Every major feature we've shipped, in order — from the first release to this week.
Today
We're building in public — the next release is already underway.
Translation now reaches every corner of the product: UI text, in-app notifications, emails, generated PDFs, API error messages, and even the shared threat-intelligence feed.
A searchable, self-service documentation site in English, French and Arabic replaces the old in-app help pages.
Online license activation for on-premises customers, plus a fully offline appliance installer for air-gapped environments.
Two-factor authentication becomes a mandatory second login step for enrolled accounts, and the Asset Cartography graph screen goes live alongside a risk-scenario timeline view.
The audit trail becomes cryptographically hash-chained and independently verifiable; TOTP-based two-factor authentication and an active-sessions view arrive in Settings.
Sync findings live from vulnerability scanners, and turn scanned documents into structured data with OCR — French recognition at launch.
A RACI accountability matrix, a governance document repository, records archiving with retention rules, an Advanced Report Builder with Excel export, and 7 new per-module analytics dashboards.
A CVE database synced from the NVD with CVSS scoring, richer Threat Library profiles, formal Risk Treatment Plans, Active Directory/LDAP single sign-on, and Oracle/SQL Server support for enterprise deployments.
A new top-tier plan debuts with an interactive asset relationship graph, CIA-based asset valuation, lifecycle tracking and ownership fields.
Saudi NCA ECC-2:2024, UAE NESA IAS, Dubai DESC ISR, Qatar NIA CSF and Bahrain CBB ISR join the built-in framework library.
Track controls by cost, effort and progress, formalize risk exceptions, publish a public Trust Center page, fire outbound webhooks, and keep a full activity audit trail.
Model Threat → Vulnerability → Asset → Control chains, define your own probability/impact scales, and quantify risk financially with Monte Carlo simulation (ALE/SLE/P90/P95).
A full security-operations suite ships in one release: categorized Incident Management with a timeline, Vulnerability Management with CVE/CVSS tracking, and a Threat Library.
Upload a vendor contract and get an AI-assisted review as part of the TPRM workflow.
Draft security policies and compliance documents with AI, then export them to CSV or styled HTML.
The platform ships bilingual, with a guided onboarding tour and a starter Information Security Policy template for new tenants.
A complete audit management module ships alongside a dedicated Auditor Portal, a Remediation Planner and a cross-framework Traceability view.
The first AI-powered features ship, backed by a self-hosted model rather than a third-party API: AI assistance for audit planning, risk analysis and vendor assessment.
GRCEye launches with a full Vendor Risk Management (TPRM) module and a Compliance Assessment engine, including a custom framework builder, evidence upload and per-control tracking.
Building in public since February 2026.
Start a free trial, or read the docs to see how each feature fits together.