at Openlane
Customize your Trust Center in real time with live color themes.
Your Trust Center should feel like an extension of your brand, not another generic portal.
We’ve made customization much easier with a new live color generator and real-time preview. Use our accessible color palette generator to instantly create a cohesive theme, fine-tune every color if you want complete control, and copy the generated palette directly into the Console.
As you make changes, you’ll immediately see exactly what your customers will see, making it faster than ever to create a Trust Center that matches your brand while maintaining a polished, accessible experience.
Don’t have a Trust Center yet? Start your free 30-day trial and customize your own Trust Center in minutes.
Automate recurring questionnaires and emails with Campaigns.
Security and compliance teams send the same requests over and over: policy acknowledgments, vendor risk assessments, employee attestations, onboarding forms, and more. Campaigns brings all of that into Openlane.
Create reusable campaigns that send configurable emails or questionnaires to employees, vendors, customers, or any other recipients. Track delivery and responses in one place, send reminders with a click, and standardize recurring workflows instead of rebuilding them every time.
Whether you’re collecting annual policy signoffs, running vendor security reviews, onboarding new employees, or requesting information from internal teams, Campaigns keeps the entire process organized and connected to your compliance program.
Learn more about Campaigns in the Openlane docs.
The dashboard is now a real starting point for your day rather than a landing page you click past.
Your Work: Everything waiting on you is collected in one place, including tasks that need your attention, evidence requests, approvals you need to sign off on, and recommendations for your program. Group the list by type or kind to focus on whatever you want to clear first.
Recent Activity: A running feed of what is happening across your organization, such as policies created, findings detected, and scans completed, so you can see how your program is moving without digging through individual records.
Getting started in Openlane now takes less guesswork. New organizations land on a guided setup flow paired with recommended tasks tailored to where you are in your compliance journey.
Guided setup: A checklist walks you through the essentials: authentication, groups, inviting your team, integrations, and payment. Alongside it, recommendations surface the next best actions for your program, such as scheduling an onboarding call, building out your asset registry, starting from policy templates, writing your first controls, or getting matched with an auditor.
Automatic discovery: A domain scan kicks off when your organization is created, and a report is ready a few minutes later. It identifies the vendors, assets, systems, and findings associated with your domain so you don’t have to enter them by hand. Review what we found, edit each section, and choose exactly what gets imported into Openlane. Nothing is added without your say-so.
Together, these give you a populated, meaningful workspace on day one instead of an empty one.
Your customers can now subscribe to updates from your Trust Center, so they no longer have to check back manually to stay current on your security and compliance posture.
Subscribers can be automatically notified about subprocessor changes and new posts, keeping them informed as your program evolves without any extra work on your end.
This makes it easier to keep customers, prospects, and auditors in the loop, and reinforces the Trust Center as a living source of truth rather than a static snapshot.
We’ve expanded SSO and organization access controls to give teams more flexibility when managing authentication, provisioning, and support access in Openlane.
Expanded SSO Controls — Organizations can now exempt specific domains or individual users from SSO enforcement. Organization owners continue to bypass SSO by default to support account recovery.
Just-in-Time Provisioning — SSO can now be used to automatically provision new organization members when they authenticate through your identity provider. This makes it easier to onboard users without manually inviting each person ahead of time.
Dedicated SSO URL — When SSO is enabled, your organization now gets a dedicated SSO URL that members can use to authenticate directly into your organization. If automatic provisioning is enabled, new members can also use this URL to sign up and be added to the organization.
SSO Enforcement Visibility — The members table now includes SSO enforcement details when SSO enforcement is enabled. You can see whether SSO applies to each user, and hover for additional context such as whether enforcement is based on domain rules or user-level exemptions.
Allowed Domains Update — Allowed Domains now only control automatic organization membership and no longer prevent you from directly inviting users from other domains. If you’re not using SSO, we recommend enabling Auto Invite for your organization’s domains. Auto Invite is not used when SSO is enabled.
