Announcements

  1. Fresh updates from RiskProfiler.io πŸŽ‰ (September 1st to September 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements and Bug Fixes

    • Introduced a two-level sidebar navigation with a dedicated submenu panel, smoother transitions, and improved menu alignment.
    • Added a Module column in Takedown Requests to show the source module of each request. The Module field is also available in filters and exports.
    • Improved Remediation Plan details loading speed for faster access.
    • Added Suggested Assets under Total Assets Discovered in the Dashboard and Vendor Portfolio Security Rating, with synced asset counts and navigation to Suggested Assets.
    • Added a YYYY-MM-DD placeholder to the Last Updated date filter in Issues β†’ Portfolio Companies to clarify the expected date format.
    • Fixed export functionality in Typosquats β†’ Unregistered so files now generate and download correctly.
    • Fixed Email bulk import in Internet Inventory so records upload, process, and display correctly, with proper validation for failed records.
    • Fixed email notifications in Evidence Locker so recipients receive alerts for document requests and revoke actions.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  2. Fresh updates from RiskProfiler.io πŸŽ‰ (August 15th to August 31th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Manually added email recipients can now receive alerts even if they are not registered in User Management.
    • Improved Issues loading speed for customers with a large number of assets.
    • Fixed the Score Impact filter in Issues β†’ My Organization so all values now work correctly.
    • Fixed the Security Ratings Export button getting stuck after validation errors.
    • Improved email handling in Credential Leaks so the correct email domain appears in filters and exports.
    • Added loading indicators while loading MSP data and searching for organizations.
    • Long report names are now shortened, with the full name available on hover.
    • Added tooltips for Download and Delete actions in Past Reports and Scheduled Reports.
    • Added helpful text to the Generate Report slider and improved the date picker experience.
    • Standardized empty result messages across the platform.
    • Improved spacing and alignment in the Takedown Details slider.
    • Added tooltips for Reload and Download actions in export sliders.
    • Improved tooltips, incident ID spacing, and sticky header behavior in Data Breach details.
    • Improved CVE details loading speed in Security Ratings.

    🐞 Bug Fixes

    • Fixed incorrect values in the Industry filter of Threat Intel News.
    • Improved the Payment Card Leak Details slider to display long analyst comments properly.
    • Fixed payment card numbers not showing correctly in exports.
    • Fixed language filtering in Brand and Dark Web Threats to show only matching findings.
    • Improved search accuracy for Source, Threat Type, and finding details in Brand and Dark Web Threats.
    • Fixed Similarity sorting in Brand and Dark Web Threats.
    • Fixed the Sentiment filter in Brand and Dark Web Threats from showing incorrect Credential Leak findings.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  3. Fresh updates from RiskProfiler.io πŸŽ‰ (August 1st to August 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸš€ New Features:

    • Introduced Microsoft Entra as an Identity Provider (IDP) integration. Users can configure their Entra integration by providing the required connection and authentication details, enabling the platform to perform supported identity-related actions directly in Entra.
    • For verified employee credential leaks, users can now take remediation actions directly from Risk Profiler when Microsoft Entra is configured as the employee IDP. Remediation can be performed manually or automatically, helping organizations respond to confirmed credential exposure more efficiently.
    • Enhanced the existing alert trigger functionality to support scheduled aggregated alerts in addition to individual alert instances. Users can receive multiple alerts together in a consolidated view and investigate those alerts using AI-powered investigation capabilities.
    • Launched 4 AI Agents and 19 AI Skills to support common investigation and analysis workflows. These ready-to-use agents and skills help users perform structured investigations and accelerate alert analysis within the platform.

    πŸ“ˆ Enhancements and Bug Fixes

    • Added API support to fetch company, third-party, and fourth-party data breaches.
    • Takedown now displays and validates the complete URL path instead of only the root domain.
    • Added full URL duplicate checks and copy support to allow separate URLs under the same domain.
    • Scheduled reports now display the correct organization name in Past Reports.
    • Security Rating now shows active findings only, similar to Vulnerabilities, with consistent counts across views.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  4. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (July 15th to July 31st)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸš€ New Features:

    • Introduced the "Suggested Assets" feature, enabling users to review, validate, add, or ignore newly discovered internet-facing assets before including them in Internet Inventory, helping reduce false positives and improve attack surface accuracy.
    • Introduced a Vendor Details view to provide detailed vendor information, document visibility, and editable vendor attributes with complete change history tracking for better visibility and auditability.

