White square

Product Guide

Future Features Roadmap

A preview of capabilities we’re exploring to deepen automation, assurance, and visibility.

What we’re building next

Planned capabilities to extend Datagrasp automation without repeating features that are already available today.

Planning status: The capabilities below are planned or being explored and are not available unless explicitly identified as current. Listing a feature does not commit to a release date or plan entitlement. Scope and timing may change. To share priorities, contact us.

Available today: Datagrasp already includes Control Assurance, policy version history, vendor questionnaires, Evidence Health and Evidence Fit analysis, a public Trust Center, and AWS, Microsoft 365 / Intune, and Google Workspace integrations. Credential Exposure Monitoring and Domain Impersonation Monitoring are also available. The proposals below extend these workflows.

Planned assurance improvements

  • Distinct risk and control outcomes: Keep risk acceptance, risk transfer, control applicability, and demonstrated control effectiveness separate so treatment decisions do not imply successful control testing.
  • Evidence-aware framework reuse: Check each destination control’s evidence and applicability before carrying completion across linked frameworks.
  • Recorded policy reviews: Track review dates and reviewers independently of ordinary document edits, with clear visibility into reviews that are due.

Planned client workflows

Datagrasp Sentinel
PlannedAudit simulation

Run a saved, evidence-backed audit simulation for an assigned compliance framework. Sentinel will distinguish declared checklist completion from what the workspace can prove, with requirement-level Evidence Confidence, defensibility results, unsupported claims, contradictions, and recommended remediation.

Phase 1 will use Auditor Mode, deterministic scoring, and bounded AI interpretation. Each completed run will retain immutable snapshots of the sources considered so the result remains explainable after records change.

Sentinel is advisory: it will not certify compliance, replace auditors, change authoritative records, or reconstruct arbitrary dates before a run was captured.

Read the planned Sentinel workflow.

Native Workforce Training
PlannedRecurring training

Deliver, assign, complete, renew, and document workforce training inside Datagrasp. Phase 1 will include a Datagrasp-managed course library, workspace assignments and reports, and a focused My Training experience with saved progress, acknowledgments, and assessments.

Published course versions, completion records, and Certificates of Completion will retain their history. Renewals will create new assignments, and successful completions will generate supporting Evidence Library artifacts without automatically completing controls.

Planned topics include HIPAA workforce privacy and security awareness, general security, privacy, AI awareness, incident reporting, and policy awareness. Client-authored courses, Policy Library acknowledgments, phishing simulations, Labs, and SCORM are future enhancements.

Read the planned Training workflow.

Evidence Requests & Review
PlannedAudit preparation

Assign evidence requests to workspace users, set due dates, collect responses, and record whether submissions are accepted or need changes. Reuse existing evidence storage and analysis while keeping the final review decision with an authorized person.

Explore the current Evidence Library.

Policy Approvals & Exceptions
PlannedAccountability

Record approval of a specific policy version and manage exceptions with a business justification, compensating controls, named approver, and expiry date. Planned review records will distinguish a formal review from a document edit.

Explore the current Policy Library.

Protected Trust Center Sharing
PlannedCustomer due diligence

Extend the public Trust Center with selected private documents, access requests, approval, NDA acknowledgement, expiring access, revocation, and download history. Share only the documents approved for each recipient.

Repeatable Audit Engagements
PlannedAssessment history

Organize named audits with a defined scope, dates, responsible users, evidence requests, and per-control test results. Preserve a closing snapshot so later workspace changes do not rewrite the record of a completed assessment.

Existing Auditor accounts will remain read-only; assessment entry and approval will require an authorized workspace role.

Reusable Control Implementations
PlannedFramework reuse

Describe how your organization implements a safeguard once, including its owner, supporting evidence, and test procedure. Link that implementation to relevant controls, policies, vendors, and risks while evaluating each framework requirement independently.

