Announcements

  1. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (July 1st to July 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Findings are no longer displayed for IPs associated with CDN and WAF, preventing unnecessary findings for assets that cannot be remediated.
    • Added the ability to export all vulnerability sections together for vendor issues in one CSV, reducing manual effort and saving time.
    • Filters in the Vulnerability List View now persist across navigation, so users don’t need to reapply them when returning to the view.
    • Questionnaires now show a clear message when a domain is not in the portfolio, replacing the previous β€œNo result to show” text.

    🐞 Bug Fixes

    • Fixed Vendor Security Rating calculation to dynamically compute industry-wise average rating, average issues, and percentile ranks.
    • Reports now correctly calculate industry-wise average rating dynamically.
    • Fixed numbering in questionnaires so that section numbers update correctly when sections are reordered via drag-and-drop.
    • Vendor Portfolio export now shows β€œAdded On” instead of β€œFirst Seen” and includes an β€œAdded By” column.
    • Reports now correctly calculate industry-wise average rating, average issues, and percentile rank based on the relevant tenant or vendor industry.

    Comments

  2. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (June 15th to June 30th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Updated the Typosquats logic to produce a larger number of diverse and higher-quality variants, improving coverage and relevance of generated typosquats.
    • Deleted IP addresses in Internet Inventory now remain removed after a domain rescan. Rescanned data no longer restores previously deleted IPs, ensuring accurate and up-to-date IP listings.
    • New sections are now added at the bottom instead of the top, resolving the reverse order issue.
    • Added sorting options in Brand & Dark Web Threats for Observed Date, Criticality, and Similarity, allowing users to organize threat data and prioritize items effectively.

    🐞 Bug Fixes

    • Fixed an issue in the Data Breaches module where the Breach Type filter was not applying. The breach list now correctly updates to show only records matching the selected type.
    • Fixed an issue in Credential Leaks where some email IDs showed a leak count but no records in the lookup table. All counts now correctly display the associated leaks.
    • Date filter now supports Start Date and End Date selection, enabling users to filter monitoring results over a range instead of a single date.
    • Fixed an issue in the Credential Leaks module where the Top Count chart failed to load when searching an email or applying filters. The chart now renders correctly in all cases.
    • Fixed drag-and-drop behavior for sections so users can reorder sections in questionnaires. The UI now updates immediately, and the order persists after refresh.
    • Question numbers now follow correct section-wise sequencing (e.g., 1.1, 1.2 for Section 1; 2.1, 2.2 for Section 2).
    • Added proper spacing between question numbers and question text for improved readability.
    • Flagged findings are now fully disabled in Payment Card Leaks, preventing clicks or slider panel access while still displaying the β€œflagged” message.
    • NDA timeline now correctly shows β€œRejected” for rejected org access and β€œOrg Requested” when a user requests access from an invited organization.
    • Flagged vulnerabilities now display correctly when applying the status filter in the Vulnerabilities module.
    • Fixed an issue in the Portfolio Companies module where filters for Status and Score Impact were not working correctly.
    • Fixed an issue in the Resolved tab of Brand & Dark Web Threats where pagination controls were disabled despite multiple records.
    • After flagging an item in Vulnerabilities, Payment Card Leaks, or Security Rating, users now stay on the current page instead of being redirected to the first page.
    • Clear Filter now works correctly when all options are selected in Vulnerabilities filters.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  3. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (June 1st to June 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Removed the Industry field from questionnaires. Going forward, industry data will be sourced directly from the Vendor Industry Key, ensuring consistency without affecting historical data.
    • End users can now update the status of Payment Card Leak findings.
    • Full subdomains are now available through hover tooltips, with a copy icon added in both list and detailed views for quick access.
    • The status dropdown is now hidden for Trust Center users with Expired or Yet to Accept status.
    • Credential Leaks now includes a Password Leak Yes/No filter, and exports will respect the selected filter.
    • Fixed Internet Inventory behavior where deleted IP addresses reappeared after a rescan. Deleted IPs now remain removed in subsequent rescans.

