Track the DORA Critical ICT functions in a dedicated registry and connect each with the assets, third parties and people who keep them in operation – through consoles, CLI,MCPsaun8n.
Changelog
Each important change is clearly explained.
august 2026
5 Changes inCookie consent now solves geolocation by state or province, so visitors to the U.S. and Canada get the banner of the privacy law that actually applies – not a generic one at country level.
Visitors to California receive a Your Privacy Choices panel in the cookie banner to opt out of selling and sharing data, plus a notification banner only for regions without legal consent.
The Dutch language is now supported on the entire console, compliance portal and cookie banner – including documents, NDA streams, access requests and a copy of the Privacy Options panel.
Run multiple compliance portals within one organization – each with its own audit and document catalog, visitor experience, and publication controls for different products or segments.
iulie 2026
17 ChangesExport audit logs or SCIM events as CSV from the console, Connect,MCPor CLI – stop asking for ZebraByte for a data dump when your auditors or SIEM need the gross history.
Audits now track a start and end date so that the review windows appear as sortable columns without opening each audit to check.
Visitors to the portal can request access to several blocked documents simultaneously, instead of submitting a separate application for each.
ZebraByte speaks French now, in the console and compliance portal that customers see, its first language delivered in addition to English.
Access Reviews now covers five other platforms, from web analytics to payment infrastructure, including Google Analytics and Segment.
Admins gets a full picture of the employee’s device posture in the console, and employees can self-service the sign-up confirmation without an alleged session.
Visitors can now browse the compliance portal updates as a real feed and subscribe via email to hear about changes automatically.
Visitors can now narrow down their list of subprocessors by faction, instead of going through everything on the public trust page.
Trust Center is now the Compliance Portal, in production with its own registration brand, custom domain and document library.
Visitors can now file GDPR and CCPA rights claims directly from the Compliance Portal and track their status without an email chain.
Update events now include the previous state of the entity, so you can differentiate the old values from the new ones without performing a separate search call.
Four new managed connectors mean fewer manual access revisions.
Climb directly from a risk to its assessments without leaving the list of risks, saving clicks every time you review the risk register.
The document.update node action now edits the body, title, classification, and type, and automatically creates a project when it does not exist.
Import FERPA and PCI DSS controls directly into your compliance program, without the manual setting required for student or payment card data.
Subscribe to created, updated, signed, and approved documents instead of voting and differentiating the outcome.
A new trigger node ZebraBytes the workflow8when a document event occurs, with HMAC verification and without a survey node.
iunie 2026
Thirteen changesThird-party verification now keeps the complete structured analysis, not just a short summary, covering risks, privacy, and AI governance.
Support, AI routing, incident response, and email marketing join the access review connector list with Pylon and three other tools.
Connect DocuSign to a full OAuth2 stream and choose which account to use without the need to manually challenge the API key or copy.
Cover banking, sales tools, and AI infrastructure in the next access review campaign with Mercury, Apollo.io, and three other tools.
Give the Compliance Portal pages a memorable custom URL slug instead of a generated ID, perfect for links in a sales pad or email.
MCP clients, such as Claude and ChatGPT, can now register with ZebraByteprint through a standard OAuth2 client metadata document instead of a pre-provided client ID.
Create, list and revoke your own carrier tokens for scripting against ZebraByteAPI, without sharing a service account with your team.
Employee document signatures now generate a real signed PDF and an esign record, in the same way that document approvals have already done.
Importing suppliers from a shared, automatically enriched directory instead of typing the same third-party details that your colleagues have already found.
Get user access directly from five other infrastructure and observability tools: Better Stack, SigNoz, Neon, Render, and Qovery.
Third parties can now nest at any depth, not just at a sub-seller level, so sub-processor subprocessors are representable.
Group risk assessment nodes within the so-called, unstable limits so that large Mermaid charts remain legible as the system map grows.
The consent banner for cookies ZebraByte adds 9 languages - bringing the total to 13 - and adapts to the language of the visitor's browser without additional configuration.
Archive documents that you no longer need to enable from the action menu in a row – non-destructive and consistent with archiving elsewhere in ZebraByte.
ZebraByte adds access review connectors for Zendesk, Okta, Clerk, SendGrid and Datadog – each pulls the user list so reviewers can see who has access to what.
ZebraBytecookie-banner SDK 0.8.0 exposes trackerType on each CookieItem, so the headless cookie list and the thematic banner can show what kind of tracker each entry is.
The publication of the cookie banner now automatically generates a tracker policy document, which lists each tracker detected and its provider.