    πŸ“ˆ Enhancements and Bug Fixes

    • Enhanced email validation now supports valid email addresses with + alias notation and process document requests successfully.
    • Fixed flagging behavior in Internet Inventory so users remain on the current page after flagging an item, instead of being redirected to the first page.
    • PDF attachments in questionnaires now download correctly, even when filenames contain special character.
    • Fixed report logic to ensure factor scores, issue counts, and severity-wise findings in Internet Inventory and Board Summary Reports match actual data across factors and domains.
    • Fixed an issue where the name updated during account activation was not reflected. User Management and Profile now display the same updated user name.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  5. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (July 1st to July 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Findings are no longer displayed for IPs associated with CDN and WAF, preventing unnecessary findings for assets that cannot be remediated.
    • Added the ability to export all vulnerability sections together for vendor issues in one CSV, reducing manual effort and saving time.
    • Filters in the Vulnerability List View now persist across navigation, so users don’t need to reapply them when returning to the view.
    • Questionnaires now show a clear message when a domain is not in the portfolio, replacing the previous β€œNo result to show” text.

    🐞 Bug Fixes

    • Fixed Vendor Security Rating calculation to dynamically compute industry-wise average rating, average issues, and percentile ranks.
    • Reports now correctly calculate industry-wise average rating dynamically.
    • Fixed numbering in questionnaires so that section numbers update correctly when sections are reordered via drag-and-drop.
    • Vendor Portfolio export now shows β€œAdded On” instead of β€œFirst Seen” and includes an β€œAdded By” column.
    • Reports now correctly calculate industry-wise average rating, average issues, and percentile rank based on the relevant tenant or vendor industry.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  6. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (June 15th to June 30th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Updated the Typosquats logic to produce a larger number of diverse and higher-quality variants, improving coverage and relevance of generated typosquats.
    • Deleted IP addresses in Internet Inventory now remain removed after a domain rescan. Rescanned data no longer restores previously deleted IPs, ensuring accurate and up-to-date IP listings.
    • New sections are now added at the bottom instead of the top, resolving the reverse order issue.
    • Added sorting options in Brand & Dark Web Threats for Observed Date, Criticality, and Similarity, allowing users to organize threat data and prioritize items effectively.

    🐞 Bug Fixes

    • Fixed an issue in the Data Breaches module where the Breach Type filter was not applying. The breach list now correctly updates to show only records matching the selected type.
    • Fixed an issue in Credential Leaks where some email IDs showed a leak count but no records in the lookup table. All counts now correctly display the associated leaks.
    • Date filter now supports Start Date and End Date selection, enabling users to filter monitoring results over a range instead of a single date.
    • Fixed an issue in the Credential Leaks module where the Top Count chart failed to load when searching an email or applying filters. The chart now renders correctly in all cases.
    • Fixed drag-and-drop behavior for sections so users can reorder sections in questionnaires. The UI now updates immediately, and the order persists after refresh.
    • Question numbers now follow correct section-wise sequencing (e.g., 1.1, 1.2 for Section 1; 2.1, 2.2 for Section 2).
    • Added proper spacing between question numbers and question text for improved readability.
    • Flagged findings are now fully disabled in Payment Card Leaks, preventing clicks or slider panel access while still displaying the β€œflagged” message.
    • NDA timeline now correctly shows β€œRejected” for rejected org access and β€œOrg Requested” when a user requests access from an invited organization.
    • Flagged vulnerabilities now display correctly when applying the status filter in the Vulnerabilities module.
    • Fixed an issue in the Portfolio Companies module where filters for Status and Score Impact were not working correctly.
    • Fixed an issue in the Resolved tab of Brand & Dark Web Threats where pagination controls were disabled despite multiple records.
    • After flagging an item in Vulnerabilities, Payment Card Leaks, or Security Rating, users now stay on the current page instead of being redirected to the first page.
    • Clear Filter now works correctly when all options are selected in Vulnerabilities filters.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  7. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (June 1st to June 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Removed the Industry field from questionnaires. Going forward, industry data will be sourced directly from the Vendor Industry Key, ensuring consistency without affecting historical data.
    • End users can now update the status of Payment Card Leak findings.
    • Full subdomains are now available through hover tooltips, with a copy icon added in both list and detailed views for quick access.
    • The status dropdown is now hidden for Trust Center users with Expired or Yet to Accept status.
    • Credential Leaks now includes a Password Leak Yes/No filter, and exports will respect the selected filter.
    • Fixed Internet Inventory behavior where deleted IP addresses reappeared after a rescan. Deleted IPs now remain removed in subsequent rescans.

