NA1 Continuous Exposure Management
Release centre

What's shipped, and what's next

Every published release alongside the roadmap items currently in progress.

Release history

2026-07-25 Enterprise

CTEM and Live Enforcement

Continuous Threat Exposure Management and live, governed FortiGate/Cato/MISP enforcement for self-hosted Enterprise deployments.

2026-07-24 Cloud

Enterprise Trust

Trust Centre, Security Centre, Compliance Centre, Platform Status, Integration Catalogue, Release Centre, ROI Calculator and Customer Success Dashboard.

2026-07-24 Cloud

Enterprise SaaS

Customer onboarding health, plan assignment, feature controls and improved tenant operations.

2026-07-24 Cloud

Installer-safe Migration Repair

Removes the SaaSControlService dependency from migration 339 and verifies normal Update Centre installation.

2026-07-24 Cloud

SaaS Control Stability Hotfix

Prevents SaaS Control failures when migration 338 was skipped and corrects scheduler readiness file detection.

2026-07-24 Cloud

Commercial SaaS Foundation

Tenant lifecycle controls, organisation invitations, quota visibility and customer control centre.

2026-07-24 Cloud

SaaS Foundation Sprint 1

Provider hierarchy, organisation switcher, active tenant context and tenant-aware routes.

2026-07-24 Cloud

CTEM Experience

Morning Security Briefing, exposure trends, daily snapshots and guided workspace onboarding.

2026-07-24 Cloud

Commercial Experience Sprint

Adds the searchable documentation portal, corrected V2 roadmap, standalone changelog, refreshed exposure-management branding and expanded public navigation.

2026-07-23 Cloud

V2 CTEM Foundation

Unified exposure management, attack surface inventory, explainable scoring, validation, attack paths and governed agent actions.

2026-07-23 Cloud

RC6.3 Agentic Remediation

Adds governed agent tasks, approval policies, playbooks, ticket workflows, rollback and post-action validation.

2026-07-23 Cloud

RC6.2 Validation & Attack Paths

Adds exposure validation, knowledge graph relationships, attack-path prioritisation, control-effectiveness evidence, retesting and explainable risk-reduction calculations.

2026-07-23 Cloud

RC6.1 Security Integrations

Adds governed Microsoft Defender, Rapid7, FortiGate and Cato connector foundations, connector health, synchronisation jobs, evidence ingestion and correlation, and approval-gated action requests.

2026-07-23 Cloud

RC6 Sprint 2 Attack Surface Management

Adds ASM dashboard, domain and certificate monitoring, discovery evidence and exposure lifecycle timeline.

2026-07-23 Cloud

RC6 CTEM Foundation

Introduces the CTEM Command Centre, explainable Exposure Score, unified asset and exposure records, AI recommendations, connector and ticket abstractions, and approval-led agent tasks.

2026-07-23 Cloud

RC5 Enterprise Reporting

Adds board-ready vector PDFs, branded dashboards, charts, risk gauges, AI-assisted threat storytelling, scheduled delivery and digital integrity.

2026-07-23 Cloud

RC4.3 SaaS Customer Provisioning

Adds one-click customer provisioning, path-based tenant portals, guided onboarding, trial assignment and welcome-email tracking.

2026-07-23 Cloud

RC2.2 Email Reliability

Corrected scheduled briefing state handling and separated test deliveries from production delivery status.

2026-07-23 Cloud

RC3 Enterprise Intelligence

Introduced Brand Protection, stored report artefacts, clean URLs and expanded automated testing.

2026-07-23 Cloud

RC4 Customer Trust & Release Centre

Adds a public product roadmap, customer feature voting, changelog, known-issues transparency and launch-focused release controls.

In progress

Testing

V2.0.1 — Commercial Experience

V2.0.1

Production public website, searchable documentation portal, V2 roadmap, public changelog and navigation refresh.

Progress95%
In development

V2.1 — External Attack Surface Management

V2.1

Automated domain, subdomain, certificate and external service discovery with ownership and change monitoring.

Progress55%
Planned

V2.2 — Integration Hub

V2.2

Microsoft Defender, Rapid7, FortiGate and ITSM connectors using common health, permission and audit controls.

Progress20%
In development

SSO / Entra ID for Enterprise

Next

OIDC-based single sign-on for self-hosted deployments.

Progress35%
Planned

V2.3 — AI Agents & Investigation

V2.3

Specialist CTEM, threat intelligence, vulnerability and reporting agents grounded in platform evidence.

Progress10%
Planned

V2.4 — Controlled Remediation

V2.4

Approval-gated ticketing, firewall, Defender and scan actions with dry-run, rollback and validation.

Progress5%
Backlog

V2.5 — Security Newsroom

V2.5

AI-assisted daily briefings, cyber news, customer relevance and source-attributed publishing workflows.

Progress0%
Backlog

V3 — Autonomous Exposure Operations

V3

Long-term vision for policy-governed autonomous exposure reduction across connected security controls.

Progress0%
Backlog

Hybrid Cloud + Enterprise Bridge

Future

For customers who want a self-hosted instance for their most sensitive site or workload, and a Cloud instance for everything else — one login story, two deployments. The self-hosted side would optionally forward summarised, non-sensitive data (exposure counts, not raw asset hostnames or IOC detail) to a Cloud dashboard for cross-site reporting, while all live enforcement (FortiGate, Cato, MISP) stays local. This is an early idea, not committed work — vote if it would matter to you.

Progress0%

View and vote on the full roadmap →