Product Updates

What's new in Fortify

New features, improvements, and changes — most recent first.

September 2026

Trust Center

Portal

A public page you can link from your own website, showing your security and compliance posture to customers and prospects — available on every plan. Choose what to show from six sections: Security Overview, Compliance & Certifications (with optional certificate upload), Vulnerability Disclosure (with a security.txt reference), Product Security, Privacy & Data Protection, and Security Contact Details — plus your own custom sections. Nothing appears until you turn it on. AI Guidance can draft a first version grounded in your actual published policies, certifications, and vendors, for you to review and edit. Strategic adds your own logo and colours; Advanced adds your own domain, e.g. trust.yourcompany.com.

Business Continuity Planning (BCP)

Assessments

A new free assessment checks whether your business has a real continuity plan — written ownership, recovery objectives, and tested backups — with the same scored report as our other free assessments. Inside the portal, Business Continuity is now a full framework audit alongside Cyber Essentials Plus, ISO 27001, NHS DSPT, and DORA. And if you’re starting from nothing, the new Continuity Builder asks a few plain-English questions about your business and its critical dependencies, then generates a realistic first-draft plan for you to edit — no RTO/RPO jargon required.

Change Requests

Portal

Track proposed changes to your systems and processes with a formal approval workflow — draft, submit for approval, approve or reject, then mark implemented. Every change request appears in the Action Hub alongside your findings, roadmap, and risks, and keeps a full approval history for auditors.

Audits: see exactly what’s included in your plan

Portal

The Audits page now shows a clear "x of N audits used" indicator based on your subscription tier — 1 on Essential, 2 on Strategic, all frameworks on Advanced. Activating a framework audit no longer requires a separate subscription; it simply uses one of your included slots for a 12-month period.

Automatic risk review reminders

Portal

Every risk in your Risk Register now gets a next-review date, calculated automatically from its rating — high risks every 3 months, medium every 6, low every 12. Mark a risk reviewed to reset the clock, and upcoming or overdue reviews now appear on your Compliance Calendar.

Internal Audits: clearer findings and evidence

ISO 27001

The Internal Audits AI assistant is now clearly labelled as an AI assistant rather than a named auditor persona. You can now attach evidence files to any audit item, and each conversation-based item automatically extracts a structured breakdown of findings by area — both now included in your generated audit report.

Startup Toolkit: tailored to your business

Portal

Answer four quick questions about your team size, industry, budget, and working style, and the Startup Toolkit reorders its recommendations to highlight the best fit — nothing is ever hidden, just prioritised. Each tool option now shows a monthly cost, checklist items link to a relevant how-to guide, and you can add any item straight to your roadmap in one click.

Incident Playbooks: full library added

Incidents

Every incident type now has a ready-made response playbook — 14 in total, covering ransomware, phishing, business email compromise, data breaches, supplier breaches, system outages, and more. Attach the relevant playbook to an incident the moment it’s logged.

August 2026

Compliance Calendar

ISO 27001

A unified compliance calendar that pulls every important deadline into one view — certification milestones, policy reviews, internal audits, agreement expiries, security goal deadlines, leadership reviews, and the annual DSPT submission. An ISO 27001 wizard lets you enter a single Stage 2 certification date and automatically creates all five linked milestones (Stage 2, two surveillance audits, recertification window, and certificate expiry). Events are grouped by urgency — overdue, this week, this month, next 3 months, and later. A 12-month timeline strip on the calendar page shows coloured dots across each month so you can see density at a glance.

Calendar reminders & iCal subscribe

Portal

Receive email reminders when a compliance event becomes overdue or when a configured reminder window (default 90, 30, and 7 days before) is reached. Subscribe to your compliance calendar from any calendar app — Apple Calendar, Google Calendar, or Outlook — using a personal subscribe URL that updates automatically as events change.

Advisor compliance calendar

Portal

Advisors managing multiple client organisations can now view all compliance events across their entire client portfolio in one place. Filter by client, priority, or event type. Each event card shows the client name and links directly to that client's calendar — giving advisors a single dashboard to spot overdue items or upcoming deadlines across all their accounts.

AI & Privacy controls

AI

Three new controls let you manage what data is shared with AI. Set an AI pseudonym for your organisation — a placeholder name used in all AI processing instead of your real company name. When logging incidents, a guide encourages using initials to avoid sending names to AI, with a private reference field (never sent to AI) to record who the initials belong to. When uploading legal agreements for AI analysis, a consent checkpoint explains exactly what will be sent before you proceed.