    🐞 Bug Fixes

    • Fixed third-party vendor issue exports to show the correct vendor customer details instead of the logged-in tenant’s customer data.
    • Edited score values now display correctly in the Remediation Plan preview and remain updated after saving.
    • Removed the unimplemented Custom Score Improvement option from the Plan Objective dropdown.
    • Factor Score Improvement plans now correctly display their associated findings.
    • Fixed an issue where past report data was not loading for free users on the Report page.
    • Resolved multiple Internet Inventory issues related to quick filters, slow certificate sliders, tracker count mismatches, failing asset APIs, verification status filters, and missing domain screenshots.
    • Fixed inconsistent date filtering across tabs in Executive Digital Monitoring. Each tab now correctly applies the selected date range independently.
    • Fixed an issue where Whois information was not populating for assets under Security Rating. Asset selection now correctly retrieves and displays the related Whois data.
    • Resolved a critical issue where flagged domains could not be deleted from Internet Inventory. Users can now remove flagged assets from all tabs, including My Domains.
    • β€œView Breaches” now correctly opens the Breach Lookup page with associated data or displays a proper β€œNo breaches found” state.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  8. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (May 15th to May 31st)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸ“ˆ Enhancements

    • Added vendor logos as clear identifiers in Issue Detail views, helping users easily recognize vendor context when redirected from Vendor Portfolio or Security Rating pages.
    • Executive Digital Monitoring profiles now open in a new tab, allowing users to retain their current page and navigate more smoothly.
    • Added a guidance message in Remediation Plan PDF reports, advising users to refer to the platform when complete risk assessment details cannot be included in the PDF.
    • Updated the default NDA file naming format to RiskProfiler_NDA_signed_.pdf for clearer identification and tracking.
    • Enhanced the Trust Center public page with a responsive, mobile-friendly layout for better navigation, readability, and usability on smaller screens.
    • Free users can now download Remediation Plan reports without access restrictions.
    • Added a dedicated illustration for the disabled NDA state in Org Details, improved settings slider visibility, and repositioned the NDA Settings tab for easier access.

    🐞 Bug Fixes

    • Resolved an issue where Remediation Plan reports and related emails were showing β€œN/A” instead of generating successfully from the receiver side.
    • Fixed an issue where new filters in Threat Intel News were not showing values due to list filter API failures.
    • Fixed the β€œSomething went wrong” error in Threat Intel News and restored filter functionality.
    • Fixed an issue where active IP details were not loading correctly in CIDR and IP Blocks. Relevant active IPs now display properly in the details view.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  9. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (May 1st to May 15th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸš€ New Feature:

    • Enhanced the Trust Centre public page with improved font readability, consistent button rendering, cleaner document cards, updated icons, smoother section navigation, refined customer logo placement, responsive Security Controls design, improved Trust Centre URL presentation, updated email icon styling, and customer branding support in the title bar.

    πŸ“ˆ Enhancements

    • Free vendor users can now accept remediation plans without encountering license upgrade icon.
    • Security Artifacts now support .xlsx file uploads in addition to PDFs and images.
    • Implemented drag-and-drop functionality in Section Settings of Trust Centre for easier section management.
    • Added filter and export functionality for PII Leaks in Credential Leaks for easier tracking and extraction.
    • Credential Leaks export now includes Status, Login Status, Verification Method, and Resolution Status for more complete reporting.
    • Added a dedicated PII Leak column displaying Yes/No values for clearer identification of PII-related leaks.
    • Updated the Remediation Plan list view by renaming Assets to Impacted Assets for better clarity.
    • Removed the domains keyword from asset counts in the Remediation Plan list view, displaying only the numeric count.
    • Added missing Status filter support and fixed visibility of applied filter data in Portfolio Companies.
    • Enhanced domain validation to handle case-insensitive entries, reject trailing dots, and properly validate or restrict wildcard domains such as *.example.com.
    • Users can now upload a custom favicon for the Trust Centre page. If no favicon is uploaded, the default RiskProfiler favicon will be used.
    • Added filter and export functionality for PII Leaks in Credential Leaks to simplify viewing, management, and data extraction.
    • Improved the domain selection dropdown UI to properly handle long domain names without breaking layout or affecting usability.

