Product release

What's new with the SimpleRisk 202600908-001 release?

SimpleRisk 20260908-001 — Document Program Redesigned, New Data Integrity Tool, and Broad Security Hardening

This release brings a redesigned Document Program and Define Exceptions experience, a new Data Integrity tool for finding and repairing corrupted uploads, and a substantial round of security hardening across authorization and access control.

Highlights

Document Program and Define Exceptions, redesigned. Both pages now open to insights tiles summarizing your documents and exceptions at a glance, and carry a rebuildable audit trail, full version history, bulk actions, and a Columns picker so you can tailor the table to what you need to see. Documents and policy exceptions also now send review-due email notifications ahead of their scheduled review date, so nothing lapses silently.

The redesigned Document Program page, showing a mix of policies, guidelines, standards, and procedures in different review states

A new Data Integrity page. Available under Settings, this new page scans for corrupted text and file uploads and helps you repair them, giving admins a single place to find and fix data issues instead of discovering them one record at a time.

A broad security hardening pass. This release closes a large batch of authorization and access-control gaps across risk, asset, governance, compliance, and assessment management, strengthens audit approval workflow integrity, fixes two issues where user-supplied content in notifications could render as active markup, and strengthens session handling after a password change. We also replaced a fixed default single sign-on administrator credential with a unique, per-install value, and strengthened how API keys are hashed at rest.

Other improvements

This release also fixes a number of smaller issues: the Dynamic Risk Report failing to load with certain risk scoring data, the risk-closed notification email showing a raw code instead of the closure reason, dashboard widgets showing encrypted text instead of risk names with Database Encryption enabled, intermittent errors logging out or resetting a password under load, and a repeated SAML login warning in the server log.

For customers running the Customization Extra: the admin page has been redesigned around Template Groups and Custom Fields, template groups now cover Assets, Projects, Frameworks, and Controls in addition to their existing record types, and a new Document field group lets you manage document types (Policies, Guidelines, Standards, Procedures, and any custom types you add) the same way. Elsewhere in the Extras: Organizational Hierarchy's Default Business Unit handling is more resilient, ComplianceForge SCF 2026.2 upgrades no longer get stuck on missing source-mapping data, Encrypted Database's background re-encryption job is fixed, and Upgrade backups no longer live in a directory a service restart can silently wipe.

Upgrading

The upgrade is delivered through the standard SimpleRisk upgrade flow. As always, we recommend backing up your database before applying any release in production.

For the full list of changes, see the release notes. For upgrade instructions, see the SimpleRisk admin guide. If you run into anything unexpected, our support team is here to help.