Inventory workflow connections
Planned extensionBusiness context

The Inventory register now supports manual entries, CSV/Nmap imports, connected source collection, ownership, and freshness. Reviewed Control Assurance snapshots and dated notes are also available. Future extensions may add asset-to-risk and recovery dependency links, plus opt-in evidence refresh; those extensions are not yet available.

Guided Spreadsheet Imports
PlannedWorkspace onboarding

Bring risk and vendor registers into Datagrasp through CSV column mapping, previews, validation, duplicate handling, and readable row errors. Review the proposed changes before saving them to the selected workspace.

Further automation and integrations

Additional Cloud & Workspace Integrations

Planned Controls monitoring Evidence automation

Expand integration coverage beyond the currently available AWS, Microsoft 365 / Intune, and Google Workspace connectors with additional native connectors to continuously collect configuration and activity evidence from:

  • Azure (Defender for Cloud, Entra ID, Storage, Activity Logs)
  • Google Cloud (Security Command Center, IAM, Cloud Logging)

Findings will map to HIPAA, NIST CSF 2.0, SOC 2 Readiness, CIS 8.1, PCI-DSS 4.0, GLBA, ISO/IEC 27001:2022, ISO/IEC 42001:2023, CMMC Level 1 SAR, and NDAA Section 889 and appear as verifiable evidence in Control Assurance and the Assurance Report.

SSO & User Provisioning

In design Okta Azure AD/Entra Google

SAML/OIDC SSO plus SCIM user provisioning for centralized access control and auditability. Conditional access signals will feed risk scenarios and access reviews.

Ticketing & SIEM Integrations

Planned Jira ServiceNow Splunk Microsoft Sentinel

Create/track remediation tasks directly in your systems of record and sync closure to Compliance & Risk. Optionally ingest SIEM signals to open risks or attach evidence automatically.

Continuous Controls Monitoring (CCM)

Planned Policy-as-code Alerts & Reminders

Policy-as-code checks to continuously validate critical controls (e.g., MFA required, encryption at rest, logging enabled). Violations raise alerts, open risks, and can schedule re-checks.

Web Vulnerability Assessment

Planned Dashboard integration Evidence linking

Streamlined website scans for common weaknesses with severity ranking and remediation guidance. Convert findings into risks and attach reports as evidence to relevant controls.

SecOps Maturity Assessment

In design Benchmarking Program roadmap

Benchmark operational security capabilities, identify gaps, and generate a prioritized improvement plan aligned to business goals and frameworks. Trends surface on the Dashboard and in the Assurance Report.

Domain Impersonation Response Workflows

Researching Brand protection Risk scenarios

Extend the existing Domain Impersonation Monitoring tool with coordinated response tracking for suspicious look-alike domains, such as defensive registration decisions, takedown requests, and awareness updates. Domain detection itself is already available.

Public API & SDK

Planned Automation Custom workflows

REST/GraphQL endpoints and a lightweight SDK to push evidence, pull status, open risks, and manage vendors programmatically. Webhooks for real-time updates to your internal systems.

Evidence Intelligence

Exploring Auto-mapping Expiry tracking

Extend the available Evidence Health and Evidence Fit capabilities with suggested mappings across multiple controls and more detailed coverage recommendations. Evidence freshness and control-specific fit analysis are already available; automated mapping remains exploratory.

Data Residency & Retention Controls

Researching Regional hosting Policy-based retention

Choose regional data hosting options and enforce retention policies with defensible deletion workflows to support regulatory needs.

How these connect to Datagrasp

  • Risk Register: open risks from findings, assign owners, track mitigation and residual risk.
  • Evidence Library: attach scans, logs, and reports as verifiable evidence.
  • Compliance Overview: reflect improvements as controls pass and evidence updates.
  • Alerts & Reminders: schedule re-scans, reviews, expirations, and attestations.
  • Analytics & Reports: include results and time-series in the Datagrasp Assurance Report.
Design partner program: Want to shape these features? Tell us your priorities via the Contact page.
👋 Hey there, curious dev! If you’re exploring under the hood:
• Read our KB  â€˘ Review Security  â€˘ Contact us