Skip to content

Changelog

Every notable change to Aegis Firma. Subscribe to RSS to stay current.

v2.4.0

EU AI Act high-risk system guidance + evidence vault improvements

Full EU AI Act Annex III high-risk classification guidance is now embedded in the AI system inventory. Evidence vault gets batch upload and ZIP export.

  • NewEU AI Act Annex III classification wizard — answers 12 questions to determine if a system qualifies as high-risk
  • NewEvidence vault batch upload — drag 50 files at once, auto-categorised by file type
  • NewEvidence vault ZIP export — download all evidence for a given assessment as a single archive
  • NewControl library — browse all NIST AI RMF 1.0, ISO 42001, and EU AI Act controls in one place
  • ImprovedRisk register now shows residual risk score as a computed column, updated instantly on likelihood/impact change
  • ImprovedVendor catalog expanded to 160+ vendors with default risk scores and DPA availability
  • FixedFixed: DPIA export PDF was missing the data subject categories section in some templates
  • FixedFixed: training course progress not saving when browser tab was backgrounded
v2.3.0

Framework crosswalk matrix + incident runbooks

Map your controls across NIST AI RMF, ISO 42001, EU AI Act, and GDPR automatically. Ten pre-built incident runbooks ready to customise.

  • NewFramework crosswalk — 45 mappings across NIST↔ISO↔EU AI Act↔GDPR with mapping strength (full/partial/informative)
  • New10 incident runbooks — AI bias, privacy breach, hallucination, data leak, model drift, prompt injection, ransomware, vendor breach, model supply chain, availability
  • NewRegulator directory — 40+ supervisory authorities with notification deadlines, complaint URLs, and enforcement history
  • ImprovedAssessment scores now show framework-specific sub-scores alongside overall score
  • RegulatoryEU AI Act: added Article 73 serious incident notification guidance (15-day timeline for high-risk AI) to all relevant runbooks
v2.2.0

Policy template library + email notifications

Twenty-five policy templates reviewed by a compliance lawyer. Configurable email alerts for every deadline type.

  • NewPolicy template library — 25 templates across AI policy, DPIA, AIA, data retention, acceptable use, incident response, and more
  • NewEmail notification system — 40 template-driven alert types covering deadlines, DSRs, breaches, training, and vendor cert expiry
  • NewVendor onboarding questionnaire — short (20 q), medium (50 q) variants published
  • ImprovedDocument generation now includes a "review notes" field for compliance team annotations
  • FixedFixed: some generated DPIAs were missing the Data Protection Officer contact field
v2.1.0

AI tool inventory v2 + bias testing improvements

Redesigned AI tool inventory with EU AI Act risk tier tagging. Bias testing now supports custom demographic attributes.

  • NewEU AI Act risk tier tags on every AI system — prohibited/high-risk/limited/minimal, with article citations
  • NewBias testing custom attributes — define your own demographic groups beyond the defaults
  • ImprovedAI system inventory exports now include risk tier and EU AI Act applicability columns
  • RegulatoryGDPR: updated Art.22 automated decision-making guidance to reflect March 2026 EDPB clarification on LLM outputs
  • SecurityRow-level security policies tightened — org members can no longer read draft documents from other orgs via the API
v2.0.0

Multi-jurisdiction engine — 169 jurisdictions

Major release: Aegis Firma now covers 160 regulatory jurisdictions across GDPR, EU AI Act, US state laws, APAC, LATAM, and more.

  • NewJurisdiction engine expanded from 40 to 169 jurisdictions with applicability rules per org profile
  • NewJurisdiction scope rules — compliance team defines where the org operates; dashboard shows only relevant obligations
  • NewRegulation deadline calendar — shows every filing, audit, and breach-notification deadline by jurisdiction
  • NewCross-framework gap analysis — where you're compliant under GDPR but not ISO 42001
  • ImprovedNavigation redesigned — dedicated sections for Assess, Document, Evidence, Vendors, Training, Incident
  • FixedFixed 23 compliance content issues found in beta — incorrect article references, missing jurisdiction mappings
v1.5.0

Data Subject Request (DSR) management

End-to-end GDPR DSR workflow: intake, identity verification, fulfilment tracking, and DPA-only access for sensitive records.

  • NewDSR intake form — embeddable widget for your privacy page, or direct link
  • NewDSR workflow — auto-routes by request type (access, deletion, rectification, portability, objection)
  • NewDSR audit trail — every action timestamped for DPA evidence
  • RegulatoryGDPR 30-day deadline enforced with automated reminder at Day 25 and escalation at Day 29
v1.4.0

Vendor risk management

Vendor catalog, risk scoring, contract tracking, and AI-specific DPA review checklist.

  • NewVendor catalog with 160+ pre-scored vendors (risk 1–5), categorised by function
  • NewVendor DPA tracker — expiry reminders, renewal workflow
  • NewAI vendor checklist — 15-point review for any AI vendor: data residency, training opt-out, SCCs, zero-retention terms
  • ImprovedVendor risk scores now consider EU AI Act applicability (DeepSeek, HireVue flagged high)
v1.3.0

Trust Centre public page + SSO (SAML 2.0)

Share your compliance posture publicly with a hosted Trust Centre. Enterprise SSO via SAML 2.0.

  • NewPublic Trust Centre — branded page at trust.aegisfirma.com/your-org showing certifications, sub-processors, uptime
  • NewSAML 2.0 SSO — enterprise plan; works with Okta, Azure AD, Google Workspace, PingIdentity
  • NewTwo-factor authentication — TOTP (Authenticator app) + backup codes for all plan tiers
  • SecuritySession token rotation on privilege change — downgraded users lose elevated access within 60 seconds
v1.2.0

AI document generation (DPIA, AIA, AI policy)

Generate first drafts of DPIAs, AI Impact Assessments, and AI policies from your system inventory in one click.

  • NewDPIA generation — Article 35 GDPR compliant template, pre-filled from your AI system profile
  • NewAI Impact Assessment generation — EU AI Act aligned, maps to Annex III risk criteria
  • NewAI Policy generation — org-wide AI acceptable use policy, customisable tone and scope
  • NewDeterministic generation — every document is built from static, audited templates; your content is never sent to a third-party AI provider
v1.0.0

Initial launch — AI compliance assessment for GDPR + EU AI Act

Aegis Firma launches with AI compliance assessments across GDPR and EU AI Act, covering the core obligations for companies deploying AI in the EU.

  • NewCompliance assessment engine — 200+ questions across GDPR and EU AI Act with scoring and gap analysis
  • NewAI system inventory — track every AI tool your org uses, with risk classification
  • NewCompliance score dashboard — overall and per-framework scores with trend over time
  • NewTeam workspace — multi-user with role-based access (Owner, Admin, Auditor, Viewer)