Support Access — You can now enable or disable Openlane Support access to your organization without inviting individual Openlane team members. Support access is disabled by default, giving you full control over when Openlane can access your organization.
We’ve updated the Controls report to make it easier to understand control coverage across your organization and frameworks.
You can now switch between organization control and framework views, making it easier to see how your internal controls map to framework requirements. The report also shows key details like owners, approval status, evidence, linked policies, framework mappings, and related organization controls in one place.
We’ve also added report filters to help you quickly identify gaps, including controls with no owner, no evidence, evidence in a non-approved state, no linked policies, or no linked organization controls.
These updates make it easier to navigate your controls, assign ownership, track evidence, and understand where your compliance program is complete or needs attention.
We’ve expanded role management to give organizations more precise control over what each user can see and do in Openlane.
Super Admin — A new organization-level role with full administrative access, including user management, billing, and organization settings. Designed for owners who need unrestricted access across the platform.
Auditor — A read-only role built for external auditors and compliance reviewers. Auditors can view evidence, controls, and documentation without the ability to make changes — keeping your audit process clean and your data intact.
Functional Roles — In addition to base organization roles, users can now be granted functional roles that scope their permissions to a specific area of the platform. Available roles include:
- Campaign Manager — Manage campaigns, assessments, templates, and email configuration
- Compliance Manager — Manage compliance programs, controls, evidence, and mapped controls
- Group Manager — Manage organization groups
- Policy Manager — Manage all policies and procedures
- Registry Manager — Manage assets, entities, contacts, platforms, and system details
- Risk Manager — Manage risks, vulnerabilities, findings, and remediation
- Workflow Manager — Manage workflow automation and task assignment
Functional roles can be layered on top of any base organization role, letting you give team members access to exactly what they need without over-provisioning.
Learn more about roles and authorization in the Openlane docs.
We’re expanding document management options to give teams more flexibility in how they store and maintain their compliance policies.
Google Drive — Sync policies directly from Google Drive for a live, read-only view in Openlane while continuing to manage edits natively in Drive. Changes in Drive are reflected automatically, keeping your policies always up to date without duplicating work.
Externally managed documents — Upload Word Documents and other externally managed files to view them directly in Openlane while retaining full editing control in the native editor of your choice.
Learn more about integrations in Openlane.
We’ve released the first set of integrations for Openlane, including support for Google Workspace, GitHub, Slack, GCP Security Command Center (SCC), and AWS.
Compliance automation only works when it reflects how teams actually operate. These integrations help bring operational data directly into your compliance program with the ability to filter out noise, focus on what matters, and turn real system context into usable evidence alongside the processes teams already rely on today.
This release is the foundation for a growing integrations ecosystem, with more providers and deeper workflows already on the way.
Learn more about integrations in Openlane.
Openlane’s Exposure features now have better vulnerability and findings filters, Integrations that provide automated vulnerability and findings creation, and deeper relationships between vulnerabilities, scans, reviews, remediations, and controls.
Openlane now provides a more holistic end to end lifecycle of what risks and exposures exist, who owns them, how they’ll be remediated, what control(s) dictate those remediations, and what SLA is applied.
Openlane’s Registry capability was expanded with new platform and system-detail objects and relationships, which allow for trust boundary definitions and association to personnel for future user access reviews and centralized system access tracking. Entities (Vendors) can be associated to platforms and systems easily, adding an additional layer of visibility surrounding what vendors you work with, what you’ve bought from them, how those systems exist in your compliance landscape, and who can access them.
Openlane’s risk workflows now include additional risk fields, risk categories and types, CSV mapping support, responsible-party improvements, and vendor risk scoring capabilities. These allow the questions you have about your vendors (like “do they have a SOC2?”) to be easily answered, and for you to standardize how you deal with Third Party Risk Management.
Openlane now includes a new Exposure section in the console with foundational screens for Vulnerabilities, Scans, Findings, and Remediations.
