{"generatedAt":"2026-08-10T16:02:40.681Z","source":"ismscopilot-marketing","contract":"v1","product":"chat","canonicalHumanPage":"https://chat.ismscopilot.com/changelog","note":"Scrubbed mirror of the chat product changelog (chat.ismscopilot.com). Platform ships: /api/public/platform-changelog/v1. GitHub PR URLs removed.","markdown":"# ISMS Copilot Product Changelog\n\nAll notable user-facing changes to the **ISMS Copilot chat app** (chat.ismscopilot.com), grouped by month.\n\nPlatform (API, embed, console) ships: `docs/platform/CHANGELOG.md`.\nheyGRC ships: `docs/heygrc/CHANGELOG.md`.\n\n<!-- changelog-voice/2026-07-v1 -->\n## How to add an entry (authors and agents)\n\n**Canon version:** `changelog-voice/2026-07-v1`  \nFull agent runbook: `founder-ops/runbooks/changelog-voice.md` (private ops repo).\n\nThis How-to block is **not** rendered on the public page (parser only accepts `## Month YYYY` month headings).\n\n### Shape (July 2026 and later)\n\n```\n## Month YYYY\n\n### Features\n\n- **Short title.** One plain sentence.\n```\n\n### Rules\n\n1. Categories only: `Features`, `Improvements`, `Fixes`, `Privacy & legal`, `Safety` (this order).\n2. One bullet = **bold title ending in a period** + **one** sentence (max ~40 words).\n3. No em dashes. No statute dumps. No internal jargon.\n4. `Privacy & legal`: one-sentence product pointer to [trust.ismscopilot.com](https://trust.ismscopilot.com/dpa); full legal text stays on the Trust Center.\n5. PR links must be `([#N](url))` (build breaks otherwise).\n6. Bundle the entry in the **feature PR** (with `docs/ENGINEERING-LOG.md` as needed). Weekly catchup is the safety net only.\n7. Do not invent `### Feature title` headings as entries; every `###` is a category.\n8. Positive style examples: January and February 2026. Do not copy dense recent prose for voice.\n9. **Chat-only scope:** platform/embed/API console ships go to `docs/platform/CHANGELOG.md`; heyGRC to `docs/heygrc/CHANGELOG.md`.\n\nValidate: `node scripts/validate-changelog.mjs docs/CHANGELOG.md`\n\n---\n\n## July 2026\n\n### Features\n\n- **Agent-ready model API scopes in Connected apps.** When creating a personal access token, you can grant Model API scopes so agents can manage keys and credit top-up once server tools are enabled.\n- **Starting a free trial keeps the mode you clicked.** Starting Plus trial from Think, Beyond, or web search applies that mode immediately.\n- **Confetti when your Plus trial starts.** Free Plus trial success uses the same celebratory modal as a paid upgrade, with trial-specific wording.\n- **AIUC-1, the security standard for AI agents, now covered.** Built-in reference knowledge for AIUC-1 sits alongside ISO 42001, NIST AI RMF, and the EU AI Act.\n- **UK Freedom of Information and Environmental Information Regulations now covered.** Built-in FOIA and EIR knowledge for public-sector information-rights questions.\n- **A redesigned ISO 27001 risk-analysis demo page.** The free logged-out risk tool has a clearer landing, results layout, and dark mode.\n- **More usage on Pro and Business.** Pro is 250 credits per 4-hour window and Business is 500, applied automatically for existing subscribers.\n- **Try Plus free for 7 days, no card.** Eligible free users start a one-week Plus trial without a credit card.\n- **Generated documents keep your section numbering.** Numbered headings in chat stay numbered in Word, PDF, and Markdown downloads.\n- **Find any past conversation fast: the new Conversations page.** Sortable, filterable list of every conversation you can access, with search.\n- **Team search now finds all shared conversations.** Shared workspace search includes teammates' conversations you have not posted in.\n- **Dark mode.** Appearance in Settings supports System, Light, or Dark and syncs across devices.\n- **Grounded web research in chat and Beyond.** Eligible plans can pull current public pages as labeled evidence; details and ADP limits are on the Trust Center.\n- **Free ISO 27001 risk analysis, no signup.** Enter a company at /iso-27001-risk-analysis and get a scored risk register in about 30 seconds.\n- **Point-level CCPA/CPRA knowledge.** California privacy answers cite section and subdivision, in chat and over the API.\n- **Point-level UK GDPR knowledge, across the whole regulation.** UK GDPR answers cite paragraph and point and track UK divergences from the EU text.\n- **Deep-reasoning (\"think\") mode works reliably from your AI agent.** MCP clients no longer time out on longer Think answers.\n- **Point-level GDPR knowledge, across the whole regulation.** GDPR answers cite paragraph and point across all 99 articles.\n- **Point-level DORA knowledge, across the whole regulation.** DORA answers cite paragraph and point across all 64 articles.\n- **Workspaces: your conversations are front and centre again.** Two-column workspace layout puts recent chats under the composer and setup in a side panel.