July was a month about exposure and connection. A brand new Risk Management module gives you a living risk register with 5×5 scoring, appetite enforcement, and a heatmap. Emails, issues, and contacts now link to help desk tickets so a conversation and the work it triggered stay joined up. We also rebuilt how invitations work, gave every ISO Mate email one branded layout, and shipped one of our longest security lists yet. Here’s the full rundown.
Risk Management
This is the headline for July. Risk Management is a first class risk register that lives inside the compliance workspace alongside your frameworks, controls, and policies. Every risk is scored on a 5×5 likelihood and impact matrix, tracked separately for inherent, residual, and target exposure, with automatic level bands (low, medium, high, critical) and an over appetite flag.
You can set a single account risk appetite or override it per category, then record a formal acceptance with a rationale and an expiry to sign off risks you choose to tolerate. Risks map to the controls that treat them and the frameworks they relate to, and they link to treatment tasks, the incidents a risk realized, and the supporting evidence behind each assessment.
Review cycles keep the register alive between audits. Each review is recorded with a full history, owners receive due and overdue reminders, and a colour coded heatmap shows your portfolio across inherent, residual, and target layers.
Getting your existing register in is straightforward. Import from CSV with a validating dry run before anything commits, export the register and a Risk Treatment Plan to CSV or PDF, and see a risk summary on the compliance dashboard. You can also draft a risk from a short description with Create with AI, and ask the assistant about risks over appetite, reviews due, acceptance needed, and risks off target. Everything is available through the API and MCP tools too.
Emails, Issues, and Contacts Meet the Help Desk
Support work rarely stays in one place, so we connected the places it travels between. From the email reading pane, a related activity panel shows the contacts on a message and the help desk tickets connected to it. You can link an email to one or more existing tickets, or create a new ticket pre-filled from the email with the sender set as the requester. Tickets already raised by the same contact are surfaced too, and you can unlink anything you no longer want associated. The same link can be made from the ticket view, so it works from whichever side you start.
Issues gained a Help Desk Tickets section listing linked tickets, loaded in pages, where you can link existing tickets or unlink them. From a ticket, you can create a new issue prefilled from the ticket and linked back to it in one step. The link is bi-directional, so the same connection is visible from both sides and selecting either one opens it.
Contacts now carry their own communication history. An Emails section lists the messages where the contact was the sender or a recipient, with sent and received labels, and a Help Desk Tickets section lists the tickets where the contact is the requester. You can create a ticket directly from the contact with the requester already set, or send them an email straight from the Emails section.
Account Invitations
Adding someone who already uses ISO Mate now sends them an invitation instead of granting immediate access. They join your account only after they accept. The invitation email names who invited them and which account, and the link opens a page where they can accept or decline. Nothing about their existing accounts changes until they accept.
The role, department, and notes you set when inviting are applied on acceptance, and the seat is only taken at that point. A Pending Invitations panel on Account Users lists everyone who has not replied yet, where you can resend or withdraw an invitation, and invitations expire after 14 days. You are notified in the app when an invitation is accepted or declined, and every invitation sent, accepted, declined, or withdrawn is recorded in the audit log. If you sign in without belonging to any organization, any invitation waiting for you now appears on the No Account Access screen so you can accept it there. Inviting someone without an ISO Mate login yet works as before: they receive an invitation to verify their email and set up a password.
Password Breach Detection
ISO Mate now checks new passwords against a database of passwords exposed in known data breaches and blocks any that are found. The check runs whenever a password is set: account registration, password reset, invited user setup, and admin user creation. It is privacy preserving by design and never exposes your actual password. If a password is rejected during registration or a reset, you now see a clear message explaining why. There is no forced rotation and existing passwords are unaffected, since the check applies only when a new password is chosen.
One Branded Email Experience
Every ISO Mate email now shares one branded layout, so the header, buttons, notices, and footer look the same across account, billing, help desk, calendar, and feedback messages. The invitation and password reset emails no longer use the default framework template, so they carry ISO Mate branding like the rest. Typography is consistent throughout, with one typeface and one set of text sizes, so copy no longer changes size or font between sections or inside highlighted panels. Every email now ends with the same sign-off, including our support address and website, in the recipient’s language.
New users also receive a branded welcome email across every sign-up path, with quick links to the console, the marketing website, the blog, the knowledge base, and the pricing page.
Diagram Builder Improvements
Orthogonal connectors now always keep their right angles. Routing is corrected automatically when shapes move, and connectors route around shapes instead of doubling back when their connection points face away from each other. Connectors can also carry a label, edited from the properties side panel and shown at the midpoint of the line in the editor, the viewer, and exports.
Routing is fully editable. Double-click a line to add a bend, double-click a segment handle to remove one, and drag segments to reposition them, where they snap and merge when aligned with neighbouring segments. A new Reset Routing button restores automatic routing in one click. Selection and hover feedback were improved throughout, and the help dialog now documents the new connector gestures.
Workflow Email Enhancements
Placeholders now resolve in workflow emails, so recipients see the real values in both the subject and the body instead of raw placeholder text. Workflows triggered by a custom object entry can insert the entry’s fields into emails, notifications, and tickets, and they resolve to the entry’s stored values. The workflow email body is now a full rich text editor with headings, bold, italics, lists, links, tables, and alignment.