AI & Privacy transparency page

AI

A new page at /ai explains what data is — and is not — sent to AI for each feature, the safeguards in place, your privacy controls, and how Fortify complies with UK and EU AI regulation. Linked from the home page footer and portal navigation.

Ask Alex: AI identity disclosure

AI

Ask Alex now clearly identifies itself as an AI assistant with a visible AI badge. A persistent disclosure strip above every conversation confirms you are interacting with an AI, not a human. This meets the transparency requirements of EU AI Act Article 50(1), which comes into force in August 2026.

Plain language throughout the portal

Portal

All specialist compliance and GRC terminology has been replaced with plain English. "CAPA" is now "follow-up action", "Nonconformity" is "Compliance Issue", "Treatment" is "Response", "Management Review" is "Leadership Review", "Audit Programme" is "Internal Audits", and "IS Objectives" are "Security Goals". The portal now speaks the same language as the people using it — no compliance background required.

First-visit guidance banners

Portal

Every section of the portal now shows a dismissable banner the first time you visit it. Each banner explains what the section is for, who should use it, and why it matters — so you never have to guess where to start. Once dismissed it won't appear again.

Vendor library: multi-product consolidation

Supply Chain

Microsoft and Google products (Microsoft 365, Microsoft Azure, Google Drive, Google Workspace, etc.) are now grouped under a single vendor entry with individual product listings. This gives a cleaner risk picture and makes it easier to manage contract and certification status at the vendor level.

July 2026

Supply Chain Reports

Supply Chain

Generate structured compliance exports at any time — a Vendor Risk Register, a DORA ICT Third-Party Register, and a GDPR Article 30 ROPA. All three pull directly from your live vendor data and are in the exact formats that auditors and regulators ask for.

CVE threat monitoring

Supply Chain

Fortify now monitors your vendor software stack daily for publicly disclosed security vulnerabilities (CVEs). Each vulnerability appears in the Threats section with AI-generated impact analysis specific to your organisation. Triage decisions (patch, accept, or not applicable) are logged for audit purposes.

Agreements & Contract Intelligence

Portal

Upload or generate NDAs, DPAs, MSAs, and other contracts. Fortify extracts the key terms automatically and flags agreements expiring within 90 days. A complete contract register is required for ISO 27001 and GDPR compliance.

June 2026

ISO 27001 internal audit framework

ISO 27001

A guided audit workflow covering all 93 ISO 27001 controls. Walk through each control, record your response, and upload evidence. The audit automatically feeds your Statement of Applicability (SoA) and Compliance Health dashboard.

Leadership Reviews

ISO 27001

Create and record formal leadership reviews of your security programme — covering performance, risks, and planned improvements. Each review record constitutes the evidence required for an external ISO 27001 auditor.

Security Goals (IS Objectives)

ISO 27001

Set measurable security goals with target metrics and deadlines. Track progress month-by-month and link goals to roadmap actions. Auditors look for evidence of planned, tracked improvement — this is where you build that record.

May 2026

Staff training with AI-generated microlessons

AI

Create security awareness training courses for your team. Each lesson is generated by AI from a topic prompt, covers practical guidance, and includes a short quiz. Fortify tracks completion per learner automatically. Required for ISO 27001 and UK GDPR compliance.

Compliance Health dashboard

Portal

A live dashboard showing how your security programme is performing across key metrics — findings, incidents, compliance issues, risks, policies, and ISO 27001 controls. Each card tells you what it means and what to do when something needs attention.

Vendor questionnaires

Supply Chain

Send security questionnaires to vendors directly from the platform. Responses are scored and feed into your overall vendor risk picture.

April 2026

Incident playbooks

Incidents

Build step-by-step response playbooks for each incident type — data breach, phishing, ransomware, system outage, and more. Attach playbooks to incidents as they occur so your team always has a clear procedure to follow.

Quarterly Review PDF

Assessments

Generate a PDF snapshot of your security progress — resilience score trends, roadmap completion, evidence uploaded, and open findings. Designed for board reporting, investor due diligence, and annual compliance sign-off.

AI response advisory (Scout)

AI

When logging an incident, Fortify's AI suggests immediate containment steps, probable root causes, and recommended follow-up actions based on the incident type and your existing programme. Available on Pro and Annual plans.

Have a feature request or found something that needs fixing?

Go to the portal →