\n- **A cleaner Connectors page.** Agent tokens, picker, and revoked-token cleanup are clearer.\n- **Connect your AI agent from the Connectors page.** PAT setup for Claude Code, Codex, Cursor, Hermes, or any MCP client lives under AI agents.\n- **Broader ISO 27000-family knowledge.** ISO/IEC 27000 overview and refreshed ISO 19011:2026 knowledge.\n- **New Dutch framework: DigiD Assessment.** DigiD Assessment plus refreshed BIO 2, NEN 7510, and UAVG knowledge.\n- **New Swiss framework: Switzerland National Cyberstrategy (NCS).** NCS plus refreshed Swiss ICT Minimum Standard and FINMA Circular 2023/01 knowledge.\n- **New country framework: Australia (Privacy Act 1988).** Australian privacy answers now draw on the Privacy Act 1988 and the Australian Privacy Principles, reflecting the 2024 reforms.\n- **New Belgian framework: Data Protection Act 2018.** ISMS Copilot now recognises Belgium's national GDPR implementation act alongside its existing CyberFundamentals knowledge.\n- **EN 18286:2026, the EU AI Act quality-management standard, now covered.** Reference knowledge for the CEN-CENELEC standard operationalising EU AI Act Article 17 for high-risk AI providers.\n- **Try ISMS Copilot for HIPAA at /hipaa-assistant.** Logged-out HIPAA landing with starter prompts (guidance only).\n- **Try ISMS Copilot for the EU AI Act at /eu-ai-act-assistant.** Logged-out EU AI Act landing with starter prompts.\n- **Try ISMS Copilot for PCI DSS at /pci-dss-assistant.** Logged-out PCI DSS landing with starter prompts on scope, SAQ selection, and the twelve requirements (guidance only).\n- **Try ISMS Copilot for ISO 27701 at /iso-27701-assistant.** Logged-out ISO 27701 landing with starter prompts on extending an ISMS for privacy and mapping to GDPR (guidance only).\n- **Try ISMS Copilot for CCPA and CPRA at /ccpa-assistant.** Logged-out California privacy landing with starter prompts on applicability, consumer rights, and opt-out (guidance only).\n- **Try ISMS Copilot for Cyber Essentials at /cyber-essentials-assistant.** Logged-out Cyber Essentials landing with starter prompts on the questionnaire, scope, and the five control themes (guidance only).\n- **The free plan now includes 10 file uploads a month (up from 5).** More room to try the product on your own documents.\n- **File uploads are no longer a plan tier.** Every paid plan includes 500 uploads per month (fair use); pinned workspace docs do not count.\n- **Pin website links to a workspace.** Pin up to 5 sites with a daily-refreshed snapshot the assistant can read.\n\n<!-- HELD until the agent product's prod launch (Tristan's flag flip). Weekly audit: PRs #1510-#1513, #1621-#1632 are covered by this held entry; do not re-add.\n\n- **Meet the ISMS Copilot agent: delegate whole documents, not just questions.** Agent mode and Tasks for bounded multi-document work with approval, refunds, and a live timeline.\n\n-->\n\n### Improvements\n\n- **ISO 27017 knowledge updated to the new 2026 edition.** The assistant now follows the ISO/IEC 27017:2026 structure published on 27 July 2026, including the four new CLD cloud controls, and still recognizes citations from the retired 2015 edition.\n\n### Privacy & legal\n\n- **xAI (Grok) is the default AI provider for paid chat and Beyond.** Full DPA text, comparison, and objection options are on the [Trust Center](https://trust.ismscopilot.com/dpa) (effective 2026-07-21).\n- **Authenticated search uses a governed Mistral discovery bridge.** Brave remains future-only; full search and ADP details are on the [Trust Center](https://trust.ismscopilot.com/dpa).\n\n### Fixes\n\n- **Downloads keep your document's identifier lines.** Document IDs, versions, classification, owner, approver, and dates now stay in Word, PDF, and Markdown exports.\n- **Usage limits now show the correct reset schedule.** In-app copy reads \"per 4-hour window\" and tells you when the next window starts, instead of \"per session\".\n- **Starting a Plus trial now asks you to confirm first.** Eligible free users see a short confirmation with the details before anything is granted, plus \"Try free\" badges on the eligible modes.\n- **Your own shared conversations now show a team badge.** Threads you started in a shared workspace are labeled \"Shared with team\" in the list and in search.\n- **The top bar now fits on phone screens.** Mobile title stays one line; upgrade is a compact icon.\n- **On phones, the button to open your conversation history was missing.** The menu button now appears at the top left on phones.\n- **Generated documents keep section numbering correct.** Numbered sections start at 1 with no gaps, and missing attachments are not invented.\n- **Links and formatting on this page now render properly.** Changelog links, bold, and inline code display as intended.\n- **Free plan message limit no longer counts internal AI calls.** Only your real chat turns count toward the free 10-per-4-hours cap.