Built in public
Changelog.
Every page, guide, and capability we've shipped to this site — dated, honest, and linked. One founder, building in the open. If it's listed here, you can click it.
Improved
Truth pass — AI providers, verified numbers, quote-based pricing
- AI provider disclosure is now per-feature: Anthropic Claude powers generation, OpenAI powers search embeddings and voice — both named subprocessors with the data flow published.
- Every marketing number re-verified against the platform codebase: 2,000+ templates, 487 phishing templates across 6 delivery channels and 14 attack themes, 425+ pre-generated documents, 29 module guides.
- Pricing moved to tailored per-organization quotes — tiers, bands, and everything included stay public; numbers are scoped with you.
- EU AI Act framework guide published — classification, FRIA, Article 73 incident windows, and the ISO 42001 bridge.
New
Platform: Human Risk Management overhaul
- Real per-user Human Risk Score computed from live signals (phishing results, overdue training, quiz outcomes) — never a fabricated number.
- Phishing point-of-failure auto-training, adaptive assignment rules, and training completions auto-mapped to framework controls (ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, NIS2) as audit evidence.
- Verifiable, revocable training certificates with public verification links; learner experience localized in 5 languages.
- LMS distribution — deliver awareness courses into SuccessFactors, Workday Learning, or Cornerstone as SCORM 1.2 / cmi5 packages with completions flowing back.
New
Platform: Questionnaire automation & Trust Center data rooms
- Governed Answer Library with review cycles and evidence freshness; AI drafting that cites its sources or refuses — with per-question SME assignment and maker≠checker approval.
- Original-format intake: upload a prospect questionnaire as xlsx/docx/pdf, answer in-platform, export back in the exact original file.
- Trust Center NDA data rooms with identity-stamped watermarked downloads, an ask-the-trust-center AI bot grounded only in approved content, and deflection analytics.
New
Platform: AI cost governance
- Per-organization AI budgets with metering on every AI surface, and a customer-facing AI Usage panel showing spend against allowance — AI cost transparency to match the AI governance story.
Content
India content cluster — eight DPDPA-era guides
- New blog cluster: a DPDPA readiness checklist, the enforcement-deadline tracker, and a DPDPA-vs-GDPR comparison.
- Added Consent Manager, CERT-In incident-playbook, and NABH + ISMS guides for Indian healthcare and SaaS teams.
- Published “ISO 42001 for Indian AI” and a DPDPA penalties tracker; all posts authored and reviewed by Vasim Vayani.
- Corrected stale module-count claims in older posts so the whole blog now matches the live platform.
New
Honest competitor comparison pages
- Shipped four side-by-side comparisons — Vanta, Drata, Sprinto, and Scrut — with a “where they win / where we win” table.
- Each page is deliberately honest about gaps (no published SOC 2 report yet, smaller logo wall) instead of hiding them.
- Added pricing context and an FAQ block with FAQ structured data for search visibility.
New
India solution pages
- New /solutions/healthcare-india page for the DPDPA + NABH + ABDM triple squeeze.
- New /solutions/saas-india page — four frameworks run as one program for globally-selling SaaS teams.
- Wired both routes into the sitemap and footer alongside the new comparison pages.
Content
Four more framework guides
- Added SOC 1, ISO 27701, and ISO 22301 framework pages.
- Published a CERT-In Directions guide covering the six-hour incident-reporting obligation.
- Rewrote the SOC 2 entry with honest evidence-connector framing — what auto-collects today versus what is manual.
New
Modules catalog expanded to 52
- Built 25 new module pages — 17 ISMS clause modules plus ESG, SOX, AI Governance, and Implementation.
- Added Sage Certified, the customer portal, the executive dashboard, and the Agent Hub to the catalog.
- Rebuilt the modules index as a category-grouped, data-driven page so every module is one click from search.
New
/sage-ai — full AI transparency page
- Published a dedicated page disclosing that Sage AI runs on Anthropic Claude — named, governed, and audited.
- Added a four-hop data-flow diagram and five plain-English AI commitments.
- Included a governance FAQ with structured data; linked it from the footer, the security page, and the home AI band.
Improved
Security page rewrite — real architecture
- Replaced marketing fluff with the real architecture: fail-closed Postgres row-level security across 133 tenant tables.
- Documented the hash-chained immutable audit log, plan-bounded RBAC, governed Claude AI, and SHA-256 evidence integrity.
- Added a roadmap-honesty section that retires unbuilt SSO, pen-test, and SOC 2-report claims until they actually ship.
Content
ISO 42001 framework page
- Shipped an ISO 42001 AIMS readiness guide built on the existing AI Governance module.
- Dogfooded our own governed-AI story as proof that the AI-management controls are real, not aspirational.
Content
DPDPA framework page
- Published a DPDPA guide with the full enforcement timeline (Nov 2026 and 13 May 2027 milestones).
- Added an obligations table, a module-mapping section, and a point-tool cost anchor for Indian buyers.
- Rebuilt the frameworks index as a data-driven page so new frameworks slot in without hand-editing.
Improved
Truth pass — every number sourced
- Routed every marketing figure through a single stats source of truth so no number can drift out of sync with the platform.
- Retired indefensible claims — inflated integration counts, “400+ tabs”, an SLA we don’t publish, and fabricated testimonials.
- Replaced them with verified figures and honest AI-accuracy and deployment framing.
Improved
Hero rewrite + SEO plumbing
- Rewrote the homepage hero around the GRC operating-system positioning, with a governed-AI band beneath it.
- Extended the sitemap to cover framework, pricing, and support routes, and fixed a canonical-URL leak in the root layout.
- Generated a proper PNG OpenGraph image to replace the unsupported SVG used for link previews.
Want a say in what ships next?
The items on this list often start as customer feedback — tell us what your program needs next.