Available today: Datagrasp already includes Control Assurance, policy version history, vendor questionnaires, Evidence Health and Evidence Fit analysis, a public Trust Center, and AWS, Microsoft 365 / Intune, and Google Workspace integrations. Credential Exposure Monitoring and Domain Impersonation Monitoring are also available. The proposals below extend these workflows.
Planned assurance improvements
- Distinct risk and control outcomes: Keep risk acceptance, risk transfer, control applicability, and demonstrated control effectiveness separate so treatment decisions do not imply successful control testing.
- Evidence-aware framework reuse: Check each destination control’s evidence and applicability before carrying completion across linked frameworks.
- Recorded policy reviews: Track review dates and reviewers independently of ordinary document edits, with clear visibility into reviews that are due.
Planned client workflows
Datagrasp Sentinel
Run a saved, evidence-backed audit simulation for an assigned compliance framework. Sentinel will distinguish declared checklist completion from what the workspace can prove, with requirement-level Evidence Confidence, defensibility results, unsupported claims, contradictions, and recommended remediation.
Phase 1 will use Auditor Mode, deterministic scoring, and bounded AI interpretation. Each completed run will retain immutable snapshots of the sources considered so the result remains explainable after records change.
Sentinel is advisory: it will not certify compliance, replace auditors, change authoritative records, or reconstruct arbitrary dates before a run was captured.
Native Workforce Training
Deliver, assign, complete, renew, and document workforce training inside Datagrasp. Phase 1 will include a Datagrasp-managed course library, workspace assignments and reports, and a focused My Training experience with saved progress, acknowledgments, and assessments.
Published course versions, completion records, and Certificates of Completion will retain their history. Renewals will create new assignments, and successful completions will generate supporting Evidence Library artifacts without automatically completing controls.
Planned topics include HIPAA workforce privacy and security awareness, general security, privacy, AI awareness, incident reporting, and policy awareness. Client-authored courses, Policy Library acknowledgments, phishing simulations, Labs, and SCORM are future enhancements.
Evidence Requests & Review
Assign evidence requests to workspace users, set due dates, collect responses, and record whether submissions are accepted or need changes. Reuse existing evidence storage and analysis while keeping the final review decision with an authorized person.
Policy Approvals & Exceptions
Record approval of a specific policy version and manage exceptions with a business justification, compensating controls, named approver, and expiry date. Planned review records will distinguish a formal review from a document edit.
Protected Trust Center Sharing
Extend the public Trust Center with selected private documents, access requests, approval, NDA acknowledgement, expiring access, revocation, and download history. Share only the documents approved for each recipient.
Repeatable Audit Engagements
Organize named audits with a defined scope, dates, responsible users, evidence requests, and per-control test results. Preserve a closing snapshot so later workspace changes do not rewrite the record of a completed assessment.
Existing Auditor accounts will remain read-only; assessment entry and approval will require an authorized workspace role.
Reusable Control Implementations
Describe how your organization implements a safeguard once, including its owner, supporting evidence, and test procedure. Link that implementation to relevant controls, policies, vendors, and risks while evaluating each framework requirement independently.
Inventory workflow connections
The Inventory register now supports manual entries, CSV/Nmap imports, connected source collection, ownership, and freshness. Reviewed Control Assurance snapshots and dated notes are also available. Future extensions may add asset-to-risk and recovery dependency links, plus opt-in evidence refresh; those extensions are not yet available.
Guided Spreadsheet Imports
Bring risk and vendor registers into Datagrasp through CSV column mapping, previews, validation, duplicate handling, and readable row errors. Review the proposed changes before saving them to the selected workspace.
Further automation and integrations
Additional Cloud & Workspace Integrations
Expand integration coverage beyond the currently available AWS, Microsoft 365 / Intune, and Google Workspace connectors with additional native connectors to continuously collect configuration and activity evidence from:
- Azure (Defender for Cloud, Entra ID, Storage, Activity Logs)
- Google Cloud (Security Command Center, IAM, Cloud Logging)
Findings will map to HIPAA, NIST CSF 2.0, SOC 2 Readiness, CIS 8.1, PCI-DSS 4.0, GLBA, ISO/IEC 27001:2022, ISO/IEC 42001:2023, CMMC Level 1 SAR, and NDAA Section 889 and appear as verifiable evidence in Control Assurance and the Assurance Report.
SSO & User Provisioning
SAML/OIDC SSO plus SCIM user provisioning for centralized access control and auditability. Conditional access signals will feed risk scenarios and access reviews.
Ticketing & SIEM Integrations
Create/track remediation tasks directly in your systems of record and sync closure to Compliance & Risk. Optionally ingest SIEM signals to open risks or attach evidence automatically.
Continuous Controls Monitoring (CCM)
Policy-as-code checks to continuously validate critical controls (e.g., MFA required, encryption at rest, logging enabled). Violations raise alerts, open risks, and can schedule re-checks.
Web Vulnerability Assessment
Streamlined website scans for common weaknesses with severity ranking and remediation guidance. Convert findings into risks and attach reports as evidence to relevant controls.
SecOps Maturity Assessment
Benchmark operational security capabilities, identify gaps, and generate a prioritized improvement plan aligned to business goals and frameworks. Trends surface on the Dashboard and in the Assurance Report.
Domain Impersonation Response Workflows
Extend the existing Domain Impersonation Monitoring tool with coordinated response tracking for suspicious look-alike domains, such as defensive registration decisions, takedown requests, and awareness updates. Domain detection itself is already available.
Public API & SDK
REST/GraphQL endpoints and a lightweight SDK to push evidence, pull status, open risks, and manage vendors programmatically. Webhooks for real-time updates to your internal systems.
Evidence Intelligence
Extend the available Evidence Health and Evidence Fit capabilities with suggested mappings across multiple controls and more detailed coverage recommendations. Evidence freshness and control-specific fit analysis are already available; automated mapping remains exploratory.
Data Residency & Retention Controls
Choose regional data hosting options and enforce retention policies with defensible deletion workflows to support regulatory needs.
How these connect to Datagrasp
- Risk Register: open risks from findings, assign owners, track mitigation and residual risk.
- Evidence Library: attach scans, logs, and reports as verifiable evidence.
- Compliance Overview: reflect improvements as controls pass and evidence updates.
- Alerts & Reminders: schedule re-scans, reviews, expirations, and attestations.
- Analytics & Reports: include results and time-series in the Datagrasp Assurance Report.