Issue Detail Improvements
The Git Activity section now sits directly below Attachments and above QA Traceability, so linked branches, commits, and pull requests are easier to find without scrolling. Issue comments also support rich text formatting such as bold, italics, lists, and links, using the same editor as issue descriptions, and saved comments keep their formatting.
AI Assistant Reliability
Every AI assistant surface now recovers automatically when the connection drops, for example after your machine sleeps, a tab is backgrounded, or the network drops briefly. The next question streams a reply with no page refresh. A lightweight “Reconnecting” indicator appears while the connection recovers and hides once it is restored. If a response is interrupted midway, the assistant stops the typing indicator, keeps any partial reply, and shows a clear message to try again instead of spinning forever. This applies consistently across every AI feature in ISO Mate.
Compliance
Policies generated when you scaffold a compliance framework (GDPR, ISO 27001, or General Business) now open with a clear notice that the content was generated by AI and must be reviewed and verified by a qualified person before it is approved or published. The notice appears in the framework’s language (English, German, or Spanish), and generated policies still stay in draft for your review.
Bug Fixes
- Email sync: new emails did not always appear on their own and only showed up after a manual refresh. Syncing is now more dependable, keeps working smoothly with many connected mailboxes, and one problem account no longer holds up the rest, so your inbox stays up to date automatically.
- Issue attachments: the Copy URL action has been removed because it duplicated the existing view and download options. Viewing, previewing, and downloading are unaffected, and opening image and PDF attachments directly in the browser now works reliably.
- Workflows: submitting a custom object entry no longer sends the workflow email twice.
- Billing: a cancelling subscription now keeps full access for the rest of the paid period instead of being locked out during the grace period.
- Account setup: the page opened from an invitation link had an oversized heading and disproportionate spacing. It has been tidied up to match the sign-in and password reset pages.
- No Account Access: the Sign Out button cleared your session but left you on the same screen. It now signs you out and returns you to the sign-in page.
Security
July was a heavy month for hardening. Alongside routine security updates across the frameworks and third-party components behind ISO Mate, here is what changed.
- Re-authentication for user removal: removing or deleting a user now requires the administrator to re-confirm their identity with their password or a Google re-authentication. The confirmation lasts a short window so a bulk removal only asks once, and every removal is recorded in the audit log with the acting administrator, the affected user, the time, the IP address, and the browser.
- Email change protection: changing your account email now requires re-authentication and confirmation from the new address before it takes effect, with the previous address notified. This closes an account takeover risk.
- Password change hygiene: changing your account password now signs you out of all your other active sessions, so access ends immediately on other browsers and devices. You receive an in-app notification in your own language, plus a security email confirming the change with the time and originating IP address and advice to contact support if it was not you. Passwords are now capped at 128 characters across every flow.
- Name and content sanitization: user and company names can no longer contain HTML, scripts, or web links, closing a stored injection vector and stopping crafted names from being used for phishing. Names are also no longer turned into clickable links inside verification, password reset, invitation, account lockout, and calendar reminder emails. Everyday names, including company names that look like a domain such as Booking.com, keep working as before. Web links inside submitted feedback are now shown as inert text in the notification emails sent to our team.
- Export and upload hardening: all CSV exports are hardened against formula injection, so values beginning with a formula character are treated as text in Excel, Numbers, and Google Sheets. SVG account logos are now sanitized, hardening logo uploads against stored cross-site scripting.
- Email address validation: password reset and other authentication flows could accept look-alike (Unicode homoglyph) email addresses and resolve them to a real account. Addresses are now validated as ASCII only and normalized consistently across all flows. We also closed a sign-up loophole where variants of the same Gmail address, such as extra dots or a plus tag, could claim multiple free trials.
- Content Security Policy: following an independent security assessment through our vulnerability disclosure program, the admin console now enforces a Content-Security-Policy that restricts scripts to trusted sources, while leaving your content, email previews, and attachment previews working as before. The marketing website no longer allows inline scripts by default, with inline scripts running only when they carry a per-request nonce, and its policy was tuned so analytics continues to report correctly.
- Header and cookie changes: the admin console now sends Cross-Origin-Opener-Policy and X-Permitted-Cross-Domain-Policies headers for stronger cross-origin isolation. The deprecated X-XSS-Protection header is no longer sent by the console, the API, or the marketing website, since Content-Security-Policy is the control we now rely on. The website language preference cookie carries an explicit SameSite=Lax attribute alongside its existing Secure and HttpOnly flags, and the API no longer reports its exact web-server version in response headers.
- Marketing website: the login now returns the same generic message for every failed sign-in, so it no longer reveals whether a username exists, and the background task scheduler was hardened so unauthenticated requests can no longer trigger excessive server work.
What’s Next
There is more on the way across the platform. If you haven’t tried ISO Mate yet, sign up for a free 14-day trial at isomate.io. No credit card required, full access to everything from day one.
Got feedback? Reach out at support@isomate.io or use the built-in feedback portal inside the platform. Your input shapes what we build next.