    🐞 Bug Fixes

    • Fixed third-party vendor issue exports to show the correct vendor customer details instead of the logged-in tenant’s customer data.
    • Edited score values now display correctly in the Remediation Plan preview and remain updated after saving.
    • Removed the unimplemented Custom Score Improvement option from the Plan Objective dropdown.
    • Factor Score Improvement plans now correctly display their associated findings.
    • Fixed an issue where past report data was not loading for free users on the Report page.
    • Resolved multiple Internet Inventory issues related to quick filters, slow certificate sliders, tracker count mismatches, failing asset APIs, verification status filters, and missing domain screenshots.
    • Fixed inconsistent date filtering across tabs in Executive Digital Monitoring. Each tab now correctly applies the selected date range independently.
    • Fixed an issue where Whois information was not populating for assets under Security Rating. Asset selection now correctly retrieves and displays the related Whois data.
    • Resolved a critical issue where flagged domains could not be deleted from Internet Inventory. Users can now remove flagged assets from all tabs, including My Domains.
    • β€œView Breaches” now correctly opens the Breach Lookup page with associated data or displays a proper β€œNo breaches found” state.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  4. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (May 15th to May 31st)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Added vendor logos as clear identifiers in Issue Detail views, helping users easily recognize vendor context when redirected from Vendor Portfolio or Security Rating pages.
    • Executive Digital Monitoring profiles now open in a new tab, allowing users to retain their current page and navigate more smoothly.
    • Added a guidance message in Remediation Plan PDF reports, advising users to refer to the platform when complete risk assessment details cannot be included in the PDF.
    • Updated the default NDA file naming format to RiskProfiler_NDA_signed_.pdf for clearer identification and tracking.
    • Enhanced the Trust Center public page with a responsive, mobile-friendly layout for better navigation, readability, and usability on smaller screens.
    • Free users can now download Remediation Plan reports without access restrictions.
    • Added a dedicated illustration for the disabled NDA state in Org Details, improved settings slider visibility, and repositioned the NDA Settings tab for easier access.

    🐞 Bug Fixes

    • Resolved an issue where Remediation Plan reports and related emails were showing β€œN/A” instead of generating successfully from the receiver side.
    • Fixed an issue where new filters in Threat Intel News were not showing values due to list filter API failures.
    • Fixed the β€œSomething went wrong” error in Threat Intel News and restored filter functionality.
    • Fixed an issue where active IP details were not loading correctly in CIDR and IP Blocks. Relevant active IPs now display properly in the details view.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  5. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (May 1st to May 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸš€ New Feature:

    • Enhanced the Trust Centre public page with improved font readability, consistent button rendering, cleaner document cards, updated icons, smoother section navigation, refined customer logo placement, responsive Security Controls design, improved Trust Centre URL presentation, updated email icon styling, and customer branding support in the title bar.

    πŸ“ˆ Enhancements

    • Free vendor users can now accept remediation plans without encountering license upgrade icon.
    • Security Artifacts now support .xlsx file uploads in addition to PDFs and images.
    • Implemented drag-and-drop functionality in Section Settings of Trust Centre for easier section management.
    • Added filter and export functionality for PII Leaks in Credential Leaks for easier tracking and extraction.
    • Credential Leaks export now includes Status, Login Status, Verification Method, and Resolution Status for more complete reporting.
    • Added a dedicated PII Leak column displaying Yes/No values for clearer identification of PII-related leaks.
    • Updated the Remediation Plan list view by renaming Assets to Impacted Assets for better clarity.
    • Removed the domains keyword from asset counts in the Remediation Plan list view, displaying only the numeric count.
    • Added missing Status filter support and fixed visibility of applied filter data in Portfolio Companies.
    • Enhanced domain validation to handle case-insensitive entries, reject trailing dots, and properly validate or restrict wildcard domains such as *.example.com.
    • Users can now upload a custom favicon for the Trust Centre page. If no favicon is uploaded, the default RiskProfiler favicon will be used.
    • Added filter and export functionality for PII Leaks in Credential Leaks to simplify viewing, management, and data extraction.
    • Improved the domain selection dropdown UI to properly handle long domain names without breaking layout or affecting usability.

