Every change to devguard, dated and in plain language. We move your certified ISMS without breaking your evidence — and keep the platform under it steady, secure and improving. Here's the record.
Want updates like these on your own stack?
Start free, and every improvement lands in your workspace automatically — no upgrades, no migrations.
This release protects your account address at sign-up and corrects how email changes are confirmed.
Sign-up notice: when someone tries to register with an address that already has an account, the account holder receives an email about it, and the person signing up sees the same message as for any new address.
Fixed email changes: the confirmation for a new primary email address now goes to your current address and is titled as a change of primary email.
Fixed connected apps: consenting for an organization whose membership has ended now explains why instead of failing.
Fixed administrator access: an administrator who also holds other roles can now open the admin pages.
Announcement
The work your people already do, on the record
Evidence is not only exports and screenshots. A great deal of it is the routine your people already carry out: the vehicle check before a shift, the visitor log, the damage report, the monthly walk through the server room. Until now that lived on paper or in a spreadsheet, and turning it into something an auditor could read was a second job. Processes put those checklists and report forms in the employee portal, where every submission is filed as a dated record the moment it is completed.
You build a process in a visual structure editor, or write it as text with a live preview beside it. Give it an audience of business roles and everyone in them finds it in their portal, with progress shown as they work and each tick saved as it is made, so a dropped connection does not cost the run. Filed submissions collect in a searchable list, can be handed to a colleague, and link to evidence and tasks like anything else. Every run is written to the audit log.
A process carries a review cadence and a deadline the same way the rest of devguard does, so a monthly walkthrough that has not happened turns up where your other overdue work already is, and a report generates from a submission just as it does from a record. The Free plan holds three processes, Business holds as many as you need.
The oldest problem in a compliance file is the file itself. Someone exports a user list, a backup report or a scan result, uploads it, and a year later it still says what it said the day it was made. Nobody notices until an auditor asks. Integration checks close that gap. You connect a provider once, devguard runs its checks on a schedule, and each result lands as an evidence record that ages in days rather than years.
The catalogue covers more than 50 providers, from AWS, Google Cloud and Azure through GitHub, GitLab, Okta, Microsoft Entra and 1Password to Slack, Datadog, Sentry, Snyk, Stripe and Jamf. Each brings checks for the questions an auditor actually asks: whether the root account has MFA, whether the default branch is protected, whether secret scanning is on, how many super-admins there are, whether stale accounts are still active. A failing check notifies the owner and files what it found. A passing one quietly replaces the file it wrote last time.
When the catalogue does not cover something, describe the check to the AI builder in plain language. It drafts the steps, you test-run them against your own connection, and publish. A generic HTTP and TLS check covers any endpoint you can reach. The Free plan runs one active check, Business runs as many as you like, and Settings then Integrations is where you enable your first.
This release adds integration checks that collect evidence on their own, processes your people carry out in the portal, two new organization roles, a risk template catalogue and a calmer surface throughout the app.
Integration checks: connect a provider once and devguard runs its checks on a schedule, filing each result as evidence and notifying the owner when one fails. More than 50 providers, plus an AI builder for anything the catalogue does not cover. See the separate announcement for the full picture.
Processes: the checklists and report forms your people carry out in the portal, filed as dated records. See the separate announcement for the full picture.
Auditor and External roles: an Auditor reads the whole app and writes nothing, meant for the certification auditor or an internal review. An External contact can be named in compliance records but signs in nowhere, and takes no seat on your plan.
Risk catalogue: create risks from the BSI IT-Grundschutz elementary threats, the ENISA Threat Landscape, CSA Top Threats, the OWASP Top 10 and the NIS2 and DORA operational risk areas. Add Risk is now a split button: the button opens a blank risk, the arrow opens the catalogue.
Assessment matrices in three views: a heat map with counts per cell and an inspector beside it, a drift view putting initial and residual exposure side by side with the biggest movers, and a plot with iso-risk curves. The asset matrix runs per CIA dimension.
Setup wizard: five steps (organization, frameworks, risks, key assets, review) that write nothing until you run them, and then go through the ordinary plan limits and audit log.
Announcement
Trainings, assigned and on record
Every organization runs security awareness training. Very few can say a year later who actually did it, and when. The material lives in an LMS or on a shared drive, the chasing happens by email, and the record is a spreadsheet nobody has updated for months. A training in devguard points at the material you already have: a YouTube or Vimeo video that plays inline, a link that opens your LMS or a vendor's portal, or a PDF you upload, served through a download link that expires rather than a public URL. Give it an assignment and it gets an audience of business roles, a first due date, and a frequency from one-off to annual. The audience resolves live, so whoever joins the role inherits the training and whoever leaves stops hearing about it.