The veteran thirdParty operation is now available in the ZebraByten8n node, a checking task that runs asynchronously without blocking the workflow.
View the provider behind each tracker on the banner tracker page and filter the entire list by a third party to audit everything a particular provider places.
mai 2026
14 ChangesIn noduln8, there are three new capabilities: archive users, linking measures with third parties and self-referential modeling relationships with third parties.
Seven new access review connectors arrive in ZebraByte, plus HTTP Basic auth support and automatic cancellation of signature request.
Disable a user with the new archiveUser operation – removed from active workflows but retained in the org for auditing tracking purposes.
Measures and third parties can now be linked much-to-many, third parties support self-referencing relationships and measure state moves to a headline label.
Synchronization errors on the SCIM bridge are now exposed inAPI and appear on the Google Workspace and Microsoft 365 connector cards in the console.
The platform’s historical line note: the previous self-managed architecture has won an official Helm deployment path.ZebraByteCloud retains the product capabilities without exposing this as a client installation method.
The risk assessment resource is available in nn8n, covering the entire risk assessment hierarchy with complete CRUD operations for automation.
The seller is now a third party in API, CLI, webhooks, and console – a reputation that fits better with compliance terminology.
Each interaction with the cookie banner is automatically mapped to the country and to the privacy regulations - consent records,APIs and the banner interface remain aligned.
The SCIM bridge synchronizes Google Cloud Identity directories in the same way as Google Workspace – automatic provisioning without a Workspace license.
Run access reviews against Microsoft 365 users and groups directly from ZebraByte, making decisions directly from Entra ID.
Synchronize users and groups in Microsoft Enter your ID in ZebraByteautomat, closing the identity synchronization gap for Microsoft 365 stores.
SCIM management aZebraByte is now accessible from your AI agent and from the terminal, so you can script provisioning without the console.
Build, theme, translate and send a GDPR-ready cookie banner from ZebraByte, with consent signals, automatic detection, CLI and support forMCP.
aprilie 2026
Twelve changesThe controls now carry a real CMMI maturity score instead of a binary implemented flag, showing how mature each control is actually.
Data exports and asset recordings have disappeared. Both records now publish the version and are signed like any other compliance document.
ZebraByte Talk Now about OAuth2 and OpenID Connect – anyone can build integrations that connect directly to your compliance set.
The Applicability Statement is now a complete document that you can edit, publish, version and send for approval and signature.
Persons with concluded contracts no longer appear in the signature request dialog, so former employees will not bother the list.
Document properties, such as classification, owner, and version, are now visible directly on the page, instead of being hidden in a drawer.
The SOA section is now correctly named Applicability Statement, which corresponds to the exact term that auditors actually use for it.
Mark the bookmark in the rich text editor and it will automatically play, including tables, headers, lists, and blocks of code.
Connect documents directly to measures for better evidence mapping so auditors can see support policies in a glance.
Run periodic access reviews to check who still has access to what by tracking evidence in ZebraByte instead of a spreadsheet.
Tasks now have an ongoing status alongside opening and completion, making the task table really useful for tracking active activity.
Write and edit documents directly in ZebraByte with tables, links, diagrams and slash commands, in a suitable WYSIWYG editor built on TipTap.
martie 2026
Thirteen changesFilter your document library by classification to quickly narrow a long list to only public policies or internal procedures.
Minor version updates no longer require everyone to sign the document again, saving re-signatures for the changes that actually matter.
The documents now go through an appropriate review and approval process before publication, tracking who signed and when for auditors.
Set priority levels, urgent, high, medium or low, on tasks so your team always knows what to approach first during a busy sprint.
Upload evidence andZebraByteanalyses the file automatically and generates a simple description of exactly what it contains.
Let search engines index your compliance page so potential customers can find it on Google when searching for your company plus “security”.
Get full visibility of each action in your organization with the SIEM-ready audit logs that auditors are waiting for during the assessmentsSOC2 and ISO27001.
Log in to ZebraByte with your Google Workspace or Microsoft Entra ID Enterprise account, no new password or magic link is needed.
Add subscribers to your compliance page mailing list without a confirmation email, ideal for contacts who have already signed a DPA or NDA.
Upload the audit report PDF files, drag them and throw them directly to the audit list, no longer dig through the attached menus.
The new Cross-Origin Request Protection (CSRF) systems prevent malicious sites from making unauthorized requests while you are logged in to ZebraByte.
Find any measurement instantly by searching in titles, descriptions and details, instead of running through long lists.
Track audit results with shared severity levels in the web application,MCPand CLI, so you don’t lose anything by switching between tools.
There are no updates in this category.