\n- **Deleting a conversation mid document-generation no longer false-errors.** Half-finished documents are discarded quietly.\n- **Document downloads survive a misbehaving formatter.** Intact documents are recovered; true failures fail fast.\n- **No more spurious \"Failed to load settings\" on first load.** Session reads are coordinated and retried.\n- **Workspaces load reliably in the sidebar on first render.** Same session-timing fix as settings.\n\n## June 2026\n\n### Privacy & legal\n\n- **DPA and Privacy Policy update: paid plan AI routing now includes the full OpenRouter allowlist.** We've updated the Data Processing Agreement, Privacy Policy, and Terms of Service (effective 2026-06-23) to document that paid plans (Plus, Standard, Pro, Business) with Advanced Data Protection off may route AI requests through any of the seven disclosed OpenRouter providers (the same providers already disclosed for the Essential plan) in any chat mode. Anthropic remains a disclosed provider on the paid path. Advanced Data Protection users stay on Mistral in the EU, unchanged. This supersedes the overflow-only routing described in our earlier June update. Full text at [trust.ismscopilot.com/dpa](https://trust.ismscopilot.com/dpa).\n\n- **DPA and Privacy Policy update: over-quota routing added for paid plans.** The Data Processing Agreement (§2.4) and Privacy Policy have been updated to document that paid plans (Plus, Standard, Pro, Business) with Advanced Data Protection off may continue chatting via OpenRouter after the 4-hour Anthropic token cap (with your explicit opt-in each session), routed to the same Google Vertex and Cerebras providers already disclosed for the Essential plan. This is consent-gated: you choose whether to continue. ADP-on users stay on Mistral in the EU and are never routed elsewhere; Slack integrations and Essential users are unaffected. Full text at [trust.ismscopilot.com/dpa](https://trust.ismscopilot.com/dpa).\n\n### New\n\n- **Connect ISMS Copilot to Claude Code.** You can now connect your ISMS Copilot account to Claude Code, Cursor, or any MCP-compatible AI tool and work with it as yourself: asking compliance questions, reading your saved context, and generating documents without leaving your coding environment. Go to Settings → Connected apps, create a personal access token, and follow the setup guide to add the ISMS Copilot MCP server. Think mode is available on paid plans.\n\n- **Upload Markdown files.** You can now attach `.md` files to a chat alongside PDFs, Word documents, and other supported formats.\n\n- **Keep going on a faster model when you reach your limit.** On paid plans, when you hit your 4-hour usage limit on the standard model you no longer have to wait. You can choose to continue the conversation on a faster model until your limit resets: a card explains the option (continue now, or upgrade for higher limits), a small banner shows while it's active, and your standard model returns automatically at the next reset. You decide each time. Advanced Data Protection stays on Mistral in the EU and is never routed elsewhere; the Essential plan is unaffected. Routing details are in the [DPA](https://trust.ismscopilot.com/dpa).\n- **Beyond mode: a new way to produce real compliance documents.** Alongside Fast and Think, premium plans get Beyond  -  for substantial, multi-document work. Instead of one answer, Beyond plans the work, drafts each document as its own step, and verifies every document against the plan before you see it, so what you get is checked, not just generated. You can watch it work (planning, writing, verifying) and expand each finished document. Best for jobs like \"draft my missing GDPR document set\" or \"turn these audit notes into a findings report\". Select it next to the message box.\n\n- **Share skills with your team.** In a team, any member can share one of their custom skills with everyone. Teammates can then enable and use it like any other skill, while it stays read-only for everyone except the owner (who can edit, unshare, or delete it). Your personal skills stay private unless you choose to share them.\n- **Suggested next steps can now be a decision card.** When the assistant lays out a real choice (for example \"SOC 2 or ISO 27001?\"), Suggested next steps shows the options as a tappable card with the recommended pick highlighted, so you can choose with one tap or the keyboard (Enter accepts the recommendation, arrow keys pick another) instead of retyping. When there's no clear choice, you still get the usual suggestions. Turn it on with the \"Suggested next steps\" toggle next to the message box.\n- **Analyze several documents in depth, one by one.** Attach 2 or more documents to a chat and choose \"Analyze each separately\"  -  ISMS Copilot gives each document its own full-depth analysis (instead of one combined pass that spreads attention thin across them), with live per-document progress. Prefer the previous behavior? Choose \"Analyze together\".