Assigned people work in the employee portal and mark the training as completed, and devguard files that with the person, the date, the cycle, and the source they were shown at the time. Reminders follow the cadence: 30 days before an annual training, three days before a monthly one, again on the due date, once more if it slips, and never again for a cycle someone has completed. Open cycles appear on Deadlines, the assignment card shows who is done, who is pending and who is overdue, and the Evidence tab holds the harder proof: an attendance export, a signed sheet, quiz results. The list supports search, bulk editing and CSV export, and a training can be referenced from the ':' command anywhere in the app.
This release rebuilds sign-in on OAuth 2.1, gives you control over which organization a connected app can see, and translates the last untranslated screens into German.
Sign-in on OAuth 2.1: signing in and out now runs through a standard authorization flow. Signing out ends your session in the application and here at the same time, without an extra confirmation step.
Connected apps: when you connect an app, you choose which organization it gets, and the consent screen names it. A grant can be revoked from your account at any time.
Access follows membership: deactivating or removing a member revokes the grants bound to that organization straight away.
Product updates: new accounts can opt in to product updates while registering.
Auditor and External roles: both can be picked when inviting someone or changing a member's role. An External contact takes no seat on your plan.
Fixed image uploads: a profile picture or a logo is now identified by its content and served with a fixed type, so only real images can be stored.
Fixed refusals: reaching your plan's user limit, or signing in with a deactivated account, now gives a clear message instead of a generic error.
Fixed missing German: the two-factor sign-in screens, and the messages shown when sign-in, registration, a password reset or an invitation is refused, are now translated.
Announcement
Your compliance data via MCP
The questions that come up rarely match one screen. Which ISO 27001 controls have no policy behind them? What is still open before the next audit? The answer sits in devguard, but assembling it means opening six views and keeping the result in your head. The MCP server lets you ask your own AI client instead: Claude, Claude Code, Cursor, VS Code, Windsurf, or the Gemini CLI. It reads your risks, controls, policies, evidence, audits, vendors, assets and deadlines as they stand right now, and five prompts come with it for the work that keeps returning: a gap analysis against a framework, a summary of your risk posture, a treatment plan for one risk, audit preparation, and a policy review.
The server is read-only. It can query, and it can read a single record at its own devguard:// address, but it cannot change or delete anything, and it only ever sees the organization you connected it to. Settings → Integrations has a tab per client with a snippet to copy. Claude Code, Cursor, VS Code, Windsurf and the Gemini CLI need the URL and nothing else: they open a browser the first time, so you sign in as yourself and no key goes into a config file. Claude Desktop connects through the mcp-remote bridge with an API key from Account → Tokens.
This release adds trainings and assignments, comment threads with mentions across the app, periodic review cadences, and a read-only MCP server that connects your AI client to your compliance data.
Employee portal: your staff sign in to a portal of their own, with policies, trainings, tasks, evidence, documents and incidents. See the separate announcement for the full picture.
Trainings: a new entity with file uploads, search, bulk editing from the list, and detail tabs that map evidence and tasks. Trainings can be referenced from the ':' command anywhere in the app.
Assignments: assign a policy or a training to a dynamic audience of business roles and track confirmation across recurring cycles. Assignments appear on Deadlines with their own overdue counts, and a publisher can reopen a confirmation mid-cycle.
Comments: comment threads with @-mentions on nineteen entity types, from risks, assets and vendors to incidents, audits, records and every collection kind. Mentions and replies notify by email, and the AI assistant can read the thread.
Periodic review cadences: policies, records, evidence and assignments now carry a review cadence driven from Schedules, so the next review date is derived rather than set by hand.
MCP server: connect Claude, Claude Code, Cursor or the Gemini CLI to your organization read-only, with five curated compliance prompts. Settings then Integrations walks you through the setup for each client.
Business role responsibilities: role pages mark the roles you belong to and count what each one carries: reviews, approvals, records, security questionnaires and assignment audiences.
Announcement
Every employee gets their own portal
Compliance work does not stay inside the compliance team. Policies have to be read and confirmed, trainings have to be completed, and the evidence an auditor asks for usually sits with the person who produced it. Until now, involving those people meant handing them an account in the full app. The employee portal gives them a place of their own instead: they sign in, see what is assigned to them, and nothing else.
Invite someone with the new Employee role and they land in the portal rather than the admin app. There they find the policies and trainings assigned to them, where confirmation only unlocks once the document or the training content has actually been opened, alongside their tasks, evidence, documents and incidents. A getting-started checklist on the overview names whatever is still outstanding, down to profile details they have not filled in, and a profile page lets them manage their phone number, two-factor authentication and account. Reminder emails arrive as deadlines approach.
