Explore the latest updates in Scytale’s AI GRC platform – Smarter Scy, AI Questionnaires, ROPA, AI TPRM, and more.
New York, NY, July 28, 2026
This quarter’s platform updates are all about helping security, risk, and compliance teams operate more efficiently at scale. With smarter automation, stronger risk management, simplified policy creation, and expanded AI capabilities, Scytale gives your organization greater visibility, consistency, and control across your GRC program.
Alongside new integrations and broader framework support, these updates help reduce manual effort, strengthen operational resilience, and keep your organization continuously audit-ready.
Here’s what’s new in our AI GRC platform:
Scy just got smarter
Meet Scy’s new dedicated homepage, your AI command center for compliance. Scy now knows your workspace, so you can ask anything, from what to tackle next to which employees still need to complete policies or training. A dedicated homepage and full-screen chat interface bring Scy’s intelligence to life, making it the most powerful way to stay on top of your compliance program.

One-click policy generation with Scy
With one click, Scy generates a fully compliant policy tailored to your unique needs, so you can produce audit-ready documentation even faster.

AI security questionnaires
Our new and enhanced Security Questionnaires feature lets you upload questionnaires from prospects or partners and get them automatically completed using AI, based on your existing compliance data.

ROPA, built right into Scytale
Build your Record of Processing Activities directly in the platform: add activities, select from pre-defined values so there’s no guesswork, and submit to the Scytale privacy team for review and approval.

AI-powered vendor risk management
Scytale’s new TPRM module automatically discovers every vendor in your stack and builds a complete risk profile using AI, pulling in certifications, security posture, known incidents, and more, to generate a risk score without any manual work. Send questionnaires directly to vendors, track responses in real time, and let AI flag the risks that matter most.

Simplified Trust Center publishing
Publishing your Trust Center just got easier. A refreshed publish flow guides you step by step through connecting your custom domain, with a cleaner, more intuitive experience from start to finish.

Submit URLs as evidence
You can now submit a URL directly as evidence, perfect for online sources like release notes, vendor terms, or legal commitments. The link is saved as clickable evidence, giving auditors easy, direct access to the source.
TISAX training
TISAX (Trusted Information Security Assessment Exchange) training is now available directly in Scytale, helping your team build the knowledge needed to meet TISAX requirements.
Coming soon: new risk hub
We’ve revamped Risk Management to give you more control and clarity over your risk registry. Each risk will get its own dedicated page with a visual heatmap, helping you choose the best strategy for how to handle it.
Enterprise customers can get access to advanced dashboards and customizations that align with their organization’s methodology.
New integrations for greater flexibility and automation
We’ve added new integrations to give you more automation, flexibility, and power in managing your security and compliance stack.

New automated tests in SOC 2
We’ve added new automated tests to our SOC 2 compliance automation, expanding coverage and cutting manual work even further. Newly automated evidence includes: employee performance evaluation records, support ticket population, credentials forbidden in released code, remote wipe/lock capability, alert configuration from EDR/malware protection tools, production uptime reports, customer support communication channels, and internal asset wiping.
A smarter Jira integration for compliance teams
Tickets now sync automatically between Jira and Scytale, so when engineers update a ticket on their end, Scytale reflects it instantly. You can also link existing Jira tickets, set assignees and priority on creation, connect multiple projects, and do it all with minimal permissions.
Expanded compliance framework coverage
Scytale now supports CRA, NIST 800-53 High Baseline, CBI IT Risk Thematic Review, NEN 7510, Joint Standard 1, and Joint Standard 2, so you can expand into new frameworks while maintaining consistency, control, and audit readiness as you grow.
Always-on GRC. Built for modern teams.
As we continue advancing our AI GRC platform, you can expect ongoing updates that help your team move faster and stay compliant at every stage.
To see how organizations are achieving real results, explore our customer stories and learn how teams, from startups to enterprises, are scaling compliance faster with greater control and visibility using Scytale.