\n- **New UK framework: NIS Regulations 2018.** Questions about the UK's Network and Information Systems Regulations 2018 now draw on that framework directly, including operators of essential services and digital service providers and the NCSC Cyber Assessment Framework basis, instead of being conflated with the EU NIS 2 Directive.\n\n### Improvements\n\n- **Your skills now shape Beyond runs.** When you have a skill active, Beyond now follows it while it plans and drafts each document, the same way the regular chat does, so a Beyond run respects your tone, format, and instructions instead of ignoring them. Works with your own skills and any team skill you have enabled.\n- **Beyond now ends with a short recap.** After a Beyond run finishes, you get a 2-3 line summary of what it produced and the key takeaway, shown as a closing note under the run, so a long output (several documents, or a detailed opinion) is easy to grasp at a glance without re-reading it. It appears only when there's enough to summarize.\n- **Beyond shows what it is doing while it plans.** When you start a Beyond run, the planning step now names what it is reading (how many documents, the relevant frameworks, your saved context), then shows it thinking and writing the plan live (with a word count climbing), instead of sitting on a spinner. You can watch real progress before the plan appears.\n- **New framework: CIS Controls v8.1 (Critical Security Controls).** Questions about the CIS Critical Security Controls now draw on the CIS Controls v8.1 structure directly instead of generalising.\n- **New framework: ISO 19011 (auditing management systems).** Questions about running or planning a management system audit, for example an ISO 27001 internal audit, now draw on the ISO 19011:2026 audit-guidance structure directly instead of generalising.\n- **More room for saved memories.** Each memory scope now holds up to 200 saved facts, up from 100.\n\n### Fixes\n\n- **Web search is clearly paused during your extra-usage window.** When you're in the extra-usage period (after hitting your plan limit), the web search toggle now shows as paused and cannot be enabled. In that window, searches would have silently produced no results, because over-cap traffic routes through a provider without web search. If web search was already on when your limit was reached, it turns off automatically.\n\n- **Saved memories are reliable again.** The assistant could stop saving new facts once you already had some memories saved, including when you explicitly asked it to remember something. It now reliably captures new details about your organization.\n- **Markdown documents generate again.** Generating a Markdown document had been silently failing since 2026-06-05. The fix restores this, and you can now also download the result as a `.md` file.\n- **Upload-slot count tooltip is no longer hidden behind the sidebar.** The tooltip showing how many file uploads you have left now appears in front of the left sidebar instead of behind it.\n\n- **The assistant now uses your most recent saved memories.** When you have many saved facts, the assistant now keeps your newest and manually-added entries instead of the oldest ones when space is tight.\n- **Dismiss suggested next steps, and clearer decision-card titles.** You can now dismiss the suggested next steps (and decision cards) with the X button or the Escape key without turning the feature off, and the small category label on a decision card no longer gets cut off mid-word.\n- **Shared workspaces now show your whole team's work.** In a shared (team) workspace, you and your teammates now see each other's conversations, generated documents, and search results, not just your own. Personal workspaces stay private to you.\n- **Generated documents are easier to notice.** When you create a document from a message with the document icon, the new document card now scrolls into view and briefly highlights, so it's clear the document was created instead of quietly appearing below a long reply.\n\n---\n\n## May 2026\n\n### Privacy & legal\n\n- **Essential plan AI routing.** The new Essential plan routes AI requests through OpenRouter, limited to Google Vertex and Cerebras, when Advanced Data Protection is off. With Advanced Data Protection on, Essential routes to Mistral in the EU like every plan. No new sub-processor was added (both providers were already in our OpenRouter allowlist). Full text at [trust.ismscopilot.com/dpa](https://trust.ismscopilot.com/dpa).\n- **DPA and Privacy Policy update: sub-processor notice mechanism aligned with industry norm, OpenRouter underlying-provider allowlist expanded to seven, effective 2026-06-25.