Openlane

What's new
at Openlane

Sep 14, 2026
Custom reports
Feature
API
Compliance

Everything in Openlane is reachable through the GraphQL API. Not everyone on your team writes GraphQL.

Custom reports put the same data in reach without a query. Choose what to report on, pick the columns to include, and add fields from related records to bring linked data into the same table. For example, to build a control matrix, report on controls with their reference code, description, and control owner, then add the mapped framework requirements. The export is ready to hand to an auditor.

Under the hood, each report runs as a GraphQL query, and the Query tab shows the one your report ran. Copy it and run it against the API yourself, or come back to it later in the report history.

Sep 8, 2026
Assign responsibilities to personnel
Registry
Exposure
Improvement

Ownership in Openlane can now reflect who is actually responsible, even if that person doesn’t have an Openlane account.

Assign personnel directly to vulnerabilities, vendors, assets, platforms, and other objects across your organization. Connect your identity provider or employee source of truth to keep Personnel up to date, then assign the right person wherever responsibility lives.

Openlane still includes unlimited seats, so anyone who needs access can have it. But when someone doesn’t need to log in, you no longer have to create an account just to show that they own a vendor, vulnerability, or other responsibility.

Aug 20, 2026
Control and policy suggestions
AI
Controls
Compliance

Openlane now makes it easier to start with a strong set of controls, then make them yours.

Based on the framework you’re working toward and the controls already in scope, Openlane suggests organization-specific controls that map back to the relevant framework requirements. You get a clear starting point without being locked into a fixed control set, and can adapt each control to reflect how your organization actually operates.

As you build out your program, Openlane can surface policies that may be missing based on those controls. Create them from a template or generate a first draft with AI, then quickly map controls and policies together to keep everything aligned as your program evolves.

Aug 14, 2026
Embedded docs and help
UI
Improvement
Documentation

Help is now built into the app. Open the docs panel from anywhere in the console and it surfaces documentation relevant to the page you’re on, so you get context for what you’re looking at rather than a generic landing page. Searching streams matching doc sections as they’re found, followed by an AI-generated summary that pulls the answer together, with links back to the full docs when you want to go deeper.

Want to see how we built it? Read more about embedded docs and AI-powered search in our blog.

Aug 4, 2026
Live preview for Trust Center colors
Trust Center
Improvement
UX

Trust Center colors now update in a live preview as you change them.

Generate an accessible palette from a base color, adjust any individual color, and copy the result into the console. The preview shows the page as your customers will see it, so you check contrast and fit before you publish.

Aug 2, 2026
Campaigns
Beta
Compliance
Automation
Assessments

Campaigns are available in beta: send an assessment, an attestation, or an email to a set of recipients and track the run in one place.

Build a campaign from a reusable assessment or an email template, send it to employees, vendors, customers, or any recipient list, and follow delivery and responses as they come in. Send reminders from the campaign, and reuse the same campaign for the next annual policy acknowledgment or vendor review instead of rebuilding it.

Read more about Campaigns in the docs.

Jul 24, 2026

The dashboard now opens on the work waiting for you and on what changed across your organization.

Your work collects everything assigned to you in one list: tasks, evidence requests, approvals, and recommendations for your program. Group it by type to clear one kind at a time. Recent activity is a running feed of what happened across the organization, such as policies created, findings detected, and scans completed, so you can follow the program without opening each record.

Jul 23, 2026
Guided onboarding
Improvement
Compliance
Registry

New organizations now start with a guided setup and a set of recommended first tasks.

The setup checklist covers authentication, groups, inviting your team, integrations, and payment. Beside it, recommendations point to the next action for your program: schedule an onboarding call, build your asset registry, start from policy templates, write your first controls, or get matched with an auditor.

A domain scan starts when the organization is created and produces a report a few minutes later with the vendors, assets, systems, and findings it associates with your domain. Review each section, edit what it found, and choose what to import. Nothing enters your Registry until you say so.

Jul 9, 2026

Visitors can now subscribe to your Trust Center and receive updates instead of checking back by hand.

Subscribers are notified when your subprocessor list changes and when you publish a new post. You publish once; the notification goes out on its own.

Jul 1, 2026

SSO enforcement, member provisioning, and support access each gain controls of their own.

You can now exempt specific domains or individual members from SSO enforcement; organization owners continue to bypass SSO by default to support account recovery. With just-in-time provisioning, a member who authenticates through your identity provider is added to the organization without an invitation. Each organization with SSO enabled gets a dedicated SSO URL that members use to sign in directly, and to sign up when provisioning is on.

The members table shows whether SSO applies to each person and, on hover, whether that comes from a domain rule or an individual exemption. Allowed domains now control automatic membership only; they no longer block direct invitations from other domains. If you do not use SSO, we recommend enabling auto invite for your organization’s domains so new colleagues join without a manual invitation; auto invite is not used when SSO is on.

Support access is a switch you control: enable it to let Openlane Support into your organization without inviting individual team members, and disable it at any time. It is off by default.

Jun 29, 2026

The Controls report now shows control coverage across your organization and across each framework.

Switch between the organization view and the framework view to see how your controls map to framework requirements, with owner, approval state, evidence, linked policies, mappings, and related controls in one place. Filter for gaps: controls with no owner, no evidence, unapproved evidence, no linked policy, or no linked organization control.

Jun 24, 2026
Role management
Feature
Auth

Roles now cover more of the ways people work in an organization, from full administration to read-only audit access.

Super Admin is an organization-level role with full administrative access, including user management, billing, and organization settings. Auditor is a read-only role for external auditors and compliance reviewers: they see evidence, controls, and documentation and cannot change any of it, so you grant auditors direct access.

Functional roles scope a member’s permissions to one area of the platform and layer on top of any base role, so you grant access to what someone needs and nothing beyond it.

RoleScope
Campaign ManagerCampaigns, assessments, templates, and email configuration
Compliance ManagerPrograms, controls, evidence, and control mappings
Group ManagerOrganization groups
Policy ManagerPolicies and procedures
Registry ManagerAssets, entities, contacts, platforms, and system details
Risk ManagerRisks, vulnerabilities, findings, and remediations
Workflow ManagerWorkflow automation and task assignment

Read more about roles and authorization in the docs.

Jun 10, 2026
Document integrations
Feature
Integrations
Compliance

Policies can now live in Google Drive or as externally managed files while staying visible in your program.

Sync a policy from Google Drive to get a live, read-only copy that updates when the Drive document changes; editing stays in Drive. Upload a Word document or another externally managed file to view it in place while you keep editing in the tool you already use.

Read more about integrations.

May 1, 2026
Native integrations
Feature
Integrations
Compliance

The first integrations are available: Google Workspace, GitHub, Slack, Google Cloud Security Command Center, and AWS.

Bring provider data into your program, filter it before ingestion so only what matters lands, and attach it to the controls it supports.

Read more about integrations.

Apr 23, 2026

Exposure now creates vulnerabilities and findings from your integrations, adds filters to both lists, and links each record to its scans, reviews, remediations, and controls.

Filter to the findings that matter, see which control governs a remediation and what SLA applies, and follow an exposure from detection to owner to fix without leaving the record.

Apr 2, 2026

Registry now tracks platforms and systems alongside vendors, assets, and personnel.

Link each platform or system to the vendor you buy it from and to the people who can access it, and draw the trust boundary around it. You can then answer which vendors you work with, what you bought from them, where those systems sit in your program, and who has access. The access links are what a user access review draws on.

Mar 18, 2026
Vendor risk scoring
Feature
Compliance
Exposure

Risks now carry a score, a category, and a type, and each vendor carries a risk score of its own.

Score a vendor, answer the questions you have about it (such as whether it holds a SOC 2 report), and assign a responsible party. Import an existing risk register from CSV with column mapping, so a standardized third-party risk process does not start from an empty table.

Mar 4, 2026
Exposure
Feature
Compliance
Exposure

Exposure is available in the console, with views for vulnerabilities, scans, findings, and remediations.

Record a finding, assign its remediation, and link a vulnerability to the controls it affects. This first release covers the records themselves: you create, review, and link them by hand.

Read more about Exposure.

Feb 24, 2026
Registry
Feature
Compliance
Registry

Registry is available: one place to record the vendors, assets, and personnel your program depends on.

Document each vendor relationship, tie assets to the controls and frameworks they fall under, and keep personnel records next to the evidence and assessments that reference them. Scope and ownership live with the record, so a control can point at the system and the people behind it.

Read more about Registry.

Feb 18, 2026
FedRAMP Moderate and ISO 42001
Feature
Compliance
Frameworks

FedRAMP Moderate and ISO 42001 join the supported frameworks.

Map your existing controls to either standard, track the evidence behind them, and run the program alongside the frameworks you already operate. Enable only the frameworks you need and run them in parallel without duplicating controls.

Feb 13, 2026
Assessments
Feature
Compliance
Assessments

Assessments are available: reusable question sets tied to the controls and frameworks they test.

Build an assessment once, assign an owner, and reuse it across audit preparation, vendor reviews, and internal control checks. Responses stay connected to the controls they cover instead of living in a separate spreadsheet.

Feb 3, 2026

You can now generate a draft policy and ask questions about a control from inside your program, with AI producing the draft.

Drafts use your organization’s structure as context and remain editable; nothing becomes a policy until you review and save it.

Feb 2, 2026
Trust Center
Feature
Trust Center

The Trust Center is available: a customer-facing view of your security and compliance posture, published from the records behind it.

Publish policies and supporting documents, show the frameworks you hold attestations or certifications for, and gate sensitive documents behind an NDA flow. Branding matches your organization. The Trust Center runs on its own or alongside the Compliance module.

Read more about the Trust Center.

Dec 3, 2025

You can now define your own status values and categories for the fields that support them.

Match the platform’s vocabulary to the one your organization already uses instead of reshaping your process to fit predefined options.

Nov 19, 2025
Redesigned dashboard
Feature
UI
Compliance

The dashboard you land on after signing in is redesigned around what needs attention.

It surfaces recent activity, open tasks, and the compliance metrics that matter for your program, so you can see where to start without opening each record.

Nov 12, 2025

The Policy Hub is available: a curated set of policy templates you can adapt instead of starting from a blank page.

Pick a template, edit it to match how your organization operates, and adopt it as a policy in your program.

The templates are maintained in the open at github.com/theopenlane/policy-hub, and contributions are welcome.

Nov 11, 2025

Single sign-on now connects to Microsoft Entra ID and to any OpenID Connect (OIDC) provider, alongside GitHub, Google Workspace, Okta, OneLogin, and Slack.

Connect the identity provider your organization already runs and keep authentication and access control in one place.

Oct 28, 2025
Initial release of the Compliance module
Feature
Compliance
Frameworks

The Compliance module is available. It brings controls, programs, evidence, framework mapping, and organizational scoping into one connected system.

Define the controls your organization operates, group them into programs, attach the evidence that shows each control working, and map one control to every framework that shares the requirement. SOC 2, HIPAA, PCI DSS, ISO 27001, NIST CSF, NIST 800-53, and GDPR are supported at launch, so one program can carry several standards without duplicated controls.

The module runs on the platform’s existing identity and access layer: SSO with MFA enforcement, passkeys and social login, fine-grained permissions, and group-based access.