

We have introduced severity-based filtering for Vendor Risk, Breach Risk and User Risk risk profiles. Users can now filter risks by Critical, High, Medium, or Low severity directly from the sidebar or by clicking on summary widgets, streamlining triage and allowing faster focus on the most critical issues. Filtered severity selections will also carry through to exported risk profile PDF and XLSX reports.
Extended audit log filtering
We've increased the maximum date range for audit log filtering from 30 days to 18 months, with the default view now set to 90 days. This update gives customers greater flexibility for investigating past activities and meeting compliance needs. As always, the Audit Log export feature remains unlimited, allowing you to download your entire historical log at any time.
Vendor Onboarding Portal (Beta) updates
We’ve introduced several new features to streamline the workflow and improve collaboration:
- Add collaborators: Add teammates to contribute directly to onboarding requests.
- Resend capability
- Exports: Full request list and individual form responses
- Email notifications: Stay informed with automated email alerts whenever a new request is submitted.
- Enhanced List View: Main dashboard improvements, including a new "Filter by Request Status" option.
The Vendor Onboarding portal gives eligible organizations a dedicated web form where business users can proactively submit vendor assessment requests, in addition to the existing functionality which allows you to send outbound requests. To learn more, explore the Vendor onboarding portal overview and talk to your UpGuard representative about joining the beta program.
2026 SIG Core & Lite questionnaire updates
We have updated our questionnaire library to include the 2026 SIG Core and Lite questionnaires. This release replaces the 2025 versions, ensuring your assessments reflect the most recent security controls and risk vectors.
Enhancement to add comments to individual risks in remediation requests
To enhance traceability and collaboration we’ve added the ability to add comments at a risk level (rather than a request level) in remediation requests for both Vendor Risk and Breach Risk.
Enhanced social media threat detection
We’ve expanded Threat Monitoring’s social media capabilities to include LinkedIn and Reddit. Customers can now detect potential data leaks, impersonation attempts, and emerging risks across an even wider set of platforms, strengthening visibility into their organization’s digital footprint.
Custom document ordering in Trust Center
We have introduced the ability to manually reorder documents and questionnaires within Trust Centers using a simple drag-and-drop interface. This feature allows Trust Center owners to prioritize critical assets such as security policies or SOC 2 reports at the top of the list, ensuring viewers can find high-value information instantly.






.png)