** We've amended DPA §2.4 and Privacy Policy §2 to distinguish materially-adverse sub-processor changes (still 30 days' advance email and in-app notice) from control-neutral changes (Trust Center and in-app changelog). Under the new wording, three vetted underlying providers (Together AI, Fireworks AI, Nebius) join the OpenRouter sub-processor allowlist alongside the original four (Inceptron, DeepInfra, Cerebras, Google Vertex); Novita AI was evaluated and not added. The privacy bar (zero retention, no training, no PRC-jurisdiction infrastructure, Advanced Data Protection Mode for EU-only processing) is unchanged. Object before 2026-06-25 by emailing privacy@ismscopilot.com. Full text at [trust.ismscopilot.com/dpa](https://trust.ismscopilot.com/dpa).\n\n### Features\n\n- **New Essential plan: $12/month.** A lower-priced paid plan for focused, individual compliance work, sitting between Free and Plus. It includes core compliance guidance, 25 file uploads per month, and cancel-anytime billing.\n- **Run several conversations at once.** Open a new chat without losing one that's still answering. The sidebar marks which chats are working, ready, or failed, and you always stay in the chat you opened.\n- **Buy more uploads when you hit your monthly limit.** If you reach your plan's monthly file-upload cap, you can buy a one-time top-up of +100 uploads for $25 (€25 in the EU). It's a separate one-off payment, so your plan, billing, and renewal date are untouched. The extra uploads stack on top of your plan allowance and last until the end of the month; the upload indicator shows your plan allowance and any top-up separately.\n- **Keyboard shortcut for new chat, plus a shortcuts cheat sheet.** Start a new conversation from anywhere with ⌘⇧O (Ctrl+Shift+O on Windows/Linux). A new keyboard icon in the sidebar opens a cheat sheet of every shortcut (new chat, search, toggle sidebar, send), so they're easy to discover.\n- **Generate a document from any AI message.** When a response would make a good document but none was created automatically, click the document icon under the message and pick a format (Word, PDF, Excel, or Markdown). The new document appears as an extra card under the message, and you can generate the same message in more than one format.\n\n### Improvements\n\n- **New interface languages: Polish and Ukrainian.** Users whose browser is set to Polish or Ukrainian, or who choose it in Settings, now see the full interface in those languages.\n- **New country frameworks: Netherlands.** Ask about the Dutch government security baseline (BIO 2), Dutch healthcare information security (NEN 7510), or the Dutch GDPR implementation act (UAVG), and the assistant now answers from those standards directly instead of generalising from GDPR or ISO 27001.\n- **New country frameworks: India.** Indian privacy and cyber questions now draw on the DPDP Act 2023 and Rules 2025, the CERT-In incident-reporting directions, the RBI IT-governance direction for banks, and the SEBI cybersecurity framework.\n- **New country frameworks: Switzerland.** Swiss data-protection and resilience questions now draw on the revised Federal Act on Data Protection (revFADP), FINMA Circular 2023/1, and the ICT Minimum Standard.\n- **New country frameworks: Germany.** German questions now draw on the BSI IT-Grundschutz catalogue and the BSI C5 cloud-attestation framework.\n- **New country frameworks: UK.** UK questions now draw on Cyber Essentials (and Cyber Essentials Plus) and the NCSC Cyber Assessment Framework.\n- **New country frameworks: France.** French cloud-security questions now draw on the ANSSI SecNumCloud qualification.\n- **New country frameworks: Belgium.** Belgian questions now draw on the CCB's CyberFundamentals (CyFun) framework, including its Basic, Important, and Essential assurance levels.\n- **New country frameworks: Canada and Quebec.** Canadian questions now draw on PIPEDA, and Quebec questions on Law 25 (Loi 25).\n- **New country frameworks: Ireland.** Irish questions now draw on the Data Protection Act 2018. Ireland's NIS 2 transposition is included as a pre-enactment placeholder, with the assistant clear that the bill is not yet law.\n- **New US frameworks: FedRAMP and CMMC 2.0.** Federal cloud-authorization questions now draw on FedRAMP, and DoD contractor questions on CMMC 2.0, instead of being conflated with each other or with NIST 800-171.\n- **New NIST references.** Added the NIST AI Risk Management Framework and its Generative AI profile, the Zero Trust Architecture guide (800-207), the Secure Software Development Framework (800-218), the Privacy Framework, and the HIPAA Security Rule implementation guide (800-66 Rev. 2).\n- **ISO 27001 companion standards.** Added ISO 27002, ISO 27017 (cloud), and ISO 27018 (cloud PII), so the assistant answers from each directly instead of folding them into ISO 27001.\n- **SOC 2 Report Review skill, version 2.** The built-in skill now gives a more rigorous walk-through of a vendor's SOC 2 report: clearer Pass / Minor / Major / Fatal verdicts, a new check for whether the auditor's testing was thorough enough to find exceptions, direct reading of attached SOC 2 PDFs, and correct handling of Type 1 reports.