    🐞 Bug Fixes

    • Credential Leaks export now includes only the records matching the currently applied filters instead of exporting all records.
    • Resolved issues causing incorrect zero asset counts for companies in the List View when assets were actually available.
    • Fixed mismatches between List View asset counts and breakdown details to ensure both display consistent and accurate data.
    • Fixed the β€œSomething went wrong” error occurring while deleting export files in Issues module.
    • Resolved an issue where shared links were opening with blank data in Issues module.
    • Fixed an issue where exports from the Breach Lookup section completed successfully but the generated file was not visible or accessible to users.
    • Fixed an issue where the status dropdown was getting hidden inside the sliding panel for bottom records in Payment Card Leaks, preventing status updates.
    • Fixed an intermittent issue where remediation plans sent to free users were not consistently visible to the receiver.
    • Fixed an issue where Issues and Vulnerabilities incorrectly displayed β€œNo results to show” while data was still loading.
    • The Leak Date filter in Breach Lookup now resets correctly when users switch tabs and return, ensuring a clean default view.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  6. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (April 16th to April 30th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸš€ New Feature:

    • Trust Center V3 launched: Launched new Trust Center features, including an Our Customers section with add/edit/delete support, a simplified Edit Company page, and a new Settings page for Organization, Section, and NDA configuration, along with auto-expiry for user access, improved access lifecycle management, bypass reason capture, revoke/resend invitation actions, enhanced user and organization views, and more consistent visibility controls across admin and public pages.
    • Optimized My Domains and Certificates with faster results, quick filters, and enhanced detailed filtering.

    πŸ“ˆ Enhancements

    • Improved the Trust Center layout to ensure proper alignment and usability on higher resolution screens, providing a consistent and visually balanced experience.
    • Admins can now re-send invitations for users in pending or yet-to-accept status.
    • Trust Center documents now support categories, and Penetration section data has been moved into Security Artifacts.
    • Added drag-and-drop functionality in Section Settings to allow easier reordering and management.
    • Added a separate PII Leak column to the list view, displaying a clear Yes/No value to distinguish PII-related leaks.
    • Activity Logs now display the time zone alongside the time for clearer and more accurate timestamp visibility.
    • Fixed sorting logic to ensure records are consistently displayed in proper descending order instead of being ordered by added date.
    • Optimized the Trust Center layout for higher-resolution screens to ensure proper alignment, spacing, and usability.
    • Optimized My Domains and Certificates with faster results, quick filters, and enhanced detailed filtering.
    • Added search and filter support for Business Unit and Questionnaire Tier to help users find and segment questionnaire records more efficiently.

    🐞 Bug Fixes

    • Updated Internet Inventory β†’ Email β†’ View Details to open the Lookup tab in a new page with the selected email ID preloaded for direct search, instead of redirecting to Credential Leaks in same page.
    • Resolved an issue where pagination showed incorrect total record count. It now correctly displays the total number of users along with the current range.
    • Standardized the ordering of Executive Members to ensure a consistent and fixed sequence across all users.
    • Fixed an issue where Issues and Vulnerabilities showed β€œNo results to show” instead of loading available data.
    • Enhanced spacing, colors, layout consistency, and visual alignment across Trust Center forms and sections.
    • Fixed issue where deleting items on later pages redirected users back to the first page in Trust Centre.
    • Applied character limits to description fields for better content control.
    • Optimized admin experience by reloading only updated sections instead of the full page.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  7. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (April 1st to April 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Trust Centre access links are now time-bound, single-use, and securely invalidated after login or logout. Each new access request generates a unique token, and expired or reused links are no longer accepted.
    • Renamed Inherit Risk to Vendor Tier for improved clarity and better user understanding.
    • Added proper loading state handling in the API Key section. The Generate Key button now remains disabled until the existing key is fully loaded, preventing unintended duplicate key generation.
    • Improved the Past Reports tab experience by displaying a proper loading state instead of briefly showing β€œNo results to show.”
    • Added a Decline Questionnaire action, allowing recipients to reject questionnaires with mandatory remarks. Status, decline reason, and notifications are now visible to both sender and receiver for improved transparency and tracking.