    🐞 Bug Fixes

    • Credential Leaks export now includes only the records matching the currently applied filters instead of exporting all records.
    • Resolved issues causing incorrect zero asset counts for companies in the List View when assets were actually available.
    • Fixed mismatches between List View asset counts and breakdown details to ensure both display consistent and accurate data.
    • Fixed the β€œSomething went wrong” error occurring while deleting export files in Issues module.
    • Resolved an issue where shared links were opening with blank data in Issues module.
    • Fixed an issue where exports from the Breach Lookup section completed successfully but the generated file was not visible or accessible to users.
    • Fixed an issue where the status dropdown was getting hidden inside the sliding panel for bottom records in Payment Card Leaks, preventing status updates.
    • Fixed an intermittent issue where remediation plans sent to free users were not consistently visible to the receiver.
    • Fixed an issue where Issues and Vulnerabilities incorrectly displayed β€œNo results to show” while data was still loading.
    • The Leak Date filter in Breach Lookup now resets correctly when users switch tabs and return, ensuring a clean default view.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments

  10. πŸŽ‰ Fresh updates from RiskProfiler.io πŸŽ‰ (April 16th to April 30th)

    Greetings, everyone! We've worked hard to bring forth various new features and improvements. Let's explore them!

    πŸš€ New Feature:

    • Trust Center V3 launched: Launched new Trust Center features, including an Our Customers section with add/edit/delete support, a simplified Edit Company page, and a new Settings page for Organization, Section, and NDA configuration, along with auto-expiry for user access, improved access lifecycle management, bypass reason capture, revoke/resend invitation actions, enhanced user and organization views, and more consistent visibility controls across admin and public pages.
    • Optimized My Domains and Certificates with faster results, quick filters, and enhanced detailed filtering.

    πŸ“ˆ Enhancements

    • Improved the Trust Center layout to ensure proper alignment and usability on higher resolution screens, providing a consistent and visually balanced experience.
    • Admins can now re-send invitations for users in pending or yet-to-accept status.
    • Trust Center documents now support categories, and Penetration section data has been moved into Security Artifacts.
    • Added drag-and-drop functionality in Section Settings to allow easier reordering and management.
    • Added a separate PII Leak column to the list view, displaying a clear Yes/No value to distinguish PII-related leaks.
    • Activity Logs now display the time zone alongside the time for clearer and more accurate timestamp visibility.
    • Fixed sorting logic to ensure records are consistently displayed in proper descending order instead of being ordered by added date.
    • Optimized the Trust Center layout for higher-resolution screens to ensure proper alignment, spacing, and usability.
    • Optimized My Domains and Certificates with faster results, quick filters, and enhanced detailed filtering.
    • Added search and filter support for Business Unit and Questionnaire Tier to help users find and segment questionnaire records more efficiently.

    🐞 Bug Fixes

    • Updated Internet Inventory β†’ Email β†’ View Details to open the Lookup tab in a new page with the selected email ID preloaded for direct search, instead of redirecting to Credential Leaks in same page.
    • Resolved an issue where pagination showed incorrect total record count. It now correctly displays the total number of users along with the current range.
    • Standardized the ordering of Executive Members to ensure a consistent and fixed sequence across all users.
    • Fixed an issue where Issues and Vulnerabilities showed β€œNo results to show” instead of loading available data.
    • Enhanced spacing, colors, layout consistency, and visual alignment across Trust Center forms and sections.
    • Fixed issue where deleting items on later pages redirected users back to the first page in Trust Centre.
    • Applied character limits to description fields for better content control.
    • Optimized admin experience by reloading only updated sections instead of the full page.

    Your participation in our journey is irreplaceable. Each piece of feedback is highly valued.

    Warm Regards,

    Setu Parimi πŸ₯³πŸ™Œ

    Comments