapshot. Auditors receive a single, self-contained evidence package per release.

25% complete
Compliance

Multi-framework control mapping

Map one control implementation across multiple frameworks — ISO/IEC 27001, SOC 2, NIS2, DORA, NIST CSF — so a customer's audit work counts once and applies to every certification target.

20% complete
Next 6
Security

Microsoft Entra ID and Google Workspace sign-in

Microsoft Entra ID and Google Workspace added as sign-in options alongside the existing email + two-factor flow, simplifying onboarding for organisations standardised on those identity providers.

Integrations

Webhooks for platform events

Subscribe to lifecycle events — risk transitions, mitigation deadlines, exception expiry, Joiner-Mover-Leaver state changes — through signed HTTPS webhooks delivered to customer endpoints, enabling integration with ticketing systems, SIEMs and custom automations.

Security

Passkeys and WebAuthn

Sign-in via platform-bound and roaming authenticators — Touch ID, Face ID, Windows Hello and hardware security keys — added alongside the existing multi-factor methods to give organisations an additional, phishing-resistant option.

Compliance

Additional GDPR modules — DPIA, RoPA and data-breach notification workflow

Three additional GDPR-specific modules — Data Protection Impact Assessment (Art. 35), Record of Processing Activities (Art. 30) and a data-breach notification workflow (Art. 33–34, 72-hour timer) — joining the right-to-erasure capability shipped in April.

User Experience

Risk heat map and matrix visualisation

Interactive 5×5 likelihood-by-impact heat map across the Risk Register, with click-through to the underlying risks and per-treatment comparison views.

Integrations

Documented REST API with OpenAPI specification

A public REST API for the platform's main resources, documented through an OpenAPI specification, with per-tenant API keys, scopes and rate limits — for building custom workflows on top of the ISMS data.

Later 5
Compliance

NIS2 and DORA framework support

First-class support for the NIS2 directive (essential and important entities) and DORA (financial-sector ICT third-party risk), with the respective incident-reporting workflows and control overlays mapped onto the existing ISO/IEC 27001 foundation.

Compliance

Real-time control posture dashboard

Each control's live state — owner attestation cycles, freshness indicators and a per-control evidence repository — surfaced in a dedicated dashboard inside the platform.

Integrations

SCIM 2.0 provisioning and multi-IdP support

Automated user lifecycle synchronisation from the customer's identity provider via SCIM 2.0; first-class Okta integration; the ability for one tenant to authenticate users from multiple identity providers concurrently (employees, contractors and partners).

Compliance

Climate risk integration (ISO/IEC 27001:2022 Amendment 1)

Built-in support for climate-related risks within the risk-assessment context — capturing climate considerations as part of the broader risk picture, in line with the 2024 amendment to ISO/IEC 27001:2022.

Integrations

Native Slack and Microsoft Teams apps

Two-way Slack and Microsoft Teams integrations — notifications, approval prompts from the channel, slash commands and digest summaries — so daily ISMS work happens where teams already work.

This roadmap reflects our current direction. Priorities and timing may shift as customer needs evolve and as we learn. Items shown here are not contractual commitments.

Want to see it in action?

Request a demo and we'll show you how Infosec Tools fits your organisation — today.