Rhindon Cyber logo
    Support & Documentation
    Contact Support

    Release Notes

    What shipped in RAIC, newest first. Dates reflect production availability on app.rhindoncyber.com. Feature availability varies by tier — see the tier notes on each module page.

    Governance Operations and Decision Rights

    Most recent release.

    • Governance Operations now has its own workspace and menu, separate from Compliance, opening on the Operator Cockpit.
    • Operator Cockpit: one prioritised queue of everything due or overdue, with a plain-language explanation of why each item is ranked where it is.
    • Councils, meetings, agendas and minutes, with decisions written to a Decision Register linked back to the forum and the records concerned.
    • Action Register, exceptions and waivers with expiry and renewal, an escalation ladder, and a governance calendar you can export to your own calendar.
    • Authority Matrix: define who may approve what, propose and publish versioned rule changes, and see how many existing records a change would reroute before it takes effect.
    • Approval steps on use cases, AI systems, controls and policy versions are generated from your matrix and fail closed, refusing self-approval and approvals beyond a delegation limit.
    • Risk acceptance as its own decision right, with a register, expiry and reassessment, plus time-bounded emergency authority that must be closed out.
    • Governance State and Continuity Pack: a branded briefing, every register, a calendar file and content hashes for 90 days, 12 months or all time.

    Evidence Integrity and the Trust Portal

    • Verifiable evidence lineage: governance history is hash-chained and sealed nightly, so a record cannot be changed after the fact without the chain showing it.
    • Signed audit packs an external auditor verifies without a RAIC account, using a bundled offline verifier and a published specification.
    • Trust Portal: a public, link-gated governance page for customers, prospects, and auditors, with per-section visibility, access requests, and visit logging.
    • Pre-publish evidence check on the Trust Portal — publishing is blocked only when the evidence chain itself would fail verification, and advisory findings are recorded with your acknowledgement.
    • Portable continuity badge you can embed on your own website, backed by a discoverable descriptor and a redacted public signal.
    • Independent verification attestation published on a fixed quarterly cadence.

    Agentless vendor collectors

    • Read-only, detect-only connections to Microsoft 365 Copilot, ChatGPT Enterprise, and Claude (Enterprise/API) — no endpoint agent, and no prompt or file content leaves the vendor.
    • Claude is collected as two independent views, administrative activity and usage analytics, each on its own schedule so a slowdown on one never blinds the other.
    • Unusual jumps in usage volume are flagged for review against your own recent baseline.
    • Vendor credentials are stored encrypted, and every sweep is recorded in your activity log and the platform log.

    AI Data Governance

    • Inline inspection of content flowing into AI tools, with classification by pattern matching and named entity recognition.
    • Allow, mask, or block policy applied inline or retrospectively, per data class.
    • Encrypted payload vault so sensitive captures are retained for investigation without being readable in the clear.
    • Findings feed the Shadow AI workspace and the risk register.

    Automation Agents

    • Governance agents for Shadow AI triage, evidence freshness, and related routine work, under Governance → Automation Agents.
    • Four autonomy modes per agent — off, draft only, auto-act, and fully autonomous — with a confidence threshold you set.
    • Run an agent on demand or leave it on its schedule; every action is attributed and audited.
    • New in-app how-to video walking through enabling, running, and reviewing agent results.

    Anonymous peer benchmarks

    • Compare governance metrics against anonymised peers in your industry sector, size band, and region.
    • Cohorts are published only once a sufficient number of firms contribute, so no single organization can be identified.
    • Cohort tags are assigned by Rhindon Cyber rather than self-declared, keeping comparisons trustworthy.
    • Peer position appears on the maturity dashboard, registers, and executive reports.

    Partner template library

    • Install canonical RAIC document templates straight into your firm's Partner Docs library from the MSP portal.
    • New MSP Shadow AI Discovery Package template for client engagements.
    • Re-installing an unchanged template is a no-op; updates land as a new document version.

    Platform videos and documentation

    • Videos section in the documentation hub: stream the MSP Partner Portal demo, MSP onboarding, the General, Starter, and Professional client onboarding walkthroughs, and the Automation Agents how-to in-app.
    • Support site rebuilt on a canonical documentation registry, so every page now appears in the index, the sidebar, the sitemap, and the AI-crawler files from one source.
    • Twelve new documentation pages covering the Risk Register, EU AI Act workbench, NIST CSF 2.0, HIPAA, Hedge Fund / FINRA WSP, AI Discovery, AI Maturity, MSP Partner Portal, MCP Server, API Tokens, Core Concepts, and these Release Notes.
    • OWASP Top 10 review completed: security response headers published, leaked-password checks enabled at sign-up, and SECURITY DEFINER function grants swept.
    • Dependency vulnerability scanning runs on every build.

    AI Catalog and Curator pipeline

    • Curated AI catalog expanded past 1,500 entries across web, model, and API detections.
    • Automatic promotion of high-confidence unknown signals into catalog drafts, with automatic patch application for safe fields.
    • Multi-tenant host handling so shared platforms no longer collapse distinct tenants into one row.
    • Version history now supports a side-by-side comparison against the previously published version.
    • Pending-change viewer showing field-level differences before you publish.

    Risk and maturity

    • Dual inherent and residual risk scoring across AI Systems, Use Cases, and the Risk Register, with a heatmap toggle between the two views.
    • AI Maturity Index dashboard with GMI, CGMI, and TGP scoring plus daily snapshots and trend charts.
    • PowerGRYD pyramid reporting: overview, maturity assessment, layer coverage, gap and risk heatmap, and trend analysis.

    Frameworks and compliance

    • HIPAA module for Professional and Enterprise tiers.
    • Hedge Fund / FINRA Written Supervisory Procedures overlay for financial-services firms.
    • SOC 2 Type 2 evidence module with the full AICPA Trust Services catalog and an auditor evidence pack.
    • NIST CSF 2.0 and CIS Controls v8 coverage through Cybersecurity Mode.
    • External ISO 42001 auditor workspace with engagement scoping, findings, and a branded report.

    Integrations and platform surface

    • RAIC MCP Server, letting AI assistants query governance data over Model Context Protocol with OAuth 2.1 and full audit logging.
    • Public REST API with org-scoped and platform-scoped tokens, webhooks, and rate limiting.
    • ConnectWise PSA connector for outbound risk-event push.
    • Microsoft Graph discovery for AI usage, entitlements, non-human identities, and Purview labels.
    • Shadow AI browser extension v1.18.3 for Chrome, Edge, and Firefox, with Intune and ADMX force-install support and MSP white-label branding for partner-managed clients.

    MSP and partner

    • MSP Partner Portal with a multi-tenant client launcher, demo sandboxes, and QBR reporting.
    • White-Label add-on for partner-branded portals, emails, and exports.
    • Guided onboarding tour for partners new to the platform.