\n- **Longer custom skills.** The Skills editor now allows up to 12,000 characters per skill (was 8,000), with room for more detailed instruction packs. Existing skills are unaffected.\n- **Inline PDF preview.** PDF documents now render as inline page images in the preview panel, alongside Word and Excel. The copy button returns the full document text. Long PDFs render up to 50 pages inline.\n- **Inline Excel preview.** Generated spreadsheets now render as a table in the preview panel, so you no longer need to download just to see what's inside. Multi-line cells and cell links are preserved.\n\n### Fixes\n\n- **Document generation failures are now shown as errors.** When the assistant fails to produce a downloadable document, you now see an error message instead of a normal-looking reply with no document attached. The document icon also briefly pulses on failure so it is easy to spot and retry.\n- **Documents now generate reliably when requested.** A conflict in the assistant's instructions could cause the document pipeline to silently produce no file even when a document was clearly requested. Fixed.\n- **Plus plan highlighted as Popular in the upgrade dialog.** The recommended-plan badge has moved from Standard to Plus.\n- **Streamed answers finish without a flicker.** When the assistant finishes writing a reply, the text now settles in place cleanly: no brief flash, no jump, and the typing cursor simply disappears. This holds during document generation too, so the answer stays put while a document is being prepared.\n- **The Skills page no longer shows up empty.** In some cases the page could show only your own custom skills, with the built-in skills missing until a hard refresh. The built-in skills now load reliably every time.\n- **Success and error messages are readable in dark mode.** Pop-up notifications (success, error, warning) and the in-chat error cards previously used light-only colors that could render unreadable in dark mode. They now adapt to the theme.\n\n---\n\n## April 2026\n\n### Features\n\n- **Workspace files: pin up to 5 files per workspace.** Pin reference files (policies, SoAs, risk registers, standards) to a personal workspace, and the assistant uses them as context in every new conversation there. Each file shows its processing status, and the eye icon previews the content. Personal workspaces only for now; team workspaces are next.\n- **Slack integration.** A new Connectors page lets you connect Slack. Click Add to Slack, approve the install, and your team can DM the bot or mention @heygrc in any channel. Solo paid users no longer need to create a team first.\n- **Skills: write your own AI instruction sets.** A new Skills page lets you create, edit, and delete instruction packs the assistant applies when your message matches what you describe. You can also browse the built-in skills and click Clone & Customize to start from one. When a skill fires, a small chip appears above the response so you can see which one was applied. Up to 20 custom skills per account.\n- **Fuller built-in skills, plus two new ones.** The built-in skills now ship with detailed content (decision rules, worked examples, severity definitions) instead of skeletons. New: SOC 2 Report Review and ISO 27001 Internal Audit. ISO 27001 Gap Analysis and Risk Register Drafting were rewritten with clearer scales and decision rules.\n- **Web search.** A toggle in the chat input lets you search the web for current information, with source links in the response. Useful for recent regulatory updates, enforcement actions, and breach reports. Available to paid users.\n- **Web search for Advanced Data Protection users.** Web search now also works on the EU (Mistral) provider, with the search handled inside EU infrastructure.\n- **Long EU-provider conversations no longer hit the context wall.** When a conversation on the EU provider grows very large, the assistant automatically summarizes older messages and continues. You see a brief \"Compacting\" indicator, then it carries on.\n\n### Improvements\n\n- **Faster message finalization.** Responses now finish immediately after the last word instead of waiting a few seconds for background processing. The typing indicator clears sooner and the input re-enables faster.\n- **Keyboard navigation for suggestions.** Tab into the suggestion chips and use the arrow keys to move between them, Enter to select, Escape to return to the input. The recommended suggestion auto-focuses so you can press Enter right away.\n- **Suggested next steps always visible.** Follow-up suggestions now appear above the chat input instead of inside the message, so you no longer scroll to find them on long responses.\n- **Refreshed chat input bar.** A cleaner, monochrome design with a circular send button.