NA1 Continuous Exposure Management
Release centre

What's shipped, and what's next

Every published release alongside the roadmap items currently in progress.

Release history

2026-07-24 Cloud

Enterprise Trust

Trust Centre, Security Centre, Compliance Centre, Platform Status, Integration Catalogue, Release Centre, ROI Calculator and Customer Success Dashboard.

2026-07-24 Cloud

Enterprise SaaS

Customer onboarding health, plan assignment, feature controls and improved tenant operations.

2026-07-24 Cloud

Installer-safe Migration Repair

Removes the SaaSControlService dependency from migration 339 and verifies normal Update Centre installation.

2026-07-24 Cloud

SaaS Control Stability Hotfix

Prevents SaaS Control failures when migration 338 was skipped and corrects scheduler readiness file detection.

2026-07-24 Cloud

Commercial SaaS Foundation

Tenant lifecycle controls, organisation invitations, quota visibility and customer control centre.

2026-07-24 Cloud

SaaS Foundation Sprint 1

Provider hierarchy, organisation switcher, active tenant context and tenant-aware routes.

2026-07-24 Cloud

CTEM Experience

Morning Security Briefing, exposure trends, daily snapshots and guided workspace onboarding.

2026-07-24 Cloud

Commercial Experience Sprint

Adds the searchable documentation portal, corrected V2 roadmap, standalone changelog, refreshed exposure-management branding and expanded public navigation.

2026-07-23 Enterprise

CTEM Foundation for Enterprise

Continuous Threat Exposure Management for self-hosted Enterprise deployments. Governed live enforcement for FortiGate, Cato and MISP is proven in our Enterprise reference implementation; integration into the unified NA1 platform is planned and not yet included in this release.

2026-07-23 Cloud

V2 CTEM Foundation

Unified exposure management, attack surface inventory, explainable scoring, validation, attack paths and governed agent actions.

2026-07-23 Cloud

RC6.3 Agentic Remediation

Adds governed agent tasks, approval policies, playbooks, ticket workflows, rollback and post-action validation.

2026-07-23 Cloud

RC6.2 Validation & Attack Paths

Adds exposure validation, knowledge graph relationships, attack-path prioritisation, control-effectiveness evidence, retesting and explainable risk-reduction calculations.

2026-07-23 Cloud

RC6.1 Security Integrations

Adds governed Microsoft Defender, Rapid7, FortiGate and Cato connector foundations, connector health, synchronisation jobs, evidence ingestion and correlation, and approval-gated action requests.

2026-07-23 Cloud

RC6 Sprint 2 Attack Surface Management

Adds ASM dashboard, domain and certificate monitoring, discovery evidence and exposure lifecycle timeline.

2026-07-23 Cloud

RC6 CTEM Foundation

Introduces the CTEM Command Centre, explainable Exposure Score, unified asset and exposure records, AI recommendations, connector and ticket abstractions, and approval-led agent tasks.

2026-07-23 Cloud

Enterprise Reporting

Adds board-ready vector PDFs, branded dashboards, charts, risk gauges, AI-assisted threat storytelling, scheduled delivery and digital integrity.

2026-07-23 Cloud

SaaS Customer Provisioning

Adds one-click customer provisioning, path-based tenant portals, guided onboarding, trial assignment and welcome-email tracking.

2026-07-23 Cloud

Email Reliability

Corrected scheduled briefing state handling and separated test deliveries from production delivery status.

2026-07-23 Cloud

Enterprise Intelligence

Introduced Brand Protection, stored report artefacts, clean URLs and expanded automated testing.

2026-07-23 Cloud

Customer Trust & Release Centre

Adds a public product roadmap, customer feature voting, changelog, known-issues transparency and launch-focused release controls.

In progress

Planned

Governed Enforcement (FortiGate/Cato/MISP)

Shipped

Governed, approval-gated writes to FortiGate, Cato and MISP are proven in our Enterprise reference implementation - real, working code, not a concept. Integration into the unified NA1 platform is planned; not yet available in NA1 today.

Progress0%
In development

V2.2 — Integration Hub

V2.2

FortiGate and Cato enforcement is proven in our Enterprise reference implementation, with unified-platform integration planned. Microsoft Defender, Sentinel, Rapid7 and OpenCTI connectors, plus common health, permission and audit controls across all of them, remain in progress.

Progress20%
In development

SSO / Entra ID for Enterprise

Next

OIDC-based single sign-on for self-hosted deployments.

Progress35%
Backlog

V2.5 — Security Newsroom

V2.5

AI-assisted daily briefings, cyber news, customer relevance and source-attributed publishing workflows.

Progress0%
Backlog

V3 — Autonomous Exposure Operations

V3

Long-term vision for policy-governed autonomous exposure reduction across connected security controls.

Progress0%
Backlog

Hybrid Cloud + Enterprise Bridge

Future

For customers who want a self-hosted instance for their most sensitive site or workload, and a Cloud instance for everything else — one login story, two deployments. The self-hosted side would optionally forward summarised, non-sensitive data (exposure counts, not raw asset hostnames or IOC detail) to a Cloud dashboard for cross-site reporting, while all governed enforcement (FortiGate, Cato, MISP) stays local. This is an early idea, not committed work — vote if it would matter to you.

Progress0%

View and vote on the full roadmap →