Note: These features, updates, and addressed issues are released first in Hyperproof US and Hyperproof EU on the date noted in the title. They are released in Hyperproof Gov one week later unless otherwise noted.
Improved
Audit request status updates
External auditors have more flexibility to manage requests directly, without needing the auditee to step in:
Auditors can now close requests, including requests where evidence was shared offline rather than uploaded in Hyperproof. Previously, only the auditee could close these.
Approved requests can be reopened by setting the status to Needs Revision. If a mistake is found or new information comes in after the request is marked Approved, the auditor can edit it directly to Needs Revision instead of asking the auditee to change the status.
Repeating tasks
Users can now clear due dates for repeating tasks, both individually and in bulk, by clearing the days later field.
Tasks
Import and export tasks linked to policies. The import wizard accurately displays all supported object types that can be linked to tasks during task import.
Assign integrated tasks directly to Jira users and groups. We're continuing to gradually roll out the capability to assign tasks directly to individuals or groups in Jira, with no Hyperproof user mapping required. Hyperproof automatically pulls in your users and groups, and assignments are clearly marked as external in the Grid View.
Note: This functionality was released for ServiceNow in the most recent release. Hyperproof is continuing to roll it out for Jira task integrations. It may not be available in your organization immediately, but it will be available soon with no action required on your part.
Integrations
Hypersync SDK
Hypersync SDK version 7.0.1 is now available. This update consists of non-breaking security updates and package dependency modernizations. While existing apps will continue to function normally, we recommend upgrading via the Hyperproof Developer Portal at your earliest convenience to keep your integrations secure. (Case # 00012481)
Download the update and find the full details on the Hyperproof Developer Portal: Hypersync V7 SDK Migration.
Hyperproof API
This release brings the audit lifecycle to the Hyperproof API, letting teams automate compliance work end-to-end instead of managing it manually in the UI. Audits give you an overview, including an engagement's timeline, health, and statistics, while Requests let you drill into the evidence work driving those numbers.
Audits API
With this release, you can:
Create, clone, update, and archive audits
Comment on an audit's activity feed
Retrieve an audit's linked controls, deduplicated across its requests
Pull health scores, statistics, and item counts — org-wide or per-audit
Configure the timeline stages used to compute health
Requires audit.read/audit.update.
Requests API
We added a new API for managing evidence requests within an audit addressed directly by ID rather than nested under their parent audit.
With this release, you can:
List, filter, create, and update requests
Comment on a request's activity feed
Link proof, controls, and labels to a request
Expand a request's related controls, labels, and proof in the same call
Requires request.read/request.update, or proof.update for linking proof.
Hypersyncs and proof types
Updated! Hypersync for BitBucket List of Commits proof type - Added the branch field to the proof and as a filter, and included the project name instead of the GUID. Hyperproof SDK update.
Updated! Hypersync for Azure: Resource group filtering settings now support selecting All resource groups for the following proof types:
Azure Database for PostgreSQL Flexible Server: Minimum TLS Version
Azure Database for MySQL Server: Minimum TLS Version
Key Vault: Firewalls and Virtual Networks
Recovery Services: List of Backup Jobs
Recovery Services: List of Backup Policies
Addressed issues
Fixed an issue where contacts assigned to assessment requests as part of a group were receiving assignment notifications. Contacts can't be assigned directly to requests and shouldn't receive notifications for requests. (Case # 00011427)
Fixed an issue in repeating tasks where integration configurations became hidden and could not be removed after the parent integration instance was deleted in the organization. (Case # 00011815)
Fixed an issue in the Proof module where proof files exported from vendor questionnaire responses were downloaded as unformatted files rather than PDFs. (Case # 00012396)
Fixed an issue in request activity feeds where pasting content into the comment field while using the Firefox browser caused an application error. (Case # 00012438)
Fixed an issue across multiple modules, including Risks, Requests, Evaluations, Vendors, Issues, and Labels, where exported CSV files omitted assigned members' data. (Case # 00012498)
Note: To ensure members' data is included, you must use the Settings option to turn on the Members column in the Grid view for Hyperproof objects that don't include it by default. See the export documentation in the Help Center for a detailed list of exported fields.Fixed an issue in the Hypersync for AWS List of DB Snapshots proof type, where the proof type was not visible when selecting Aurora PostgreSQL database types. (Case # 00012542)
Fixed an issue in the Jira Task integration where searching for existing Jira issues failed when linking a task if a mapped Jira project key matched a reserved JQL keyword (such as AUDIT). (Case # 00012551)
Fixed an issue in the Requests module where archived requests remained visible in Card view when active record filters were applied. (Case # 00012559)
Fixed an issue in the Reassign Work module where the user assignment dropdown lacked search functionality. (Case # 00012560)
Fixed an issue in the Audits module where users were unable to resize column widths in the grid view. (Case # 00012561)
.. plus other fit and finish, performance, stability, and security issues — as always!