\n- **Fewer duplicate memories.** The assistant now detects far fewer near-duplicate memories from the same conversation.\n- **Excel files keep their layout.** Uploaded spreadsheets now preserve their structure (orientation, merged cells) when the assistant completes or regenerates them.\n- **Workspace file preview shows the real content.** The eye icon now previews the actual file content the assistant reads, with a clear note for very long files about which parts are visible to the assistant.\n\n### Fixes\n\n- **NIS 2 in Germany now uses the finalised law.** German NIS 2 questions now reference the finalised BSI-Gesetz and its current section numbers, instead of sometimes quoting outdated draft sections. Reported by a customer.\n- **File upload on a brand-new chat works again.** Uploading a file before sending the first message could briefly fail with a \"Failed to save file record\" error between April 21 and 24. Fixed.\n- **Pinned workspace files are read in full.** The assistant now reads the entire pinned document (up to about 50,000 characters) instead of a short summary, and garbled German characters in extracted text are fixed.\n- **Word spell-check now works in your language.** Generated Word, PDF, and Excel documents now open with the correct language set, so spell-check flags typos in German, French, and other languages instead of always assuming English. Reported by a customer.\n- **Large generated documents no longer come back half-finished.** Long policies and reports (especially in German) could quietly produce a cut-off Word file. Fixed, including the German quotation marks that triggered it.\n- **Stopped messages are kept.** When you stop the assistant mid-response, the partial answer now stays on screen and in the conversation, with a subtle \"Generation stopped\" note. Previously it disappeared.\n- **Suggestions no longer appear in the wrong language.** Follow-up suggestions could show in German on an English conversation. Fixed.\n- **No more scroll jump after long responses.** The view no longer jumps to the top of a message when a long response finishes, and you can scroll up freely while it streams.\n- **The skill chip no longer jumps around.** When a skill activates mid-response, its chip now appears in its final position instead of snapping into place afterward.\n- **Connectors page no longer blocked by ad blockers.** The page could show an endless spinner, or wrongly show \"Upgrade\" to paid users, when an ad blocker was active. Fixed.\n- **The compaction indicator no longer looks frozen.** When summarizing a long conversation, the indicator could sit at 95% and look stuck. It now shows elapsed time and reassurance text so it's clear work is still happening.\n\n---\n\n## March 2026\n\n### Features\n\n- **Automatic language detection.** The app detects your browser language and sets it as your default, so new users see everything in their language from the first visit. Supports English, German, Dutch, French, Italian, Spanish, and Portuguese. Change it anytime in Settings.\n- **Advanced Data Protection on by default for DE, NL, IT, FR, and PT users.** New users with those browser languages get EU-only AI processing enabled automatically. Toggle it anytime in Settings.\n- **Team workspaces.** Invite team members to shared workspaces from Settings → Team. Each member gets their own usage limits at the same per-seat price, and shared workspaces show a \"Shared\" badge.\n- **Data export.** Download all your personal data as a JSON file from Settings → Data Protection. Covers conversations, file metadata, workspaces, memories, and settings. Meets GDPR Article 20 (data portability).\n- **Delete your own account.** Permanently delete your account and all its data from Settings → Data Protection. You'll be asked to cancel an active subscription first. This is irreversible.\n- **Better Advanced Data Protection.** The EU AI model now supports reasoning mode and a larger context window (256K tokens).\n- **Workspace memories.** The assistant remembers your organization's context (tools, team size, certifications) across all conversations in a workspace. Memories are auto-detected and can also be added by hand.\n- **Personal memories.** Memories now work outside workspaces too, so personal facts you share are remembered across sessions.\n- **Memory controls.** Turn memory detection on or off per workspace or for general chats, see how many memories you have with a capacity indicator, edit memories in place, and tell auto-detected from manual ones with a small badge. The limit was raised from 50 to 100.\n- **Custom instructions.** Set persistent personal preferences that apply to every conversation, like \"always respond in bullet points\" or \"focus on SOC 2\". Configurable in Settings.\n- **Document library.** View and manage all generated documents in a workspace from one page.\n- **Conversation search.** Find past conversations with full-text search.\n- **UK frameworks.** Added UK GDPR, the UK Data Protection Act 2018, and the Data (Use and Access) Act 2025.\n- **Framework version display.** See which version of each framework the assistant is using.\n- **Workspace sorting.** Sort workspaces alphabetically, by newest, or by oldest.\n\n### Safety\n\n- **Content moderation.** Chat messages are now automatically screened for harmful content. Flagged conversations are protected from deletion to support review.\n\n### Improvements\n\n- **Memories are now opt-in.** New accounts start with memories off; enable them anytime in Settings. Existing users are unaffected.\n- **Clearer invite billing.** The invite flow now shows a confirmation explaining the prorated charge applies when the invitee accepts.\n- **Document generation overhaul.** PDF and Word exports now use a more reliable pipeline, so even 20-plus-page policies covering all 93 Annex A controls come out complete.\n- **Longer responses.** Maximum response length was raised significantly, allowing much more detailed answers.\n- **The assistant responds in your language.** It now automatically uses the language set in the UI.\n\n### Fixes\n\n- **Correct dates in generated documents.** The assistant now knows today's date in your language, so documents no longer contain unresolved date placeholders.\n- **Correct ß in German documents.** The assistant no longer replaces \"ß\" with \"ss\" (for example \"Maßnahme\", not \"Massnahme\").\n- **More reliable document downloads.** Documents that occasionally failed to generate now recover in most cases.\n- **You keep your partial answer when the AI is busy.** If the AI service is briefly overloaded mid-response, you now keep what you already received, with a clearer, softer warning.\n- **Oversized Excel files no longer freeze the service.** Spreadsheets with millions of empty rows are now stripped and capped.\n- **Fixed false subscription downgrades.** Caused by a billing webhook race condition.\n- **Fixed documents cut off partway through.** Downloaded files could be missing most of their content; they now generate in full.\n- **Accurate upload counter.** Only fully processed files count toward your monthly limit.\n- **Reset stuck conversations yourself.** If a conversation gets stuck in \"processing\", you can now unstick it.\n\n---\n\n## February 2026\n\n### Features\n\n- **Context compaction.** Long conversations are automatically summarized as they approach the context limit, so you can keep going without starting over.\n- **Think mode.** Turn on extended reasoning for more thorough analysis (paid plans).\n- **Change password in the app.**\n- **Copy a whole conversation to your clipboard.**\n- **Usage and stats.** View your token consumption in Settings.\n- **Split-screen document preview.** Preview generated documents side by side with your conversation.\n- **Name your generated documents.**\n- **Report an issue** from below the chat, with the error context pre-filled.\n- **Interface in 6 languages.** English, French, German, Spanish, Italian, and Dutch.\n- **5 new frameworks.** ISO 22301 (business continuity), TISAX (automotive), the EU AI Act, ISO 9001 (quality), and HDS (French health-data hosting).\n- **Automatic provider failover.** If the main AI provider is down, conversations switch to a backup automatically.\n- **Faster responses** through prompt caching.\n- **Free-tier limits with clear upgrade prompts** when you reach the conversation or upload cap.\n- **Date awareness.** The assistant now knows today's date, useful for compliance deadlines.\n\n### Improvements\n\n- **Smarter framework detection** that uses fewer tokens to work out which framework you're asking about.\n- **Better table rendering.** Tables in responses now copy and display correctly.\n- **Clearer upload-limit messages** as you approach your plan's cap.\n\n### Fixes\n\n- **Fixed silent file-upload failures** caused by a race condition.\n- **Fixed file-processing timeouts** on large documents.\n- **Fixed paying users showing as free** after the subscription system migration.\n- **Clear error on expired password-reset links** instead of a blank screen.\n- **Fixed document generation** skipping legitimate requests.\n\n---\n\n## January 2026\n\n### Features\n\n- **New subscription system.** Four plans (Free, Plus, Pro, Business) with clear feature tiers, managed through Stripe.\n- **AI model switching.** Choose between Anthropic (Claude), OpenAI, Mistral (EU), Grok, and Gemini.\n- **Upload several files at once.**\n- **Message feedback.** Copy any message, thumbs up or down, or report an issue from the chat.\n- **Help form** in the sidebar for quick support requests.\n- **Think / Fast mode selector.** Choose between quick answers and deeper reasoning.\n- **Password reset** from the login page.\n- **Privacy-first analytics.** Switched to cookieless tracking.\n","byteLength":38692}