You decide how much of the portal exists. Settings carries one switch for the portal as a whole and a switch per section, so you can open with policies and trainings and add the rest when you are ready, and your own company links appear in the portal footer. Employees count towards your plan's user limit like any other member.
This release introduces the Employee role that the new portal runs on, enforces your plan's user limit consistently, and makes signing in more resilient.
Employee role: a new portal-only organization role you can pick when inviting someone or changing a member's role.
Phone numbers: members can now store a phone number on their account.
User limits: your plan's limit is enforced when you invite someone, when you add a member, and again when an invitation is accepted, so a pending invitation can no longer push you over it.
Plan visibility: every member can see the organization's subscription state, not only administrators.
Fixed sign-in redirects: signing in returns you to the page you asked for, and a destination in the frameworks app survives the two-factor step.
Fixed a slow or unavailable sign-in service: you now get a clear message instead of being bounced back to the login screen in a loop.
Fixed single sign-on: you are returned to the right application after the callback.
Fixed removed members: someone removed from an organization no longer keeps access through a session that still names it.
Fixed a rare error state: a temporary failure while loading your organizations no longer looks as though you belong to none.
Mark as not applicable: a control, category, chapter or group can be marked not applicable with a justification. The decision cascades to everything below it, the confirmation says how many controls it touched, and the Statement of Applicability follows it.
Account settings: profile, notifications, tokens and connected apps move out of organization Settings into their own Account area, with an Organizations tab that lists your memberships and lets you leave one.
Connected apps: see every app connected to your account, and disconnect one.
Search palette: it now opens on where you left off, with chips for every searchable type and a live count on each. Selecting a chip scopes the search to that type.
Trainings: a Comments tab, the assignment beside the details, a completion table that says how each person is reached, and PDFs shown inline.
Reports: a progress panel while a report renders instead of a blank frame, and an error state when rendering fails. The Statement of Applicability derives its coverage and prints register codes.
Row menus and sheets: every register's row menu lists the entity's detail tabs, and closing a sheet returns you to where you opened it.
A calmer surface: a new ground palette across cards, tables, tabs and the page canvas, and a dark mode restructured so a card reads as a card.
CLI sign-in: the devguard CLI signs you in through the browser by default, keeps the key flag for headless use, and its logout revokes the login.
Plan limits: the Free plan's published ceiling of 10 treatment actions is now enforced, and restoring an archived entity takes a plan slot again.
Manual coverage assessment is back on the policy-section, risk and asset mapping cards, and sits above the automatic signals. Where the two differ, the card shows the automatic status as well.
Vendor questionnaire templates get the visual builder, a text mode and a live preview, and are called Templates in the sidebar.
Fixed policy control mappings: removing a mapping now works, instead of leaving a row that could be neither removed nor mapped again.
Fixed audits: an audit or a finding no longer prints a bare identifier after the framework or control it named was deleted.
Fixed notification settings: a toggle shows as pending until its value is known, instead of showing off and then flipping on.
Fixed Jira: status sync no longer stops silently when its webhook registration expires.
Fixed permissions: a denied action now appears as a notice instead of taking over the page, and read-only roles no longer see actions they cannot use.
Fixed reminder emails: an item stops being nudged once it is a month overdue, and a large weekly digest no longer drops entries.
Fixed smaller things: the audit log scrolls with the page, the evidence links tab shows a 0 count like Tasks and Comments, and deactivated administrators sit behind a switch in the members list.
Notificationemails are now queued and paced rather than sent while you wait, and a weekly digest bundles everything into a single mail.
Reports from a record: generate a report straight from a record's detail page.
Task assignees: assign a task to a person, and change the assignee later.
Keep your place: stepping between records holds your position in the list, and the header no longer jumps as you move.
CLI documentation: the devguard CLI now has full documentation.
Fixed policy PDFs: images in an exported policy now render instead of breaking.
Fixed asset and control hierarchies: an item can no longer be made its own parent, a cycle no longer hides a row from the list, and the parent picker no longer offers an item's own descendants.
Fixed search and AI results: semantic matches no longer come back short.
Fixed the organigram: member avatars now appear where available.
Fixed empty gauges: a gauge with no data shows 0% instead of NaN%.
Fixed policy categories: a name that is already taken now says so instead of failing quietly.
Fixed the Trust Center: adding an entry no longer collides with a concurrent save.
Fixed email excerpts: an excerpt no longer cuts an emoji in half.
Fixed missing German translations across several screens.