    🐞 Bug Fixes

    • Fixed an issue where screenshots in the Typosquats module were not displaying properly. Images now render correctly.
    • Resolved UI issues in sliders and popups observed after performing rescans, ensuring consistent behavior across the platform.
    • Alerts are now triggered only for vendors tagged for monitoring, preventing notifications for unmonitored vendors and reducing unwanted alerts.
    • Fixed search behavior in the Vulnerability tab so users can enter full keywords without interruption.
    • Search input in Vulnerability now clears correctly when the MSP is changed.
    • Fixed incorrect notification behavior in Vulnerability when flagging snoozed findings. The flag action is now disabled when it is not applicable.
    • Resolved an issue in Vulnerability where snoozed, flagged, or resolved findings could still open the slider despite being disabled.
    • Resolved an issue where reports were not generated immediately after plan creation.
    • Fixed count refresh behavior when plans are created or deleted, so totals update correctly without requiring a page reload.
    • Fixed the β€œplan not found” error shown when findings were deleted before submitting a plan.
    • Newly created plans now appear at the top of the list in both sender and receiver views.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  8. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (March 17th to March 31st)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • The Subprocessors section in the Trust Center now supports countries, regions, continents, and global selections, providing more comprehensive and flexible location representation.
    • Removed the Logo column from the Data Leaks table in Security Ratings to simplify the view and reduce clutter.
    • The Usage Report has been enhanced to align with the revised subdomain and IP logic for billable assets, ensuring more accurate usage reporting.
    • Vendor invitations can now be sent to any valid email address, with users automatically added to the organization upon admin approval.

    🐞 Bug Fixes

    • NVD and MITRE details are now more consistently available for vulnerabilities with product and vendor data.
    • Fixed pagination to prevent navigating beyond available data, with Next now disabled on the last page across all views.
    • Resolved an issue where question type options were not visible while creating custom questionnaires.
    • Fixed issue preventing users from uploading files via drag-and-drop in questionnaires.
    • Fixed inconsistencies between questionnaire name and breadcrumb display.
    • Fixed incorrect numbering sequence when categories are deleted with custom numbering enabled.
    • Resolved issue showing incorrect default selections in question type during review.
    • Fixed validation error blocking publishing of cloned questionnaires due to duplicate question IDs.
    • Pagination count now updates immediately after deleting a questionnaire without requiring refresh.
    • Questionnaire name now correctly appears in breadcrumbs during editing.
    • Upload counts now update correctly for questions with multiple upload fields.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  9. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (March 1st to March 16th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Enhanced Column Sorting in My Organization View: Introduced sorting functionality for Severity, Security Factor, Findings, Status, and Score Impact to improve data visibility and analysis.
    • Improved Default Severity Prioritization in ASI Vulnerabilities: Implemented default severity ordering (Critical β†’ High β†’ Medium β†’ Low β†’ Positive β†’ Info) for consistent and prioritized vulnerability visibility.
    • CVE Column Added in Vulnerabilities List: A CVE column has been added to the Vulnerabilities list to display associated CVE IDs with direct links to their detail pages.
    • Vendor Name Added in Questionnaire Emails: Questionnaire emails now display the Vendor Name above the Vendor Domain for clearer vendor identification.
    • Improved Access View for Logged-In Users: Logged-in users in the Trust Center Page now see their name and email with a logout option, while the Request Access button is hidden.
    • Confirmation for Access Management Actions: Admins now receive a confirmation prompt before approving or rejecting access requests in the Trust Center Access Manage access.
    • Mandatory Decline Reason for Rejections: Admins must now provide a decline reason when rejecting Trust Center Manage access, which appears as a tooltip in the access list.
    • Comment Field Added to Invite User in Trust Center: The Invite User form in the Trust Center now includes an optional comment field visible as a tooltip in the user list.
    • Flexible NDA Options During Trust Center Invitations: The Trust Center invitation flow now allows admins to require NDA, exempt a user, or exempt an entire domain based on configuration.
    • Dynamic Subscription Controls in Trust Center: The Trust Center subscription button now automatically toggles between Subscribe and Unsubscribe based on the user’s current status.
    • Questionnaire Workflow Enhancements: Enhanced Send and Received Questionnaire features with new Business Unit and Tier fields, searchable framework selection, Date Sent visibility, and improved detailed views accessible via the Eye icon.
    • Takedown Findings Prioritized Across Modules: Findings with newly initiated takedown actions now appear at the top in Brand & Dark Web Threats, Typosquats, Executive Digital Monitoring, and Takedown & Disruption modules.
    • Unarchive functionality Added for Questionnaires: Added Unarchive functionality and a new Inactive tab. Archived, and Declined questionnaires now appear in Inactive, while Completed shows only Approved, and Rejected records.
    • Enhanced List View and Export for Questionnaires: Introduced an updated list view UI for Send and Receive Questionnaires with advanced capabilities including search, filters, column selection, and customizable export based on the selected list view results.
    • Country Field Made Optional Across Executive Modules: The Country field is now optional in Internet Inventory – Executive Members, Brand Configuration, and Executive Digital Monitoring to prevent users from being blocked if the dropdown fails.
    • Vendor Edit Functionality Added to Vendor Portfolio: Vendor details can now be edited directly from the Vendor Portfolio for Third-party Company and Subsidiary Company records.
    • Password Masking Enabled in Slack Notifications: Passwords for Credential Leak related Slack notifications are now fully masked to prevent sensitive credential exposure.
    • Vendor Invitations and Questionnaires Support External Emails: Vendor invitations and questionnaires can now be sent to any valid email address.