This section establishes the foundation for centralized visibility into security exposures across integrated systems. Teams will be able to review findings, track remediation activity, and connect vulnerabilities to their broader compliance program.
Openlane now includes a unified Registry for tracking vendors, assets, and personnel.
The Registry provides a centralized source of truth for the entities that power your compliance program. Teams can document vendor relationships, associate assets with controls and frameworks, and manage personnel records, all directly connected to evidence and assessments within Openlane.
By linking vendors, systems, and people to your controls and workflows, the registry reduces duplication, improves visibility, and ensures your compliance program reflects how your organization actually operates.
Openlane now supports additional compliance frameworks: FedRAMP Moderate and ISO 42001.
Organizations operating in regulated or AI-governed environments can now map controls, track evidence, and structure programs aligned to these standards directly within Openlane.
Framework support remains modular — teams can enable only what they need and manage multiple frameworks in parallel without duplicating work.
Assessments are now available in Openlane.
Teams can create structured assessments tied to controls and frameworks, assign ownership, collect responses, and track progress over time.
Assessments help operationalize compliance work - whether you’re preparing for an audit, reviewing vendor risk, or validating internal controls. Responses are connected directly to your program, reducing duplicate work and improving visibility across stakeholders.
Today we’re launching the Openlane Trust Center.
The Trust Center gives organizations a structured, customer-facing view of their security and compliance posture. Teams can publish policies and supporting documentation, display framework attestations, and share materials with confidence.
This release includes:
- NDA-gated document access flows
- Customizable branding to match your organization
- Framework attestation displays for supported standards
The Trust Center is modular by design. Use it on its own, pair it with the Compliance Module, or integrate it into your existing workflows.
Trust should reflect real work — not static PDFs.
We’re launching Openlane’s first AI-powered workflows.
Teams can now generate draft policies and get information about controls directly within their compliance program. The goal isn’t to replace expertise and customization, it’s to remove the friction of starting from a blank page and help first-time users with a good starting point.
AI-generated content is contextual to your organization’s structure and always editable, giving you a strong starting point without sacrificing control.
Organizations can now define custom enum values across supported fields in Openlane.
This allows teams to configure status values, categories, and other structured fields to match how they already operate — without reshaping internal processes to fit predefined options.
Openlane is built to adapt to your program, not the other way around.
We’ve redesigned the Openlane homepage to give users immediate clarity when they log in.
The new experience surfaces relevant activity, open tasks, and key compliance metrics so teams can quickly see what needs attention.
The goal is simple: reduce friction and make compliance work easier to navigate.
We’re introducing the Openlane Policy Hub — a curated collection of vetted policy templates designed to help teams move faster.
Instead of starting from a blank page, organizations can now begin with practical, real-world policy foundations and adapt them to their environment.
The templates are maintained openly at https://github.com/theopenlane/policy-hub and are built to be improved collaboratively over time.
We’ve expanded Single Sign-On (SSO) support in Openlane.
In addition to existing providers — GitHub, Google Workspace, Okta, OneLogin, and Slack — organizations can now connect Microsoft Entra ID or any Generic OIDC provider.
This gives teams more flexibility to integrate Openlane with their existing identity infrastructure while maintaining centralized authentication and access controls.
Today we’re launching the Openlane Compliance Module — the foundation for building and managing a structured, sustainable compliance program.
This release introduces controls, programs, evidence tracking, framework mapping, and organizational scoping. Openlane now supports SOC 2, HIPAA, PCI DSS, ISO 27001, NIST CSF, NIST 800-53, and GDPR, allowing teams to manage one or multiple frameworks in a single, connected system without duplicating work.
The Compliance Module is built on top of Openlane’s core security and identity architecture, including:
- Authentication via SSO, social login, passkeys, and traditional credentials
- Support for SSO integrations and MFA enforcement
- Fine-grained permissions
- Group-based access controls
- and more
Compliance is ongoing work, not a point-in-time report, and this module is designed to support the real structure behind your program.