    🐞 Bug Fixes

    • Flagged Task Visibility Restored for Reviewers: Reviewers can now view tasks created for flagged questions after the questionnaire transitions back from flagged status.
    • Description Generation Issue Resolved: Fixed an error encountered during description generation in custom questionnaires.
    • Multi-Select Task Creation UI Fixed: Resolved UI rendering issues when creating tasks for multi-select answer types in reviewer view.
    • Notify Field Default and Validation Improved: Corrected default email population and validation handling in the Notify field during task creation for sender/reviewer.
    • Trust Center Preview Mode Visibility Improved: Preview Mode now displays FAQs, Updates, and Security Controls even when the Trust Center page is unpublished, ensuring all subsection data is visible before publishing.
    • Flagged Items Now Visible in Security Rating: Flagged items from the Security Dashboard β†’ Information Leak section are now correctly reflected in Security Rating when viewing details.
    • Export Value Correction for Unanswered Questions: In exported questionnaire files, the Updated By field now shows N/A instead of AI when non-mandatory questions are left unanswered by the user.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  10. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (Feb 15th to Feb 28th)

    New Feature
    Improvement

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Security Ratings Performance Improved: Optimized Security Ratings endpoints to reduce response times to under 1 second for organizations with large volumes of findings.
    • Enhancements to Executive Digital Monitoring: Executive Digital Monitoring now supports adding multiple emails, domains, profile pictures, and social media handles for a single executive across Internet Inventory, Brand Config, and Executive Monitoring. Additionally, users can now remove an uploaded profile picture.
    • Vendor Invitations Restricted to Enterprise Users only: Free users attempting to send vendor invitations will now see an upgrade prompt instead of accessing the invite workflow.
    • Executive Members Tab Added to Asset Export: The Executive Members tab is now included in the export file for all assets.
    • Custom Questionnaire Category Ordering Fixed: Newly created categories now appear in the correct sequential order, preventing misalignment and jumbled question IDs in exports.
    • AI Overwrite Now Updates All Answer Types: AI overwrite functionality now consistently updates all answer types, including Upload File fields.

    🐞 Bug Fixes

    • Fixed Recipient Email Validation Issue: Resolved an issue where Create Task incorrectly rejected valid recipient emails, even when the user existed in the sender domain’s User Management.
    • Ignored Tab Source Search Fixed: Source search now works in the Ignored tab and returns matching result.
    • Type of Threat Search Fixed: Search now returns results for all threat types, including newly added options and Credential Leaks, across all tabs.
    • Archive Toast Redirect Corrected: Resolved incorrect redirection from archive notification emails. Users are now directed to Send Questionnaires β†’ Completed instead of the Receiver tab.
    • Yet to Accept Pagination Fixed: Corrected pagination inconsistencies in the Received Questionnaires β†’ Yet to Accept tab to ensure accurate record navigation.
    • Uploaded File Access in Export Enabled: File responses uploaded by receivers are now properly accessible and downloadable by senders/reviewers in exported questionnaires.
    • Yet to Start Pagination Fixed: Fixed pagination errors in the Received Questionnaires β†’ Yet to Start tab for consistent record display.
    • Export β€œUpdated By” Field Corrected: Unanswered questions in exported files will now display N/A instead of incorrectly showing β€œAI” in the Updated By field.
    • Custom Questionnaire Category Ordering Fixed: Newly created categories now appear in the correct sequential order, preventing misalignment and jumbled question IDs in exports.
    • Submission Notification Restored: Restored missing notification trigger after questionnaire submission from the In Progress tab.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments