Changelog
What we are building and shipping — one update at a time.
July 2026
July 12, 2026
The assistant now leads with your context
- When you open the cajeX assistant with something on screen — a finding, project, application, diagram, framework, or any other view — its suggested prompts are now about that object: "What is blocking closure?" on a project, "Are the security zones sound?" on a diagram, "Which of our directives implement it?" on a framework.
- Switch to a different object mid-conversation and the assistant offers that object's questions once, dismissibly, without interrupting your chat.
July 11, 2026
Smarter review scope and a guided document handover
- AI reviews now default to a seeded scope: the directives you've linked to the project or application — plus, for applications, the directives of every framework whose applicability matches it. The trigger dialog shows exactly where the scope came from and lets you switch to any other scope; nothing is decided for you silently.
- Completing a project now offers a document handover when it has linked applications: promote current-state documentation (architecture, runbooks, interface catalogs) to the delivered application, keep change documentation on the project. Ask AI to suggest destinations — each suggestion comes with a reason, and nothing moves without your confirmation. Always skippable.
July 11, 2026
The assistant now knows your whole workspace, not just what's open
- Ask the cajeX assistant to recommend frameworks, summarize your posture, or list your applications — from any screen. It now grounds on your live workspace data (the frameworks catalogue, dashboard totals, applications, scheduled sessions, recent documents, reports, and — for admins — members and plan), not only the single record you happen to have open.
- Framework recommendations are ranked to your question: ask for "AI governance" frameworks and it surfaces the ones that actually apply, out of the hundreds in the catalogue, and tells you which are already enabled for your workspace.
- Everything stays read-only and access-aware: the assistant only sees data you can access (confidential projects are respected, and members/plan details are admin-only), and it never changes anything without your explicit confirmation.
July 11, 2026
Park a diagram, keep working: diagram sessions in the top bar
- Minimize the diagram editor and keep working anywhere in cajeX — the diagram stays open with its full undo history, and a chip in the top bar brings it back with one click.
- Park up to three diagrams at once: the chip becomes a dropdown showing each file with its project or application and an unsaved-changes indicator.
- Opening a diagram that's already parked returns you to the live session instead of opening a copy.
July 11, 2026
Diagram XML source view with two-way selection sync
- A new Split toggle in the diagram editor opens the XML source beside the canvas — bulk-edit properties, paste fragments between diagrams, or inspect exactly what a shape carries.
- Canvas and XML stay in sync in both directions, and selection follows you both ways: click a shape to jump to its XML, click in the XML to select the shape. Invalid XML never touches the canvas.
July 11, 2026
Diagrams grow up: application architecture, versions, and review-aware drawings
- Diagrams now attach to applications as well as projects (where the Applications feature is enabled): keep the current-state architecture on the application's Documents tab, where it outlives any single project.
- Save as version stores your canvas as a milestone — earlier versions stay in the document's Version History while lists always show the latest.
- Saved diagrams now inform AI reviews and global search: cajeX distills each diagram's components, properties, and connections into text that flows into project and application review context — draw the architecture accurately and reviews can reason about it.
July 11, 2026
The assistant can now edit your diagrams
- With a diagram open in the editor, ask the cajeX assistant to change it — "add a firewall between the web tier and the database", "re-route the integration through the DMZ" — and it proposes the edit as a confirmable card, with your live (even unsaved) canvas as its starting point.
- Confirm applies the change to the open editor only: review it on the canvas, undo if it's not right, and Save when it is. The assistant never saves a diagram itself, and every applied edit is captured by your local draft immediately.
- Works in workspaces with both the Diagrams feature and the assistant enabled.
July 11, 2026
Diagrams: draw architecture where it's governed
- New optional feature: draw and maintain architecture diagrams inside cajeX with a built-in draw.io editor — self-hosted by cajeX, so diagram content never leaves the platform. Enable it under Settings → Features → Diagrams.
- A diagram is a regular project document (a .drawio file): create one from the project's Documents section with New Diagram, open any existing .drawio document in the editor with one click, and download, rename, version, or delete it like any other document.
- The editor includes cajeX shape libraries for enterprise and manufacturing architecture (ISA-95 functional levels, security zones) alongside the standard draw.io shapes.
- Your work is protected twice over: cajeX keeps a continuous local draft on your device (with a Restore-draft offer if you close without saving), and a conflict check stops teammates from silently overwriting each other — if someone saved first, you choose between loading their version or overwriting with yours.
July 10, 2026
Application AI Review: audit the asset, not just the change
- AI Review now comes in two flavors sharing one engine: Project AI Review evaluates the documents of a change, and the new Application AI Review evaluates an application's current documented state — its living documents plus its accepted architecture decisions (ADRs). Run it from the application's new AI Review tab.
- Application reviews respect your decision record: a deviation already captured in an accepted ADR is treated as a known, governed exception — referenced, not re-flagged — unless its documented scope has been exceeded.
- The review scopes to the application's linked directives from the Posture tab by default (falling back to all approved directives), and its findings land on the application's own risk register.
- Application windows also got a polish pass: properly spaced header actions, consistent design tokens throughout, and the owner field now shows a name instead of a raw identifier.
July 10, 2026
Findings that outlive the project: transfer them to an application
- The cajeX assistant now handles applications too (when the feature is enabled): ask it to register an application, link one to the project you have open, or draft an ADR for a linked application — each lands as a proposal card you review and confirm, like every other assistant action. In workspaces without the feature, the assistant explains how an owner can enable it instead of pointing at screens that aren't there.
- Let AI draft your application registry: from a project (or the Applications screen), cajeX reads the project's description and documents and proposes the applications it builds or changes — classified, rationale included, and de-duplicated against your existing registry. Every proposal is a draft you review and confirm; nothing is saved until you accept.
- Every application now has a Posture tab: which of your enabled frameworks apply to this application — with every match explained against its data classification, criticality, and tags, never imposed — plus the directives you've linked to it, their decision (ADR) relations, the open risk register, and the evidence behind it all. Browse an applicable framework's directives and link the relevant ones in place.
- Applications now carry Architecture Decision Records: capture the context, decision, and consequences of significant technical choices as numbered, markdown ADRs on the application — proposed, accepted, superseded, or deprecated, with the chain kept visible.
- Link an ADR to your directives with a stated relation: complies, or deviates with a mandatory justification. Accepting a deviating ADR automatically raises a finding on the application's risk register — a deviation becomes a tracked exception you can review, accept, or plan away, not a note buried in a document. If the ADR is later superseded, its exceptions are flagged for re-evaluation.
- Findings can now live on an application, not just a project (when the optional Applications feature is enabled). Enduring risks — tech debt, accepted risks, unresolved non-conformities — get transferred to the delivered application instead of dying in a completed project's archive. Each application's Findings tab becomes its standing risk register.
- Projects now have a completion gate: a project can't be marked Completed while findings are still open. Close, reject, or defer each one — or transfer it to one of the project's applications — so nothing falls through the cracks at handover.
- Transferred findings keep their full history, including which project they came from. Confidential findings stay within their project — they can't be transferred where project access controls wouldn't follow.
- You can also raise a finding directly on an application, for risks that belong to the asset rather than to any change.
July 9, 2026
Applications: give your projects a durable home for governance
- Adds Applications — an optional feature a workspace owner or admin can switch on under Settings → Features: register the IT applications your projects build or change, and link them with a role — builds, changes, integrates, or decommissions. Projects come and go; the application keeps the story.
- Each application carries the metadata governance actually needs: how it's sourced (custom-built, off-the-shelf, SaaS), how it's delivered (web, mobile, desktop, API, batch), where it runs (SaaS-hosted, cloud, on-premises), plus lifecycle, criticality, and data classification.
- Map how applications connect: typed interfaces (API, file, event, database) between your applications — including lightweight external stubs for systems outside your scope, so integration points are captured honestly without pulling them into governance.
- Applications hold living documents: attach current-state architecture, interface catalogs, and runbooks directly to the application, and re-link a project document to its delivered application when the project wraps up.
July 5, 2026
The cajeX assistant can now see and prioritise a project's findings
- With a project open, the assistant now understands the project's findings — not just its description. Ask it to summarise the open risks, tell you what's overdue, or decide what to tackle first, and it answers grounded in the actual findings (counts by severity and status, what's past its due date, and the most pressing items). It respects your access: if you can't see a confidential project's findings, neither can the assistant.
- With a directive open, the assistant now understands the findings raised against it. Ask about your conformance to a directive, what's currently violating it, or the impact of changing it, and it answers grounded in those findings — counting only the ones you're allowed to see across projects.
- Open the assistant without a specific item and ask what's on your plate. It now sees your own open findings across every project you can access, so it can tell you what's overdue and what to tackle first — a quick daily stand-up for your work.
- You can now ask the assistant to move a directive through its lifecycle — submit it for review, approve, reject, deprecate, reactivate — just like it already does for findings. It only ever offers moves that are valid for the directive's current status and that your role permits, proposes the change as a Confirm card, and runs the same audited status action your manual controls do.
- And on a draft directive, you can ask the assistant to help rewrite its title, statement, rationale, or guidance. It proposes the revision as a before → after card you can Accept, Edit, or Dismiss — the same review-and-apply loop findings already have. (Approved directives stay locked; evolving one still means creating a new version.)
- The same help now covers projects: with a project open, you can ask the assistant to sharpen its name or description, review the proposed wording, and apply it in one click. Every item you can open — findings, directives, and projects — now supports assistant-suggested revisions.
- The assistant now understands your knowledge base too. Open a KB entry and there's an "Ask cajeX" button: it can explain the entry, answer questions grounded in it, and help you rewrite its title or content — proposed as a before → after card you review and apply, just like everywhere else. You can also ask it to archive an entry or restore an archived one, confirmed the same way.
July 4, 2026
Ask the cajeX assistant to run an AI review of a project
- With a project open, you can ask the assistant to run an AI review of it. It proposes the review as a Confirm card — including any focus you asked for — and only when you Confirm does it start, running the same audited review your manual controls do, against your approved directives and within your plan's limits. The review then runs in the background as usual.
- Fixed the assistant panel so your own messages and the Confirm button on a proposed action are always clearly visible (previously they could render with no colour against the panel background).
- Finding edits now appear in the finding's Activity. Changing a finding's severity, due date, description, owner, or other fields — whether from the edit form or via the assistant — leaves a legible entry in the Activity thread, alongside state changes.
- When the assistant acts on something you have open, the page now updates immediately instead of needing a refresh — an edited finding, a finding it creates on a project, or an AI review it starts for a project all show up right away.
July 3, 2026
The cajeX assistant can now act on a finding — move it through its lifecycle, set its due date or severity — with your confirmation
- When you have a finding open, you can ask the assistant to change its state (start work, resolve, defer, reject, …), set a due date, change its severity, or add a comment. It proposes the change as a clear Confirm card — nothing happens until you click Confirm, and when you do it runs the exact same audited action the manual controls do, with your permissions. For state changes it only ever offers moves that are valid for the finding's current state.
- And with a project open, you can ask the assistant to draft a new finding for it — it proposes the finding (title, description, category, severity) for you to review, and only creates it when you Confirm.
- The same works for directives: with a directive open, you can ask the assistant to draft a new one — it proposes the directive (title, statement, rationale, type, category) for you to review, and only creates it when you Confirm.
July 2, 2026
Meet the cajeX assistant — ask how anything works, right inside the app
- A new in-app assistant answers your questions about how cajeX works — projects, directives, AI reviews, findings, sessions, workspace settings, and more — grounded in the product guide and citing the relevant chapter so you can read further. Open it from the sparkle button in the top bar; it docks to the side of your screen and answers stream in as you chat. It’s available now and off by default — a workspace admin or owner can turn it on in Settings › AI.
- The assistant is now context-aware on your work: open a finding, project, or directive and it can read what’s on screen — and, for a finding, the directive it’s meant to satisfy — to help you understand or improve it. For findings it can also propose a wording change as a clear before/after suggestion; you can accept it to update the finding, tweak the wording first, or dismiss it — nothing is ever changed without you.
June 2026
June 29, 2026
A native-style bottom navigation bar on phones
- On phones, navigation moves to a bottom tab bar — Dashboard, Projects, Findings, Sessions, and a “More” button that slides up the full menu — so the everyday destinations are within thumb’s reach. The old left icon rail is hidden on mobile, giving pages the full screen width. Desktop keeps its sidebar, unchanged.
June 29, 2026
Directives no longer open to an empty list when you have no workspace-authored directives
- The Directives page defaulted to showing only “Workspace directives,” so workspaces whose directives all come from frameworks landed on an empty “No directives found” page. It now automatically shows all your directives when there are no workspace-authored ones.
June 29, 2026
Easier-to-read, easier-to-tap pages on phones
- Page titles are sized to fit phone screens (no more headlines wrapping across three lines), and buttons, dropdowns, and form fields now have larger tap targets on mobile. Desktop is unchanged.
June 28, 2026
Mobile header fixes: no more cut-off top bar, and it gets out of your way as you scroll
- Fixed the top workspace/scope bar being clipped (“half displayed”) on phones — it now sizes to fit its contents instead of cutting off the top and bottom rows.
- On mobile, the top bar now slides out of the way when you scroll down a page and slides back in when you scroll up, giving you more room to read.
- On phones, list pages now tuck the search/filter and summary-stat bars away by default so the list fills the screen — a floating Filters button reveals or hides them on demand. The top bar still slides away as you scroll. (Desktop is unchanged.)
June 28, 2026
See and manage your generated calendar availability at a glance
- Admin → Calendar now shows a “Generated Availability” overview: the recurring pattern (e.g. Mon–Fri 09:00–11:00, 13:00–15:00), the date range covered, and how many upcoming slots are available, booked, or blocked.
- You can block, unblock, or delete a whole date range of generated availability in one action (no more per-slot fiddling). Booked sessions are always preserved — blocking or deleting a range never touches a scheduled session.
June 27, 2026
Clean cutover when you change the calendar timezone or schedule
- “Generate Default Slots” now has a “Replace existing availability” option that clears existing unbooked slots in the date range before regenerating — so after changing the workspace timezone or weekly schedule, your availability moves cleanly instead of leaving old, mistimed slots behind. Booked sessions and blocked dates are always kept, and any booking that no longer matches the schedule still shows up under “Out-of-Schedule Booked Sessions”.
June 27, 2026
Mandatory expert-assignment questions are now required to save a project
- When a project's expert-assignment questions are marked mandatory, you must now answer them before saving the project — the form flags any unanswered required question instead of saving silently.
June 27, 2026
Workspace timezone is now its own setting you can save directly
- Admin → Calendar now has a dedicated “Workspace Timezone” section with its own Edit/Save, so you can set the timezone without re-saving the whole weekly schedule. It clearly shows when no timezone is saved (the calendar defaults to UTC until you save one), and reminds you to regenerate slots afterward.
June 27, 2026
The session calendar now uses your workspace timezone, and the profile timezone menu opens correctly
- The AG session calendar now displays availability in the workspace timezone set in Admin → Calendar (e.g. Europe/Copenhagen), so everyone on the team sees the same times the admin configured — instead of each viewer's own timezone.
- Fixed the Timezone and Language submenus in the profile menu, which could appear to do nothing when clicked (they were being clipped). They now open as expected.
June 27, 2026
Fixed: assigning experts to roles and to projects now works end-to-end
- In Admin → Expert Roles, the “Assign AG Team Member” search now reliably lists your workspace members (it could come up empty depending on timing).
- On a project’s Edit screen, your answers to the expert-assignment questions are now remembered and re-shown when you reopen Edit, and saving them assigns the matching experts.
June 27, 2026
The booking calendar opens on the first week you can actually book
- If your workspace requires sessions to be booked a number of days in advance, the calendar now opens on the first bookable week instead of the current (un-bookable) one. AG Core Team members, who are exempt from the lead time, still open on the current week. Use the week arrows or “Today” to move around as before.
June 27, 2026
Project team is now managed from Edit, with a consistent count
- The project detail panel now shows the project team as a clear read-only list; add or remove managers and members from the project’s Edit screen (where changes are saved together). The team count on the detail panel now matches the project card and everywhere else.
June 27, 2026
Fixed: long dialogs now scroll instead of clipping
- The Request AG Session dialog (and the Create Service Credential dialog) now scroll when their content is taller than the window, so the form and action buttons are always reachable. Dialog subheadings are also aligned with the rest of the dialog.
June 27, 2026
Session invites: assigned experts show, and any project manager can invite the Core Team
- The AG Experts assigned to a project (via the project’s assignment questions) now appear in the session invite list — answering the questions when creating or editing a project resolves the matching expert roles to people and attaches them to the project.
- Project managers who aren’t workspace admins can now see and invite the AG Core Team when requesting a session, instead of getting an empty list.
June 27, 2026
Fixed: AG Core Team now appears when requesting a session
- When requesting an AG session, the invite list now shows your AG Core Team even if the project has no project members assigned — so a project manager can always call a session with the governance experts. Previously the list could read “No team members found for this project.”
June 27, 2026
Pick any timezone for your account
- Your personal timezone picker (Profile, and the profile menu) now offers the full list of world timezones with their UTC offsets, so you can set your exact zone instead of choosing from a handful of presets. Your current zone is always shown and selected.
June 27, 2026
Timestamps across the app now follow your timezone
- Building on the timezone-aware calendar, dates and times elsewhere now render in your timezone too — including the audit log, Knowledge Base version history, session details, and findings. Your timezone is detected from your browser and can be overridden from the profile menu.
June 27, 2026
Calendar now shows session times in your own timezone
- The governance calendar now renders every available and booked slot in your personal timezone, detected automatically from your browser — so 09:00 means 09:00 where you are. You can override it any time from the timezone picker in your profile menu, and your choice is remembered across devices. Booking a session still lands on exactly the slot you clicked.
June 27, 2026
Set a workspace timezone for your governance calendar
- Admin → Calendar now has a single workspace timezone. Your default weekly schedule times (e.g. 09:00–11:00) are interpreted in that timezone when sessions are generated — and correctly account for daylight-saving changes — so slots land at the right local time year-round. This replaces the old per-row timezone picker with one clear setting for the whole schedule.
June 26, 2026
New workspaces start with a default weekly governance schedule
- Brand-new workspaces now ship with a sensible default AG calendar schedule — Monday to Friday, 09:00–11:00 and 13:00–15:00 — so project managers can book sessions right away instead of waiting for an admin to set one up. The schedule is fully editable (or removable) from Admin → Calendar at any time.
June 26, 2026
Framework Compliance Report is now a readable, on-screen report
- Generating a Framework Compliance Report now opens a formatted, on-screen report — a coverage scorecard, clause-by-clause coverage, the gap list, and linked findings — instead of immediately downloading a file. From the report you can print it or download the CSV whenever you're ready.
June 26, 2026
Cards or rows — your choice — on every main list view
- Projects, Sessions, Directives, the Knowledge Base and Frameworks can now switch between cards and a compact row/table layout, matching Findings and Documents. In row view you can drag to reorder columns and show/hide them, and your layout — view mode and columns — is saved to your account, per workspace.
June 25, 2026
Sharper project report cards — Governance Scorecard + focused directive compliance
- Project report cards now open with a Governance Scorecard — a RED/AMBER/GREEN status with a one-line summary for each area (Risk, Directive compliance, Finding resolution, Review currency), so the project's governance posture is clear at the top.
- The Directive Compliance section now lists only the directives this project was actually evaluated against (via its findings or AI reviews), instead of every approved directive in the workspace — so the section is focused and every row is relevant.
June 25, 2026
Fixed: documents on Enterprise workspaces could fail to extract or download
- Resolved an issue where documents in Enterprise (dedicated-storage) workspaces could report their file as missing — failing text extraction and download — even though the upload had succeeded. Affected documents now extract and download normally; just re-run extraction on any document still showing “Extraction failed.”
June 24, 2026
“Top Directives by Open Findings” on the main dashboard
- Alongside the conformance chart, the dashboard now lists the approved directives with the most open findings in your workspace — each with its open-finding count, latest conformance verdict, and severity — so you can see at a glance which rules are getting flagged the most.
June 24, 2026
Directive Conformance chart on the main dashboard
- The main dashboard now shows a Directive Conformance donut for your workspace — at a glance, how many of your approved directives are conformant, partially conformant, non-conformant, lacking evidence, or not yet evaluated. (Previously only on the Enterprise dashboard.)
June 24, 2026
Cleaner, consistent summary cards across list pages
- The clickable summary cards (states, categories, file types, severities) now hide empty buckets, so you only see cards you can actually filter by — and every card has a consistent colour-coded accent across all the list pages.
June 23, 2026
Knowledge Base now uses the same category set as Directives
- The Knowledge Base and Directives now share one consistent set of categories, so the KB category cards are a clean, fixed list instead of dozens of overlapping auto-generated ones. Existing entries were re-filed onto the shared categories, and new entries (including AI-generated ones) stick to it.
June 23, 2026
List pages keep their summary cards and filters in view as you scroll
- Across the app's list pages — Projects, Sessions, Directives, Knowledge Base, Frameworks, Programs, Compliance Rules, Pipelines and more — the summary cards and filter bar now stay pinned at the top while just the list below scrolls, so the totals and filters are always one click away, no scrolling back up.
June 23, 2026
Fixed: Projects summary counts now reflect all projects
- The Draft / Active / On Hold / Completed / Cancelled cards on the Projects page now count every project in the workspace, not just the ones loaded on screen — so the numbers no longer grow as you scroll, and stay correct when you filter by phase.
June 23, 2026
Customise your tables — columns, card view, saved to your account
- Dense tables (Findings, Documents) now have a “Columns” menu so you can show or hide the columns you care about, and the Findings list gained a Directive column.
- Findings and Documents now have a card view — switch between the table (rows) and a card grid with the list/grid toggle in the toolbar.
- Your table preferences — column choices and the row/card view — now save to your account, so they follow you across devices and browsers (per workspace), instead of just the current browser.
June 22, 2026
Findings now connect back to the directive they’re about
- Every finding is evidence about a governance rule — so it now shows which directive it maps to. The Findings list has a new Directive column and an “All Directives” filter, and clicking a directive (in the list or on a finding’s detail) opens that directive directly.
- Each directive page now has a Conformance section: its current status (conformant, partially conformant, non-conformant, or not yet evaluated), when it was last evaluated, the open findings against it broken down by severity, the projects they span, and a one-click jump to those findings. The rule and its evidence finally live in one place.
- The Enterprise dashboard’s Top Violated Directives now shows each directive’s conformance status alongside its finding count, so you can tell a genuinely non-conformant rule from one that simply has a lot of observations.
- The Enterprise dashboard has a new Directive Conformance chart — a portfolio-level view of how many of your approved directives are currently conformant, partially conformant, non-conformant, or not yet evaluated.
June 21, 2026
AI reviews no longer cut short when a model response is truncated
- If the review model occasionally cut off its response mid-way (it can happen on very dense batches), that batch used to fail and the whole review came back marked “partial.” Now the review recovers every complete finding from the truncated response and keeps going, so reviews stay complete instead of dropping a batch’s worth of findings.
June 21, 2026
Fixed: large documents are now reliably included in AI reviews
- A large document could be silently left out of an AI review when the project also had other attachments — the step that compresses an oversized document to fit the review was unreliable and, when it failed, the document was dropped without warning, so the findings weren’t based on it. That compression step is now reliable, and it uses the model you select in Model Config. Just as importantly, if any document still can’t be included, the review now says so prominently at the top of the results instead of presenting a score as if it had read everything.
June 21, 2026
Clearer “applies to” labels on frameworks
- Each framework now shows a clearer label for what it primarily applies to — your organization, a system or product, your data wherever it flows, your AI program, or your supply chain. We re-reviewed all 300+ frameworks so the label is accurate (for example, privacy laws now read “Data-flow” and SBOM/supply-chain frameworks read “Supply chain”), making it easier to tell at a glance how a framework fits your environment.
June 21, 2026
Smarter framework recommendations during setup
- When you pick your industry during setup, cajeX now recommends a sensible starting set — a small foundational core that applies to every organization (information security, privacy, resilience, risk, AI governance, secure development, quality) plus the frameworks specific to your industry. Highly-regulated industries see more; every industry sees a focused, useful list instead of either a couple of frameworks or a wall of them.
June 21, 2026
Framework picker is calmer, and respects your plan
- Setting up a workspace no longer pre-ticks dozens of frameworks for you. Your cajeX baseline is always included, recommended frameworks for your industry are highlighted and expanded so they're easy to find, and you choose which to add — so a new workspace starts focused instead of buried in directives.
- The number of frameworks a workspace can have now follows your plan's allowance. Workspaces already above their plan's limit keep everything they have; the limit only applies when adding new frameworks. Upgrade for a higher allowance.
June 20, 2026
Scope an AI review to a whole domain
- When starting an AI review you can now scope it to an entire subject domain — for example "all my AI-governance frameworks" or "all my information-security frameworks" — instead of running it one framework at a time. Pick a domain and the review runs against every framework you hold in it; picking a single framework still works exactly as before.
June 20, 2026
Easier framework selection when setting up a workspace
- The compliance-framework picker during workspace creation is now organised by subject domain — Information Security, Privacy & Data Protection, AI Governance, and so on — instead of one long flat list. The domains most relevant to your industry are expanded and pre-selected, the rest are one click away, and each framework now shows whether it's a regulation, a standard, or a best practice. Choosing the right frameworks for a new workspace is much faster to scan.
June 19, 2026
Fixed: sign-in links could appear "expired" for corporate inboxes
- Some new sign-ups — especially on company email — clicked their magic link and were told it had already expired, even moments after signing up. The cause was their own email-security scanner: these gateways silently pre-open every link in a message to check it for safety, and because our sign-in link was single-use, that automated visit consumed it before the person ever clicked. Sign-in links now open a quick "Confirm sign-in" page first and are only used up when you actually click Continue, so scanners can no longer burn them
June 19, 2026
Fixed: a document could get stuck on "Extracting…"
- Occasionally a document upload (or a re-extract) could sit on "Extracting…" indefinitely — the background extraction job was lost before it finished and nothing picked it back up. A stuck extraction is now automatically retried within minutes and only marked failed if it genuinely can't be recovered, so documents no longer hang in limbo
June 18, 2026
Fixed: AI review could stall on large projects
- An AI review covering many directives could fail with a timeout. Under the hood, the model occasionally returned a truncated or empty response for an oversized batch, and a single bad batch took down the entire review. Reviews now run in smaller batches so responses stay comfortably within limits, and a batch that does come back malformed is retried on its own rather than failing the whole run
June 18, 2026
Audit log retention now matches your plan
- Workspace audit logs are now kept for the full window your plan includes — up to 365 days on Enterprise — rather than a fixed 90 days for everyone. Each plan's audit retention is enforced exactly: longer history on higher tiers, shorter privacy-minimizing retention on lower tiers
June 16, 2026
Fixed: AI review could fail on large projects with many directives
- A review covering a large set of directives (e.g. a few hundred) could fail immediately with a storage error before it even started, because the review packed all of its working data into a single internal record that exceeded a size limit. Reviews now store that working data per-batch, so they run regardless of how many directives are in scope
June 15, 2026
Threat intelligence + incident response — FIRST CVSS + NIST SP 800-61 + STIX/TAXII (3 frameworks, 141 directives)
- Three security-operations standards every team can use day-to-day, complementing the OWASP, MITRE ATT&CK/ATLAS, and incident-management coverage already in cajeX — vulnerability scoring, incident-response process, and threat-intelligence exchange
- **FIRST CVSS v4.0 — Common Vulnerability Scoring System** — the universal open standard for scoring vulnerability severity: Base (exploitability + impact on vulnerable and subsequent systems), Threat, Environmental, and Supplemental metric groups, the vector string, and qualitative severity bands used to drive remediation SLAs. 18 clauses, 12 in-scope, 36 directives. Vendor-open (FIRST.org) with attribution
- **NIST SP 800-61 — Computer Security Incident Handling Guide** — the foundational incident-response lifecycle: Preparation; Detection & Analysis; Containment, Eradication & Recovery; and Post-Incident Activity, plus coordination and information sharing (the Rev. 3 update reframes these around the NIST CSF 2.0 functions). 24 clauses, 19 in-scope, 57 directives. Public domain (NIST)
- **STIX / TAXII** (OASIS) — the open standards for cyber-threat intelligence: STIX 2.1 for representing intelligence (indicators, malware, threat actors, attack patterns, relationships, observables, TLP data markings) and TAXII 2.1 for exchanging it (collections, channels, API roots), feeding SIEM/SOAR enrichment and ISAC sharing. 21 clauses, 16 in-scope, 48 directives. Vendor-open (OASIS) with attribution
- Companions cross-walk CVSS ↔ OWASP Top 10 + the vulnerability-management directives; NIST 800-61 ↔ NIST CSF 2.0 + NIST 800-53 IR family + ISO 27035; STIX/TAXII ↔ MITRE ATT&CK/ATLAS + NIST 800-61 + CVSS. cajeX now covers the full detect-score-respond-share security-operations loop
June 15, 2026
Crypto-assets + blockchain — EU MiCA + ISO/TC 307 (2 frameworks, 114 directives)
- Two frameworks for organisations building or regulating crypto-assets and distributed-ledger systems — the binding EU market regulation plus the ISO technical standards suite
- **EU MiCA — Markets in Crypto-Assets Regulation** (Regulation (EU) 2023/1114) — the binding EU regime for crypto-asset issuers and crypto-asset service providers (CASPs): authorization and governance, white-paper and marketing disclosure, client-asset safeguarding and custody, reserve and redemption requirements for asset-referenced and e-money tokens, market-abuse prevention, complaint handling, and ICT/operational resilience (cross-referencing DORA). 28 clauses, 17 in-scope, 51 directives. Public domain (EUR-Lex)
- **ISO/TC 307 — Blockchain & Distributed Ledger Technologies** — the ISO standards family anchored by ISO 22739 (vocabulary) and ISO 23257 (reference architecture), plus governance (TS 23635) and privacy (TR 23244): DLT concepts, system roles and layers, governance and accountability, key management and node security, on-/off-chain PII strategy, and smart-contract lifecycle and interoperability. 27 clauses, 21 in-scope, 63 directives. Paywalled ISO/IEC — paraphrase + trademark
- Companions cross-walk MiCA ↔ DORA + PSD2 + the financial-services set; ISO/TC 307 ↔ ISO 27001 + MiCA. cajeX now covers digital assets from the technical architecture through the binding market regulation
June 15, 2026
Records + information governance — ISO 15489 + ISO 19650 (2 frameworks, 118 directives)
- Two information-governance standards for records-intensive and built-asset organisations, joining the data-governance and document-management coverage already in cajeX
- **ISO 15489 — Records Management** — the international standard for creating and managing authentic, reliable records: records characteristics (authenticity, reliability, integrity, usability), records-management policy and responsibilities, records controls (classification scheme, retention and disposition authorities, access rules, metadata), the records processes (capture, register, classify, store, access, migrate, dispose), and appraisal. 25 clauses, 19 in-scope, 55 directives. Paywalled ISO — paraphrase + trademark
- **ISO 19650 — BIM / Built-Asset Information Management** — information management across the built-asset lifecycle using Building Information Modelling: the information requirements (OIR/AIR/EIR/PIR), the Common Data Environment, the delivery-phase and operational-phase information-delivery processes, and the Part 5 security-minded approach for sensitive assets. 27 clauses, 21 in-scope, 63 directives. Paywalled ISO — paraphrase + trademark
- Companions cross-walk ISO 15489 ↔ GDPR retention + the data-governance directives; ISO 19650 ↔ ISO 55000 asset management + the document-management directives
June 15, 2026
Energy / grid security — IEC 62351 + NIST IR 7628 (2 frameworks, 103 directives)
- Two power-grid cybersecurity frameworks, deepening cajeX's critical-infrastructure / OT coverage (which already includes IEC 61850, IEEE 1547, IEC 62443, and NIST SP 800-82)
- **IEC 62351 — Power System Communications Security** — end-to-end security for grid communication protocols: TLS for TCP/IP profiles, authentication for serial / GOOSE / Sampled-Values (IEC 61850) and 60870-5 / ICCP / DNP3, role-based access control (62351-8), certificate and key management (62351-9), and network/system security monitoring (62351-7). 24 clauses, 17 in-scope, 50 directives. Paywalled IEC — paraphrase + trademark
- **NIST IR 7628 — Smart Grid Cybersecurity Guidelines** — the US smart-grid guidance: the logical reference model and interface categories, cybersecurity strategy and risk, technical security requirements (access control, identification/authentication, cryptography, communications protection), operational requirements, and energy-usage-data privacy. 25 clauses, 18 in-scope, 53 directives. Public domain (NIST)
- Companions cross-walk both to IEC 61850 + IEC 62443 + NIST 800-82 + the OT/ICS directives. cajeX now covers grid security from protocol-level communications through smart-grid strategy and privacy
June 15, 2026
Regional regulatory — eIDAS 2.0 + India RBI + Japan METI (3 frameworks, 154 directives)
- Three regional regulatory frameworks extending cajeX's geographic coverage across EU digital identity, Indian banking cyber, and Japanese corporate cyber governance
- **eIDAS 2.0 — European Digital Identity Framework** (Regulation (EU) 2024/1183) — the EU electronic-identification and trust-services framework as amended to introduce the European Digital Identity Wallet (EUDI Wallet): wallet issuance and selective-disclosure presentation, trust services (qualified e-signatures, e-seals, timestamps, website-authentication certificates), electronic attestation of attributes, qualified-trust-service-provider requirements, and relying-party obligations. 25 clauses, 19 in-scope, 56 directives. Public domain (EUR-Lex)
- **India RBI Cyber Security Framework + CERT-In Directions** — the Reserve Bank of India's mandatory cyber-security framework for banks (board-approved policy, baseline controls, cyber-crisis management plan, SOC/continuous surveillance, RBI incident reporting) plus the CERT-In 2022 directions (6-hour incident reporting, 180-day log retention, time synchronization). 25 clauses, 18 in-scope, 54 directives. Public domain (RBI/CERT-In)
- **Japan METI Cybersecurity Management Guidelines** (Ver 3.0) — the cyber-risk responsibilities of corporate management issued by METI with IPA: the three management principles, the ten important items management directs the CISO to implement (risk framework, resourcing, asset protection, detection/response/recovery, incident readiness, supply-chain security, information sharing, disclosure). 21 clauses, 15 in-scope, 44 directives. Public domain (METI/IPA)
- Companions cross-walk eIDAS 2.0 ↔ GDPR + FIDO2/WebAuthn + NIST 800-63; India RBI ↔ NIST CSF + ISO 27001 + the financial-services set; Japan METI ↔ NIST CSF + ISO 27001 + Japan APPI
June 15, 2026
APAC regulatory — China MLPS 2.0 + Korea ISMS-P + HKMA C-RAF (3 frameworks, 199 directives)
- Three Asia-Pacific cyber and governance frameworks, closing the region's biggest coverage gap — cajeX's Asia footprint was privacy-heavy (China PIPL, Japan APPI, India DPDP, Singapore PDPA) plus Singapore's AI-governance and CII codes; these add the mandatory cyber/security-management regimes for mainland China, South Korea, and Hong Kong
- **China MLPS 2.0 — Multi-Level Protection Scheme (等保 2.0)** — the cybersecurity grading regime mandated by China's Cybersecurity Law and effectively required to legally operate IT systems in mainland China. Systems are classified into five protection levels, filed with the Public Security Bureau, and (for Level 2+) tested by accredited evaluators against the GB/T 22239 baseline — secure physical environment, communication network, area boundary, computing environment, and security management center, plus management requirements and extended modules for cloud, mobile, IoT, and industrial control. This is the first China cyber framework in cajeX (complementing PIPL on the privacy side). 35 clauses, 25 in-scope, 75 directives. Based on Chinese national standards (GB/T) — paraphrase + attribution
- **Korea ISMS-P — Information Security & Personal Information Management System** — South Korea's combined security + privacy certification administered by KISA (merging the former ISMS and PIMS schemes), mandatory for ISPs, IDCs, large hospitals and universities, and businesses above defined thresholds. Covers the management system (establishment, operation, review), 64 protection-measure controls, and the personal-information processing lifecycle; ties into the Personal Information Protection Act (PIPA). 25 clauses, 20 in-scope, 60 directives. Public domain (KISA) with attribution
- **HKMA C-RAF — Cyber Resilience Assessment Framework** — the Hong Kong Monetary Authority's cyber-resilience regime for authorized institutions under the Cybersecurity Fortification Initiative: an Inherent Risk Assessment to set the risk tier, a Maturity Assessment across seven domains (governance, identification, protection, detection, response & recovery, situational awareness, third-party risk), and intelligence-led red-team testing (iCAST) for higher-risk institutions. Pairs with MAS TRM in the APAC-financial set. 32 clauses, 22 in-scope, 64 directives. Public domain (HKMA)
- Licensing: China MLPS 2.0 (GB/T national standards, paraphrase + attribution) · Korea ISMS-P + HKMA C-RAF (public domain, attribution for ISMS-P). Companions cross-walk MLPS 2.0 ↔ China PIPL + ISO 27001 + NIST CSF; ISMS-P ↔ APPI + PIPL + GDPR + ISO 27001/27701; C-RAF ↔ MAS TRM + APRA CPS 234 + DORA + ISO 27001. cajeX now covers the major APAC cyber + privacy + financial-resilience regimes end-to-end
June 15, 2026
US state privacy expansion — Colorado CPA + Connecticut CTDPA + Texas TDPSA (3 frameworks, 165 directives)
- Three comprehensive US state consumer-privacy laws, joining the CCPA/CPRA (California) and VCDPA (Virginia) already in cajeX. They follow the now-standard US state model — controller/processor duties, the consumer rights set (access, correction, deletion, portability, opt-out of sale / targeted advertising / profiling), universal opt-out mechanisms, sensitive-data opt-in consent, and data protection assessments — so satisfying these three covers the pattern the other ~14 enacted state laws closely track
- **Colorado Privacy Act (CPA)** — in force since July 2023 with detailed AG rules: applicability thresholds (100k+ consumers, or 25k+ with revenue from data sale), the five consumer rights, a required Universal Opt-Out Mechanism, duty of purpose specification + data minimization, sensitive-data opt-in consent, and Data Protection Assessments for high-risk processing. 30 clauses, 22 in-scope, 64 directives. Public domain
- **Connecticut Data Privacy Act (CTDPA)** — Public Act 22-15, in force since July 2023: controller duties, the consumer rights set with an appeal process, the universal-opt-out mandate (Jan 2025), sensitive-data consent including precise geolocation and enhanced protections for minors/teens, and data protection assessments. 26 clauses, 18 in-scope, 51 directives. Public domain
- **Texas Data Privacy and Security Act (TDPSA)** — in force since July 2024, with a distinctive applicability test: it applies to any non-small-business processing personal data in Texas, with no consumer-count or revenue threshold like the other states. Adds a required sensitive-data sale-notice disclosure on top of the standard duties, rights, universal opt-out, consent, and assessment obligations. 25 clauses, 17 in-scope, 50 directives. Public domain
- All three are public domain (US state statutes). Companions cross-walk them to each other + CCPA/CPRA + VCDPA + GDPR, so a workspace can manage the US state-privacy patchwork as one connected set. The remaining state laws map closely to this trio — cross-referenced, and individually authored on request
June 15, 2026
National security baselines — Germany BSI IT-Grundschutz + Canada ITSG-33 (2 frameworks, 114 directives)
- Two national-government security baselines, extending cajeX's coverage of country-level frameworks (which already includes UK Cyber Essentials + NCSC CAF, Australia's Essential Eight, France SecNumCloud, and Singapore CCoP). Both are general-applicability baselines an organisation can adopt as its core security framework
- **BSI IT-Grundschutz** (Germany) — the German Federal Office for Information Security's baseline-protection methodology and Compendium: the ISMS + Basic/Standard/Core protection approaches (BSI Standards 200-1/200-2/200-3/200-4), structure analysis and modeling against the Compendium building blocks, and the full layer model (organization & personnel, concepts, operations, detection & response, applications, IT systems, industrial IT, networks, infrastructure). Certification is available on the basis of IT-Grundschutz (ISO 27001 compatible). 28 clauses, 16 in-scope, 48 directives. Public domain (BSI) with attribution
- **ITSG-33 — IT Security Risk Management** (Canada) — the Canadian Centre for Cyber Security's lifecycle approach: a two-level risk-management model (departmental security control profiles + information-system level), a security control catalogue closely aligned with NIST SP 800-53 control families, security control profiles by sensitivity (e.g., PROTECTED B), and integration of security activities into the system-development lifecycle. 29 clauses, 22 in-scope, 66 directives. Public domain (CCCS) with attribution
- Companions cross-walk BSI IT-Grundschutz ↔ ISO 27001 and ITSG-33 ↔ NIST 800-53 + NIST 800-37 (RMF) + ISO 27001, so teams operating across jurisdictions can map a single control programme to multiple national baselines
June 15, 2026
Vendor + supply-chain assurance — Microsoft SSPA + ISO/IEC 27036 + MVSP (3 frameworks, 188 directives)
- Three frameworks covering third-party / supplier-security assurance — what you ask of your vendors, and what your customers ask of you. They join the SLSA, SBOM (CycloneDX/SPDX), in-toto, Sigstore, and NIST 800-161 software-supply-chain set already in cajeX, extending it from build-artifact integrity to the supplier-relationship and vendor-due-diligence layer
- **Microsoft SSPA — Supplier Security & Privacy Assurance** — Microsoft's mandatory program for suppliers that process Microsoft Personal or Confidential data: an attestation regime built on the Microsoft Data Protection Requirements (DPR), with data-handling-profile scoping, annual self-attestation, independent assessment for higher-risk suppliers, and privacy + security control domains (data handling, access control, encryption, sub-processor flow-down, incident notification). Distinct from the Microsoft SDL already in cajeX — SSPA governs supplier data-handling assurance, not how software is built; the two are cross-referenced in the picker. 28 clauses, 20 in-scope, 60 directives. Vendor-open (Microsoft) with attribution
- **ISO/IEC 27036 — Information Security for Supplier Relationships** — the supplier-relationship counterpart to ISO 27001/27002, across its four parts: concepts + governance (Part 1), supplier-agreement security requirements + risk management (Part 2), ICT supply-chain security — component integrity, transparency, tiered-supplier propagation (Part 3), and cloud-service acquisition security — shared responsibility, monitoring, exit/portability (Part 4). Covers the full supplier lifecycle from due diligence through termination + data return. 24 clauses, 19 in-scope, 56 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- **MVSP — Minimum Viable Secure Product** — the minimalistic, vendor-neutral B2B security baseline developed collaboratively (Google, Salesforce, Okta, and others) at mvsp.dev, widely used as a lightweight vendor-security questionnaire and a minimum bar ahead of full SOC 2 / ISO 27001. Four sections: Business controls, Application design controls, Application implementation controls, and Operational controls. 28 clauses, 24 in-scope, 72 directives. Creative Commons with attribution
- Licensing: Microsoft SSPA + MVSP (vendor-open / Creative Commons with attribution) · ISO/IEC 27036 (paywalled ISO/IEC, paraphrase + trademark). Companions cross-walk SSPA ↔ Microsoft SDL + SOC 2 + ISO 27001 + ISO 27701 + TISAX; ISO 27036 ↔ ISO 27001/27002 + NIST 800-161 + the SLSA/SBOM set; MVSP ↔ SOC 2 + ISO 27001 + OWASP ASVS. cajeX now covers supply-chain security from build-artifact integrity through supplier-relationship assurance and vendor due diligence
June 14, 2026
Financial + operational resilience — APRA CPS 234/230 + CRI Profile + UK FCA/PRA OpRes + Basel + MAS TRM (6 frameworks, 362 directives)
- Six frameworks covering the financial sector's operational-resilience and technology-risk layer — the standards a bank, insurer, or fintech is held to on top of the DORA, BCBS 239, FFIEC, SOX, and NYDFS frameworks already in cajeX. Together they span prudential information security, operational-risk management, financial-sector cyber, and the operational-resilience regimes now mandatory across Australia, the UK, Singapore, and the Basel-aligned world
- **APRA CPS 234 — Information Security** (Australia) — APRA's mandatory prudential standard for banks, insurers, and superannuation funds: board ultimate accountability for information security, capability commensurate with threats (including third-party-managed assets), information-asset identification + classification, controls across the asset lifecycle, incident detection + response, systematic control testing, internal audit, and the mandatory APRA notifications (72 hours for material incidents, 10 business days for material control weaknesses). 25 clauses, 15 in-scope, 44 directives. Public domain (APRA)
- **APRA CPS 230 — Operational Risk Management** (Australia, in force 1 July 2025) — the operational-resilience successor consolidating the older outsourcing + BCM standards: operational-risk management framework, identification of critical operations + tolerance levels, business-continuity planning + scenario testing, and a rigorous service-provider management regime (register, due diligence, agreements, fourth-party risk, APRA notification). 25 clauses, all in-scope, 75 directives. Public domain (APRA)
- **CRI Profile — Cyber Risk Institute Profile** — the financial-sector cyber framework that harmonises FFIEC, NIST CSF, and other regulatory expectations into one assessment, used by banks worldwide to answer many examiners with one control set. Govern / Identify / Protect / Detect / Respond / Recover functions plus the financial-sector extensions (three-lines-of-defence, FS-ISAC information sharing) and impact-tiering diagnostic. 31 clauses, 23 in-scope, 69 directives. Vendor-open (Cyber Risk Institute) with attribution
- **UK FCA/PRA Operational Resilience** (SS1/21, PS21/3) — the UK regime requiring firms to identify their Important Business Services, set impact tolerances, map the people/processes/technology/third parties underpinning them, run severe-but-plausible scenario testing, and remain within tolerance — backed by SM&CR accountability and a board-approved self-assessment. 25 clauses, 17 in-scope, 50 directives. Public domain (FCA/PRA)
- **Basel — Principles for Operational Resilience (PSMOR)** — the Basel Committee's international principles that the national regimes above implement: governance, operational-risk management, business-continuity planning + testing, mapping of interconnections + interdependencies, third-party dependency management, incident management, and ICT/cyber resilience. The cross-walk spine that ties the cluster (and DORA, ISO 22301, BCBS 239) together. 19 clauses, 16 in-scope, 48 directives. Public domain (BCBS)
- **MAS TRM — Technology Risk Management Guidelines** (Singapore) — the Monetary Authority of Singapore's technology-risk guidelines, the APAC financial-sector gold standard referenced across Asian banking the way DORA is in the EU: technology-risk governance + board/senior-management oversight, the TRM framework, IT outsourcing + cloud, secure SDLC, IT service management (change + incident), IT resilience + disaster recovery, access control, cryptography, data + infrastructure security, cyber-security operations (threat intel, surveillance, incident response, cyber exercises), online financial-services security, and independent audit. 38 clauses, 26 in-scope, 76 directives. Public domain (MAS)
- Licensing: APRA CPS 234/230, UK FCA/PRA, Basel PSMOR, MAS TRM (public domain) · CRI Profile (vendor-open with attribution). Companions cross-walk the cluster to each other and to DORA, BCBS 239, FFIEC, ISO 22301, ISO 27001, SOX, and NYDFS. cajeX now covers financial operational resilience end-to-end across the EU, US, UK, Australia, Singapore, and the Basel-aligned regimes
June 14, 2026
IoT security — ETSI EN 303 645 + NIST IR 8259 + ISO/IEC 27400 (3 frameworks, 189 directives)
- Three frameworks covering connected-device / IoT security — the consumer-device baselines plus the broader IoT-ecosystem standard. Net-new coverage for the connected-product layer every hardware + smart-product team builds against, and aligned with the EU Cyber Resilience Act + supply-chain set already in cajeX
- **ETSI EN 303 645 — Cyber Security for Consumer IoT** — the most widely-referenced consumer-IoT security baseline; 13 provisions (no universal default passwords, a vulnerability-disclosure means, keep software updated, securely store credentials, communicate securely, minimise attack surface, ensure software integrity, protect personal data, resilience to outages, examine telemetry, easy user-data deletion, usable security, validate input) + data-protection provisions. Underpins the UK PSTI Act + national IoT labelling schemes; TS 103 701 conformance companion. 23 clauses, 19 in-scope, 57 directives. Public domain (ETSI)
- **NIST IR 8259 / 8259A / 8425 — IoT Device Cybersecurity** — the US counterpart: IR 8259's 6 foundational activities for manufacturers + IR 8259A's 6-capability device core baseline (device identification, configuration, data protection, interface access, software update, cybersecurity state awareness) + IR 8259B non-technical capabilities + IR 8425's consumer profile behind the US Cyber Trust Mark. 26 clauses, 22 in-scope, 66 directives. Public domain (NIST)
- **ISO/IEC 27400:2022 — IoT Security and Privacy Guidelines** — the broader system-level standard covering the whole IoT ecosystem (devices + services + networks + stakeholders) across BOTH security and privacy — secure design, authentication, cryptography, secure update, monitoring, decommissioning, plus privacy-by-design, transparency/consent, PII controls, and data minimisation. The dual security+privacy lens distinguishes it from the device-only baselines. 27 clauses, 22 in-scope, 66 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- Licensing: ETSI EN 303 645 + NIST IR 8259 (public domain) · ISO/IEC 27400 (paywalled ISO/IEC, paraphrase + trademark). Companions cross-walk all three to each other (consumer baselines ↔ ecosystem standard) + EU CRA (product cyber) + ISO 27001 + ISO 27701 (privacy) + ISA/IEC 62443 (industrial IoT) + the supply-chain set. cajeX now covers IoT from consumer-device baseline through full-ecosystem security + privacy
June 13, 2026
Health information security + interoperability — ISO 27799 + NEN 7510 + HL7 FHIR + DICOM + ICH GCP (5 frameworks, 365 directives)
- Five frameworks deepening healthcare + life-sciences coverage — the security, interoperability, and clinical-trial standards a health-tech, medical-device, or pharma organisation runs on. They join the HIPAA, ISO 13485, IEC 62304, ISO 14971, ISO 81001, and EU GMP frameworks already in cajeX
- **ISO 27799:2016 — Health Information Security** — the health-sector application of ISO/IEC 27002: how to implement each information-security control for personal health information, with the clinical-safety dimension where integrity + availability carry life-safety stakes. Distinctive health controls: unique patient identification, break-glass emergency access, and patient-record access audit logging. 29 clauses, all in-scope, 86 directives. Paywalled ISO — paraphrase + trademark notice
- **NEN 7510 — Dutch Health Information Security** — the effectively-mandatory baseline for organisations processing personal health data in the Netherlands; ISO 27001/27002/27799-based with Dutch legal embedding, plus the companion NEN 7512 (data-exchange trust) and NEN 7513 (patient-record access logging). 27 clauses, 23 in-scope, 67 directives. Industry-membership — paraphrase + NEN notice
- **HL7 FHIR — Fast Healthcare Interoperability Resources** — the modern standard for exchanging health data: modular Resources over RESTful APIs, conformance via CapabilityStatement + Profiles + Implementation Guides (US Core, IPS), the SMART on FHIR OAuth 2.0 security model with granular scopes + AuditEvent/Provenance/Consent, plus Bulk Data and Subscriptions. Mandated by US ONC/CMS interoperability rules. 27 clauses, 22 in-scope, 66 directives. Vendor-open (HL7) with attribution
- **DICOM — Digital Imaging and Communications in Medicine** — the universal medical-imaging standard: the Patient-Study-Series-Instance data model, DIMSE network services + DICOMweb (WADO-RS/QIDO-RS/STOW-RS), the Conformance Statement interoperability contract, and the security essentials — de-identification (Confidentiality Profiles, including burned-in-pixel PHI), TLS, and audit. 26 clauses, 25 in-scope, 74 directives. Vendor-open (NEMA) with attribution
- **ICH E6(R3) — Good Clinical Practice (GCP)** — the international standard for designing, conducting, and reporting clinical trials with human subjects; the 2025 R3 revision modernised it with quality-by-design + risk-based quality management, decentralised trials, and a major data-governance expansion (data integrity + computerised systems intersecting 21 CFR Part 11 + GAMP 5). Principles + IRB/IEC + investigator + sponsor responsibilities + the Trial Master File. 30 clauses, 24 in-scope, 72 directives. Public domain (ICH)
- Licensing: ISO 27799 (paywalled ISO) · NEN 7510 (NEN industry-membership) · HL7 FHIR + DICOM (vendor-open with attribution) · ICH GCP (public domain). Companions cross-walk ISO 27799 ↔ ISO 27002 + HIPAA + NEN 7510 + ISO 81001; NEN 7510 ↔ ISO 27799 + GDPR; HL7 FHIR ↔ DICOM + HIPAA + the OAuth/API-auth-hardening framework + IEC 62304; DICOM ↔ HL7 FHIR + IEC 62304 + ISO 81001; ICH GCP ↔ ICH Q9/Q10 + 21 CFR Part 11 + GAMP 5 + EU GMP Annex 11. cajeX now covers healthcare from quality systems + device software through health-data security, interoperability, and clinical-trial conduct
June 13, 2026
Compliance-platform parity — SOC 1 + TISAX + ISO 27032 + BSI C5 + Quebec Law 25 + COPPA (6 frameworks, 362 directives)
- Six frameworks closing the gap against what leading commercial compliance platforms support today — selected by diffing cajeX's catalogue against a major GRC platform's framework list, so every one is demand-validated. They span financial-reporting attestation, automotive information security, internet-security guidance, German cloud assurance, and two privacy regimes
- **SOC 1 (SSAE 18 / ISAE 3402)** — the AICPA report on a service organisation's controls relevant to user entities' internal control over financial reporting (ICFR) — the financial-reporting counterpart to SOC 2. Type 1 (design) vs Type 2 (design + operating effectiveness), management's system description + control objectives + assertion, ITGCs + completeness/accuracy/authorization controls, Complementary User Entity Controls; supports the user's SOX 404. 28 clauses, 21 in-scope, 63 directives. Industry-membership — paraphrase + AICPA notice
- **TISAX (VDA ISA / ENX)** — the automotive industry's information-security assessment + exchange, required by virtually every major OEM (VW, BMW, Mercedes) for suppliers. Built on ISO 27001/27002 but with the distinctive **Prototype Protection** module (securing pre-release vehicles/parts) + a Data Protection module; Assessment Levels AL1–3, TISAX labels shared on the ENX exchange, maturity-level (0–5) scoring. 25 clauses, all in-scope, 72 directives. Industry-membership — paraphrase + VDA/ENX notice
- **ISO/IEC 27032:2023** — guidelines for internet / cyberspace security, covering the cross-organisational-boundary internet threats an ISMS alone doesn't fully address: internet-facing threats (phishing, malware, web attacks, DDoS), controls for internet services, cross-stakeholder information sharing, and internet-security readiness. 27 clauses, 19 in-scope, 53 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- **BSI C5 — Cloud Computing Compliance Criteria Catalogue** (Germany) — the German cloud-security assurance baseline, obtained via a C5 attestation (ISAE 3000 / IDW PS 951, like SOC 2). 17 criteria domains across governance, operations, IAM, cryptography, resilience, supplier control, and the distinctive **government-investigation-request transparency** criterion + Surrounding Parameters disclosure model. 31 clauses, 23 in-scope, 69 directives. Public domain (BSI)
- **Quebec Law 25 (Bill 64)** — the strictest privacy law in Canada (GDPR-comparable), phased in through 2024: Privacy Officer + governance policies + Privacy Impact Assessments, enhanced consent + transparency, individual rights (access, portability, de-indexing, automated-decision review), confidentiality-incident reporting + cross-border PIA, privacy by default; distinct from federal PIPEDA. 23 clauses, 16 in-scope, 48 directives. Public domain
- **COPPA — Children's Online Privacy Protection Act + FTC Rule** — protects the online privacy of children under 13: direct + online notice, Verifiable Parental Consent before collection, parental access/deletion rights, data minimisation + retention limits, third-party-disclosure restrictions (strengthened in the 2025 Rule amendments), FTC-approved Safe Harbor programs. 27 clauses, 19 in-scope, 57 directives. Public domain (FTC)
- Also in this release: our existing **StateRAMP** framework is now labelled **GovRAMP** (its 2024 rebrand) so it matches what teams search for. Licensing: SOC 1 + TISAX (industry-membership) · ISO 27032 (paywalled ISO/IEC) · BSI C5 + Quebec Law 25 + COPPA (public domain). Companions cross-walk SOC 1 ↔ SOC 2 + SOX; TISAX ↔ ISO 27001 + IATF 16949 + ISO/SAE 21434; ISO 27032 ↔ ISO 27001 + NIST CSF; BSI C5 ↔ FedRAMP + SecNumCloud + CSA CCM; Quebec Law 25 ↔ PIPEDA + GDPR; COPPA ↔ FERPA + CCPA + GDPR. cajeX is now at strong parity with leading commercial compliance platforms
June 13, 2026
Defense / DIB — DFARS cyber clauses + ITAR/EAR + NISPOM + DISA STIGs + MIL-STD-882E (5 frameworks, 300 directives)
- Five frameworks closing the defense-specific regulatory, classified-handling, export-control, and hardening gap that sits *above* the CMMC 2.0 + NIST 800-171/172 + FedRAMP control sets already in cajeX. Together they cover what a defense prime or Defense Industrial Base (DIB) supplier actually has to satisfy on a classified or CUI contract — the legal mandate, export law, classified-handling baseline, hardening spec, and system-safety standard
- **DFARS Cybersecurity Clauses (252.204-7012 / -7019 / -7020 / -7021)** — the contractual mandate that *obligates* DoD contractors to protect CUI/CDI. -7012 requires NIST 800-171 + 72-hour cyber incident reporting to DIBNet; -7019/-7020 require a current SPRS-recorded 800-171 DoD Assessment; -7021 requires a CMMC certificate; all flow down to subcontractors. The legal hook above the 800-171 + CMMC controls. 25 clauses, 18 in-scope, 54 directives. Public domain
- **US Export Control — ITAR + EAR** — ITAR (defense articles on the US Munitions List, State/DDTC) + EAR (dual-use items on the Commerce Control List, Commerce/BIS). Jurisdiction + classification (USML vs ECCN), registration + licensing, the deemed-export trap (releasing controlled tech to a foreign person in the US), restricted-party screening, Technology Control Plans, recordkeeping. Critical for any defense/aerospace/tech firm handling controlled technology. 25 clauses, 20 in-scope, 60 directives. Public domain
- **NISPOM / 32 CFR Part 117** — the National Industrial Security Program: the baseline for any contractor handling classified information. Facility + Personnel Security Clearances (FCL/PCL), Foreign Ownership Control or Influence (FOCI) mitigation, the Insider Threat Program, classified safeguarding (marking / storage / transmission / destruction), classified information-system authorization, self-inspections + reporting. DCSA-administered. 30 clauses, 23 in-scope, 69 directives. Public domain
- **DISA STIGs + DoD Cloud Computing SRG** — the DoD's concrete configuration-hardening standards: the Security Requirements Guide → Security Technical Implementation Guide hierarchy, CAT I/II/III severity, check + fix content with SCAP automation, and the DoD Cloud SRG's Impact Levels (IL2–IL6) + FedRAMP+ baseline. The operational hardening layer beneath RMF/FedRAMP — where 800-53 is the control, the STIG is the exact setting. 26 clauses, 21 in-scope, 63 directives. Public domain
- **MIL-STD-882E — DoD System Safety** — the US DoD standard practice for system safety: the 8-element process, hazard analyses (PHA/SHA/O&SHA/HHA/FHA), the Risk Assessment Code matrix (Severity I–IV × Probability A–F), the system-safety order of precedence (eliminate-by-design first), software Level of Rigor, and hazard tracking to closure. The defense analog to ARP 4761A + IEC 61508 + ISO 26262 already in cajeX. 23 clauses, 18 in-scope, 54 directives. Public domain
- Licensing: all five public-domain US-Gov publications (DoD/DFARS, State/Commerce, DCSA, DISA). Companions cross-walk DFARS ↔ NIST 800-171/172 + CMMC 2.0 + FedRAMP (the controls it mandates); ITAR/EAR ↔ DFARS + NISPOM (export + classified overlap, FOCI); NISPOM ↔ NIST 800-53 + RMF (classified-IS authorization); DISA STIGs ↔ NIST 800-53 + RMF + FedRAMP + CIS Benchmarks (the civilian analog); MIL-STD-882E ↔ ARP 4761A + IEC 61508 + ISO 26262 (the safety family). cajeX now covers the US defense / DIB compliance stack end-to-end — mandate, export, classified, hardening, and safety — on top of the existing CMMC/800-171 control layer
June 12, 2026
Sustainability depth — ISO 50001 + SBTi + CDP (3 frameworks, 165 directives)
- Three frameworks deepening cajeX's sustainability + climate coverage, joining the ISO 14001 / ISO 14064 / GHG Protocol / TCFD / CSRD-ESRS / ISSB / Green Software Foundation set already in the catalog. Together they cover energy management, science-based target setting, and environmental disclosure — the operational, target-setting, and reporting sides of corporate climate action
- **ISO 50001:2018 — Energy Management Systems** — the international standard for an Energy Management System (EnMS), following the same Annex SL structure as ISO 9001/14001/27001. Energy review, Significant Energy Uses (SEUs), Energy Performance Indicators (EnPIs) and Energy Baseline (EnB), energy-efficient design + procurement, and — distinctively — a requirement to demonstrate *continual energy-performance improvement*, not just maintain a management system. A core tool for industrial decarbonisation + cost reduction. 31 clauses, 21 in-scope, 63 directives. Paywalled ISO — paraphrase + trademark notice
- **SBTi — Science Based Targets initiative** — the de-facto global standard for corporate climate-target setting aligned with the Paris 1.5°C goal. The Corporate Net-Zero Standard (near-term + long-term + net-zero targets), Scope 1/2/3 coverage with the Scope 3 value-chain requirement, target-setting methods (absolute contraction, Sectoral Decarbonization Approach), and the third-party validation process. Built on the GHG Protocol. 27 clauses, 21 in-scope, 63 directives. Vendor-open (SBTi) with attribution
- **CDP — Environmental Disclosure and Scoring** — the world's leading environmental disclosure system: companies disclose climate / water / forests data through CDP questionnaires and are scored A to D-. Governance + risk + targets + Scope 1/2/3 emissions + energy + value-chain engagement; the A-to-Leadership scoring methodology + the CDP A List credential; TCFD-, ISSB-, GHG-Protocol- and SBTi-aligned. The practical disclosure-and-benchmark mechanism through which much corporate climate data flows. 17 clauses, 13 in-scope, 39 directives. Vendor-open (CDP) with attribution
- Licensing: ISO 50001 (paywalled ISO, paraphrase + trademark) · SBTi + CDP (vendor-open with attribution). Companions cross-walk ISO 50001 ↔ ISO 14001 + ISO 14064 + GHG Protocol (energy → emissions); SBTi ↔ GHG Protocol (the inventory foundation) + CDP + TCFD + CSRD/ESRS + ISSB IFRS S2; CDP ↔ GHG Protocol + TCFD + ISSB + SBTi + CSRD/ESRS (the disclosure integration point). cajeX now covers corporate sustainability from energy management through science-based targets to environmental disclosure + scoring
June 12, 2026
Automotive QMS + risk-assessment techniques — IATF 16949 + ISO 31010 + IEC 61882 HAZOP (3 frameworks, 225 directives)
- Three frameworks adding automotive quality-management depth plus a reusable risk-assessment-technique toolbox that any industry can draw on. They complement the ISO 26262 (functional safety), ASPICE (process), ISO/SAE 21434 (cyber), and ISO 31000 (risk principles) already in cajeX
- **IATF 16949:2016 — Automotive Quality Management System** — the global QMS standard every automotive supplier certifies to. Built on ISO 9001 with automotive-sector additions: the core tools (APQP Advanced Product Quality Planning, PPAP Production Part Approval Process, FMEA, MSA Measurement Systems Analysis, SPC Statistical Process Control, Control Plans), customer-specific requirements, supplier development, lot traceability, error-proofing, and 8D problem solving. 43 clauses, 32 in-scope, 96 directives. Industry-membership — paraphrase + IATF trademark notice
- **ISO/IEC 31010:2019 — Risk Assessment Techniques** — the how-to toolbox companion to ISO 31000's risk-management principles. Catalogues 30+ concrete techniques with guidance on when each applies: elicitation (brainstorming, Delphi), identification (FMEA, HAZOP, SWIFT, scenario analysis), analysis (Fault/Event Tree Analysis, bow-tie, LOPA, Monte Carlo, Bayesian networks, Markov), and evaluation (risk matrix, cost-benefit, multi-criteria analysis, ALARP). 30 clauses, 18 in-scope, 54 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- **IEC 61882:2016 — Hazard and Operability Studies (HAZOP)** — the canonical standard for the HAZOP method: a structured, facilitated team technique that applies guide words (NO, MORE, LESS, REVERSE, OTHER THAN, …) to design parameters to systematically surface deviations from design intent, then traces causes, consequences, safeguards and actions. The definition → preparation → examination → documentation procedure with a multidisciplinary team. The deep-dive on one of ISO 31010's techniques; widely used in process, OT, and functional-safety contexts. 26 clauses, 25 in-scope, 75 directives. Paywalled IEC — paraphrase + trademark notice
- Licensing: IATF 16949 (industry-membership, paraphrase + trademark) · ISO 31010 + IEC 61882 (paywalled ISO/IEC, paraphrase + trademark). Companions cross-walk IATF 16949 ↔ ISO 9001 (the base QMS) + ISO 26262 + ASPICE + ISO/SAE 21434 (the automotive engineering stack); ISO 31010 ↔ ISO 31000 (the parent risk framework) + COSO ERM + the safety frameworks that use FTA/FMEA; IEC 61882 ↔ ISO 31010 + IEC 61511 + IEC 61508 (HAZOP feeding SIL determination). cajeX now covers automotive quality end-to-end alongside a cross-industry risk-technique reference
June 12, 2026
Public-sector cloud + CII cyber — StateRAMP + TX-RAMP + Singapore CCoP 2.0 + France SecNumCloud (4 frameworks, 249 directives)
- Four government cloud-authorization + critical-infrastructure cyber programs, extending cajeX's public-sector coverage beyond the US-federal FedRAMP + CMMC already in the catalog to US-state, Singapore-CII, and French-sovereign-cloud
- **StateRAMP — State Risk and Authorization Management Program** — the US state + local government (SLED) counterpart to FedRAMP. Built on NIST 800-53 baselines (Low / Moderate / High), with a Security Snapshot → Progressing → Ready → Authorized maturity model, 3PAO assessment + POA&M + continuous monitoring, an Authorized Product List, and FedRAMP reciprocity. 25 clauses, 20 in-scope, 60 directives. Vendor-open (StateRAMP) with attribution
- **Texas TX-RAMP** — the State of Texas cloud-security certification, administered by the Texas DIR and **statutorily required** by Texas Gov Code §2054.0593 for state-agency cloud procurement. A 2-level model (Level 1 low-impact, Level 2 moderate/high) built on NIST 800-53, with a recognition path that fast-tracks FedRAMP- and StateRAMP-authorized products. 28 clauses, 21 in-scope, 63 directives. Public domain (Texas DIR)
- **Singapore CCoP 2.0 — Cybersecurity Code of Practice for Critical Information Infrastructure** — the mandatory CII cyber requirements issued by the Cyber Security Agency of Singapore (CSA) under the Cybersecurity Act 2018, covering CII Owners across 11 critical sectors. Six domains (governance, identify, protect, detect, respond/recover, resilience) with a distinctive **2-hour incident notification to CSA** plus mandatory cyber exercises + audits. 31 clauses, 25 in-scope, 75 directives. Public domain (CSA)
- **France ANSSI SecNumCloud** — the French national cloud-security qualification (v3.2). Unique for combining strong technical security controls (built on ISO 27001/27002/27017, reinforced) with **digital-sovereignty requirements**: immunity to extraterritorial law (e.g. the US CLOUD Act), EU data localisation, and EU-controlled operations — the security-plus-sovereignty model that distinguishes it from FedRAMP/StateRAMP and that shaped the EU Cloud Services Scheme (EUCS) debate. Required/preferred for sensitive French public-sector + OIV/OSE cloud. 22 clauses, 17 in-scope, 51 directives. Public domain (ANSSI)
- Licensing: StateRAMP (vendor-open with attribution) · TX-RAMP + Singapore CCoP + France SecNumCloud (public-domain government publications). Companions cross-walk StateRAMP + TX-RAMP ↔ FedRAMP + NIST 800-53 + NIST 800-37 RMF (the shared US control + reciprocity foundation); Singapore CCoP ↔ NIST CSF 2.0 + IEC 62443 (OT) + Singapore PDPA + MGAIF; France SecNumCloud ↔ ISO 27001/27017 + NIS2 + EU CRA. cajeX now covers government cloud + critical-infrastructure cyber across US-federal, US-state, Singapore, and France
June 12, 2026
Privacy jurisdictions — UK GDPR + DPA 2018, Switzerland nFADP, Singapore PDPA, Saudi PDPL (4 frameworks, 258 directives)
- Four national data-protection regimes that complete cajeX's privacy-jurisdiction coverage alongside the EU GDPR already in the catalog. Each is a distinct framework — not a duplicate of EU GDPR — because the divergences (regulator, transfer mechanism, breach threshold, penalties, age of consent, criminal liability) are exactly what a multinational compliance team has to track per-country
- **UK GDPR + Data Protection Act 2018** — the post-Brexit UK regime, ICO-regulated. Mirrors EU GDPR's principles, lawful bases, data-subject rights, DPbDD, breach notification (72h to the ICO) and DPIAs, but with UK divergences: age of consent 13 (not 16), UK-specific exemptions (DPA 2018 Schedules), and UK international-transfer mechanisms (the IDTA + the UK Addendum to EU SCCs, plus UK adequacy regulations). DPA 2018 Parts 3–4 (law-enforcement + intelligence-services processing) registered out-of-scope. 27 clauses, 20 in-scope, 60 directives. Public domain (Open Government Licence)
- **Switzerland nFADP — revised Federal Act on Data Protection** (in force Sept 2023) — GDPR-aligned to keep Switzerland's EU adequacy, but with notable Swiss specifics: it protects only natural persons (dropped legal-person data), carries **personal criminal liability** (fines up to CHF 250,000 on responsible individuals, not the company), has no general DPO mandate, requires a Swiss representative for foreign controllers, and follows a generally-permitted processing model rather than GDPR's lawful-basis-required default. FDPIC-regulated. 24 clauses, all in-scope, 72 directives. Public domain
- **Singapore PDPA — Personal Data Protection Act** (2012, major 2020 amendments) — PDPC-regulated, structured as 11 Data Protection Obligations (consent, purpose limitation, notification, access/correction, accuracy, protection, retention, transfer, accountability + mandatory DPO, plus the 2020-added breach notification and data portability). Breach notification to the PDPC within 3 days; penalties up to 10% of Singapore turnover or S$1m. Pairs with the Singapore Model AI Governance framework already in cajeX. 28 clauses, 22 in-scope, 66 directives. Public domain
- **Saudi Arabia PDPL — Personal Data Protection Law** (enforced Sept 2024) — SDAIA-regulated (the authority that uniquely combines data protection + AI), part of Vision 2030. Principles + data-subject rights + controller obligations (RoPA, DPIA, DPO, 72h breach notification) with Saudi specifics: enhanced rules for health + credit data, the evolution from strict data-localisation to a risk-based cross-border transfer regime, and criminal penalties (fines to SAR 5m, imprisonment for unlawful sensitive-data disclosure). 31 clauses, 20 in-scope, 60 directives. Public domain
- Licensing: all four public-domain legislation (UK OGL, Swiss Confederation, Singapore Statutes, SDAIA). Companions cross-walk each ↔ EU gdpr-2016 (the comparison baseline) + iso-27701-2025 (PIMS) + nist-privacy-framework; Singapore PDPA ↔ singapore-mgaif (the AI-governance companion). cajeX now covers EU + UK + Swiss + Singapore + Saudi data-protection law — a multinational compliance team can map one directive set across all five regimes with the per-jurisdiction divergences called out
June 12, 2026
Post-quantum migration — NSA CNSA 2.0 + NIST IR 8547 + ENISA PQC (3 frameworks, 219 directives)
- Three operational post-quantum-cryptography migration frameworks — the *how-and-when* companions to the FIPS 203/204/205 algorithm specs already in cajeX (nist-pqc-2024). Where those define the quantum-resistant algorithms, these define the migration: which current algorithms are being retired, by what deadlines, and how to plan the transition (cryptographic inventory + crypto-agility + protocol migration). Driven by the harvest-now-decrypt-later threat — adversaries collecting encrypted data today to decrypt once a cryptographically-relevant quantum computer exists
- **NSA CNSA 2.0 — Commercial National Security Algorithm Suite 2.0** — the NSA's PQC mandate + binding migration timeline for U.S. National Security Systems. The approved suite (ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, SHA-384/512, AES-256) plus per-product-category deadlines (software/firmware signing, web/cloud, networking, OS) culminating in exclusive PQC use by 2033. Crypto-agility + cryptographic inventory as the core engineering requirements. 24 clauses, all in-scope, 72 directives. Public domain (NSA)
- **NIST IR 8547 — Transition to Post-Quantum Cryptography Standards** — the civilian / general-industry transition guidance. The binding planning horizon: quantum-vulnerable public-key crypto (RSA, ECDSA, EdDSA, DH, ECDH) **deprecated after 2030, disallowed after 2035**. Transition planning (cryptographic inventory, risk-based prioritisation of long-lived secrets, crypto-agility, hybrid approaches) + protocol migration (TLS, IPsec, SSH, S/MIME, PKI / X.509 certificates). 25 clauses, all in-scope, 75 directives. Public domain (NIST)
- **ENISA Post-Quantum Cryptography** — the EU's PQC guidance + transition strategy. Aligns with the NIST algorithms but takes a distinctive **hybrid-first** position (classical + PQC combined during transition, to hedge against PQC implementation flaws) plus an algorithm-diversity hedge (interest in Classic McEliece / FrodoKEM for high-assurance use). Anchored by the 2024 EU Coordinated PQC Roadmap Recommendation and connected to NIS2 + the EU Cyber Resilience Act. 24 clauses, all in-scope, 72 directives. Public domain (ENISA)
- Licensing: all three public-domain government/agency publications (NSA, NIST, ENISA). Companions cross-walk all three ↔ nist-pqc-2024 (the FIPS 203/204/205 algorithms they mandate/transition to) + fips-140-3 (crypto module validation) + NIST SP 800-208 (stateful hash-based signatures); CNSA 2.0 ↔ NIST IR 8547 (NSS mandate vs civilian guidance — note CNSA prefers pure-PQC where ENISA prefers hybrid); ENISA ↔ NIS2 + EU CRA (the EU regulatory drivers). cajeX now covers the post-quantum transition end-to-end — the algorithms (nist-pqc-2024) plus the US-NSS, US-civilian, and EU migration mandates
June 12, 2026
AI standards depth — ISO 23053 + ISO 5259 + ISO 5338 + IEEE 7000 (4 frameworks, 261 directives)
- Four AI engineering standards that put concrete technical structure under the AI governance frameworks already in cajeX (EU AI Act, ISO 42001, NIST AI RMF, OECD AI Principles). Where those say *what* to govern, these define *how* the AI system is actually built — its architecture, its data quality, its lifecycle, and its ethics-by-design process
- **ISO/IEC 23053:2022 — Framework for AI Systems Using Machine Learning** — the generic AI/ML system reference model: the canonical ML pipeline (data acquisition → pre-processing → feature engineering → training → tuning → evaluation → deployment → monitoring → retraining) + the AI system component architecture + ML approaches (supervised / unsupervised / reinforcement). The architectural companion to ISO 42001 + ISO 22989 — the lifecycle the EU AI Act and NIST AI RMF implicitly assume. 29 clauses, 20 in-scope, 60 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- **ISO/IEC 5259 series — Data Quality for Analytics and Machine Learning** (parts 1–5, 2024) — the formal framework for the #1 determinant of AI performance + fairness: data quality. Quality measures (accuracy, completeness, consistency, representativeness / balance, traceability, currentness, …), the data-quality management process, the data-quality lifecycle, and data-quality governance. The standard behind EU AI Act Article 10 (training / validation / testing data governance + bias examination). 27 clauses, 25 in-scope, 75 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- **ISO/IEC 5338:2023 — AI System Life Cycle Processes** — extends the ISO/IEC/IEEE 12207 + 15288 software + systems lifecycle (shipped last in cajeX) with the AI-specific processes those general standards don't cover: continuous validation (AI behaviour validated continuously, not once), data management across the lifecycle, model lifecycle management (registry, retraining triggers), and AI-specific operation monitoring (drift, degradation). Treats data + model + code as first-class lifecycle artifacts. 32 clauses, 24 in-scope, 72 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- **IEEE 7000-2021 — Model Process for Addressing Ethical Concerns During System Design** — a concrete, auditable process for engineering ethics into system design (Value-Based Engineering): elicit + prioritise stakeholder values (including society + environment), translate them into Ethical Value Requirements (EVRs), and trace them through design + verification with an ethics case (analogous to a safety case). The flagship of the IEEE 7000-series; applicable to any system, heavily used for AI. 24 clauses, 18 in-scope, 54 directives. Industry-membership — paraphrase + IEEE trademark notice
- Licensing: ISO 23053 + ISO 5259 + ISO 5338 (paywalled ISO/IEC, paraphrase + trademark) · IEEE 7000 (IEEE industry-membership, paraphrase + trademark). Companions cross-walk ISO 23053 ↔ ISO 42001 + ISO 22989 + NIST AI RMF + EU AI Act (the architecture under the governance); ISO 5259 ↔ EU AI Act Art. 10 + ISO 42001 + DAMA DMBOK; ISO 5338 ↔ ISO 12207/15288 + ISO 42001 + ISO 23894 (the AI extension of the lifecycle); IEEE 7000 ↔ ISO 42001 + EU AI Act + OECD AI Principles + ISO 42005. cajeX now covers AI from governance principle down to the concrete engineering of architecture, data quality, lifecycle, and ethics-by-design
June 12, 2026
Secure-SDL + engineering-process maturity — BSIMM + Microsoft SDL + CMMI v3 + ISO 12207/15288 + ISO 27034 (5 frameworks, 312 directives)
- Five frameworks deepening the secure-development + engineering-process-maturity layer. They complement (not duplicate) the **NIST SSDF** + **OWASP SAMM** + **OWASP DSOMM** already in cajeX: SSDF/SAMM are prescriptive maturity models, BSIMM is the descriptive peer-benchmark, Microsoft SDL is the foundational process model, CMMI + ISO 12207/15288 are the broader engineering-process backbone, and ISO 27034 is the ISO application-security control framework
- **BSIMM v15 (Building Security In Maturity Model)** — the descriptive software-security maturity model built from observing 100+ real organisations (so it measures what firms *do*, not what they *should* do). 4 domains (Governance, Intelligence, SSDL Touchpoints, Deployment) × 12 practices × ~120 activities at 3 levels; v15 adds supply-chain + AI/ML + shift-everywhere signals. Use it to benchmark your program against peers. 19 clauses, 14 in-scope, 42 directives. Vendor-open (Black Duck, CC BY-SA) with attribution
- **Microsoft Security Development Lifecycle (SDL)** — the foundational secure-development process that influenced SSDF + SAMM. The 10 SDL Practices (security standards + governance, proven languages/frameworks, threat modeling, crypto standards, supply-chain security, engineering-environment hardening, security testing, operational platform security, monitoring + response, training) + STRIDE threat modeling + the classic 7-phase model + SDL-Agile mapping. 24 clauses, 21 in-scope, 63 directives. Vendor-open (Microsoft) with attribution
- **CMMI for Development v3.0 (ISACA)** — the canonical software + systems engineering process-maturity model. 4 capability areas (Doing / Managing / Enabling / Improving) spanning ~20 Practice Areas; ML1–ML5 maturity levels; appraisals rate organisations; v3.0 adds Safety + Security as first-class practice areas plus stronger Agile/DevOps integration. 27 clauses, 23 in-scope, 69 directives. Industry-membership — paraphrase + ISACA trademark notice
- **ISO/IEC/IEEE 12207 + 15288 — Software & Systems Life Cycle Processes** (12207:2017 software + 15288:2023 systems). The foundational, harmonised process framework (Agreement / Organizational Project-Enabling / Technical Management / Technical process groups) that CMMI, ASPICE and ISO 33000 all assess against. The reference model under most engineering-process standards. 29 clauses, 25 in-scope, 75 directives. Paywalled ISO/IEC/IEEE — paraphrase + trademark notice
- **ISO/IEC 27034 — Application Security** — the ISO process framework for application security: the Application Security Management Process (ASMP), Organizational + Application Normative Frameworks (ONF/ANF), and reusable, verifiable **Application Security Controls (ASCs)** with a defined level-of-trust and assurance-prediction model. Integrates with the ISO 27001 ISMS; the ISO complement to SSDF + SAMM + BSIMM + Microsoft SDL. 28 clauses, 21 in-scope, 63 directives. Paywalled ISO/IEC — paraphrase + trademark notice
- Licensing: BSIMM + Microsoft SDL (vendor-open with attribution) · CMMI (ISACA industry-membership, paraphrase + trademark) · ISO 12207/15288 + ISO 27034 (paywalled ISO/IEC/IEEE, paraphrase + trademark). Companions cross-walk BSIMM ↔ NIST SSDF + OWASP SAMM + OpenSSF Scorecard + SLSA (descriptive vs prescriptive); Microsoft SDL ↔ SSDF + SAMM + STRIDE; CMMI ↔ ISO 9001 + ISO 25010 + ASPICE + ISO 12207/15288; ISO 27034 ↔ ISO 27001 + ISO 27002 + SSDF + OWASP ASVS. cajeX now covers the secure-development + engineering-process-maturity space from descriptive benchmark through prescriptive practice to formal lifecycle process and application-security controls
June 11, 2026
Aerospace companions — DO-254 + DO-326A/ED-202A family + ARP 4761A (3 frameworks, 210 directives)
- Three aerospace companion frameworks landing alongside the AL pharma GxP cluster as part of the v3 expansion backlog. Together they complete the **safety + security + assurance** triad that pairs with **DO-178C** (software), **ARP 4754A** (system development), and the **ISO 26262 / IEC 61508 / IEC 61511** functional-safety stack already in cajeX
- **DO-254 / ED-80 — Design Assurance Guidance for Airborne Electronic Hardware** (RTCA/EUROCAE 2000, with FAA Order 8110.105A + EASA CM-SWCEH-001 Issue 02 supplements). The hardware-side companion to DO-178C — covers FPGAs, PLDs, ASICs and complex custom microcoded components on aircraft. Same DAL A–E scale; 5 planning documents (PHAC + HDP + HVVP + HCMP + HPAP); 4 design lifecycle phases (Requirements → Conceptual → Detailed → Implementation); validation (right requirements?) + verification (correct implementation?) with independence at Levels A/B; Simple-vs-Complex Hardware distinction drives rigor. 34 clauses, 23 in-scope, 69 directives. Industry-membership — paraphrase + RTCA/EUROCAE trademark notice
- **DO-326A / ED-202A + DO-356A + DO-355 + DO-379 — Airworthiness Security Process family** (RTCA/EUROCAE 2014 onwards). The standards that make **aircraft cybersecurity part of airworthiness certification**. DO-326A specifies PSecAC (Plan for Security Aspects of Certification) + Aircraft Security Risk Assessment (ASRA) + Security Verification. DO-356A supplies threat-modelling methods, architecture patterns, verification techniques. DO-355 covers continued airworthiness security (vulnerability disclosure, security updates, A-ISAC coordination). DO-379 structures verification completeness. FAA AC 20-205A + EASA AMC 20-42 formal adoption. 34 clauses, 28 in-scope, 84 directives. Industry-membership — paraphrase + RTCA/EUROCAE trademark notice
- **ARP 4761A — Safety Assessment Process** (SAE 2023, revising 1996). The system-safety partner to ARP 4754A — formalises the **FHA → PSSA → SSA cascade** that allocates Design Assurance Levels (DAL) to software + hardware items. Aircraft-level FHA + System-level FHA + classification (Catastrophic / Hazardous / Major / Minor / NoEffect); FTA + Markov + FMEA / FMES; Common Cause Analysis (Particular Risk + Zonal Safety + Common Mode); **new in revision A**: Model-Based Safety Analysis (MBSA), updated systematic-capability methods, expanded human factors. Satisfies FAA AC 25.1309-1B + EASA CS 25.1309. 32 clauses, 19 in-scope, 57 directives. Industry-membership — paraphrase + SAE trademark notice
- Licensing: all three industry-membership (RTCA / EUROCAE / SAE) — paraphrase + trademark notice. Companions cross-walk DO-254 ↔ DO-178C (HW + SW DAL siblings) + ARP 4754A + ARP 4761A + DO-330 (tool qualification); DO-326A ↔ DO-178C + DO-254 + ARP 4754A + ISO/SAE 21434 (the automotive parallel) + NIST SP 800-30; ARP 4761A ↔ ARP 4754A (development partner) + ISO 26262 (HARA + ASIL automotive analog) + IEC 61508 (generic functional-safety parent). cajeX now covers the airworthiness certification + safety assessment + product cybersecurity workflow end-to-end alongside the existing aerospace stack (AS9100D + DO-178C + ARP 4754A)
June 11, 2026
A friendlier message when your workspace reaches its AI budget — now across every AI feature
- When your workspace reaches its monthly or weekly AI budget, AI features now pause with a clear, supportive message that tells you **when it frees up** — the start of next month for the monthly budget, or over the coming days for the rolling weekly window — instead of a terse error
- The message always offers two ways to keep going now: a workspace admin can add a **paid-usage budget** under Settings → AI, or switch to a **lighter model** that stretches the remaining budget further
- This budget check now applies uniformly to **all** AI features — knowledge-base, directive, and project generation, and document extraction — not just AI review. Work already in progress always finishes; only new jobs wait for the budget to refresh
June 11, 2026
Pharma GxP depth — 21 CFR Part 11 + GAMP 5 2e + ICH Q9 R1 + ICH Q10 + EU GMP Annex 15 + ISO 81001-1 (6 frameworks, 412 directives)
- Six frameworks landing the pharma GxP + digitised-pharma + medical-IT-network stack in cajeX. Pairs with the EU GMP Vol.4 + Annex 11 + ISO 13485 + IEC 62304 + ISO 14971 already in catalog. cajeX now covers digitised pharma + medical-device-on-hospital-network end-to-end — regulation (Part 11, Annex 15) + validation methodology (GAMP 5) + risk + quality system (ICH Q9/Q10) + medical IT-network risk (ISO 81001)
- **21 CFR Part 11 — Electronic Records; Electronic Signatures (FDA)** — the bedrock spec for digitised pharma/medical-device/biotech operations under FDA jurisdiction. Subpart B §11.10(a)-(k) — the 11 closed-system controls (validation, accurate copies, retention, access, audit trails, operational + authority + device + training checks, accountability, documentation) + §11.30 open-systems + §11.50 signature manifestation + §11.70 signature/record linking + Subpart C electronic signatures (§11.100 general, §11.200 components, §11.300 ID controls). 25 clauses, 21 in-scope, 63 directives. Public domain (FDA)
- **ISPE GAMP 5 Second Edition (2022)** — the industry-standard methodology for validating computerised systems against 21 CFR Part 11 + EU GMP Annex 11. 2e modernised with critical thinking, agile/DevOps in regulated software, cloud/SaaS shared-responsibility, AI/ML in GxP, ICH Q9 R1 alignment, ALCOA+ data integrity. Categories 1/3/4/5 drive validation rigor; lifecycle (Concept → Project → Operation → Retirement) with URS-FS-CS-DS specification + IQ/OQ/PQ. 30 clauses, 25 in-scope, 75 directives. Industry-membership — paraphrase + ISPE trademark notice
- **ICH Q9(R1) — Quality Risk Management (2023)** — the harmonised QRM methodology for pharma. Q9(R1) finalised Jan 2023 added subjectivity in risk assessment, formality calibration (informal/structured/formal as a spectrum), risk-based decision-making criteria, product availability risk. Process cycle (identify → analyse → evaluate → reduce → accept → communicate → review) + 5 formal tools (FMEA/FMECA, FTA, HACCP, HAZOP, PHA) + Annex II 14 application areas. 30 clauses, 23 in-scope, 69 directives. Public domain (ICH)
- **ICH Q10 — Pharmaceutical Quality System (2008)** — the strategic PQS spec that overlays cGMP. 4 lifecycle stages (Development → Tech Transfer → Commercial Manufacturing → Discontinuation) × 4 PQS elements (Process Performance + Product Quality Monitoring, CAPA, Change Management, Management Review) + 2 enablers (Knowledge Management + ICH Q9 QRM) + objectives (product realisation, state of control, continual improvement). 23 clauses, 19 in-scope, 56 directives. Public domain (ICH)
- **EU GMP Annex 15 — Qualification and Validation (in force October 2015)** — the EU regulation establishing requirements for qualification of equipment/facilities/utilities + validation of processes/cleaning/transport/packaging/CSV/analytical methods. URS → DQ → IQ → OQ → PQ qualification ladder + Process Validation (Traditional 3-batch / CPV / Hybrid / Ongoing) + cleaning validation with Health-Based Exposure Limits (HBEL, 2015 expansion) + risk-based + lifecycle (ICH Q9 R1 + Q10) integration throughout. 27 clauses, 26 in-scope, 78 directives. Public domain (EU)
- **ISO 81001-1:2021 (incl. IEC 80001 family + IEC 81001-5-1:2021)** — risk management for IT networks incorporating medical devices. Safety + effectiveness + security as the key-property triad; joint HDO ↔ Medical Device Manufacturer risk model (uniquely cross-organisational); IT-network characterisation as a regulated artefact; IEC 81001-5-1 cybersecurity companion (pre-market + post-market activities aligning with FDA + EU MDR cyber expectations). 34 clauses, 24 in-scope, 71 directives. Paywalled ISO/IEC — paraphrase + ISO/IEC trademark notice
- Licensing: 21 CFR Part 11 + ICH Q9 R1 + ICH Q10 + EU GMP Annex 15 (public domain — FDA, ICH, EU Commission) · GAMP 5 (ISPE industry-membership, paraphrase + trademark notice) · ISO 81001-1 (ISO/IEC paywalled, paraphrase + trademark notice). Companions cross-walk Part 11 ↔ Annex 11 (EU equivalent) + GAMP 5 (validation methodology) + ISO 13485 + IEC 62304 + ISO 27001 already in cajeX; GAMP 5 ↔ ICH Q9 R1 + ICH Q10 + Annex 15; Annex 15 ↔ EU GMP Vol.4 + ICH Q2 (analytical method validation) + ISO 14971; ISO 81001 ↔ IEC 62304 + ISO 14971 + ISO 13485 + AAMI TIR57 + FDA pre-market/post-market cyber guidance
June 11, 2026
Fixed: a canceled workspace now correctly returns to the Free plan
- When a paid subscription ended (you cancelled it and the period elapsed), the workspace previously kept its paid plan and entitlements instead of dropping to **Free**. It now correctly returns to Free when the subscription ends — matching the "will drop to Free" notice shown at cancellation
- On the billing page, the plan cards for an ended subscription now treat **Free** as your current plan and present the paid tiers as **selectable to resubscribe**, instead of mislabelling the old (canceled) tier as current with Upgrade/Downgrade buttons
June 10, 2026
Fixed: billing showed "Cancellation scheduled" for a workspace whose subscription had already ended
- When a subscription was fully **canceled**, the billing page could still show a **Cancellation scheduled / Keep my subscription** prompt — and clicking it failed, because an ended subscription can't be un-cancelled. The workspace now shows a clear **Your subscription has ended** message with a prompt to **choose a plan to resubscribe**
- Cancelling a subscription now records the exact date paid access ends, so the banner shows a real date instead of a blank — and an already-ended subscription returns an actionable message instead of a generic error
June 10, 2026
Fixed: long PDFs were truncated to 50 pages during extraction
- Document extraction split large PDFs into a fixed number of page-batches that capped coverage at **50 pages** — any document longer than that had its remaining pages silently dropped, so AI review never saw them. Extraction now sizes itself to the document's actual page count and covers the whole file (up to a 200-page ceiling)
- If a document does exceed the ceiling, or its page count can't be read, the extracted text now carries a clear notice at the top instead of truncating silently — so you always know whether the full document was processed
June 9, 2026
Workspace model selection now applies — and the cap units are clearer
- The **Model** you pick under **Workspace → Settings → AI** now actually drives your AI jobs. Previously the selection was saved but ignored at run time (jobs used the platform default), so the page could show one model while a different one ran. Your choice now overrides the platform default for every job type
- The model card shows the **true** effective model — including when different job types run different models — instead of always showing the plan default
- Each model in the dropdown now shows its **cap cost multiplier** (e.g. *Opus 4.8 — 19× the default's cap cost*), and the usage meters explain that **effective tokens** are cost-equivalent to the default model (MiniMax M3 = 1×). This makes it obvious why a premium model draws down your monthly/weekly cap much faster than the raw token count suggests
June 9, 2026
Fixed: AI Settings — BYOK form layout and the per-model usage table
- On **Workspace → Settings → AI**, the **Bring Your Own Key** fields (endpoint, model ID, API key) were mis-styled — labels collided with unformatted inputs. The form now renders with proper labels and full-width fields
- The **Usage by model this month** table was querying the wrong token columns and silently failed to load. It now shows your per-model call counts, raw and effective tokens, cache-hit rate, and paid spend
June 9, 2026
Fixed: cramped buttons on AI-generation dialogs and other screens
- The **Generate** button in **AI Generate Project** (and its later steps) rendered too small and tightly-packed because it was missing its base button styling. It now matches the standard button size and spacing across every step
- Applied the same fix to other action buttons that had the same issue — including **AI review finalize**, several **empty-state retry buttons** (Code, PR review, programs, reviews, compliance rules), and the **Generate** button in **AI Generate Knowledge Base**
June 9, 2026
Clearer document extraction status
- A document that has never been processed for text extraction now shows a **Not extracted** tag, instead of an empty space that looked identical to a blank cell. You can tell at a glance which documents still need extracting and trigger it from the document list
June 5, 2026
Clearer AI review completion emails
- The “review is ready” email now names the **project** you reviewed (e.g. “your review for *Headless CMS Content Flow*”) instead of mislabelling it with the findings count
- If a review finished **partial** (some sections couldn't be completed), the email now says so and suggests re-running for full coverage — previously a partial run was emailed as a clean completion
June 5, 2026
Fixed: estimated AI cost was overstated for some models
- The **Est. Cost** figures on the AI Usage page (and the cost total in consumption reports) were overstated for the newer **MiniMax M2.7** model — it was being priced at a more expensive model's rate. Cost estimates now use each model's actual catalogue price, so a typical M2.7 review reads cents rather than dollars
- This was display-only: your **actual billed usage** (paid-usage metering) always used the correct price, so no charges were affected. Token counts, budget meters, and cap percentages were also already correct
June 4, 2026
Fixed: AI review on large workspaces could report no directives
- Starting an AI review in a workspace with a large approved-directive library (hundreds across several frameworks) could fail with **“No approved directives found matching the selected filters”** even though the chosen framework clearly had approved directives. The review now considers your **entire** approved library when applying framework/category/type filters, so the right directives are always in scope
- Same fix hardens duplicate-detection when generating directives in large workspaces — overlap checks now compare against every live directive, not just the most recent batch
June 4, 2026
Clearer status for partial AI reviews
- When an AI review finishes with some batches incomplete, the run now shows simply **Partial** instead of always reading **Partial (Rate Limited)** — the old label guessed a cause that often wasn't the real one. Open the run to see the actual reason for the incomplete batch
- Reviews are also more resilient: a transient upstream model error on a single batch now retries automatically instead of dropping the whole run to partial, so more reviews come back complete
June 3, 2026
Monthly consumption reports — a PDF snapshot of your workspace
- Subscription workspaces now get a **monthly consumption report** as a downloadable PDF, listed under **Workspace > Settings > Billing**. It's generated automatically at each billing-cycle rollover and kept indefinitely
- Each report covers **AI usage** (effective tokens vs cap, premium spend, cache hit rate, per-model and per-job-type breakdowns), **workspace activity** with month-over-month change (projects, findings, documents, sessions, directives, KB entries, members), a **billing summary**, and **plan utilization**
- It's the portable end-of-month snapshot to hand to finance or archive for compliance — the same numbers you see live in your usage view, frozen as of cycle close. Authoritative charges still live on your Stripe invoice, which the report links to
June 2, 2026
AI token usage meters now reflect real usage
- The monthly + weekly token meters in Workspace AI Settings (and the overview tab) now move with your actual AI usage. Each review or generation accrues **cost-equivalent (effective) tokens** — a cheaper model consumes your budget more slowly than a more expensive one
- Usage accrues from today forward — nothing is backdated, so you start the month with a clean meter
- If you've approved a paid usage budget, calls that run past your standard cap now draw from that budget and appear as paid usage in your breakdown. No budget = the cap is a hard stop until next month, exactly as described when you set up your workspace
June 2, 2026
Pricing now in your local currency — EUR, GBP, and DKK alongside USD
- The pricing page now shows prices in **USD, EUR, GBP, or DKK**. We default to your region automatically and you can switch with the currency selector — your choice is remembered. Prices are VAT-inclusive in EUR/GBP/DKK markets
- **Updated plan pricing** (USD): Basic $11.99, Pro $49.99, Team $79.99, Enterprise $119.99 per user/month. Annual billing saves ~17%. These reflect the expanded AI model catalogue and capabilities added over the last month
- Your currency locks to your subscription when you first subscribe, so your bill stays predictable. Existing subscriptions are unaffected — you keep your current price until you change plans
- Local pricing examples: Pro is €45.99 / £39.99 / 399 kr per user/month; Enterprise is €109.99 / £95.99 / 899 kr
June 2, 2026
Workspace usage view now shows live AI token usage + per-model breakdown
- **Workspace > Admin > Overview** has a new row: **AI Tokens This Month (effective)** — your live month-to-date token use against the workspace cap (per-seat × seat count). It's the same number the dispatcher uses for routing decisions, so what the meter shows is what enforcement will do
- **Workspace AI Settings** has a new **Usage by model** table — see exactly how many calls + tokens + cache hits + paid spend each (provider, model) combination consumed this month. Sorted by effective tokens (heaviest first) so the hot path is obvious
- **Cache hit rate** is surfaced workspace-wide and per row. Cache hits are dramatically cheaper than fresh inference, so a 60%+ hit rate on repeat prompts is a meaningful margin lever
- **BYOK rows** (Enterprise) are shown info-only with $0 — those tokens went to your own provider account, not through cajeX's billing
June 1, 2026
New Workspace AI Settings tab — pick your model, see your usage, approve paid overflow
- The AI tab in Workspace Settings used to be Enterprise-only and was BYOK-focused. From today it shows for **every plan** and unifies model selection, cap visibility, and paid usage overflow in one place
- **Pick your model** — choose from the 7-model catalogue (Llama 3.2, Qwen3, gpt-oss-120b, MiniMax M2.7, Kimi K2, Claude Haiku, Claude Sonnet). The dropdown labels each model as either burning the cap faster (more expensive) or stretching it further (cheaper), so you can pick the right trade-off for your workload
- **See your usage** — live meters for monthly + weekly token usage, with the same numbers cajeX's dispatcher uses to make routing decisions. No more guessing what 'review #15' will cost
- **Approve paid usage overflow** — set an optional monthly USD budget. When your standard cap is exhausted, AI calls draw from this budget at the metered rate. Leave it blank to opt out entirely
- **Kill-switch banner** — when cajeX has a platform-wide model override active (rare, used during provider outages), the workspace sees a non-dismissible banner explaining what's happening and the expected restore time
- BYOK provider keys are still Enterprise-only and remain unchanged for existing Enterprise customers; a follow-up release collapses the 5-provider key table into a single OpenAI-compatible config
June 1, 2026
AI reviews on paid plans now run against a monthly token budget
- Paid plans (Basic, Pro, Team, Enterprise) used to cap AI reviews by count — for example Basic allowed 15 review runs per calendar month, regardless of how big each review was. From today, paid plans are bounded by a **monthly token budget** per seat that scales with your seat count, so a small review costs less of your budget than a large one and the cap reflects the actual work the model did rather than just the number of times you clicked Run
- Per-seat monthly token budgets: Basic 3M, Pro 10M, Team 20M, Enterprise 28M. Your workspace's effective budget = per-seat × active seats — so a 5-seat Pro workspace has a 50M monthly budget. Effective tokens use cost-equivalent accounting: a cheaper model (Llama 3.2, Qwen3) consumes the budget more slowly than a more expensive one (Kimi K2, Claude Opus)
- A 7-day sliding session window also applies (Basic 1.5M, Pro 4M, Team 7M, Enterprise 10M per seat). This prevents one burst from exhausting the monthly budget on day 1 — but it slides forward continuously so capacity comes back as the window rolls
- Free plan unchanged: the lifetime 3-review trial still applies, and the lifetime cap is the only block
- Mid-job protection: if a review is partway through and you hit your cap, that in-progress job runs to completion (you don't get stuck with a half-finished result). New jobs after the cap will be blocked until the next month starts or you approve a paid usage budget in workspace settings
May 2026
May 31, 2026
Telecom — GSMA NESAS (+ 3GPP SCAS) + 3GPP TS 33.501 5G security architecture (2 frameworks, 141 directives)
- Two paired telecom-security frameworks landing the mobile-network-equipment + 5G-system security stack in cajeX. **TS 33.501** is the canonical 5G system security architecture (what 5G must do); **NESAS+SCAS** is how vendors prove their boxes correctly implement that architecture (the assurance side). The two are designed to be consumed together — operator + regulator pick TS 33.501 for system design + NESAS+SCAS for vendor procurement
- **GSMA NESAS (Network Equipment Security Assurance Scheme) + 3GPP SCAS** — the industry baseline for proving mobile-network-equipment vendor security; referenced by EU 5G Toolbox + UK TSA Code of Practice + Germany BSI 5G Catalogue + Korea/China procurement specs. Two pillars: (1) **NESAS audit framework** (GSMA FS.16/FS.31) — 20 audit objectives across 5 domains (governance, secure SDLC + SBOM, build + release integrity, vulnerability management + CVD, personnel + supplier security); (2) **3GPP SCAS per-product-class testing** (TS 33.117 general SCAS + TS 33.216/33.511/33.512-33.519 product-class specs covering gNB, AMF, UPF, UDM, SMF, AUSF, SEPP, NRF, NEF, SBI, NIWF, slice subnet). 33 clauses, 26 in-scope, 78 directives. Industry-membership — paraphrase + GSMA/3GPP trademark notice
- **3GPP TS 33.501 — 5G System Security Architecture (Release 18)** — the canonical 5G security spec. Primary authentication (5G AKA + EAP-AKA') + KAUSF/KSEAF/KAMF/KgNB key hierarchy; SUCI subscriber-identifier privacy via Home Network Public Key concealment; NAS + AS confidentiality + integrity (NEA0-3 + NIA0-3); mandatory User Plane integrity protection (a 5G first); service-based interface security with TLS + OAuth 2.0 scoped tokens; SEPP roaming + N32-c/f + PRINS for inter-PLMN; slice-specific authentication NSSAA; quantum-safe considerations (Annex H Rel-18). 27 clauses, 21 in-scope, 63 directives. Vendor-open (3GPP/ETSI, freely downloadable)
- Licensing: GSMA NESAS + 3GPP SCAS (industry-membership, paraphrase + trademark notice) · 3GPP TS 33.501 (vendor-open with attribution, freely downloadable). Companions cross-walk NESAS+SCAS ↔ TS 33.501 (vendor assurance ↔ system architecture) · NESAS ↔ EU 5G Toolbox + UK TSA + BSI 5G Catalogue + ENISA 5G Threat Landscape · TS 33.501 ↔ ISA/IEC 62443 (industrial trust-model parallels) + NIST 800-187 (4G/5G recommendations). cajeX now covers mobile-telecom security end-to-end — the architecture + the vendor assurance + the regulatory baselines that consume both
May 31, 2026
Emerging cross-cutting — EU Cyber Resilience Act + ISSB IFRS S1/S2 + EU Data Act + Singapore Model AI Governance (4 frameworks, 234 directives)
- Four emerging cross-cutting frameworks that span product-cyber, sustainability-finance, data-economy, and Asia-Pacific AI governance — landing in cajeX ahead of their phased compliance deadlines (CRA reporting Sept 2026 / full Dec 2027; Data Act applicable Sept 2025; ISSB voluntary in 17+ jurisdictions; MGAIF / MGenAIGF the Asia-Pacific anchor)
- **EU Cyber Resilience Act (Regulation 2024/2847)** — EU horizontal product-cyber regulation for products with digital elements (PDEs). Annex I Part I essential cybersecurity properties (no known exploitable vulns, secure-by-default, update mechanism, AuthN, conf+integrity, attack-surface minimisation, logging) + Annex I Part II vulnerability handling (SBOM, remediation, testing, coordinated vulnerability disclosure, secure update distribution) + manufacturer obligations (risk assessment, conformity assessment, CE marking, 24h/72h/14d incident + actively-exploited-vuln reporting via ENISA single platform, 5-year default support period). 26 clauses, 19 in-scope, 57 directives. Public domain (EU)
- **ISSB IFRS S1 + IFRS S2 — Sustainability + Climate Disclosure** — the first two IFRS Sustainability Disclosure Standards adopted by 17+ jurisdictions (UK, AU, JP, MX, BR, SG, CA in adoption). 4 TCFD-aligned pillars (Governance / Strategy / Risk Management / Metrics & Targets) under each of S1 (general sustainability) + S2 (climate, fully integrates TCFD); mandatory Scope 1+2+3 GHG (with Year-1 Scope 3 relief), Industry-Based Metrics (Appendix B, 68 industries, SASB-derived), transition plan, scenario analysis, internal carbon price, climate-linked remuneration; interoperability guidance with ESRS (EFRAG Nov 2024). 28 clauses, 20 in-scope, 60 directives. Industry-membership — paraphrase + IFRS trademark notice. Pairs with our existing TCFD + CSRD/ESRS + GHG Protocol
- **EU Data Act (Regulation 2023/2854)** — EU regulation on fair access to + use of data; applicable Sept 12, 2025. Connected-product data sharing by design (Art 3) + user access + third-party access at user request (Arts 4–6) + FRAND access (Arts 8–11) + B2G exceptional-need data sharing (Ch III) + cloud + edge switching: functional equivalence, application + data + digital-asset portability, switching charges reducing to zero by 2027 (Ch IV) + interoperability essentials including smart contracts (Ch V) + unfair-terms protection for SMEs (Art 13) + €20m / 4% turnover penalties. 27 clauses, 20 in-scope, 60 directives. Public domain (EU)
- **Singapore Model AI Governance Framework (+ Model GenAI Governance Framework)** — IMDA/PDPC voluntary AI governance: Model AIGF Ed.2 (4 areas — internal governance, human involvement in AI decisions [HITL/HOTL/HOVER per harm × probability], operations management [data accountability, model selection, robustness, tuning], stakeholder communication) + Model GenAIGF (May 2024, 9 dimensions — accountability, data + IP, trusted development + deployment, incident reporting, testing + assurance, security including ATLAS/OWASP LLM Top 10, content provenance + C2PA, safety + alignment R&D, AI for public good) + AI Verify Foundation toolkit. The Asia-Pacific anchor alongside EU AI Act + ISO 42001 + NIST AI RMF + OECD AI Principles already in cajeX. 22 clauses, 19 in-scope, 57 directives. Vendor-open (IMDA / PDPC) with attribution
- Licensing: EU CRA + EU Data Act (public domain — EU regulations) · ISSB S1+S2 (industry-membership — IFRS Foundation paraphrase + trademark notice) · Singapore MGAIF/MGenAIGF (vendor-open with attribution). Companions cross-walk EU CRA ↔ CycloneDX + SPDX + SLSA + SSDF (SBOM + supply chain) + ENISA (reporting) + IEC 62443 (product cyber); ISSB ↔ TCFD (S2 superset) + CSRD/ESRS (EFRAG interoperability) + GHG Protocol; EU Data Act ↔ GDPR (personal data interplay) + DMA + Data Governance Act; Singapore MGAIF ↔ EU AI Act + ISO 42001 + NIST AI RMF + OECD AI + MITRE ATLAS + NIST AI 100-2 + OWASP LLM Top 10. cajeX now covers the 2025–2027 emerging-regulation horizon across product cyber, sustainability disclosure, data-economy, and global AI governance
May 31, 2026
Operational excellence — Google SRE + PMBOK 7e + PRINCE2 + SAFe (4 frameworks, 313 directives)
- Four frameworks covering site reliability engineering, project management, and enterprise agile delivery — the operating-model dimension of how engineering and program teams actually run. Pairs with cajeX's existing DORA Capabilities, 12-Factor, CNCF Cloud-Native Maturity, ITIL 4, and CD4ML
- **Google SRE — Site Reliability Engineering** — Google's canonical practices from the SRE Book + SRE Workbook: SLI/SLO/error budgets, the toil cap, four golden signals (latency/traffic/errors/saturation), blameless postmortems, release engineering (hermetic builds, progressive rollouts), on-call discipline (max 2 pages/shift, IC + ops + comms structure), production readiness reviews, capacity planning. 25 clauses, 18 in-scope, 54 directives. Vendor-open (Google) with attribution
- **PMBOK Guide 7e (PMI)** — the principles-based 7th Edition (2021) — major shift from process-based earlier editions. 12 Principles (stewardship, team, stakeholders, value, systems thinking, leadership, tailoring, quality, complexity, risk, adaptability, change) + 8 Performance Domains (stakeholders, team, lifecycle, planning, work, delivery, measurement, uncertainty) + tailoring + 12 models / 36 methods / 132 artifacts + PMI ethics. 32 clauses, 27 in-scope, 80 directives. Industry-membership — paraphrase + PMI trademark notice
- **PRINCE2 7e (PeopleCert)** — UK government + EU project methodology, 7th Edition (2023). 7 Principles (continued business justification, learn from experience, defined roles, manage by stages, manage by exception, focus on products, tailor) + 7 Practices (renamed from Themes in 7e: Business Case, Organisation, Plans, Quality, Risk, Issues, Progress) + 7 People practices (new in 7e) + 7 Processes (SU/IP/DP/CS/MP/SB/CP) + 26 Management Products + tailoring + PRINCE2 Agile. 41 clauses, 34 in-scope, 102 directives. Industry-membership — paraphrase + PeopleCert trademark notice
- **SAFe 6.0 (Scaled Agile, Inc.)** — most widely adopted enterprise-agile framework. 7 Core Competencies of Business Agility × 4 configurations (Essential / Large Solution / Portfolio / Full SAFe). Agile Release Train (ART), Program Increment (PI) Planning, DevOps + CALMR (Culture/Automation/Lean flow/Measurement/Recovery), Continuous Delivery Pipeline, Lean Portfolio Management, Built-In Quality, WSJF prioritisation, Inspect & Adapt, SAFe roles (RTE, PM, SA, BO, Epic Owner, etc.). 36 clauses, 26 in-scope, 77 directives. Industry-membership — paraphrase + Scaled Agile trademark notice
- Licensing: Google SRE (vendor-open with attribution) · PMBOK 7e + PRINCE2 7e + SAFe (industry-membership, paraphrase + trademark notice). Companions cross-walk Google SRE ↔ DORA Capabilities + 12-Factor + CD4ML (delivery practices); PMBOK ↔ PRINCE2 (alternative PM standards); SAFe ↔ ITIL 4 + IT4IT (enterprise operating models). cajeX now covers the project + ops + reliability operating-model layer end-to-end
May 31, 2026
National cyber baselines + OT — NIST 800-82 + ASD Essential Eight + UK Cyber Essentials + UK NCSC CAF (4 frameworks, 206 directives)
- Four government-published cyber baselines covering OT/ICS security + 3 national/government cybersecurity certification or assessment schemes. Pairs with the full ISA/IEC 62443 family already in cajeX for OT, and gives UK + Australian government baseline coverage alongside the US Phase AA set
- **NIST SP 800-82 Rev 3 — OT Security Guide (Sept 2023)** — NIST flagship OT/ICS security guide; pairs with ISA/IEC 62443 + NIST CSF crosswalk + 800-53 OT overlay (all in cajeX). OT system characteristics + program development + risk management + defense-in-depth architecture + consequence-based engineering. 30 clauses, 22 in-scope, 66 directives. Public domain (NIST)
- **ASD Essential Eight (ACSC)** — Australian government baseline of 8 prioritised mitigation strategies (application control, patch apps, MS Office macros, user app hardening, restrict admin, patch OS, MFA, regular backups) × 4 maturity levels (ML0-3). Required for non-corporate Commonwealth entities under PSPF Policy 10; widely adopted globally as minimum-viable-cyber baseline. 12 clauses, 11 in-scope, 32 directives. Public domain (ASD/ACSC)
- **UK Cyber Essentials (+ Plus)** — UK government baseline cybersecurity certification (NCSC + IASME) required for UK central government contracts handling personal/sensitive data. 5 technical control themes: firewalls + gateways, secure configuration, security update management, user access control (MFA + privileged separation), malware protection. Plus tier adds on-site/remote technical testing. 26 clauses, 21 in-scope, 63 directives. Public domain (NCSC/IASME)
- **UK NCSC Cyber Assessment Framework (CAF v3.2)** — outcome-focused cyber-resilience framework for UK critical national infrastructure + NIS Regulations Operators of Essential Services. 4 Objectives (Managing security risk · Protecting against cyber attack · Detecting cyber events · Minimising impact of incidents) × 14 Principles × ~39 outcomes × IGP achievement levels (Not Achieved / Partially Achieved / Achieved). 19 clauses, 15 in-scope, 45 directives. Public domain (NCSC)
- All four are public-domain government publications. Companions cross-walk NIST 800-82 ↔ IEC 62443 + NIST CSF + NIST 800-53 (OT overlay); ASD Essential Eight ↔ ASD ISM (parent doc); UK Cyber Essentials ↔ IASME certification body; UK NCSC CAF ↔ NIS Regulations + UK GDPR. cajeX now covers Australian, US, and UK government cybersecurity baselines end-to-end (US in AA, UK + Australia in AH)
May 31, 2026
Functional safety + transport/medical cyber — IEC 61508 + ISO/SAE 21434 + IEC 62304 + ISO 14971 + UNECE WP.29 R155/R156 (5 frameworks, 413 directives)
- Five frameworks anchoring cajeX's safety + transport/medical-cyber stack. **IEC 61508** is the parent functional-safety standard from which ISO 26262 (automotive), IEC 62278 (railway), and IEC 61511 (process — already in catalog) derive — adding it completes the safety family. **ISO/SAE 21434** + **UNECE WP.29 R155/R156** make vehicle cybersecurity certifiable + type-approved. **IEC 62304** + **ISO 14971** are the engineering-side counterparts to ISO 13485 (already in catalog) for medical device software + risk management
- **IEC 61508 — Functional Safety of E/E/PE Safety-Related Systems** — the parent generic functional-safety standard; 7 parts (general, hardware, software, definitions, SIL methods, application guidelines, techniques); SIL 1–4 quantitative + qualitative targets; the 16-phase safety lifecycle; Functional Safety Assessment (FSA1–5). 29 clauses, 18 in-scope, 54 directives. Paywalled IEC — paraphrase + IEC trademark notice
- **ISO/SAE 21434 — Road Vehicles Cybersecurity Engineering** — the joint ISO/SAE standard required by UNECE WP.29 R155 for vehicle type approval. Clauses 4–15: organisational + project + distributed CS management, continual activities (monitoring, vuln management), concept phase (TARA — assets, damage scenarios, attack paths, feasibility), product development, CS validation, production, OPS+OTA, end-of-support. 48 clauses, 45 in-scope, 134 directives. Paywalled ISO/SAE — paraphrase + trademark notice
- **IEC 62304 — Medical Device Software Lifecycle Processes** — required by FDA + EU MDR. Software Safety Classification (Class A/B/C) drives process depth. §5 Development (planning → requirements → architecture → detailed design [Class C] → unit/integration/system test → release); §6 Maintenance; §7 Risk Management (cross-references ISO 14971); §8 Configuration Management; §9 Problem Resolution; cross-cutting SOUP (Software of Unknown Provenance) + cybersecurity expectations. 34 clauses, 33 in-scope, 99 directives. Paywalled IEC — paraphrase + IEC trademark notice
- **ISO 14971 — Medical Device Risk Management** — foundational medical-device risk-management standard required by FDA QSR/QMSR + EU MDR + ISO 13485 + IEC 62304. §4 General RM; §5 Risk Analysis; §6 Risk Evaluation; §7 Risk Control (inherently safe design > protective measures > information for safety); §8 Overall Residual Risk; §9 RM Review; §10 Production + Post-Production Activities; cybersecurity integration (with IEC 62304 + AAMI TIR57). 29 clauses, 19 in-scope, 57 directives. Paywalled ISO — paraphrase + ISO trademark notice
- **UNECE WP.29 R155 + R156** — UN type-approval regulations making CSMS (Cybersecurity Management System, R155) + SUMS (Software Update Management System, R156) mandatory for new vehicles in 60+ countries (EU, UK, Japan, Korea — mandatory for new types from 2022; all new vehicles produced in EU from 2024). Annex 5 threat list (~70 threats); RxSWIN; OTA-specific requirements (secure transmission, fail-safe rollback). 23 clauses, all in-scope, 69 directives. Public domain (UNECE intergovernmental)
- Licensing: IEC 61508 + IEC 62304 (IEC) · ISO 14971 (ISO) · ISO/SAE 21434 (ISO + SAE) — all paywalled, paraphrase + trademark notice · UNECE WP.29 (public domain UN). Companions cross-walk IEC 61508 ↔ ISO 26262 + IEC 62278 + IEC 61511 (parent ↔ children); ISO/SAE 21434 ↔ UNECE WP.29 R155 + ISO 26262 (engineering ↔ regulation + safety); IEC 62304 ↔ ISO 14971 ↔ ISO 13485 (medical SW + risk + QMS triad); UNECE WP.29 R156 ↔ ISO 24089 (SW update engineering). cajeX now covers safety + automotive cyber + medical software end-to-end
May 31, 2026
Payments + financial-crime — PCI SSF + SWIFT CSCF + NYDFS 500 + PSD2/SCA + FATF Recommendations (5 frameworks, 398 directives)
- Five frameworks deepening cajeX's financial-services coverage — software-vendor payments security (PA-DSS replacement), SWIFTNet bank cybersecurity, NY financial-institution cyber, EU payments / strong customer authentication, and global AML/CFT/CPF. Pairs with PCI DSS 4, BCBS 239, FFIEC, SR 11-7, Basel III ORM, Solvency II, NAIC AI, and IFRS 17 already in catalog
- **PCI Secure Software Framework (SSF)** — replaces PA-DSS; two paired standards: Secure Software Standard (payment software — sensitive auth data, CHD encryption, transmission protection, attack mitigation, audit logs) + Secure SLC Standard (vendor SDLC — governance, training, threat modeling, vuln detection, change mgmt, software integrity, sensitive-data protection in development) + QSA-SSF assessor validation. 25 clauses, 23 in-scope, 69 directives. Industry-membership — paraphrase + PCI SSC trademark
- **SWIFT Customer Security Programme (CSCF)** — SWIFT-mandated security controls: 3 objectives (Secure your environment / Know and limit access / Detect and respond) × 7 principles × 32 controls. Annual KYC-SA self-attestation; independent assessment for advisory controls. Required for every bank on SWIFTNet. 43 clauses, all in-scope, 128 directives. Industry-membership — paraphrase + SWIFT trademark
- **NYDFS 23 NYCRR Part 500** — NY financial-institution cyber regulation (Second Amendment Nov 2023): cybersecurity program + CISO + risk assessment + audit trail + access privileges + MFA + encryption + 72-hour incident notification + IRP/BCP + Class A additional requirements (independent audit, privileged-access monitoring, password vaulting, EDR/SOC). 28 clauses, 21 in-scope, 63 directives. Public domain. Pairs with our existing nydfs-ai-circular-2024
- **PSD2 + SCA RTS** — EU Payment Services Directive + Strong Customer Authentication regulatory technical standard. Articles 64–98 (AISP/PISP, operational risk, 4-hour incident reporting, SCA mandate) + Delegated Reg 2018/389 (two-factor, dynamic linking, exemptions including TRA, personalised security credentials, dedicated AISP/PISP interface, contingency fallback). 29 clauses, 22 in-scope, 66 directives. Public domain (EU)
- **FATF 40 Recommendations** — the global AML/CFT/CPF standard underpinning every national AML regime (US BSA, EU AMLD6, UK MLR 2017). 40 Recommendations across 7 topic areas; Preventive Measures (Recs 9–23 — CDD/EDD, PEPs, correspondent banking, virtual assets Travel Rule INR 15, wire transfers, internal controls, STRs) fully in-scope; beneficial ownership transparency (24–25); supervision/enforcement (26–40) partly OOS. 47 clauses, 24 in-scope, 72 directives. Public domain (FATF)
- Licensing: PCI SSF + SWIFT CSCF — industry-membership, paraphrase + trademark notice · NYDFS 500 + PSD2/SCA + FATF — public domain. Companions cross-walk PCI SSF ↔ PCI DSS 4 (vendor + merchant); SWIFT CSCF ↔ BCBS 239 + FFIEC (banking cyber); NYDFS 500 ↔ NY AI Circular; PSD2/SCA ↔ FAPI 2.0 (in API auth hardening); FATF ↔ all financial laws. cajeX now covers the financial-services regulatory + security stack end-to-end
May 30, 2026
Container, Kubernetes & cloud-native config — CSA CCM + CIS K8s + NSA/CISA K8s Hardening + CIS Docker + CIS Cloud Foundations (5 frameworks, 397 directives)
- Five frameworks covering the container + Kubernetes + cloud-native configuration hardening layer — the operational config audit that complements the AWS/Azure/GCP Well-Architected pillars (architectural) already in catalog. Net-new coverage for the cloud-config + container + K8s posture that every modern engineering team builds against
- **CSA Cloud Controls Matrix v4 (+ STAR)** — the Cloud Security Alliance crosswalk hub: 197 cloud controls in 17 domains (Audit & Assurance, Application & Interface Security, BCM, Change Control, Cryptography & Key Management, Datacenter Security, Data Security & Privacy Lifecycle, GRC, HR Security, IAM, Interoperability & Portability, Infrastructure & Virtualization Security, Logging & Monitoring, Security Incident Mgmt, Supply Chain Mgmt, Threat & Vuln Mgmt, Universal Endpoint Mgmt) + the STAR assurance program (Level 1 CAIQ self-assessment, Level 2 third-party certification, Level 3 continuous monitoring). The cross-walk hub mapping to ISO 27001 / NIST 800-53 / PCI DSS / HIPAA / SOC 2 / GDPR / FedRAMP. 67 clauses, 49 in-scope, 147 directives. Vendor-open (CSA) with attribution
- **CIS Kubernetes Benchmark** — the de-facto K8s hardening baseline across 8 sections: master node security (API server, controller-manager, scheduler, etcd), worker node (kubelet, container runtime), policies (RBAC, Pod Security Standards), logging & auditing, networking (NetworkPolicy default-deny, CNI), secrets management (KMS), image security (signed images, admission control), workload security (read-only root, drop capabilities, runAsNonRoot). 26 clauses, 17 in-scope, 51 directives. Vendor-open (CIS) with attribution
- **NSA/CISA Kubernetes Hardening Guide** — the jointly-published US-federal CTR providing the architectural threat-model companion to the CIS line-by-line audit: pod security, network separation & hardening, authn/authz, log auditing, application security & threat detection (Falco/Tetragon, service mesh, admission controllers). 24 clauses, 19 in-scope, 57 directives. Public domain (NSA + CISA)
- **CIS Docker Benchmark** — container image + runtime hardening baseline across 7 sections: host config, Docker daemon config, daemon config files, container images & build files, container runtime (drop capabilities, read-only root, no privileged mode), Docker security ops, Docker Swarm. 30 clauses, 23 in-scope, 68 directives. Vendor-open (CIS) with attribution
- **CIS Cloud Foundations Benchmarks (AWS / Azure / GCP)** — one umbrella covering the account-level config hardening baselines for the three major clouds: AWS Foundations (IAM, S3, CloudTrail, CloudWatch, VPC), Azure Foundations (Entra ID, Microsoft Defender, Storage Accounts, Key Vault, NSGs), GCP Foundations (IAM, Cloud Audit Logging, VPC, Cloud SQL, BigQuery). Pairs with cajeX's existing AWS/Azure/GCP Well-Architected pillars — architectural pillars vs account-level config audit. 46 clauses, 25 in-scope, 74 directives. Vendor-open (CIS) with attribution
- Licensing: NSA/CISA Kubernetes Hardening (public domain — US federal) · all four others vendor-open (CSA + CIS) with attribution. Companions cross-walk CSA CCM ↔ ISO 27001 / NIST 800-53 / PCI DSS / SOC 2 / FedRAMP (the crosswalk hub); CIS K8s ↔ NSA/CISA K8s Hardening (line-by-line + architectural); CIS Cloud Foundations ↔ AWS/Azure/GCP Well-Architected (config vs architecture); CIS Docker ↔ CIS K8s (container vs orchestrator). cajeX now covers cloud-native end-to-end: control catalog (CCM) → cloud account config (Foundations) → container image (Docker) → orchestrator (K8s) → architectural posture (cloud WA)
May 30, 2026
Identity, authN & cryptography — NIST 800-63-4 + FIPS 140-3 + NIST PQC + API Auth Hardening + FIDO2/WebAuthn (5 frameworks, 271 directives)
- Five frameworks covering the identity/cryptography stack — federal digital identity, cryptographic module validation, post-quantum migration, OAuth/FAPI API authorization, and phishing-resistant authentication. Net-new coverage for the authN/authZ/crypto layer that underlies every other security control in the catalog
- **NIST SP 800-63-4 — Digital Identity Guidelines (final July 2025)** — the revised federal identity guidelines with risk-based DIRM, phishing-resistant authenticators (syncable + device-bound passkeys), digital wallets. Four volumes: 800-63 base (DIRM), 800-63A (Identity Assurance Levels), 800-63B (Authenticator Assurance Levels), 800-63C (Federation Assurance Levels). 26 clauses, 22 in-scope, 66 directives. Public domain (NIST)
- **FIPS 140-3 — Security Requirements for Cryptographic Modules** — the federal CMVP module-validation standard (4 levels × 11 requirement areas — module spec, interfaces, roles/services/authn, software/firmware security, operational environment, physical security, non-invasive security, SSP management, self-tests, lifecycle assurance, mitigation of other attacks). Required by FedRAMP/CJIS/IRS-1075/CMMC/HIPAA-aligned crypto. Incorporates ISO/IEC 19790 + 24759. 31 clauses, 17 in-scope, 62 directives. Public domain (NIST)
- **NIST Post-Quantum Cryptography (FIPS 203/204/205)** — the finalised PQC standards (August 2024): ML-KEM (key encapsulation, lattice-based) · ML-DSA (digital signatures, lattice-based) · SLH-DSA (digital signatures, hash-based). Plus the migration playbook (SP 1800-38 / CSWP 38) — cryptographic inventory, risk prioritisation, hybrid deployment, crypto agility, PKI transition, vendor coordination — and stateful HBS (SP 800-208 LMS/XMSS). The migration imperative against harvest-now-decrypt-later. 21 clauses, all in-scope, 63 directives. Public domain (NIST)
- **API Authorization Hardening — OAuth 2.0 Security BCP + OpenID FAPI 2.0** — combined IETF + OpenID Foundation profile for high-assurance API auth: PKCE everywhere, exact redirect URI matching, sender-constrained tokens (mTLS/DPoP), Pushed Authorisation Requests (PAR), JWT-Secured Authorisation Request (JAR), refresh token rotation + family theft detection, mix-up attack defence (RFC 9207), no implicit/ROPC, step-up authn (RFC 9470), audience restriction + resource indicators. 15 clauses, 13 in-scope, 29 directives. Vendor-open (IETF + OpenID Foundation) with attribution
- **FIDO2 / WebAuthn** — the W3C WebAuthn Level 3 + FIDO Alliance CTAP 2.x suite underlying passkeys (the phishing-resistant authn implementation NIST 800-63-4 mandates at AAL2+). Covers registration + authentication ceremonies, attestation + MDS, discoverable credentials (passkeys), syncable vs device-bound (AAL implications), authenticator transports incl. hybrid/caBLE, user verification, account recovery, CTAP 2.1/2.2. 26 clauses, 17 in-scope, 51 directives. Vendor-open (W3C + FIDO Alliance) with attribution
- All five are public domain or vendor-open. Companions cross-walk NIST 800-63-4 ↔ FIDO2/WebAuthn (identity layer + implementation); FIPS 140-3 ↔ NIST PQC (module validation + algorithm migration); API Auth Hardening ↔ NIST 800-63-4 (API-side authz layer); FIPS 140-3 + NIST PQC ↔ FedRAMP/CJIS/IRS-1075/CMMC (the federal regimes that require validated crypto). With this release cajeX covers identity + crypto end-to-end: digital identity proofing → authenticator + passkey → validated crypto module → post-quantum migration → API authorisation
May 30, 2026
AI security & assurance — MITRE ATLAS + NIST AI 100-2 + Google SAIF + OWASP ML Top 10 + ISO 42005 (5 frameworks, 297 directives)
- Five frameworks extending cajeX's AI coverage from *governance* (EU AI Act, ISO 42001, NIST AI RMF, OECD AI) into *security and assurance* — adversarial-ML threat modeling, attack/mitigation taxonomy, vendor security frameworks, classical-ML risks, and AI system impact assessment. Closes the gap between AI policy and AI-attack defense engineering
- **MITRE ATLAS — Adversarial Threat Landscape for AI** — the ATT&CK of AI: 14 tactics × techniques × mitigations covering reconnaissance, ML model access, poisoning, evasion, LLM jailbreak / prompt injection (direct + indirect via RAG), ML supply chain, data exfiltration via inference API, model theft, and ML impact (cost harvesting, IP theft, denial of ML service). 41 clauses, 27 in-scope, 81 directives. Vendor-open (MITRE) with attribution
- **NIST AI 100-2 — Adversarial ML Taxonomy** — NIST's systematic reference covering PredAI (evasion, poisoning, privacy attacks — membership inference, model inversion, model extraction) and GenAI (supply-chain corpus poisoning, direct + indirect prompt injection, training-data extraction, system-prompt leakage, abuse violations) plus the mitigation classes (robust training, detection, DP-SGD, access controls, provenance, defense in depth). 25 clauses, 18 in-scope, 54 directives. Public domain (NIST). Pairs operationally with MITRE ATLAS
- **Google SAIF — Secure AI Framework** — Google's vendor-neutral 6-element framework: expand security foundations to AI, extend detection & response, automate defenses, harmonize platform-level controls, adapt mitigations with faster feedback loops, contextualize AI risks in business processes. Plus SAIF Risk Assessment practices (model lineage, output filtering, red-teaming). 26 clauses, 19 in-scope, 57 directives. Vendor-open (Google) with attribution
- **OWASP ML Security Top 10** — the OWASP top 10 for *classical* ML (distinct from the OWASP LLM Top 10 already in catalog): input manipulation, data poisoning, model inversion, membership inference, model theft, AI supply chain attacks, transfer learning attacks, model skewing, output integrity attacks, and federated/parameter poisoning. 11 clauses, 10 in-scope, 30 directives. Creative Commons (OWASP CC-BY-SA)
- **ISO/IEC 42005 — AI System Impact Assessment** — the 2025 standard providing the framework for assessing AI impacts on individuals, groups, society, and the environment (the DPIA-for-AI). Pairs with cajeX's existing ISO 42001 (AIMS) and ISO 23894 (AI risk management) as the third leg of the AI-governance ISO triad — and operationalises the EU AI Act Article 27 Fundamental Rights Impact Assessment. 38 clauses, 25 in-scope, 75 directives. Paywalled ISO — paraphrase-only with ISO/IEC trademark notice
- Licensing: ISO 42005 (paywalled ISO, paraphrase + ISO/IEC attribution) · NIST AI 100-2 (public domain) · MITRE ATLAS + Google SAIF (vendor-open, verbatim with attribution) · OWASP ML Top 10 (Creative Commons CC-BY-SA). Companions cross-walk MITRE ATLAS ↔ NIST AI 100-2 (operational matrix ↔ formal taxonomy); Google SAIF ↔ NIST AI RMF + ISO 42001 (defensive engineering ↔ governance); OWASP ML Top 10 ↔ OWASP LLM Top 10 (classical-ML ↔ LLM-specific); ISO 42005 ↔ ISO 42001 / 23894 + EU AI Act Art. 27. cajeX now covers AI end-to-end: policy → governance → risk → impact assessment → adversarial defense
May 30, 2026
Privacy management + sectoral US privacy — ISO 27701 + NIST Privacy FW + GLBA + FERPA + Virginia VCDPA + ISO 31700 PbD (6 frameworks, 400 directives)
- Six frameworks covering the privacy-*management* (vs privacy-*law*) layer plus three sectoral US privacy regimes. Pairs with the 10 privacy laws already in the catalog (GDPR, CCPA/CPRA, HIPAA, PIPEDA, LGPD, India DPDP, Australia Privacy Act, China PIPL, Japan APPI, POPIA) — these new frameworks turn the *law* into a *management system* + extend to financial, education, and second-tier US state regimes
- **ISO/IEC 27701:2025 — Privacy Information Management System (PIMS)** — the recently revised PIMS standard, now **standalone** (no longer requires ISO 27001 certification). Annex-SL clauses 4–10 with clause 8 (Operation) as the PIMS heart — RoPA, privacy-by-design, DPIA, data subject rights, controller-processor contracts, cross-border transfers. 35 clauses, 25 in-scope, 75 directives. Paywalled ISO — paraphrase-only with ISO/IEC trademark notice
- **NIST Privacy Framework 1.0** — the privacy companion to NIST CSF (already in catalog). Five Functions (Identify-P / Govern-P / Control-P / Communicate-P / Protect-P) with Categories and Subcategories, mirroring the CSF structure. 21 clauses, 16 in-scope, 48 directives. Public domain (NIST)
- **GLBA Safeguards Rule (16 CFR Part 314)** — the FTC's Safeguards Rule under Gramm-Leach-Bliley with the 2021 amendments adding 8 specific safeguards (access controls, encryption, MFA, secure dev, change mgmt, monitoring, disposal, training) + the 2023 notification rule (500+ consumers, 30-day FTC reporting). 26 clauses, 17 in-scope, 68 directives. Public domain (FTC)
- **FERPA — Family Educational Rights and Privacy Act** — the US federal student-records law (20 U.S.C. §1232g; 34 CFR Part 99). Education records definitions, annual notification, access + amendment rights, consent for disclosure + 11 enumerated exceptions, directory information, the EdTech vendor school-official designation (FPCO 2014 guidance). 26 clauses, 16 in-scope, 58 directives. Public domain (US DOE)
- **Virginia VCDPA** — the leading second-tier US state privacy law and the template for Colorado CPA, Connecticut CTDPA, Utah UCPA. Scope thresholds (100k VA residents or 25k + 50% revenue), 6 consumer rights, sensitive-data consent, Data Protection Assessments, processor obligations, universal opt-out signals (post Jan-2025), AG-only enforcement with 30-day cure. 30 clauses, 19 in-scope, 72 directives. Public domain (Commonwealth of Virginia)
- **ISO 31700 — Privacy by Design for Consumer Goods and Services** — the 2023 standard operationalising Cavoukian's 7 PbD principles + 30 capabilities across the consumer-product lifecycle (planning → design → development → operation → decommissioning). 33 clauses, 22 in-scope, 79 directives. Paywalled ISO — paraphrase-only with ISO trademark notice
- Licensing: ISO 27701 + ISO 31700 (paywalled ISO, paraphrase + ISO/IEC attribution) · NIST Privacy Framework + GLBA + FERPA + Virginia VCDPA (public domain). Companions cross-walk ISO 27701 ↔ GDPR + the 9 other privacy laws (operational management layer); NIST Privacy ↔ NIST CSF; Virginia VCDPA ↔ CCPA/CPRA + GDPR; ISO 31700 ↔ ISO 27701 (PbD-of-products vs PIMS-of-organisations)
May 30, 2026
US government + defense cyber — FedRAMP + CMMC 2.0 + NIST RMF + CJIS + IRS Pub 1075 (5 frameworks, 296 directives)
- Five frameworks covering the US public-sector cyber stack — cloud authorization, defense contracting, the federal risk-management process, law-enforcement data, and federal tax information. Builds on the NIST 800-53 / 800-171 / 800-172 control sets already in catalog with the program-layer obligations every public-sector buyer requires. Net-new coverage for an entire customer segment that was previously a blocker
- **FedRAMP — Federal Risk and Authorization Management Program (Rev 5)** — the US federal cloud-authorization program: JAB Provisional ATO vs Agency ATO paths; Low/Moderate/High baselines tailored from NIST 800-53; 3PAO independent assessment (SAP/SAR); continuous monitoring with monthly POA&M + vuln scans; Significant Change Request; authorization boundary + SSP. 32 clauses, 22 in-scope, 66 directives. Public domain (FedRAMP PMO / GSA)
- **CMMC 2.0 — Cybersecurity Maturity Model Certification** — DoD certification program (DFARS final rule effective 2025-11-10): Level 1 (17 FCI practices, self-assess) → Level 2 (110 practices = NIST 800-171 R2, C3PAO assessment for prioritized acquisitions) → Level 3 (NIST 800-172 subset, DIBCAC). Scoping (CUI/SPA/CRMA/Specialized/OOS asset categories), senior-official annual affirmation, limited POA&M, 3-year assessment validity, FedRAMP Moderate reciprocity for cloud. 26 clauses, 16 in-scope, 47 directives. Public domain (US DoD)
- **NIST SP 800-37 Rev 2 — Risk Management Framework (RMF)** — the canonical 7-step federal risk process: Prepare (org-level + system-level), Categorize (FIPS 199), Select (controls from 800-53), Implement, Assess (SAP/SAR/POA&M), Authorize (AO decision/ATO), Monitor (continuous). The process layer over our existing NIST 800-53 control catalog. 30 clauses, 23 in-scope, 69 directives. Public domain (NIST)
- **CJIS Security Policy** — the FBI policy for any agency or vendor accessing Criminal Justice Information (CJI), structured around 13 numbered policy areas: information exchange agreements, security awareness training, incident response, auditing, access control, identification & authentication (advanced authn aligned to NIST 800-63 AAL2/AAL3), config management, media protection, physical protection, system & comms protection (FIPS 140-3 crypto), audits, personnel security, mobile devices. 28 clauses, 14 in-scope, 42 directives. Public domain (FBI)
- **IRS Publication 1075 — Tax Information Security Guidelines** — IRS safeguards manual for any agency receiving Federal Tax Information (FTI): recordkeeping, secure storage, restricting access, the Safeguard Security Report (SSR), Safeguard Procedures Report (SPR), inspection, FTI disposal, and Section 9 computer system security (aligned to NIST 800-53 across all 15 control families). 33 clauses, 24 in-scope, 72 directives. Public domain (IRS)
- All five are public domain (US federal). Companions cross-walk FedRAMP ↔ NIST 800-53 (cloud baselines), CMMC ↔ NIST 800-171/172 (DoD CUI), NIST RMF ↔ NIST 800-53 (process ↔ catalog), CJIS ↔ NIST 800-63 (advanced authn), and IRS 1075 ↔ NIST 800-53 (Section 9 IT controls). With this release cajeX serves every major US public-sector cyber regime — the gate to federal, defense, and state/local government deals
May 29, 2026
Critical infrastructure + transport safety — IEEE 1547 + IEC 61850 + IMO Cyber + IACS UR E26 + IEC 62278 + EN 50128 (6 frameworks, 299 directives)
- Six frameworks covering the energy-grid, maritime, and rail critical-infrastructure stack — distributed-energy interconnection, substation automation, maritime cyber resilience, and railway safety/software assurance. Complements the IEC 62443 (industrial automation / OT security) coverage already in catalog with the sector-specific engineering and safety standards
- **IEEE 1547 — Interconnection of Distributed Energy Resources** — the standard for connecting DER (solar, storage) to the grid: voltage/reactive-power regulation, abnormal-condition ride-through, power quality, islanding detection, protection, interoperability/communications, and commissioning tests. 25 clauses, 17 in-scope, 51 directives. Paywalled IEEE — paraphrase-only
- **IEC 61850 — Power Utility Automation Communication** — the substation-automation communication standard: the object-oriented data model & logical nodes, ACSI/SCSM, GOOSE peer-to-peer messaging, Sampled Values, Substation Configuration Language (SCL), time synchronization, network redundancy (PRP/HSR), and IEC 62351 security alignment. 30 clauses, 17 in-scope, 50 directives. Paywalled IEC — paraphrase-only
- **IMO Maritime Cyber Risk Management** — the IMO requirement (Resolution MSC.428(98)) to manage maritime cyber risk within the ship's Safety Management System under the ISM Code, structured on the NIST CSF functions (Identify/Protect/Detect/Respond/Recover) across onboard IT and OT. 18 clauses, 11 in-scope, 33 directives. Public domain (IMO)
- **IACS UR E26 — Cyber Resilience of Ships** — the classification-society Unified Requirement (in force for ships contracted on/after 1 July 2024) governing ship-level cyber resilience: CBS inventory, network topology, security zones & conduits, access control, monitoring, incident response & recovery, and the required cyber-resilience documentation package. 21 clauses, 14 in-scope, 42 directives. Industry-membership — paraphrase-only with IACS attribution
- **IEC 62278 (EN 50126) — Railway RAMS** — the Reliability, Availability, Maintainability & Safety standard for railway: the system-lifecycle V-cycle, risk analysis & acceptance criteria, SIL apportionment, the safety case, and lifecycle RAM tasks (modelling, FRACAS). 28 clauses, all in-scope, 63 directives. Paywalled IEC/CENELEC — paraphrase-only
- **EN 50128 — Railway Software Safety** — the CENELEC standard for safety-related railway software: SW-SIL levels, role independence, the software lifecycle (planning/requirements/architecture/design/implementation/verification/validation/assessment/maintenance), the recommended-technique tables, and tool qualification. 33 clauses, 20 in-scope, 60 directives. Paywalled CENELEC — paraphrase-only
- Licensing: IMO Cyber (public domain) · IACS UR E26 (industry-membership, paraphrase + IACS attribution) · IEEE 1547 + IEC 61850 + IEC 62278 + EN 50128 (paywalled IEEE/IEC/CENELEC, paraphrase-only with attribution). Companions cross-walk IEEE 1547 ↔ IEC 61850 (grid/substation), IMO Cyber ↔ IACS UR E26 (maritime), IEC 62278 ↔ EN 50128 (rail safety/software), and the OT-facing ones to IEC 62443 so critical-infrastructure teams see the related standards in the workspace picker
May 29, 2026
OWASP application security — Top 10 + MASVS + Proactive Controls + DSOMM + LLM Top 10 (5 frameworks, 191 directives)
- Five OWASP frameworks rounding out the application-security catalog — web risks, mobile verification, developer proactive controls, DevSecOps maturity, and LLM/GenAI risks. Joins the OWASP ASVS, OWASP API Security Top 10, OWASP SAMM, and OWASP SCVS already in catalog to give near-complete OWASP coverage
- **OWASP Top 10 (2021)** — the ten most critical web application security risks (Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration, Vulnerable Components, Auth Failures, Software/Data Integrity Failures, Logging & Monitoring Failures, SSRF), each with concrete mitigation directives. 11 clauses, 10 in-scope, 29 directives. Creative Commons (OWASP)
- **OWASP MASVS — Mobile Application Security Verification Standard** — the mobile-app security control groups (Storage, Crypto, Auth, Network, Platform, Code, Resilience, Privacy) with verification requirements. 24 clauses, 16 in-scope, 48 directives. Creative Commons (OWASP)
- **OWASP Proactive Controls** — the security techniques developers should build into every project: access control, proper cryptography, input validation, security-from-the-start, secure-by-default config, secure components, digital identity, browser security features, logging & monitoring, SSRF prevention. 11 clauses, 10 in-scope, 30 directives. Creative Commons (OWASP)
- **OWASP DSOMM — DevSecOps Maturity Model** — the graded path for embedding security into DevOps across five dimensions (Build & Deployment, Culture & Organization, Implementation, Information Gathering, Test & Verification) at maturity levels 1-4. 23 clauses, 18 in-scope, 54 directives. Creative Commons (OWASP)
- **OWASP Top 10 for LLM Applications (2025)** — the most critical LLM/GenAI vulnerabilities: Prompt Injection, Sensitive Information Disclosure, Supply Chain, Data & Model Poisoning, Improper Output Handling, Excessive Agency, System Prompt Leakage, Vector & Embedding Weaknesses, Misinformation, and Unbounded Consumption. 11 clauses, 10 in-scope, 30 directives. Creative Commons (OWASP). Pairs with the EU AI Act / NIST AI RMF / ISO 42001 AI-governance set
- All five are Creative Commons (OWASP CC-BY-SA). Companions cross-walk the OWASP frameworks to each other (Top 10 ↔ ASVS ↔ Proactive Controls, MASVS for mobile, SCVS/SAMM/DSOMM for the build/maturity dimension) and the LLM Top 10 to the AI-governance frameworks, so security teams see the full OWASP set in the workspace picker
May 29, 2026
Digital accessibility law + standards — ADA Title III + Section 508 + EN 301 549 + WAI-ARIA APG (4 frameworks, 174 directives)
- Four frameworks covering the digital-accessibility legal + standards stack — the US and EU laws plus the implementation-practice guide that reference WCAG. Builds directly on the WCAG 2.2 coverage already in catalog: WCAG defines the success criteria, these frameworks are the statutes and standards that make WCAG conformance a legal obligation and show engineers how to achieve it
- **ADA Title III — Public Accommodations (Digital Accessibility)** — the US statute (42 U.S.C. §12181 et seq.) as applied to websites and apps: the general non-discrimination prohibition, effective communication / auxiliary aids, reasonable modifications, WCAG AA as the DOJ-operative benchmark, mobile-app coverage, third-party content responsibility, and accessibility statements. 15 clauses, 10 in-scope, 30 directives. Public domain (US DOJ). Physical-premises and litigation-procedure clauses registered out-of-scope
- **Section 508 — ICT Accessibility (Revised 508 Standards)** — the US federal ICT accessibility regulation (36 CFR Part 1194): the Functional Performance Criteria, WCAG 2.0 AA incorporation, and hardware / software / support-documentation requirements. 26 clauses, 20 in-scope, 60 directives. Public domain (US Access Board)
- **EN 301 549 — ICT Accessibility Requirements (EU)** — the European harmonized standard underpinning the Web Accessibility Directive and the European Accessibility Act: functional performance, generic requirements, two-way voice (RTT), video (captions/audio description), Web (WCAG 2.1 AA), non-web documents, software, and documentation. 21 clauses, 16 in-scope, 48 directives. Public domain (ETSI/CEN/CENELEC)
- **WAI-ARIA Authoring Practices Guide (APG)** — the W3C guide on how to build accessible components: the five rules of ARIA, keyboard interaction & focus management, landmark regions, the widget pattern library, accessible names/descriptions, and live regions. The how-to companion to WCAG's what. 19 clauses, 12 in-scope, 36 directives. Vendor-open (W3C WAI)
- Licensing: ADA Title III + Section 508 + EN 301 549 (public domain — US statute/regulation + EU harmonized standard) · WAI-ARIA APG (vendor-open, W3C). Companions cross-walk all four to WCAG 2.2 (the shared success-criteria substrate) and to each other (US ADA ↔ Section 508, EU EN 301 549) so a team building for multiple jurisdictions sees the full accessibility obligation set in the workspace picker
May 29, 2026
Software supply-chain security — CycloneDX + SPDX + NIST 800-161 + in-toto + TUF + Sigstore + OWASP SCVS (7 frameworks, 388 directives)
- Seven frameworks covering the software supply-chain security stack end to end — SBOM standards, supply-chain risk management, build-integrity attestation, update-system security, artifact signing, and component verification. Deepens the SLSA, OWASP SAMM, OpenSSF Scorecard, and NIST 800-218 SSDF coverage already in catalog with the concrete SBOM-format and signing/attestation standards teams implement
- **CycloneDX — Bill of Materials Standard** — the OWASP / ECMA-424 BOM standard across the xBOM family (SBOM, SaaSBOM, HBOM, ML-BOM, CBOM, VDR/VEX): metadata, components with PURL/CPE identifiers, dependency graph, compositions, pedigree & provenance, license expressions, embedded vulnerabilities, and JSON/XML/Protobuf encodings with JSF signing. 23 clauses, 17 in-scope, 51 directives. Vendor-open (OWASP/ECMA). Names cdxgen, Syft, Dependency-Track
- **SPDX — Software Package Data Exchange** — the ISO/IEC 5962 / Linux Foundation SBOM + license exchange standard (3.0 profiles): document metadata, the Core relationship graph, Software profile (packages/files/snippets with hashes + PURL), licensing (concluded vs declared, SPDX License Expressions), Security profile (VEX/CVSS), and Build + AI/Dataset profiles. 25 clauses, 18 in-scope, 53 directives. Vendor-open (CC-BY-3.0 / ISO/IEC). Names FOSSology, ScanCode, Syft
- **NIST SP 800-161 — Cybersecurity Supply Chain Risk Management (C-SCRM)** — C-SCRM across the three organizational levels (Enterprise / Mission / Operational): strategy & policy, ERM integration, acquisition flow-down, supplier criticality & risk assessment, the SR control family (provenance, tamper resistance, counterfeit prevention), SBOM use, and supply-chain incident response. 30 clauses, 24 in-scope, 71 directives. Public domain (NIST)
- **in-toto — Supply Chain Integrity Framework** — the CNCF framework that cryptographically verifies each supply-chain step was performed as planned by authorized actors: layout definition, signed link metadata, functionaries & key thresholds, the verification workflow with artifact rules, and the in-toto Attestation Framework that underpins SLSA provenance. 20 clauses, 14 in-scope, 42 directives. Vendor-open (CNCF)
- **TUF — The Update Framework** — the CNCF framework securing software update systems against key compromise and repository attacks: the four roles (Root, Targets, Snapshot, Timestamp), delegations, threshold signing with offline/online key separation, attack resistance (rollback/freeze/mix-and-match), and the secure client update workflow. 22 clauses, 13 in-scope, 39 directives. Vendor-open (CNCF)
- **Sigstore — Software Signing & Transparency** — keyless, identity-based signing: Cosign (artifact + container signing), Fulcio (short-lived certificate authority bound to OIDC identity), Rekor (the tamper-evident transparency log), verification policy at admission, SLSA/in-toto attestations, and Gitsign. 21 clauses, 14 in-scope, 42 directives. Vendor-open (OpenSSF)
- **OWASP SCVS — Software Component Verification Standard** — the 6 control families (Inventory, SBOM, Build Environment, Package Management, Component Analysis, Pedigree & Provenance) across three verification levels, giving a graded assurance target for the whole supply chain. 36 clauses, 30 in-scope, 90 directives. Creative Commons (OWASP CC-BY-SA)
- Licensing: NIST 800-161 (public domain) · CycloneDX + SPDX + in-toto + TUF + Sigstore (vendor-open — OWASP/ECMA, Linux Foundation, CNCF, OpenSSF, verbatim with attribution) · OWASP SCVS (Creative Commons). Companions cross-walk CycloneDX ↔ SPDX (SBOM formats), in-toto ↔ Sigstore ↔ SLSA (attestation + signing), TUF ↔ in-toto (key distribution), and the cluster to NIST 800-218 SSDF + OWASP SAMM + OpenSSF Scorecard so teams hardening their build pipeline see the related standards in the workspace picker
May 29, 2026
Banking + insurance risk — BCBS 239 + FFIEC IT Handbook + SR 11-7 + Basel III Operational Risk + Solvency II + NAIC AI Bulletin + IFRS 17 (7 frameworks, 383 directives)
- Seven frameworks covering the banking and insurance prudential / risk-governance stack — the financial-sector supervisory standards that complement the DORA, SOX, ISO 31000, and COSO ERM coverage already in catalog with the sector-specific data-aggregation, model-risk, operational-risk, and insurance-prudential regimes
- **BCBS 239 — Risk Data Aggregation & Risk Reporting** — the Basel Committee's 14 principles across governance & infrastructure, risk data aggregation capabilities (accuracy, completeness, timeliness, adaptability), and risk reporting practices. 18 clauses, 11 in-scope, 33 directives. Public domain (BIS). Principles 12-14 (supervisory review) registered out-of-scope
- **FFIEC IT Examination Handbook** — the US interagency IT examination guidance institutions self-assess against: Information Security, Business Continuity Management, Architecture/Infrastructure/Operations, Development & Acquisition, Management/IT governance, and Outsourcing / TSP supervision booklets. 27 clauses, 20 in-scope, 59 directives. Public domain (FFIEC)
- **SR 11-7 — Model Risk Management** — the canonical Federal Reserve / OCC model-risk guidance, now the de-facto standard applied to AI/ML models: the three validation elements (conceptual soundness, ongoing monitoring, outcomes analysis / backtesting), effective challenge, model inventory, and governance. 18 clauses, all in-scope, 54 directives. Public domain (Federal Reserve / OCC). Companions the EU AI Act / NIST AI RMF / ISO 42001 AI-governance set
- **Basel III — Operational Risk Management** — the operational-risk slice of Basel III: the Principles for the Sound Management of Operational Risk (PSMOR), the Standardised Approach loss-data-collection requirements, and the Principles for Operational Resilience (third-party dependency, ICT/cyber resilience, mapping interconnections). 25 clauses, 23 in-scope, 69 directives. Public domain (BIS)
- **Solvency II — EU Insurance Prudential Regime** — the three-pillar regime for EU insurers, scoped to the engineering + governance dimensions: Pillar 2 System of Governance (risk management system, ORSA, internal control, internal/actuarial audit functions, outsourcing) fully in-scope; capital-calculation mechanics and supervisory reporting templates registered out-of-scope. 20 clauses, 14 in-scope, 42 directives. Public domain (EU / EIOPA)
- **NAIC Model Bulletin — Use of AI Systems by Insurers** — the model bulletin adopted across US states setting expectations for insurer AI use: the AIS Program (governance, risk management & internal controls across the full AI lifecycle, third-party AI due diligence). 16 clauses, 14 in-scope, 42 directives. Public domain (NAIC). Pairs with the NYDFS AI guidance and the EU AI Act
- **IFRS 17 — Insurance Contracts** — the IFRS Foundation's insurance-accounting standard, scoped to the data-governance, actuarial-process, and systems controls of implementation: level of aggregation, the General Measurement Model (fulfilment cash flows + CSM), Premium Allocation Approach, Variable Fee Approach, onerous contracts, reinsurance, disclosure, and transition. 28 clauses, all in-scope, 84 directives. Industry-membership — paraphrase-only with IFRS® attribution
- Licensing: BCBS 239 + FFIEC + SR 11-7 + Basel III ORM + Solvency II + NAIC AI Bulletin (public domain — supervisory standards + national/EU regulation, verbatim with attribution) · IFRS 17 (industry-membership, paraphrase-only + IFRS Foundation attribution). Companions cross-walk BCBS 239 ↔ Basel III ORM (banking risk), SR 11-7 ↔ the AI-governance set (model risk), Solvency II ↔ IFRS 17 ↔ NAIC AI (insurance), and the cluster to DORA + ISO 31000 + COSO ERM so financial-sector teams see the related regimes in the workspace picker
May 29, 2026
MLOps + ML production readiness — ISO/IEC 25059 + Google MLOps Maturity + Microsoft MLOps Maturity + CD4ML + ML Test Score (5 frameworks, 277 directives)
- Five frameworks covering the machine-learning operations and ML production-readiness stack — the AI/ML delivery discipline that complements the EU AI Act / ISO 42001 / NIST AI RMF governance frameworks already in catalog with the engineering operating-model, maturity, and test-rubric standards teams actually build against
- **ISO/IEC 25059 — Quality Model for AI Systems** — the SQuaRE-series extension of ISO/IEC 25010 specialized for AI: AI-specific quality characteristics layered on the inherited software-quality model — functional adaptability, AI accuracy, robustness, transparency, intervenability (human oversight), and controllability. 12 clauses, 11 in-scope, 33 directives. Paywalled ISO — paraphrase-only. Companions ISO/IEC 25010 (software quality) and ISO/IEC 42001 (AI management system)
- **Google Cloud MLOps Maturity Model** — the three-level progression (Level 0 manual process → Level 1 ML pipeline automation / continuous training → Level 2 CI/CD pipeline automation) with the capabilities at each level: automated data + model validation, feature store, ML metadata management, pipeline orchestration, model registry, and monitoring-triggered retraining. 16 clauses, 16 in-scope, 48 directives. Vendor-open (Google Cloud)
- **Microsoft MLOps Maturity Model** — the five-level model (Level 0 No MLOps → Level 4 Full MLOps Automated Operations) assessed across people, model creation, model release, and application integration: reproducible + traceable training, full deployment-to-data traceability, automated A/B testing, and production-metric-triggered retraining. 18 clauses, 18 in-scope, 54 directives. Vendor-open (Microsoft)
- **CD4ML — Continuous Delivery for Machine Learning** — ThoughtWorks / Martin Fowler's end-to-end ML automation discipline: versioned data pipelines, reproducible training + experiment tracking, automated evaluation gates with metric thresholds, standardized model serving + canary rollout, data / bias / contract testing, multi-environment promotion with tri-artifact (code + model + data) versioning, and drift monitoring + continuous training. 16 clauses, 16 in-scope, 48 directives. Creative Commons
- **ML Test Score — Rubric for ML Production Readiness** — Google Research's 28-test rubric across four categories (Tests for Features & Data, Model Development, ML Infrastructure, and Monitoring) for scoring production-readiness and reducing ML technical debt; the final score is the minimum across categories. 32 clauses, 32 in-scope, 94 directives. Vendor-open (Google)
- Licensing spans three classes: ISO/IEC 25059 (paywalled ISO, paraphrase + ISO/IEC attribution) · CD4ML (Creative Commons) · Google + Microsoft MLOps Maturity + ML Test Score (vendor-open, verbatim with publisher attribution). Companions cross-walk the MLOps frameworks to ISO/IEC 42001 (AI management system), NIST AI RMF, and the EU AI Act so teams building an AI/ML delivery pipeline see the related governance standards in the workspace framework picker
May 28, 2026
Sustainability + ESG — ISO 14001 + ISO 14064 + GRI + GHG Protocol + TCFD + CSRD/ESRS + Green Software Foundation (7 frameworks, 201 directives)
- Seven frameworks covering the corporate sustainability and ESG-reporting stack — environmental management, carbon accounting, sustainability disclosure, climate-risk reporting, and engineering-level green software. Layers on top of the AWS WA / Azure WAF / GCP AF Sustainability pillars already in catalog (which cover cloud-workload sustainability) with the organization-level reporting + accounting standards
- **ISO 14001 — Environmental Management System** — the certifiable EMS standard (Annex-SL clauses 4-10): environmental aspects, compliance obligations, objectives, operational control, emergency preparedness, audit + management review. 18 clauses, 11 in-scope, 33 directives. Paywalled ISO
- **ISO 14064 — Greenhouse Gas Accounting + Verification** — the 3-part GHG standard: Part 1 (org-level inventory: boundaries, Scope 1/2/3 quantification, reduction initiatives, reporting), Part 2 (project-level GHG), Part 3 (validation + verification). 10 clauses, 6 in-scope, 18 directives. Paywalled ISO
- **GRI Standards** — the most widely-used sustainability reporting standard. Universal Standards (Foundation, General Disclosures, Material Topics + double materiality) + Topic Standards across Economic (200), Environmental (300 — emissions/energy/water/biodiversity/waste), and Social (400 — labor, human rights, communities). 15 clauses, 10 in-scope, 30 directives. Free with attribution (GRI®)
- **GHG Protocol — Corporate Standard** — the canonical carbon-accounting framework. 5 accounting principles, organizational + operational boundaries, Scope 1 (direct), Scope 2 (purchased energy, location + market-based), Scope 3 (15 value-chain categories), base-year recalculation, inventory quality. 14 clauses, 9 in-scope, 27 directives. Free (WRI/WBCSD). Names Watershed, Persefoni, SBTi, emission-factor databases
- **TCFD — Climate-related Financial Disclosures** — the 4-pillar climate-risk disclosure framework (Governance, Strategy, Risk Management, Metrics & Targets) with all 11 recommended disclosures, including climate scenario analysis and Scope 1/2/3 reporting. 16 clauses, 11 in-scope, 33 directives. Free (FSB) — now consolidated into IFRS S2; disclosures map directly
- **CSRD / ESRS** — the EU Corporate Sustainability Reporting Directive + the EFRAG-developed European Sustainability Reporting Standards. Cross-cutting (ESRS 1 General Requirements + double materiality, ESRS 2 General Disclosures), Environmental (E1 Climate through E5 Circular Economy), Social (S1-S4), Governance (G1). 17 clauses, 12 in-scope, 36 directives. Public domain (EU). Names XBRL digital tagging, limited→reasonable assurance, GRI/ISSB interoperability
- **Green Software Foundation — Principles + Software Carbon Intensity** — the engineering-facing sustainability standard: 3 principles (energy efficiency, carbon awareness, hardware efficiency), the SCI specification (now ISO/IEC 21031:2024), and cloud/web/AI-ML patterns. 12 clauses, 8 in-scope, 24 directives. CC BY 4.0. Names Cloud Carbon Footprint, Kepler, CodeCarbon, Electricity Maps/WattTime, Carbon Aware SDK, Impact Framework
- Licensing spans four classes: ISO 14001 + 14064 (paywalled ISO) · GRI + GHG Protocol + Green Software Foundation (Creative Commons, verbatim with attribution + trademark notices) · TCFD (vendor-open, FSB) · CSRD/ESRS (public domain, EU). Companions cross-walk GRI ↔ CSRD/ESRS ↔ TCFD ↔ ISSB (disclosure interoperability), GHG Protocol ↔ ISO 14064 (carbon accounting), and Green Software Foundation ↔ the cloud-vendor Sustainability pillars (engineering implementation)
May 28, 2026
Risk management + business continuity — ISO 31000 + ISO 22301 + COSO ERM + NIST 800-34 + BCI GPG (5 frameworks, 185 directives)
- Five frameworks covering enterprise risk management and business continuity / resilience — complements the existing DORA (EU operational resilience), NIS2, and SOX coverage with the dedicated risk + BC standards
- **ISO 31000 — Risk Management Guidelines** — the canonical risk-management standard: 8 Principles, the Framework (leadership, integration, design, implementation, evaluation, improvement), and the Process (communication & consultation, scope/context/criteria, risk identification/analysis/evaluation, treatment, monitoring & review, recording & reporting). 21 clauses, 15 in-scope, 45 directives. Paywalled ISO — guidance standard (not certifiable)
- **ISO 22301 — Business Continuity Management System** — the certifiable BCMS standard (Annex-SL clauses 4-10). Clause 8 covers the BCMS operation: business impact analysis + risk assessment, BC strategies and solutions, BC plans and procedures, and the exercise programme. 16 clauses, 13 in-scope, 38 directives. Paywalled ISO
- **COSO ERM — Enterprise Risk Management (2017)** — the canonical ERM framework integrating risk with strategy and performance. All 20 principles across the 5 components: Governance & Culture (P1-5), Strategy & Objective-Setting (P6-9), Performance (P10-14 — risk identification, severity assessment, prioritization, responses, portfolio view), Review & Revision (P15-17), Information/Communication/Reporting (P18-20). 26 clauses, 20 in-scope, 60 directives. Industry-membership — COSO® trademark notice, paraphrase-only
- **NIST SP 800-34 — Contingency Planning Guide** — the 7-step IT contingency planning process (policy, business impact analysis, preventive controls, contingency strategies, ISCP development, testing/training/exercises, plan maintenance) plus the plan-type taxonomy (ISCP, BCP, COOP, DRP, Crisis Comms, Cyber Incident Response). 11 clauses, 8 in-scope, 24 directives. Public domain — names AWS Backup / Azure Site Recovery / Veeam, hot/warm/cold sites, RTO/RPO, NIST 800-53 CP control alignment
- **BCI Good Practice Guidelines** — the Business Continuity Institute's body of knowledge: 6 Professional Practices across Management (Policy & Programme Management, Embedding BC) and Technical/Lifecycle (Analysis/BIA, Design, Implementation, Validation). 9 clauses, 6 in-scope, 18 directives. Industry-membership — BCI® trademark notice, paraphrase-only
- Licensing: ISO 31000 + 22301 (paywalled ISO) · COSO ERM + BCI GPG (industry-membership, paraphrase + trademark notice + coverage cap) · NIST 800-34 (public domain). Companions cross-walk ISO 31000 ↔ ISO 23894 (AI risk) ↔ COSO ERM (enterprise risk), and ISO 22301 ↔ NIST 800-34 ↔ BCI GPG (continuity) ↔ DORA (financial-sector resilience)
May 28, 2026
IT service management + governance — ITIL 4 + ISO/IEC 20000 + ISO/IEC 38500 + IT4IT (4 frameworks, 189 directives)
- Four frameworks covering the IT service-management and IT-governance layer — the operating-model and board-oversight standards that sit above the technical engineering frameworks already in catalog. Pairs naturally with COBIT 2019 (program-level governance) and the cloud/platform frameworks (technical delivery)
- **ITIL 4 — IT Infrastructure Library** — the dominant ITSM framework. The Service Value System framing (7 guiding principles, Service Value Chain, Continual Improvement) plus 24 of the highest-value management practices across General (Information Security, Risk, Supplier, Relationship, Financial, Org Change, Knowledge, Measurement & Reporting), Service (Service Level, Incident, Problem, Change Enablement, Release, Service Request, Service Desk, Capacity, Availability, Service Configuration, IT Asset, Monitoring & Event, Service Continuity), and Technical (Deployment, Infrastructure & Platform, Software Development) categories. 32 clauses, 27 in-scope, 81 directives. Industry-membership — paraphrase-only with ITIL® trademark notice and coverage cap
- **ISO/IEC 20000-1 — Service Management System** — the certifiable ITSM standard (the ISO counterpart to ITIL). Annex-SL clause structure (4 Context, 5 Leadership, 6 Planning, 7 Support, 8 Operation of the SMS — service portfolio / relationship & agreement / supply & demand / design-build-transition / resolution & fulfilment / service assurance, 9 Performance evaluation, 10 Improvement). 20 clauses, 13 in-scope, 39 directives. Paywalled ISO — paraphrase-only
- **ISO/IEC 38500 — Governance of IT for the Organization** — the board-level IT governance standard. The 6 governance principles (Responsibility, Strategy, Acquisition, Performance, Conformance, Human Behaviour) plus the Evaluate / Direct / Monitor model the governing body applies to each. 12 clauses, 9 in-scope, 27 directives. Paywalled ISO — distinguishes board governance from operational management
- **IT4IT 3.0 — IT Operating Model Reference Architecture** — The Open Group's value-stream reference architecture for managing the business of IT. The 4 value streams — Strategy to Portfolio (S2P), Requirement to Deploy (R2D), Request to Fulfill (R2F), Detect to Correct (D2C) — plus cross-stream foundations (digital product backbone / service model, financial transparency, sourcing & ecosystem). 20 clauses, 14 in-scope, 42 directives. Industry-membership — paraphrase-only with IT4IT® trademark notice. Complements ITIL's process view with an information-model + value-stream view
- Licensing: ITIL 4 + IT4IT (industry-membership, paraphrase + trademark notice + coverage cap) · ISO/IEC 20000 + 38500 (paywalled ISO, paraphrase + ISO/IEC attribution). Companions cross-walk ITIL 4 ↔ ISO 20000 (process vs certifiable SMS), ISO 38500 ↔ COBIT 2019 (board governance), and IT4IT ↔ ITIL (information model vs process model) so teams adopting one see the related standards in the picker
May 28, 2026
Global privacy expansion — PIPEDA + LGPD + India DPDP + Australia Privacy Act + China PIPL + Japan APPI + POPIA (7 frameworks, 230 directives)
- Seven national privacy laws covering the major jurisdictions beyond the GDPR / CCPA / HIPAA already in the catalog. Unlocks global-SaaS compliance positioning — a workspace operating across multiple regions can now pick the privacy regime for each market it serves and get directives traced back to the originating statutory article. All seven are public-domain national legislation, so cajeX quotes the binding text verbatim with the source-law citation
- **PIPEDA (Canada)** — the 10 Fair Information Principles of Schedule 1 (Accountability, Identifying Purposes, Consent, Limiting Collection, Limiting Use/Disclosure/Retention, Accuracy, Safeguards, Openness, Individual Access, Challenging Compliance) plus the 2018 mandatory breach-of-security-safeguards reporting to the OPC. 15 clauses, 12 in-scope, 36 directives. Consent-centric model (vs GDPR's lawful-basis menu)
- **LGPD (Brazil)** — Law 13.709/2018, closely modeled on GDPR. Legal bases (Art. 7), sensitive + children's data, data subject rights (Art. 18), Encarregado/DPO (Art. 41), security measures, RIPD impact report (Art. 38), records of processing, ANPD breach notification (Art. 48), international transfer (Art. 33). 14 clauses, 9 in-scope, 27 directives. Orgs with GDPR programs can extend rather than rebuild
- **India DPDP Act 2023** — consent + notice (s.5-6), legitimate uses (s.7), Data Fiduciary obligations (s.8), Significant Data Fiduciary duties incl. DPO + DPIA + audit (s.10), children's data (s.9), Data Principal rights (s.11-14), and the blacklist cross-border transfer model (s.16 — more permissive than GDPR adequacy). 15 clauses, 10 in-scope, 29 directives
- **Australia Privacy Act 1988 + Australian Privacy Principles** — all 13 APPs (open management, anonymity, collection, notification, use/disclosure, direct marketing, cross-border disclosure, government identifiers, quality, security, access, correction) plus the Notifiable Data Breaches scheme with its 30-day assessment clock. 17 clauses, 14 in-scope, 42 directives. Surfaces the 2024 reforms (statutory tort, AUD 50M penalty)
- **China PIPL** — the strictest cross-border-transfer regime of the major laws: CAC security assessment / certification / standard contract, separate consent, and CIIO localization (Art. 38-43). Plus legal bases (Art. 13), consent + sensitive PI (Art. 14-32), individual rights incl. deceased relatives (Art. 44-50), PIPIA (Art. 55-56), breach notification (Art. 57), and large-platform gatekeeper obligations (Art. 58). 16 clauses, 11 in-scope, 33 directives
- **Japan APPI** — purpose specification + notification (Art. 17-21), proper acquisition + special-care-required data (Art. 20), security control measures across 4 categories (Art. 23), third-party provision + opt-out records (Art. 27), cross-border transfer (Art. 28), data subject rights (Art. 32-39), PPC leakage reporting (Art. 26), and the pseudonymously/anonymously-processed-information regime that enables internal analytics with relaxed obligations (Art. 41-43). 15 clauses, 10 in-scope, 30 directives
- **POPIA (South Africa)** — the 8 conditions for lawful processing (Accountability, Processing Limitation, Purpose Specification, Further Processing Limitation, Information Quality, Openness, Security Safeguards, Data Subject Participation) plus special personal information + children, transborder flows (s.72), and direct marketing + automated decision-making (s.69-71). 14 clauses, 11 in-scope, 33 directives. The 8-condition structure maps cleanly onto GDPR principles
- All seven are public-domain (national legislation) with no attribution chip or trademark notice required. Companions cross-walk each privacy law to GDPR + the cajeX privacy baseline so multi-jurisdiction teams see the related regimes in the workspace framework picker. With this release cajeX covers the privacy laws of the US, EU, Canada, Brazil, India, Australia, China, Japan, and South Africa — the broadest published privacy-framework picker we know of
May 28, 2026
Sector compliance + practical engineering — NERC CIP + HITRUST CSF + COBIT 2019 + OWASP ASVS + OWASP API Top 10 + WCAG 2.2 (6 frameworks, 538 directives)
- A six-framework bundle that fills two industry-specific compliance gaps (energy utilities + healthcare) and adds three practical engineering frameworks (IT governance, application security, accessibility). Exercises five of the six license classes in a single release
- **NERC CIP — Critical Infrastructure Protection** — the FERC-enforced cybersecurity standard binding on North American Bulk Electric System operators. All 12 published standards (CIP-002 through CIP-014; CIP-012 is reserved): BES Cyber System categorization, security management controls, personnel & training, electronic + physical security perimeters, system security management, incident response, recovery plans, configuration change management + vulnerability assessment, information protection, supply-chain risk management, and physical security of transmission substations. 50 clauses, 37 in-scope, 160 directives. Public domain. Fills the binding utilities-sector gap (the catalog had ISA/IEC 62443 for OT cybersecurity generally, but not the enforced electric-grid regulation)
- **HITRUST CSF — Common Security Framework** — the practical certification healthcare orgs and healthcare-SaaS vendors pursue for deals. 32 control objectives across 14 domains (Access Control, Risk Management, Compliance, Communications & Operations, Information Systems Acquisition/Development/Maintenance, Incident Management, Business Continuity, Privacy Practices, etc.), cross-mapped to HIPAA / HITECH / PCI-DSS / ISO 27001. 47 clauses, 95 directives. Industry-membership — paraphrase-only with HITRUST CSF® trademark notice and a coverage-breadth cap
- **COBIT 2019 — Governance and Management Framework for Enterprise I&T** — ISACA's premier IT-governance framework. All 40 governance + management objectives across the 5 domains: Evaluate/Direct/Monitor (EDM01-05), Align/Plan/Organise (APO01-14), Build/Acquire/Implement (BAI01-11), Deliver/Service/Support (DSS01-06), Monitor/Evaluate/Assess (MEA01-04). 46 clauses, 40 in-scope, 119 directives. Industry-membership — paraphrase-only with COBIT® trademark notice. Pairs at the program level with NIST CSF + ISO 27001
- **OWASP ASVS — Application Security Verification Standard v4.0.3** — the canonical app-security verification checklist. 32 requirement areas across the 14 chapters (Architecture/Threat Modeling, Authentication, Session Management, Access Control, Validation/Encoding, Cryptography, Error Handling/Logging, Data Protection, Communications, Malicious Code, Business Logic, Files/Resources, API/Web Service, Configuration). 47 clauses, 95 directives. Pairs with NIST 800-218 SSDF. Named tooling: Semgrep, CodeQL, OWASP ZAP, Burp Suite, OWASP Dependency-Check, OSV-Scanner, Argon2id, WebAuthn/FIDO2, HashiCorp Vault
- **OWASP API Security Top 10 (2023)** — the 10 most-critical API risks: Broken Object Level Authorization (BOLA), Broken Authentication, Broken Object Property Level Authorization (BOPLA), Unrestricted Resource Consumption, Broken Function Level Authorization, Unrestricted Access to Sensitive Business Flows, SSRF, Security Misconfiguration, Improper Inventory Management, Unsafe Consumption of APIs. 12 clauses, 30 directives. Named tooling: Cedar / OPA / Casbin for fine-grained authz, Kong / Tyk / Apigee for rate limiting, OAuth 2.1 + PKCE
- **WCAG 2.2 — Web Content Accessibility Guidelines** — the W3C accessibility standard required for ADA Title III (US) and the EU Accessibility Act. All 13 guidelines across the 4 POUR principles (Perceivable, Operable, Understandable, Robust), with the new-in-2.2 success criteria called out explicitly (Focus Not Obscured, Focus Appearance, Dragging Movements, Target Size minimum 24×24px, Consistent Help, Accessible Authentication, Redundant Entry; 4.1.1 Parsing deprecation noted). 18 clauses, 39 directives. Named tooling: axe DevTools, WAVE, Lighthouse, NVDA / JAWS / VoiceOver, jest-axe / cypress-axe / @axe-core/playwright for CI
- License coverage: NERC CIP (public domain) · HITRUST CSF + COBIT 2019 (industry-membership, paraphrase + trademark notice + coverage cap) · OWASP ASVS + API Top 10 (Creative Commons, verbatim with attribution) · WCAG 2.2 (W3C, verbatim with attribution). Companions cross-walk NERC CIP to ISA/IEC 62443 + NIST CSF, HITRUST to HIPAA + ISO 27001, COBIT to NIST CSF + ITIL territory, OWASP ASVS + API Top 10 to NIST 800-218 SSDF + OWASP SAMM, and WCAG to the design-system layer
May 27, 2026
Fixed: Framework Templates list returned "Internal server error" once the catalog crossed 100 enabled frameworks
- The platform-admin Framework Templates tab and the workspace `/api/ag/frameworks` listing started returning Internal Server Errors after the catalog expansion this week pushed the enabled-framework count past 100. Root cause: Cloudflare D1 caps bound parameters at 100 per query, and the `listWithCoverage` repository function passed every enabled framework_id as `IN (?, ?, ...)` placeholders in two grouped queries (clause counts + mapping counts). At 112 enabled frameworks both queries exceeded the cap and 500'd
- Fixed by chunking the framework_id IN clauses into 90-id batches in the repository, and chunking both framework_id and template_id dimensions at 45/45 in the workspace-coverage path so the combined bind count always stays under D1's limit. Pure runtime fix — no schema change, no migration, no API contract change. Both the platform admin Framework Templates tab and the tenant frameworks listing now render correctly with 112+ frameworks live
May 27, 2026
Cybersecurity depth — NIST 800-218 SSDF + NIST 800-172 + MITRE ATT&CK + MITRE D3FEND (4 frameworks, 255 directives)
- Cybersecurity catalog expansion across four canonical references covering secure-SDLC, advanced CUI protection, and the full offense + defense matrix. All four are free / public-domain / vendor-open so customers can pick them without IP-licensing friction. Combined with existing NIST 800-53 / 800-171 / CSF 2.0 / ISO 27001-02-17-18 / PCI DSS / SOC 2 / CIS Controls v8 / ISA-IEC 62443 coverage, the cajeX cybersec catalog is end-to-end across program controls, secure-SDLC, offense knowledge, and defensive countermeasures
- **NIST SP 800-218 — Secure Software Development Framework (SSDF) v1.1** — 19 secure software development practices across four groups: Prepare the Organization (PO.1-5), Protect the Software (PS.1-3), Produce Well-Secured Software (PW.1/2/4-9 — PW.3 removed in v1.1), Respond to Vulnerabilities (RV.1-3). Named tooling throughout: SLSA build provenance, Sigstore cosign, in-toto attestations, OWASP ASVS for design, STRIDE / OWASP Threat Dragon for threat modeling, OpenSSF Scorecard, fuzzing (libFuzzer, AFL++), OSV-Scanner. 24 clauses, 57 directives
- **NIST SP 800-172 — Enhanced Security Requirements for Protecting CUI** — 35 enhanced security requirements supplementing 800-171 for CUI protection against advanced persistent threats. 14 families spanning Access Control, Awareness and Training, Configuration Management, Identification and Authentication, Incident Response, Personnel Security, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity. Includes 24/7 SOC requirement (3.6.1e), threat hunting (3.11.2e), supply-chain risk management (3.11.4e-3.11.7e), and deception/honeypots (3.13.2e). 46 clauses, 105 directives. Pairs with existing nist-800-171-r3 in the catalog
- **MITRE ATT&CK Enterprise Matrix v15** — 14 tactics covering the full adversary kill chain: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact. Each tactic body names key sub-techniques + concrete EDR/SIEM/detection tooling (Microsoft Defender for Endpoint, CrowdStrike Falcon, Sysmon + Sigma rules, Zeek + Suricata, MITRE Caldera, Atomic Red Team, OpenCTI, MISP). cajeX abstracts the 600+ technique catalog to tactic-level granularity for actionable directives. 29 clauses, 42 directives
- **MITRE D3FEND v0.13** — the defensive counterpart to ATT&CK. 17 defensive techniques across 6 categories (Model, Harden, Detect, Isolate, Deceive, Evict). Each clause cross-references the ATT&CK T-codes it addresses. Named tooling: Microsoft Entra Conditional Access, Falco runtime detection, Cloudflare Zero Trust, Thinkst Canary deception, OPA / Kyverno policy. 24 clauses, 51 directives
- Both MITRE frameworks carry the ATT&CK® / D3FEND™ trademark notice on framework cards per The MITRE Corporation's attribution guidance. All four are licensed for free use (NIST publications: public domain; MITRE: CC BY 4.0)
May 26, 2026
Automotive software safety — Automotive SPICE v4 + AUTOSAR + ISO 26262 (3 frameworks, 198 directives)
- Closes the Tier 2 automotive software-safety domain deferred from the original sprint plan. Three canonical references for automotive OEM / Tier-1 software engineering: process maturity, ECU software architecture, and functional safety. Combined with the aerospace track (ARP 4754A, AS9100D, DO-178C) already in catalog, cajeX now covers safety-critical software for both major transportation industries
- **Automotive SPICE (ASPICE) v4.0** — 24 processes across all seven categories (SYS.1-5, SWE.1-6, MAN.3/5/6/7, SUP.1/8/9/10, ACQ.4 + SPL.2, HWE.1-2 + VAL.1). Includes the v4.0 additions: Cybersecurity Risk Management (MAN.7), Hardware Engineering (HWE.1-2), and Validation (VAL.1). 32 clauses, 72 directives. Paywalled — VDA QMC paid PDF; the cajeX paraphrase pattern (citation + intent paraphrase + 'See ASPICE v4.0 PAM for binding text') applies
- **AUTOSAR — AUTomotive Open System ARchitecture** — 20 architectural concepts spanning Classic Platform (layered architecture, BSW module organization, RTE, OS, communication stack, diagnostics, memory stack), Adaptive Platform (ARA, FCM, ara::com, execution management, persistency, IAM), Methodology (ARXML, VFB, SWC modeling, mapping), and Cross-cutting concerns (cybersecurity — CryptoStack / SecOC / IdsM, ISO 26262 safety alignment, time sync gPTP). 25 clauses, 60 directives. Abstracts the 80+ BSW modules to architectural layer/cluster level rather than enumerating each — directive depth lives in concrete engineering deliverables, not module API names
- **ISO 26262:2018 — Road vehicles, Functional safety** — 22 in-scope across the engineering-relevant parts (3 through 9), skipping general/glossary/semiconductors/motorcycles. Part 6 (Software Level) is the most elevated with 6 leaves: SWREQ, SWARCH, SWUNIT, SWVER, SWINT, SWTEST — including ASIL-keyed quantitative bounds like MC/DC coverage at ASIL D, SPFM ≥ 99% for hardware metrics, and the decomposition rules from Part 9. 30 clauses, 66 directives. Paywalled ISO standard
- All three carry registered trademarks (Automotive SPICE®, AUTOSAR®, ISO) which now render as attribution chips + trademark notices in the framework About panel via the license-classification update earlier this week. Companions wire ASPICE + ISO 26262 + AUTOSAR to each other, plus to existing safety-critical frameworks (DO-178C, ARP 4754A, ISA-IEC 62443)
May 26, 2026
Software architecture + QA catalog — 12 frameworks (TOGAF, IEEE 42010, ISO 25010, C4 Model, ADR, arc42, Kruchten 4+1, ISO 29119, ISTQB, TMMi, xUnit Patterns, Google Testing — 428 directives)
- Software-architecture and quality-assurance frameworks for engineering organizations. Twelve new frameworks across two disciplines, exercising all five license classes simultaneously (the broadest license-class test the catalog has run)
- Software architecture (7 frameworks): **ISO/IEC/IEEE 42010 — Architecture Description** (the formal joint standard, paywalled, 14 clauses / 30 directives) · **ISO/IEC 25010 — Software Quality Model** (the canonical 8-characteristic quality model, paywalled, 11 clauses / 27 directives) · **TOGAF 10 — The Open Group Architecture Framework** (industry-membership, 14-stage ADM + supporting components, 19 clauses / 42 directives) · **C4 Model** (Simon Brown's diagrammatic notation — System Context, Containers, Components, Code, CC BY-SA, 13 clauses / 27 directives) · **ADR Pattern — Architecture Decision Records** (Michael Nygard open methodology, 15 clauses / 33 directives) · **arc42** (Gernot Starke's 12-section open template, CC BY-SA, 14 clauses / 36 directives) · **Kruchten 4+1 View Model** (the foundational 1995 IEEE paper, free, 10 clauses / 21 directives)
- Quality assurance (5 frameworks): **ISO/IEC/IEEE 29119 — Software Testing** (the joint ISO/IEC/IEEE testing standard parts 1-5, paywalled, 17 clauses / 33 directives) · **ISTQB Foundation Level Syllabus v4.0** (industry-membership certification body of knowledge, 24 clauses / 50 directives) · **TMMi — Test Maturity Model Integrated** (5-level open maturity model, free, 22 clauses / 48 directives) · **xUnit Test Patterns** (Gerard Meszaros' Addison-Wesley book — commercial-book IP profile: paraphrase-only with attribution + 'See xUnit Test Patterns (Meszaros, 2007) for binding text' closing, 19 clauses / 42 directives) · **Google Testing Practices** (Software Engineering at Google + Google Testing Blog, free, 19 clauses / 39 directives covering test sizes S/M/L/EN, testing pyramid, hermetic/deterministic/fast tests, flaky test management)
- Every paywalled framework carries the registered trademark notice in the framework About panel (TOGAF® / ISTQB® / TMMi® where applicable, plus ISO/IEC/IEEE attribution). Companions wire IEEE 42010 to TOGAF + C4 + arc42, ISO 25010 to ISO 9001 + GBP, ADR pattern to arc42 section 9 + 12-Factor, and Kruchten 4+1 to C4 + ISO 42010 view-correspondence rules. Test frameworks cross-walk: ISO 29119 to ISTQB, ISTQB to TMMi, TMMi to DORA Capabilities + Google Testing Practices
May 26, 2026
Data domain catalog + new attribution / trademark badges — DAMA-DMBOK + DCAM + CDMC (3 frameworks, 162 directives)
- Opens the data-domain track of the catalog with three canonical data management frameworks. First commercial-book and industry-membership data sources to land at scale — proves the new license-classification safeguards built into the catalog work end-to-end for IP-sensitive content
- **DAMA-DMBOK 2nd Edition (2017)** — Data Management Body of Knowledge, the canonical methodology covering the 11 Knowledge Areas of the DAMA Wheel: Data Governance, Data Architecture, Data Modeling and Design, Data Storage and Operations, Data Security, Data Integration and Interoperability, Document and Content Management, Reference and Master Data, Data Warehousing and BI, Metadata Management, Data Quality, plus the DAMA Data Management Maturity Model. 36 clauses, 23 in-scope, 69 directives. Commercial book published by Technics Publications — cajeX uses the paraphrase template (citation + intent paraphrase + 'See DAMA-DMBOK 2nd Edition for binding text' closing) with a hard coverage-breadth cap to keep usage well clear of fair-use concerns
- **DCAM — Data Capability Assessment Model** — EDM Council's framework for measuring data management capability maturity. 17 in-scope leaf controls across 8 components: Data Management Strategy, Business Case & Funding, Program, Governance (3 sub-capabilities), Data Architecture, Technology Architecture, Data Quality, Data Control Environment. 26 clauses, 51 directives. Industry-membership paywall
- **CDMC v1.1 — Cloud Data Management Capabilities** — EDM Council framework with Google Cloud sponsorship. 14 canonical Key Controls (KC-01 through KC-14) across 6 capability categories: Governance & Accountability, Cataloging & Classification, Accessibility & Usage, Protection & Privacy, Data Lifecycle, Data & Technical Architecture. Freely downloadable so cajeX quotes the published Key Controls verbatim. 20 clauses, 42 directives
- **New customer-visible UI behavior — attribution chips and trademark notices on framework cards.** Frameworks that require attribution (every paywalled source plus a few free-but-trademarked ones like Backstage® and DORA®) now show a small 'Attribution required' chip on the framework card, plus the trademark notice ('DAMA-DMBOK® is a registered trademark of DAMA International. Methodology summaries here are paraphrased educational references; consult the 2nd Edition for binding text.') in the framework About panel. Built so customers exporting evidence packs can see at-a-glance which content was paraphrased vs verbatim
May 26, 2026
Supply chain + platform engineering frameworks — SLSA, OWASP SAMM, OpenSSF Scorecard, Backstage Maturity, CNCF Cloud Native Maturity (5 frameworks, 244 directives)
- Closes two engineering-domain tracks of the catalog: software-supply-chain integrity and internal-developer-platform / cloud-native maturity. All five frameworks are free / CC-licensed so customers can pick them without IP-licensing friction
- Supply chain (3 frameworks, 133 directives): **SLSA v1.0 — Supply-chain Levels for Software Artifacts** (OpenSSF, 11 in-scope Build Track requirements covering Provenance L1/L2/L3, isolation, non-forgeability + 2 consumer Verification requirements; Source Track registered for v1.1 upgrade path; names GitHub Actions OIDC + Sigstore cosign + in-toto + Tekton Chains + BuildKit) · **OWASP SAMM v2.0 — Software Assurance Maturity Model** (15 practices across 5 business functions: Governance, Design, Implementation, Verification, Operations; each practice rolls up its 2 streams + 3 maturity levels into the leaf body; names ThreatModeler, OWASP ZAP, OWASP Dependency-Check, Cornucopia) · **OpenSSF Scorecard 2024** (19 automated OSS-project health checks across Source Code Hygiene, Build & CI, Dependencies & Vulnerabilities, Project Health, Security Documentation; names Dependabot / Renovate / CodeQL / Semgrep / OSV-Scanner / Trivy / OSSF Allstar / Sigstore cosign / gh-action-pin-current-version)
- Platform engineering (2 frameworks, 111 directives): **Backstage Maturity Model (Spotify, CNCF Incubating)** — 16 platform-portal maturity markers across 5 dimensions: Catalog Coverage, Software Templates, TechDocs and Knowledge, Plugins and Integration, Adoption and Operations. Names specific Backstage plugins by npm package name (`@backstage/plugin-kubernetes`, `@backstage/plugin-pagerduty`, `@backstage/plugin-cost-insights`, scaffolder templates, `catalog-info.yaml`, tech-radar, Permissions framework). 22 clauses, 48 directives · **CNCF Cloud Native Maturity Model v3** — 21 in-scope across the 5 maturity levels (Build / Operate / Scale / Improve / Optimize) crossed with the 4 cross-cutting dimensions (People, Process, Policy, Technology). Names CNCF projects + cloud-native tooling: Kubernetes, Istio, ArgoCD, Flux, OpenTelemetry, Prometheus, Falco, OPA, Kyverno, Crossplane, Thanos, OpenCost, Tetragon, KEDA. 27 clauses, 63 directives
- All five carry CC BY 4.0 or CC BY-SA 4.0 licenses so cajeX quotes the published spec text verbatim with attribution. Companions wire SLSA + SAMM + Scorecard to each other and to NIST 800-218 SSDF (also added this week), and Backstage + CNCF CNMM to DORA Capabilities + 12-Factor App + AWS / Azure / GCP cloud frameworks
May 26, 2026
Cloud-vendor parity — Microsoft Azure Well-Architected + Google Cloud Architecture Framework (11 frameworks, 489 directives)
- Multi-cloud parity for the engineering-domain catalog. After AWS Well-Architected × 6 pillars shipped earlier this week, customers running multi-cloud now get equivalent pillar-level guidance regardless of cloud provider. Each pillar lands as its own framework (mirroring how AWS WA is split) so customers can pick the cloud they run on and get pillar-specific directives — Cost Management policies for Azure, Cloud Cost Anomaly Detection rules for GCP, the same way AWS WA gives you AWS Cost Explorer baselines from aws-wa-cost-optimization
- **Microsoft Azure Well-Architected (5 pillars)**: Cost Optimization (19 in-scope, 57 directives — Microsoft Cost Management, Reservations, Savings Plans, Spot VMs, Azure Hybrid Benefit, Budgets, Azure Advisor) · Operational Excellence (16 in-scope, 48 directives — Azure DevOps, GitHub Actions, ARM/Bicep, Azure Monitor, Application Insights, Log Analytics, Azure Policy) · Performance Efficiency (16 in-scope, 48 directives — Azure Front Door, Application Gateway, Cache for Redis, Cosmos DB, AKS autoscaling, Azure Load Testing) · Reliability (16 in-scope, 47 directives — Availability Zones, Azure Site Recovery, Azure Backup, Chaos Studio, Cosmos DB multi-region) · Security (17 in-scope, 51 directives — Microsoft Entra ID, Defender for Cloud, Sentinel, Key Vault, Confidential Computing, Azure Firewall, Purview)
- **Google Cloud Architecture Framework (6 pillars)**: Cost Optimization (12 in-scope, 36 directives — Cloud Billing, BigQuery billing export, Committed Use Discounts, Spot VMs, Recommender, Active Assist) · Operational Excellence (14 in-scope, 42 directives — Cloud Build, Cloud Deploy, Anthos Config Management, Cloud Operations Suite SLO monitoring) · Performance Optimization (13 in-scope, 39 directives — Cloud Load Balancing, Cloud CDN, Memorystore, BigQuery, Spanner, GKE Autopilot) · Reliability (16 in-scope, 46 directives — Cloud Spanner multi-region, GKE multi-cluster, Anthos Service Mesh, Active Assist, Google SRE error-budget burn rates) · Security, Privacy, and Compliance (15 in-scope, 45 directives — Cloud IAM, IAP, Cloud KMS, Cloud HSM, Confidential Computing, VPC Service Controls, Cloud Armor, Chronicle, Binary Authorization, Assured Workloads, Cloud DLP) · Sustainability (10 in-scope, 30 directives — Google Cloud Carbon Footprint, Active Assist sustainability recommendations, Spot VMs, Tau / Axion ARM instances)
- Both Azure WAF and Google Cloud AF are vendor-published and free to reference. Companions cross-walk equivalent pillars across all three clouds (AWS Cost Optimization ↔ Azure Cost Optimization ↔ GCP Cost Optimization, etc.) so multi-cloud customers picking one pillar see the cross-cloud equivalents in the workspace framework picker
May 25, 2026
Engineering-domain catalog opens — Twelve-Factor App + DORA Capabilities + AWS Well-Architected × 6 pillars (8 frameworks, 375 directives)
- Opens an entirely new track in the cajeX catalog: engineering-domain frameworks that ship directives as design patterns, not compliance clauses. The catalog previously focused on regulatory + best-practice baselines (ISO 27001, NIST CSF, EU AI Act, etc.); this release adds the canonical software-delivery references customers use to build the systems those frameworks audit against
- **The Twelve-Factor App (Heroku / Adam Wiggins)** — the 12 canonical factors for cloud-native software-as-a-service applications: Codebase, Dependencies, Config, Backing services, Build/release/run, Processes, Port binding, Concurrency, Disposability, Dev/prod parity, Logs, Admin processes. 14 clauses (12 in-scope factors I-XII), 34 directives. Named tooling throughout: SLSA build provenance, distroless container bases, CycloneDX SBOMs, environment-config injection, GitHub Packages / Artifactory / CodeArtifact dependency registries
- **Google DORA Capabilities Model (2024)** — Google's evidence-based DevOps capability framework, derived from a decade of Accelerate State of DevOps Report research. 24 capabilities across 5 categories: Continuous Delivery (8 — version control, CI, deployment automation, trunk-based dev, test automation, test data management, shifting left on security, CD as a meta-capability), Architecture (2 — loosely coupled, empowered teams), Product and Process (4 — customer feedback, value stream visibility, small batches, team experimentation), Lean Management & Monitoring (5 — lightweight change approval, monitoring & observability, proactive notification, WIP limits, visual management), Cultural (5 — Westrum generative culture, learning support, team collaboration, job satisfaction, transformational leadership). 30 clauses, 72 directives
- **AWS Well-Architected (all 6 pillars) — each pillar as its own framework**: aws-wa-operational-excellence (16 in-scope, 48 directives) · aws-wa-security (18 in-scope, 53 directives) · aws-wa-reliability (18 in-scope, 54 directives) · aws-wa-performance-efficiency (10 in-scope, 30 directives) · aws-wa-cost-optimization (16 in-scope, 48 directives) · aws-wa-sustainability (12 in-scope, 36 directives). Full WA Tool depth: design principles + OPS01-11 / SEC01-11 / REL01-13 / PERF01-05 / COST01-11 / SUS01-06 best-practice questions. Best practices under each question roll into the question body — so picking a pillar surfaces ~30-50 actionable directives covering the named AWS services (IAM, KMS, CloudTrail, GuardDuty, Security Hub, Macie, Auto Scaling, Multi-AZ RDS, Aurora, Route 53, Resilience Hub, Fault Injection Simulator, Cost Explorer, Compute Optimizer, Graviton, Customer Carbon Footprint Tool)
- All eight are free / CC-licensed (Twelve-Factor App: CC BY-SA 3.0; DORA: CC BY-SA; AWS WA: vendor-open). cajeX quotes the published spec text verbatim with attribution rather than paraphrasing. Companions wire 12-Factor + DORA to each other and to the AWS / Azure / GCP cloud frameworks; AWS pillars cross-walk to existing NIST 800-53, NIST CSF, SOC 2, ISO 27001 where applicable
May 25, 2026
Industrial reference + wireless bundle — ISA/IEC 62443-1-x + 3-1 + ISA-100.11a (5 frameworks, 97 directives)
- Phase J.4 closes out the Industrial OT track. Adds the four reference parts of the ISA/IEC 62443 family that round out the complete 62443 catalog, plus the actionable ISA-100.11a wireless standard. After this release the 62443 family is fully represented (parts 1-1, 1-3, 1-4, 2-1, 2-3, 2-4, 3-1, 3-2, 3-3, 4-1, 4-2 — all 11 published parts)
- **ISA/IEC 62443-1-1 — Terminology, Concepts and Models** — the foundational reference for the entire 62443 family. Defines the 7 Foundational Requirements (FRs), Security Levels (SL-T / SL-C / SL-A), zones + conduits concept, defense-in-depth strategy, and IACS reference architecture. 16 clauses (3 in-scope conceptual obligations, 13 OOS reference) — used primarily as the family glossary. 9 directives
- **ISA/IEC 62443-1-3 — System Security Compliance Metrics** — quantitative metrics framework for IACS security posture (capability metrics, performance metrics, lifecycle metrics, reporting cadence). 13 clauses (5 in-scope), 11 directives
- **ISA/IEC 62443-1-4 — IACS Security Lifecycle and Use Cases** — Technical Report (status=draft) providing reference use cases that illustrate how the rest of the 62443 family applies across asset-owner / integrator / product-supplier perspectives. 11 clauses (2 in-scope navigational obligations), 4 directives
- **ISA/IEC 62443-3-1 — Security Technologies for IACS** — Technical Report surveying the security technology classes used in IACS deployments (authentication, encryption, segmentation, firewalls, IDS/IPS, vulnerability assessment, recovery). 18 clauses (4 in-scope architectural-selection obligations, 14 OOS technology survey), 12 directives
- **ANSI/ISA-100.11a — Wireless Systems for Industrial Automation** — the actionable wireless protocol stack for process-industry instruments and sensors (alongside WirelessHART). Defines architecture, application layer, transport, network (6LoWPAN), data link (TDMA + channel hopping), physical layer (IEEE 802.15.4), security (key management, authentication, confidentiality, integrity, replay protection), provisioning, conformance. 32 clauses (21 in-scope), 61 directives
- With this release the Industrial OT track J is comprehensive: 62443 cybersecurity family (all 11 parts), ISA-95 / 88 / 18.2 / 101 operations, ISA-84 / IEC 61511 + TR84.00.07 functional safety, ISA-100.11a wireless. Process manufacturers in oil & gas, petrochemical, pharma, power, manufacturing, utilities — and IACS product vendors — get end-to-end coverage from a single workspace selection
May 25, 2026
Industrial functional safety bundle — ISA-84 / IEC 61511 + ISA TR84.00.07 (2 frameworks, 108 directives)
- Phase J.3 completes the third leg of the Industrial OT track, after J.1 cybersecurity and J.2 operations. Functional safety frameworks for process industries (oil & gas, petrochemical, pharmaceuticals, power, LNG, offshore) — used to satisfy OSHA PSM, EPA RMP, and Seveso III safety-management obligations
- **ANSI/ISA-84.00.01 (IEC 61511) — Safety Instrumented Systems for the Process Industry** — the international SIS standard. Covers the full SIS lifecycle: management of functional safety, PHA and risk analysis, allocation to protection layers (IPLs), SIS safety requirements specification, design and engineering, FAT/SAT, validation, operation/maintenance/proof testing, modification, decommissioning, and documentation. 28 clauses, 60 directives at 1020c body avg. Required reference for any process plant operating SIS
- **ANSI/ISA TR84.00.07 — Fire, Combustible Gas, and Toxic Gas System Effectiveness** — Technical Report providing the F&G-specific design methodology that complements ISA-84/IEC 61511 for the F&G safety function class. Covers performance-based F&G design, hazard identification, detector selection and placement (point IR, line-of-sight, optical flame, smoke, heat), voting and logic, performance metrics, validation and testing. 24 clauses, 48 directives at 1020c body avg
- All paywalled (ISA + IEC) — clauses use the cajeX paraphrase template (citation + intent paraphrase + 'See standard for binding text' attribution). Companions wire the two together plus to ISA-18.2 (alarm management), ISA-101 (HMI), and ISA/IEC 62443-2-1 (cybersecurity wrapper for SIS infrastructure). With this release the Industrial OT track is comprehensive: 62443 family for cybersecurity, ISA-95/88/18.2/101 for operations, and ISA-84/TR84.00.07 for functional safety
May 25, 2026
Industrial operations management bundle — ISA-95 + ISA-88 + ISA-18.2 + ISA-101 (4 frameworks, 270 directives)
- Phase J.2 extends the Industrial OT track from cybersecurity (J.1 — ISA/IEC 62443 family) into operations management. Four canonical ISA operations standards covering enterprise-control integration, batch control, alarm management, and HMI design. Process manufacturers (oil & gas, petrochemical, pharma, food & beverage, biotech) get the core architectural + operational standards in one workspace selection
- **ANSI/ISA-95 (IEC 62264) — Enterprise-Control System Integration** — multi-part standard defining the Purdue Reference Model levels (0-4), object models (equipment, material, personnel, product definition), activity models for manufacturing operations management (MOM), and business-to-manufacturing transactions. 38 clauses, 81 directives. The architectural backbone for MES, scheduling, quality, and maintenance integration with enterprise ERP
- **ANSI/ISA-88 (IEC 61512) — Batch Control** — defines the physical model, procedural control model, recipe model, and information exchange for batch manufacturing. Used heavily in pharma, specialty chemicals, food & beverage, biotech. 32 clauses, 69 directives. Pairs with EU GMP Annex 11 for pharma electronic batch records
- **ANSI/ISA-18.2 — Management of Alarm Systems for the Process Industries** — 10-stage alarm management lifecycle: philosophy, identification, rationalization, design, implementation, operation, maintenance, monitoring & assessment (with EEMUA 191 KPI targets), management of change, audit. Widely referenced by OSHA PSM and EPA RMP. 30 clauses, 60 directives
- **ANSI/ISA-101.01 — Human Machine Interfaces for Process Automation Systems** — HMI lifecycle plus design principles (display hierarchy, grey-scale baseline, color discipline, dynamic representation, anti-clutter). The de facto standard for high-performance HMI design in process plants. 26 clauses, 60 directives. Pairs with ISA-18.2 for integrated alarm/operator-interface design
- All four are paywalled (ISA + IEC) — clauses use the cajeX paraphrase template (citation + intent paraphrase + 'See standard for binding text' attribution), never verbatim. Companions wire them to each other plus EU GMP, ISO 9001, and ISA/IEC 62443-2-1 for the security wrapper. After this release the catalog provides end-to-end coverage of the core ISA standards process manufacturers use day-to-day: 62443 for OT cybersecurity, 95 for enterprise integration, 88 for batch control, 18.2 for alarm management, 101 for HMI
May 25, 2026
Industrial OT cybersecurity bundle — ISA/IEC 62443 family completion (6 frameworks, 347 directives)
- Phase J.1 completes the ISA/IEC 62443 industrial-automation cybersecurity family in the cajeX catalog. The catalog previously had only IEC 62443-3-3 (System Security Requirements). With this release the full set of high-value 62443 parts is live — covering both asset owners (organizations operating IACS) and IACS product suppliers / integrators / maintenance providers. Multi-jurisdictional IACS programs (US ISA + international IEC + EU EN) get a single coherent governance baseline
- **ISA/IEC 62443-2-1 — Security Program Requirements for IACS Asset Owners** — establishes the cybersecurity management system (CSMS) for organizations operating industrial automation. 27 clauses, 54 directives. Three CSMS elements: risk analysis, addressing risk via the CSMS, monitoring and improvement
- **ISA/IEC 62443-2-3 — Patch Management in the IACS Environment** — covers patch management for both asset owners and IACS product suppliers. Patch information, evaluation, testing, deployment, post-deployment validation, exception handling. 23 clauses, 45 directives
- **ISA/IEC 62443-2-4 — Security Program Requirements for IACS Service Providers** — security capabilities required of integrators and maintenance providers (audited via IECEE conformity assessment). 12 capability areas: solution staffing, assurance, architecture, wireless, security engineering, configuration management, remote access, event management, account management, malware protection, patch management, backup/restore. 17 clauses, 36 directives
- **ISA/IEC 62443-3-2 — Security Risk Assessment for System Design** — the zone-and-conduit risk-assessment workflow (ZCR 1–8). Used by asset owners + integrators to identify zones/conduits, perform high-level + detailed risk assessments, determine SL-T, and document the cybersecurity requirements specification (CRS). 22 clauses, 54 directives
- **ISA/IEC 62443-4-1 — Secure Product Development Lifecycle** — for IACS product suppliers (component vendors). Eight SDL practice areas: Security Management, Specification of Security Requirements, Secure by Design, Secure Implementation, Security Verification and Validation Testing, Defect Management, Security Update Management, Security Guidelines. Audited via ISASecure Component Security Assurance (CSA). 29 clauses, 74 directives
- **ISA/IEC 62443-4-2 — Technical Security Requirements for IACS Components** — technical attributes of IACS components (embedded devices, host devices, network devices, software apps) organized around the 7 Foundational Requirements (FR1–7) with Component Requirements (CR) and capability Security Levels (SL-C 1–4). Counterpart to 62443-3-3 at the component level. 34 clauses, 84 directives
- All paywalled (ISA + IEC publications) — clauses use the cajeX paraphrase template (citation + intent paraphrase + 'See standard for binding text' attribution), never verbatim text. Companions wire the 62443 parts to each other and to ISO 27001, ISO 27005, NIST CSF 2.0, and SOC 2. With this release the catalog provides end-to-end IACS cybersecurity coverage for both asset-owner and product-vendor sides of the IACS market
May 24, 2026
UK financial-services AI bundle — BoE PRA SS1/23 (Model Risk Management) + FCA AI Update April 2024
- Phase H.3 of the AI Governance roadmap ships the UK financial-services AI regulatory pair. Two frameworks covering the two principal UK financial-services regulators — the Bank of England (Prudential Regulation Authority) and the Financial Conduct Authority — so that UK banks, investment firms, and FCA-authorised firms get consistent coverage across both regulator surfaces from a single workspace selection
- **BoE PRA SS1/23 — Model Risk Management Principles for Banks** — Supervisory Statement effective 17 May 2024, binding on PRA-regulated firms (UK banks, building societies, designated investment firms, PRA-designated insurance firms). Sets out FIVE high-level principles for model risk management covering ALL models including AI/ML: (1) Model Identification and Risk Tiering, (2) Governance (board accountability, SMF responsibility, internal audit), (3) Model Development / Implementation / Use, (4) Independent Model Validation, (5) Model Risk Mitigants (post-model adjustments, overrides, deactivation). 24 clauses, 54 directives at 1065c body avg
- **FCA AI Update — April 2024** — UK Financial Conduct Authority's articulation of its current regulatory approach to AI in financial services. Principles-based, technology-neutral; existing FCA frameworks (Principles for Businesses, Consumer Duty, SYSC, SMCR) apply to AI use. The Update endorses the five cross-sectoral AI principles from the UK government white paper (Safety/Security/Robustness, Transparency/Explainability, Fairness, Accountability/Governance, Contestability/Redress) and clarifies FCA-specific expectations under each. 27 clauses, 56 directives at 979c body avg
- With H.3 dual-regulated UK firms (banks providing FCA-regulated activities) get the full UK regulatory stack from one selection: SS1/23's binding model risk management practices + FCA's principles-based supervisory expectations. Companions wire both to NIST AI RMF, ISO 42001, EU AI Act, DORA, and (for the FCA side) NYDFS Circular Letter so multi-jurisdictional firms see the full picture. Note: the EU AI Liability Directive originally scoped for H.3 was withdrawn by the European Commission in February 2025; the EU AI Act remains the principal EU AI regulatory mechanism
May 24, 2026
Medical-device AI bundle — FDA PCCP (predetermined modification authority) + EU MDR AI-relevant subset
- Phase H.2 of the AI Governance roadmap ships the medical-device AI regulatory pair: the US and EU regimes that govern AI/ML-enabled medical devices. Both frameworks declare crosswalk companions to FDA GMLP, ISO 13485, NIST AI RMF, ISO 42001, and EU AI Act so the workspace picker surfaces the full implementation stack for medical-device AI teams
- **FDA Predetermined Change Control Plan (PCCP) — Dec 2024 final guidance** — Describes the recommended contents of a PCCP that supports modifications to AI/ML-enabled device software functions (ML-DSFs) without requiring a new FDA marketing submission for each modification. Builds on FDA GMLP. Covers Description of Modifications (what changes are authorized), Modification Protocol (data management / re-training / validation / update procedures), and Impact Assessment (benefit-risk / cybersecurity / post-market surveillance / traceability). 27 clauses, 51 directives at 1010c body avg with named SKUs (21 CFR 820.30, FD&C §524B cybersecurity, ISO 13485, GMLP P1-P10)
- **EU MDR 2017/745 — AI-Relevant Subset** — Curated subset of the EU Medical Device Regulation focused on the obligations most relevant to AI/ML SaMD (Software-as-a-Medical-Device) and MDSW (medical-device software). Covers Annex VIII Rule 11 (software classification — most AI SaMD lands Class IIa+), General Safety and Performance Requirements Annex I §1/§3/§17 (electronic programmable systems, software lifecycle, IT security, V&V), Article 10 manufacturer duties, Article 27/28 UDI, Article 52 + Annex IX conformity assessment, and Articles 83/86/87 post-market surveillance + PSUR + vigilance. 36 clauses, 69 directives at 1023c body avg. NOT a full MDR transcription — the 123 articles + 17 annexes of the full MDR remain out of scope; this is the AI-relevant slice. Workspace owners operating in both US + EU markets pick this alongside FDA PCCP and FDA GMLP
- With H.2 the cajeX catalog provides end-to-end medical-device AI coverage: design + lifecycle practices (GMLP), US predetermined-modification authority (PCCP), EU regulatory regime (EU MDR subset), QMS baseline (ISO 13485), and AI risk management (NIST AI RMF + ISO 23894). Multi-region medical-device AI teams get the full stack from a single workspace selection
May 23, 2026
Sector AI bundle — FDA GMLP (medical device), NYDFS Circular Letter (insurance), EEOC TAD (employment), ISO/IEC 23894 (AI risk)
- Phase H.1 of the AI Governance roadmap ships the first sector-specific AI add-on bundle. Four new frameworks that bind general AI governance practice to specific regulated sectors — medical device, insurance, employment, and the ISO companion to ISO 42001. All four are wired with crosswalk companions to NIST AI RMF, ISO/IEC 42001, and (where applicable) the sector-baseline frameworks (ISO 13485 for FDA GMLP, NYC LL 144 + Colorado AI Act for EEOC, EU AI Act for FDA GMLP)
- **FDA GMLP (Good Machine Learning Practice) — Oct 2021** — Joint guiding-principles document from FDA / Health Canada / UK MHRA. 10 principles covering multi-disciplinary TPLC expertise, software and security engineering, representative training and test data, reference dataset selection, model design fit-for-intended-use, human–AI team performance, clinical-condition testing, user-facing transparency, and post-deployment monitoring of AI/ML-enabled SaMD. 10 clauses, 30 directives at 979c body avg with named SKUs (21 CFR 820.30, ISO 14971, IEC 62304, ISO 13485 §7.3)
- **NYDFS Circular Letter No. 7 (2024)** — New York Department of Financial Services guidance on AI use by insurers. Covers fairness analysis and disparate-impact testing across protected classes (race, color, national origin, gender, age, religion, sexual orientation, marital status, disability), governance and risk management, data sourcing and lineage, third-party vendor management, and consumer disclosure. 20 clauses, 59 directives at 1007c body avg. NYDFS explicitly recognises NIST AI RMF as suitable underlying methodology
- **EEOC AI in Hiring TAD (May 2023)** — Equal Employment Opportunity Commission Technical Assistance Document on the assessment of adverse impact in employment selection procedures used to make employment decisions. Covers adverse-impact testing, the four-fifths rule, vendor responsibility under UGESP, remediation, and recordkeeping — all grounded in Title VII. 20 clauses, 60 directives at 1001c body avg with 87% named-SKU rate (UGESP, Title VII, EEO-1, 4 / 5ths rule, OFCCP)
- **ISO/IEC 23894:2023 (AI Risk Management)** — companion to ISO/IEC 42001. Built on ISO 31000, supplies the AI-specific risk principles, framework integration, and risk-management-process detail (communication, consultation, scope-context-criteria, assessment, treatment, monitoring, recording-reporting). 21 clauses, 60 directives at 935c body avg. Paywalled — verbatim_allowed=false; clause titles paraphrase intent and reference the ISO standard for binding text
- Each framework declares crosswalk companions so the workspace picker surfaces the broader baselines. FDA GMLP pairs with ISO 42001, NIST AI RMF, ISO 13485, EU AI Act. NYDFS pairs with NIST AI RMF, ISO 42001, Colorado AI Act. EEOC pairs with NIST AI RMF, NYC LL 144, Colorado AI Act, California AB 2013. ISO 23894 pairs with ISO 42001 and NIST AI RMF. With this release the cajeX catalog has the most comprehensive sector AI coverage we know of — workspace owners in regulated industries can pick the sector framework and get the cross-walked baseline practice in the same selection
May 23, 2026
AI jurisdictional bundle — California (AB 2013 + SB 1120 + AB 3030), Texas TRAIGA, Canada AIDA
- Phase E.5 rounds out the Tier-2 AI jurisdictional surface in the cajeX catalog. Five new frameworks covering the practical surface a US / Canada-operating AI vendor or deployer needs in 2026 alongside the existing Colorado AI Act and NYC LL 144. All five are wired with crosswalk companions to NIST AI RMF and ISO/IEC 42001 so the workspace picker surfaces the broader baselines the laws explicitly reference
- **California AB 2013 (GenAI Training Data Transparency)** — effective Jan 1, 2026. Requires developers of GenAI systems made available to Californians to publish a high-level summary of training data on their public website. 20 clauses, 45 directives. Codified at Cal. Bus. & Prof. Code §§22757-22757.4
- **California SB 1120 (Physicians Made Decisions Act)** — in effect since Jan 1, 2025. Constrains AI / algorithm use in health-plan and disability-insurer utilization review. Requires licensed-physician oversight, evidence-based criteria, individualised review, and prohibits denials based solely on AI categorical determinations. 13 clauses, 33 directives. Codified at Cal. Health & Safety Code §1367.01 + Cal. Insurance Code §10123.135
- **California AB 3030 (Generative AI in Healthcare Communications)** — in effect since Jan 1, 2025. Requires healthcare providers using GenAI to generate written or verbal patient-facing clinical communications to disclose the AI use and provide instructions for contacting a human provider. 8 clauses, 21 directives. Codified at Cal. Health & Safety Code §1339.75
- **Texas Responsible AI Governance Act (HB 149)** — effective Jan 1, 2026. Texas's first comprehensive AI law, narrower than the originally-proposed HB 1709. Focuses on governmental-agency AI use, prohibited applications (manipulation, social scoring, biometric surveillance, discrimination, CSAM/deepfakes), and consumer disclosures. AG-enforced; NIST AI RMF / ISO 42001 compliance is an explicit affirmative defense to civil penalties. 15 clauses, 27 directives. Codified at Tex. Bus. & Com. Code Ch. 552 + 553
- **Canada AIDA (Artificial Intelligence and Data Act)** — DRAFT. Originally bundled into Bill C-27 (2022); died on the order paper January 2025 when Parliament was prorogued; awaiting re-introduction or successor legislation. Imposes obligations on persons responsible for high-impact AI systems: risk assessment, mitigation, monitoring, human oversight, recordkeeping, incident notification. 21 clauses, 53 directives. Ships in draft status so Canadian-operating organisations can prepare ahead of finalisation
- Each framework's status flag is honest about its enforcement state: AB 2013, SB 1120, AB 3030, and Texas TRAIGA are published and in effect; Canada AIDA carries status='draft' so the picker surfaces it as still-pending. With this release the cajeX catalog has the most comprehensive published AI-governance picker we know of in any architecture-governance platform — covers EU (AI Act, GMP Annex 22), US federal voluntary (NIST AI RMF + GAI Profile), US state-comprehensive (Colorado, Texas), US sector-narrow (NYC LL 144, California three-bill bundle), international voluntary (ISO 42001, OECD AI Principles), and Canada federal (AIDA, draft)
May 22, 2026
EU GMP Annex 11 (Computerised Systems) and Annex 22 (AI in pharma manufacturing — draft)
- Phase E.4 of the AI Governance roadmap ships the two EU GMP annexes that supplement Volume 4 — the first end-to-end demonstration of the AI add-on pattern in cajeX. Both annexes are independent frameworks that declare a 'required' companion to eu-gmp-vol4; selecting either pulls Volume 4 in as the base, and selecting Annex 22 additionally pulls Annex 11 because AI/ML systems are a subset of computerised systems and inherit the Annex 11 baseline
- **EU GMP Annex 11 (Computerised Systems)** — 51 clauses covering the 17 sections of the 2011 revision: risk management, supplier qualification, validation (URS/FS/IQ/OQ/PQ), data integrity, accuracy checks, audit trail, change and configuration management, IT security, electronic signatures, batch release, business continuity. 102 directives at round-2 quality. Major EU revision is in consultation through 2025 with finalisation expected 2026 — cajeX will regenerate against the final text once published. Crosswalks ISO 27001 for the IT-security overlap
- **EU GMP Annex 22 (Artificial Intelligence in Pharma Manufacturing) — DRAFT** — 45 clauses across 12 sections: quality risk management for AI (with ICH Q9 integration), development of AI models, validation, operational performance monitoring, change control, data management, human oversight and decision support, documentation, continuous learning (Class B specific), and decommissioning. 99 directives at round-2 quality. **Currently DRAFT** — based on the July 2024 EMA stakeholder consultation; finalisation expected H2 2026. Marked status='draft' in the workspace picker so customers know the obligations may shift; cajeX will regenerate against the final text within one week of publication. Crosswalks both NIST AI RMF and ISO/IEC 42001 — pair them for cross-jurisdiction AI governance evidence
- Strategic significance: this is the first add-on framework pattern in the cajeX catalog where the picker chains companions explicitly — Annex 22 requires Annex 11 requires Volume 4. The pattern generalises: future sector annexes (FDA 21 CFR Part 11, medical device cybersecurity, etc.) can layer on top of their respective bases the same way without polluting the base framework's clause set
May 22, 2026
New framework — EU GMP EudraLex Volume 4 (Good Manufacturing Practice for medicinal products)
- Phase E.3 of the AI Governance roadmap lays the foundation for the pharma AI add-on pattern by adding the EU's primary GMP framework. EudraLex Volume 4 binds every Manufacturing Authorisation Holder (MIA, MIA-IMP) and Marketing Authorisation Holder (MAH) supplying medicinal products to the EU/EEA market — regardless of where the manufacturing physically takes place — under Directive 2001/83/EC. Harmonised across all EU/EEA national medicines agencies plus MHRA UK, and aligned with PIC/S GMP and ICH Q7-Q10
- cajeX maps Part I (Basic Requirements for Medicinal Products) end-to-end across its nine chapters: §1 Pharmaceutical Quality System, §2 Personnel, §3 Premises and Equipment, §4 Documentation, §5 Production, §6 Quality Control, §7 Outsourced Activities, §8 Complaints, Quality Defects and Product Recalls, §9 Self-inspection. 80 clauses total, 59 in-scope leaf controls, 176 directives at body avg 1004 chars per directive — concrete, named-procedure framing (PQS quality manual structure, CAPA workflows, change control thresholds, ICH Q9 risk-management techniques, GDocP requirements, cross-contamination prevention, batch processing records, QC laboratory independence, root-cause-analysis methodology for product recalls, self-inspection cadence)
- Part II (Active Substances), Part III (Quality Risk Management + Pharmaceutical Quality System guidance docs), and Part IV (Advanced Therapy Medicinal Products) are registered as out-of-scope placeholders for ToC completeness — they ship as separate cajeX frameworks if customer demand surfaces. The 22 Annexes (Annex 1 Sterile, Annex 11 Computerised Systems, Annex 22 AI in pharma manufacturing — draft, etc.) are NOT clauses on this framework; each ships as its own separate framework declaring a supplements companion to EU GMP Vol 4. This is the foundation for Phase E.4 which will add Annex 11 + Annex 22 as the first two such supplements
- Cross-walks ISO 13485:2016 (medical device QMS — combination-product manufacturers often hold both certifications) and ISO 9001:2015 (general QMS — useful when transitioning from a general quality system to pharma-specific GMP). Picker surfaces these crosswalks automatically when EU GMP Vol 4 is selected. Pairs with ICH Q10 / Q9 / Q7 when those eventually ship
May 22, 2026
Two new AI jurisdictional frameworks — Colorado AI Act and NYC Local Law 144 (AEDT Bias Audit)
- Phase E.2 of the AI Governance build adds the two highest-priority US state / city AI laws. Both are in-effect (NYC LL 144 since July 2023; Colorado AI Act takes effect February 2026) and both carry concrete employer-facing obligations, so workspaces preparing for either can now pick them directly. Each is wired with crosswalk companions to NIST AI RMF and ISO/IEC 42001 so the picker surfaces the broader AI governance baselines that the laws explicitly accept as evidence of reasonable care
- **Colorado AI Act (SB 24-205)** — first US-state comprehensive AI law. 31 clauses covering the developer obligations under §6.5-1702 (reasonable care, documentation to deployers, public statement, AG notification of algorithmic discrimination, NIST AI RMF safe harbor), deployer obligations under §6.5-1703 (risk management policy, annual impact assessment, consumer notice, public summary), and consumer rights under §6.5-1704–§6.5-1706 (notice, explanation, correction, appeal, human review). 48 directives at round-2 quality. Definitions (§6.5-1701) and enforcement / exemptions (§6.5-1707) registered for ToC completeness as out-of-scope. The Colorado AG-enforcement / reasonable-care framing relies on NIST AI RMF compliance, so the framework cross-walks both NIST AI RMF and ISO 42001
- **NYC Local Law 144 of 2021** — the AEDT (Automated Employment Decision Tool) bias audit law. 13 clauses covering §20-871 bias audit (independent auditor, annual cadence, disparate-impact analysis by sex / race-ethnicity / intersectional categories), §20-872 candidate and employee notice (10 business days before AEDT use, alternative selection process on request), and §20-873 publication of results on the employer's public website. 24 directives at round-2 quality. Triggered when an employer or employment agency uses an AEDT for any NYC-resident candidate or NYC role, regardless of employer headquarters. Cross-walks NIST AI RMF for the underlying bias risk-function methodology
- Both frameworks ship at the same round-2 quality bar as ISO 27001 and the rest of the catalog — body avg 988–998 chars per directive with named statutory triggers, quantitative thresholds (the 10-business-day notice clock, $1,500 LL 144 penalty cap, $50M Colorado revenue exemption, four-fifths-rule impact ratios), and vendor-neutral framing. Each carries the system applicability scope since both laws are per-AEDT / per-AI-system in scope rather than program-level
May 20, 2026
Mouse back button + tab persistence on IT Services, App Landscape, and Data Architecture
- The browser back button (and the back button on a mouse) now navigates between tabs on the IT Services (CMDB / ITSM / Correlation), App Landscape (Inventory / Sync / AI Review / Analytics), and Data Architecture (Assets / Domains / Sync / Quality / Lineage) views. Previously back left the page entirely; now it walks one tab at a time within the view, the same way it already did on the workspace surface
- Those same views also remember which tab you were on after a refresh — previously every refresh dropped you back on the leftmost tab. The tab name is stored per-view, so e.g. landing on Data Architecture → Lineage and refreshing brings you back to Lineage
May 20, 2026
AI governance frameworks (ISO 42001, NIST AI RMF, OECD AI Principles) now render their scope label
- Frameworks whose scope is the organisation's AI program (rather than the org as a whole, a single system, or a regulated data flow) now carry an "AI program" chip in the workspace Frameworks settings tab and in the onboarding framework picker. The chip and its tooltip ("Applies to the organisation's AI program / portfolio") were missing for these frameworks because the frontend hadn't been taught about the AI-program scope when the AI Governance pack shipped
- Same fix also prevents an edge-case render error on a future framework added with a brand-new scope value the frontend hasn't seen yet — the chip falls back to the raw scope value with an empty tooltip rather than crashing the page
May 20, 2026
Activity thread on projects + readable state-change log on findings
- Project detail now has an Activity section at the bottom that shows the project's full lifecycle history — every Activate / Put on Hold / Resume / Complete / Cancel / Reopen / Reactivate transition, plus the reason captured at the time of each change. You can also add free-form comments to the same thread (visible to anyone who can see the project), so discussion that previously had no home on a project finally has one. Previously the lifecycle reasons were recorded server-side but had no surface in the UI, and there was no way to leave a comment on a project at all
- Finding state changes no longer render as blank rows in the comment thread. Clicking Start Work, Submit for Verification, Reopen for Work, or Reactivate (transitions that don't require a typed reason) previously left behind comment-thread entries that displayed only the user's name and timestamp — no badge, no text, nothing about what actually changed. Both the status badge (e.g. "Reopened for work (Pending Verification → In Progress)") and a derived action label now render in the row body, so every transition is legible whether or not the user typed something
- The detail-page section that used to be called "Comments" on findings, projects, directives, and knowledge-base entries is now "Activity" — a single name that fairly covers both free-form discussion and the automatic state-change log it's always also displayed
May 19, 2026
Project card badges no longer clip on narrow layouts
- Project card badges (state, phase, organisation) now wrap to a second row when there isn't horizontal space for all three on one line — previously the rightmost badge clipped at the card's edge on the 5-column grid (most visible when the organisation name was long, e.g. "l2-developer-experience"). A single badge that's still wider than the card on its own row truncates with an ellipsis, and hovering reveals the full value via the existing tooltip
May 19, 2026
Doc Extract no longer fails with "R2 object missing" on workspaces with dedicated storage
- Uploading a document to a project, finding, or directive on a workspace with dedicated R2 storage previously surfaced "Error: R2 object missing" in the AI Activity log — the upload itself succeeded (the file landed in the workspace's own bucket) but the follow-on text extraction read from the shared default bucket and found nothing. Doc Extract now routes the read through the same bucket resolver the upload uses, so files in dedicated buckets extract correctly. Shared-bucket workspaces were unaffected; only workspaces migrated to dedicated storage hit this
May 19, 2026
Project lifecycle now has Activate / Put on Hold / Complete / Cancel buttons (matches directive + finding pattern)
- Project detail view now exposes a row of state-transition buttons at the top — Activate, Put on Hold, Resume, Complete, Cancel, Reopen, Reactivate — instead of forcing you into the edit form just to change the state dropdown. Buttons available at any moment depend on the project's current state (e.g. an On Hold project shows Resume and Cancel; a Completed one shows Reopen). Same state-machine pattern that already drives directives, findings, and knowledge-base entries — single source of truth in backend/src/services/transitions.ts
- Transitions that materially change the audit trail (cancel, hold, complete, reopen, reactivate) prompt for a reason inline before dispatching. The reason is recorded against a semantically-named field — "Reason for cancellation", "Reason for putting on hold", "Closing summary" — so the audit log row carries intent, not just generic text. Terminal transitions (Complete, Cancel) also show a confirm dialog before firing
- Activating a project from Draft and resuming from Hold are one-click — no reason required, since the audit trail of the activation/resume itself is the meaningful signal. The button bar disappears entirely for read-only seeded sample projects and for viewer-role members, so the affordance never appears for users who can't act on it
May 19, 2026
Project detail now reflects state and phase edits immediately, without close + reopen
- Editing a project's state, phase, or other fields and clicking Update Project now refreshes the detail view in place — previously the detail panel kept showing the pre-edit values until you closed and re-opened it (even though the project list cards and dashboard reflected the change immediately). Cause: the detail view's data-fetch only ran on a new project ID, so an in-place edit silently left the panel stale. The save flow now signals the detail panel to re-fetch, while preserving local UI state like description expand and dismissed banners
- Project cards in the grid no longer mash the "Updated" date against the Managers/Members count on narrow layouts — the date now wraps cleanly to its own line when there isn't horizontal room
May 19, 2026
Delete confirmation dialog now appears reliably for projects, directives, and knowledge base entries
- Clicking the trash icon on a project, directive, or knowledge base entry detail panel sometimes did nothing — the page would dim slightly but no confirmation dialog appeared, leaving the user with no way to delete from the detail view. Cause: a CSS cascade conflict between two backdrop classes applied to the same portaled overlay (one set z-index to 20, the other to 400, and whichever loaded later won), which on some chunk load orders dropped the dialog underneath the detail panel itself. The redundant class is removed; the dialog now reliably renders on top, centered over the viewport
May 19, 2026
Directives seeded from retired framework templates now auto-deprecate with a reversible explainer
- When a framework gets regenerated in the cajeX catalog at a higher quality bar, the old template rows are retired — but tenant workspaces that previously imported those templates kept the old directives, with their source-template reference now pointing to a deleted catalog row. Those directives now auto-deprecate with a clear explanation. The badge "Auto-deprecated" (amber) on the directive card and detail panel distinguishes them from manually-deprecated directives, and the directive detail shows the full reason inline — including the original catalog template_id for audit and the two paths forward (Reactivate to keep, or leave deprecated to clean up)
- Auto-deprecation is fully reversible — click Reactivate on any auto-deprecated directive to move it back to draft. Edits and content are preserved. The 24-hour cron only runs at 06:00 UTC and is bounded by a 25% per-tenant safety cap so a catalog issue cannot trigger a mass deprecation event in one go
- The catalog re-seed orchestrator (scripts/seed-curation/sweep-stale-directives.ts) is also available as an operator-side CLI for one-shot backfills with --dry-run and --tenant filters
May 19, 2026
Workspace Frameworks tab now shows the right "X of Y imported" count
- The Workspace Settings → Frameworks tab counted each tenant directive against a single "primary" framework (the one with the lowest sort_order it was mapped to in the catalog). When a directive served multiple frameworks (a shared crypto / IAM / observability directive mapped to both cajeX General Best Practices 2026 and ISO/IEC 27001, for example), it counted only toward ISO 27001 — so the GBP row showed "280 of 284 imported" even though all 284 were physically present in the workspace. Each framework row now counts every catalog directive present in the workspace regardless of what else it's mapped to. Shared directives count toward every framework they serve
May 19, 2026
Four new AI governance frameworks live — ISO 42001, NIST AI RMF, NIST GAI Profile, OECD AI Principles
- Four AI-governance frameworks are now available in every workspace, covering both the certifiable management-system standard (ISO/IEC 42001:2023), the US risk-management baseline (NIST AI RMF 1.0), the Generative AI extension (NIST AI 600-1), and the global values-based principles (OECD AI Principles 2019/2024). Combined with the EU AI Act 2024 that was already live, cajeX now covers the four most-referenced AI compliance vocabularies in one workspace — pick whichever your customers, regulators, or board demand, and have your directives traced back through their clause to the originating principle
- **ISO/IEC 42001:2023** — first certifiable AI management system standard. 93 clauses across the §4–10 management-system structure (same as ISO 27001 / 9001) plus the AI-specific Annex A control set (10 control objectives, 38 controls). 195 directives at round-2 quality (named SKUs, quantitative bounds). Layered companion to ISO 27001 for organizations adding AI governance on top of their existing ISMS
- **NIST AI Risk Management Framework 1.0** — voluntary US risk framework organized around 4 functions (GOVERN, MAP, MEASURE, MANAGE) and 72 subcategories. 214 directives. Foundation for most US enterprise AI programs
- **NIST AI 600-1 — Generative AI Profile** — companion to AI RMF specifically for generative and dual-use foundation models. 212 actions organized around 12 GAI-specific risk categories (CBRN information, confabulation, data privacy, environmental impacts, harmful bias, human-AI configuration, information integrity, information security, intellectual property, value chain integration, and others). 633 directives. Cross-walks back to its parent AI RMF subcategories — when you select both, the GAI actions surface alongside the AI RMF baseline they refine
- **OECD AI Principles (2019, updated 2024)** — the global intergovernmental baseline adopted by 46 countries. Five values-based principles (inclusive growth + well-being; human rights and democratic values; transparency and explainability; robustness, security and safety; accountability). 15 directives. Crosswalks to ISO 42001 and NIST AI RMF — typically layered with one or both rather than standalone
- All four frameworks ship at the same round-2 quality bar as ISO 27001, PCI DSS, and the rest of the catalog (1,057 directives total across the four, body average 973 chars per directive). ISO 42001 + NIST AI RMF are declared as mutual crosswalk companions — picking one surfaces the other as a complementary option in the workspace framework picker. NIST GAI Profile is declared as a crosswalk on top of NIST AI RMF so the two pair naturally for organizations doing generative-AI risk work
May 18, 2026
Findings now show their framework → clause → directive trail everywhere
- Every finding on the Findings page (and inside the finding detail panel) now shows the same framework → clause → directive trail that AI Review results already displayed — so you can tell at a glance which framework clause a finding traces back to without having to re-open the originating review run. Previously the trail only rendered inside an AI Review's results view; on the standalone Findings page the only context you had on a finding was the directive ID it was filed against
- The Framework dropdown in the AI Architecture Review modal no longer overflows the modal when long framework names are involved (for example "ISO/IEC 27017:2015 — Code of Practice for Information Security Controls Based on ISO/IEC 27002 for Cloud Services"). The dropdown now shows the short name ("ISO/IEC 27017:2015") with the full name on hover, and stops appending the version when it's already part of the name
May 18, 2026
Expand all in the Frameworks browser no longer dumps every parent's directives
- Clicking Expand all in the framework clause browser now opens the children tree under each category, but stops short of auto-rendering the directives mapped directly to top-level clauses. Previously, on frameworks where parent clauses themselves carry directives (ISO/IEC 27001 §4 "Context of the organization" maps three; same for §5, §6, etc.), Expand all unfolded the entire directive list for every fat parent in one go — a wall of content. Clicking an individual parent row in the tree still surfaces both its own directives and its children in one click; only the bulk Expand all action is now the lighter, structure-only view
May 18, 2026
Expand all / Collapse all in the Frameworks browser now works on every click
- In the framework clause browser (the side panel that opens when you click a framework card on the Frameworks page), the Expand all and Collapse all buttons now reliably fire every time you click them. Previously a click was a no-op if the panel was already in that state — for example, after Expand all had already opened everything, manually closing a category and clicking Expand all again silently did nothing. Both buttons now act as commands rather than a toggled state, so they always re-apply across whatever individual categories you've opened or closed in between
May 18, 2026
Frameworks tab no longer disappears after switching workspaces
- If you switched from a workspace with no selected frameworks to one with frameworks enabled (e.g. moving between a personal sandbox and your main workspace), the Frameworks tab in the Library section could stay hidden for up to two minutes even though the new workspace had frameworks. Cause: the cache that the sidebar uses to decide whether to show the tab was shared across all workspaces, so the empty result from the previous workspace silently carried over. Every workspace-scoped cache (frameworks, projects, findings, sessions, KB entries, directives, documents, dashboard metrics, calendar) is now isolated per workspace, so the sidebar — and every other view that reads them — reflects the active workspace immediately on switch
May 18, 2026
Press Esc or click outside to close any dialog — consistent across the platform
- Every modal and confirmation dialog in cajeX (Upload Document, Invite Member, AI Review, generate wizards, finding/session/project detail views, plan-change, billing, settings — the lot) now behaves the same way when you want to dismiss it. Esc closes, clicking on the dimmed area outside the panel closes, and the close button still works. Previously a handful of dialogs — including the Upload Document modal — only responded to the X button, so once you'd opened them you had no way out except finding the corner button. Long-running operations like saving, generating, or charging Stripe still block Esc/outside-click so you can't accidentally abandon them mid-flight
May 14, 2026
New framework — General Best Practices 2026 (cross-industry engineering baseline)
- A new directive framework called General Best Practices 2026 is now available in every workspace. 19 clauses spanning the modern software-delivery lifecycle — code quality, architecture, APIs, test strategy, build & CI/CD, deployment, reliability + error budgets, performance & capacity, observability, incident response, security, IAM, data governance, vendor & supply-chain risk, FinOps, developer experience, documentation, sustainability, and compliance operations. 91 directives total, each at the same depth as the ISO 27001 / EU AI Act content — named technologies (OpenTelemetry, Sigstore, OpenSLO, Sloth, Backstage, FIDO2, SCIM, SLSA, Vault, OneTrust, etc.), quantitative bounds (SLO burn-rate windows, retention SLAs, cost-attribution cadences), and vendor-neutral framing. Designed as a daily engineering reference that complements certification-driven frameworks (ISO 27001, SOC 2, EU AI Act, PCI DSS, HIPAA) — pick it up alongside whichever regulated framework your industry requires, or as the standalone baseline before you adopt one. The legacy General Best Practices framework remains enabled for now; both coexist while workspaces transition
May 13, 2026
New dedicated pages for AI Co-Worker, Team Workspaces, and Integrations
- The Product page used to fold AI, Workspaces, and Integrations into hash-based tabs that all shared a single URL. Each is now a standalone page — /features/ai-co-worker, /features/team-workspaces, and /features/integrations — with deeper content, example findings, FAQ sections, and full SEO metadata. The Product page itself becomes an overview with teaser cards linking to each. Anyone still on the old /product#ai, /product#tenancy, or /product#integrations URLs is automatically forwarded to the new feature page
May 12, 2026
Stuck AI document extractions auto-recover instead of spinning forever
- If a document extraction job ever gets stuck in "pending" (rare, but possible when the Worker DO is evicted mid-dispatch under heavy load), a new background sweeper now marks it as failed after 15 minutes so the AI Usage view doesn't show a perpetual "Running" row. The matching sweeper for the AI Usage placeholder row was already in place (30-minute timeout); this closes the gap on the extraction-row side. The DO's own 10-minute watchdog still runs first under normal conditions
May 12, 2026
Parallel PDF extraction is now actually parallel — and the batch progress is visible
- AI document extraction's parallel fan-out no longer does the work twice. The 5 page-range batches are now dispatched sequentially (each POST returns its 202 in under a second) instead of as a single connect-burst that the Cloudflare tunnel layer would occasionally treat as a flap and silently retry. On the previous parallel-burst code path a single retry doubled the proxy load — extracting a long PDF on the sandbox proxy ran 10 concurrent Claude vision jobs instead of 5, took ~10 min instead of ~4 min, and burned twice the Anthropic quota. Same wall-clock improvement applies in production
- The "Extracting attachments" status panel now shows the "batch X / N" sub-progress as soon as fan-out starts, not after every batch successfully dispatched. Previously the row only got its `batches_total` count after all 5 dispatches landed; on a slow proxy this delay was long enough that users saw a frozen "Extracting attachments (0/1)…" without any per-batch visibility
May 12, 2026
AI KB Generation also benefits from parallel extraction
- AI Knowledge Base Generation now reuses the same upload-time document extraction that AI Project Generation already uses, so a large PDF only gets extracted once even when you re-trigger generation. Previously KB Generation re-ran extraction from scratch every time, which on a long book-length PDF would add another ~1.5 minutes per attempt. The KB Generation progress panel now also shows the "batch X/N" per-attachment substage while parallel extraction is running
May 12, 2026
AI document extraction now runs in parallel — long PDFs finish in roughly a minute
- Document extraction for AI features (AI Project Generation, AI Review attachments, KB attachments) now fans out large PDFs into 5 parallel sub-jobs and merges the results in page order. End-to-end extraction wall-clock on a 50-page document drops from ~6 minutes to ~1.5 minutes because the bottleneck — Claude vision OCR of the rendered pages — runs concurrently across the slices instead of sequentially in one call. Smaller files (under 1 MB) are unchanged; they were already fast
- AI Project Generation's status panel now shows live per-batch progress — "Bible.pdf: batch 3/5" — while a fanned-out PDF is extracting, so the wait no longer looks like a frozen spinner
May 12, 2026
AI generation no longer times out on very long PDFs
- AI Project Generation and AI KB Generation no longer fail with a "Document extraction failed — please retry" error when the uploaded PDF is hundreds of pages long. Internally the document-to-image step was rendering every page of the input before applying a 50-page cap, so a long book-length PDF would blow past the 60-second render budget and return nothing. The cap is now applied during rendering so wall-clock time is bounded by the cap (≈15s) regardless of document length, and the first 50 pages — typically the executive summary, scope, and overview — make it through to the AI
May 12, 2026
Admin Overview and project limits now match your actual plan
- The Admin Overview "Workspace Usage" badge and the project / directive / member quota gates now read your plan from the same source as the Billing tab, so they can no longer disagree. Previously a subscribed workspace could see Billing show "Current Plan: Basic (Active)" while Admin Overview still rendered a "FREE" badge and the Create Project button rejected at the 1-project free limit. The discrepancy happened when the Stripe webhook that mirrors your plan onto the platform record didn't deliver (rare in production, easy in sandbox), and previously needed a manual "Refresh from Stripe" click to clear
May 12, 2026
Modals and confirmation dialogs now float correctly over the page
- Uploading attachments directly to a Knowledge Base entry's detail view now succeeds. The form was sending a stale value for the upload target ("knowledge_base" instead of "kb") so the backend rejected every file with a generic validation error. Uploads from the KB entry form, projects, and the Documents view were unaffected
- The Upload Documents modal now floats correctly centered over the page regardless of which view opened it. Previously, when opened from the KB entry slide-over or any other slide-over panel, the modal rendered offscreen at the top and you had to scroll inside the panel to find it
- Every other confirmation dialog, edit-acknowledgement modal, and "mark as reviewed" / regeneration modal also now appears centered over the page when opened from inside a detail panel (Knowledge Base entries, Directives, Projects, Sessions) — same root cause as the file-upload fix above, swept across the codebase
- State-transition comment boxes (e.g. archive a Knowledge Base entry, deprecate a Directive, change a Finding's state) now correctly say "Add a comment (required)…" instead of "(optional)…". The Confirm button has always required a non-empty comment on these flows; the placeholder used to claim optional, so users typed nothing and wondered why Confirm stayed grey
May 11, 2026
Admin Organisations — new orgs now keep the values you entered
- Creating an Organisation now correctly persists the Abbreviation, Display Order, and Active state from the form. Previously the create endpoint silently dropped those three fields, so every new Organisation came back with no abbreviation, display order zero, and an Inactive badge — even though the form had captured the values you typed. Existing Organisations are unaffected; only new creates were broken
May 11, 2026
Small bug fixes — KB, Reports, Projects, Admin Organisations
- Archiving or restoring a Knowledge Base entry now updates the overview filters and entry list immediately. Previously the status change went through on the detail page but the overview cached its previous status until you hard-refreshed the browser
- Reports → Report Card → back button now reads "Back to Reports" instead of "Back to Projects" (the destination was always Reports; only the label was wrong)
- Create Project form in Safari no longer pops the iOS / macOS Contacts picker on the Project Name field — Safari's autofill heuristic was matching the substring "name" and offering to fill the field with people from your address book
- Admin → Organisations → Add Organisation modal now exposes the Active checkbox at creation, matching Expert Roles and Categories. Defaults to checked, so the create flow is one click for the common case
May 11, 2026
AI Directive Generation progress UI now matches the KB Generation flow
- Step 2 (generating directives) and Step 3 (analyzing relationships) of the AI Directive Generation modal now use the same stage-row layout as KB Generation — a checked-or-spinning row per stage with clear running/done/pending labels — instead of an outsized top spinner with redundant stage text underneath
- The analyzing step now shows both stages explicitly ("Scoring against existing directives" and "Classifying with AI (N/M)") so it's obvious which phase you're in and how far along the per-draft classification has progressed
- Both steps now show a consistent dismiss hint making it clear generation continues in the background if you close the window
- Closing the modal during relationship analysis no longer prompts you to discard your unsaved drafts — analysis continues in the background, and a new "AI directive analysis in progress" banner lets you re-open the modal and resume exactly where you left off. Previously the close button asked whether to discard, and accepting silently dropped the in-flight work
- Version History on the directive detail page now reflects the correct "Viewing" version after navigating between siblings (e.g. clicking v2 from the v1 page). Previously the "Viewing" tag stayed on the version you opened from, because the timeline data was cached on the original directive and never re-fetched for the new one
May 11, 2026
Free signup now reliably seeds your new workspace
- Free-plan workspaces created via magic-link signup now reliably receive their starter directives and sample project — previously the workspace could ship empty whenever the underlying shard fleet wasn't perfectly balanced, because the routing record and the foreign-key anchor for the new workspace's data landed on different shards and every seed insert was rejected silently
May 11, 2026
Admin Overview directive count + onboarding picker polish
- Admin → Overview's "Directive Health" tiles now show the true counts for every status (Approved, Draft, In Review, Deprecated) regardless of library size. Previously the panel fetched a paginated directive list and capped at the first 100, so any workspace with more than 100 directives quietly undercounted
- Workspace Usage panel now has a small note clarifying that sample data and framework-seeded content are read-only and excluded from these quotas — so seeing "Directives 0 / 1,000" right next to a full library of seeded directives no longer reads as a bug
- Onboarding wizard's framework picker gets a "Clear all" link next to the selection counter, so a user who has manually ticked several frameworks can deselect everything except General Best Practices (which stays locked) in one click
May 10, 2026
Workspace creation reliability + framework directives no longer count toward your plan quota
- cajeX-provided framework directives (anything you got from importing General Best Practices, ISO 27001, NIST, GDPR, etc.) no longer count toward your workspace's directive quota — only directives you author yourself do. Workspaces that imported large frameworks were showing thousands of directives against a 5-directive Free-plan cap; that's now corrected everywhere it appeared (Workspace Usage panel, Billing usage, plan-downgrade eligibility checks)
- New workspace onboarding no longer hangs on the Launch step when you select multiple frameworks. Directive seeding now writes in batches instead of one row at a time, so even a maximal-import workspace finishes well within the request window
- Framework recommendations on the Plan step are now industry-specific instead of cross-industry by default. Picking your industry pre-selects only frameworks explicitly tagged for that industry (plus General Best Practices); broad cross-industry frameworks like SOC 2, ISO 27001, and GDPR remain visible and one-click selectable but no longer auto-tick on every onboarding
- Frameworks you select during workspace onboarding now appear correctly in the Frameworks tab and the Directives page's framework filter. Previously the initial onboarding wizard seeded the directives but didn't record which frameworks were imported, so the picker only listed General Best Practices even when you'd added several others
- Sample workspace data shipped with new onboardings (the demo projects, sessions, findings, attachments, and pre-completed AI reviews) is now properly tagged as cajeX-provided. Two consequences: (1) sample data no longer counts against your plan's project, storage, or AI-review quotas — only your own work does — and (2) sample rows are read-only in the UI, so you can't accidentally edit or delete the demo content. New workspaces start with extra room to create your own work, and a small lock icon marks every sample item
May 10, 2026
AI Directive Generation — major upgrade to the relationship analysis step
- Two-axis decisions instead of a single conflated dropdown — Step 3 now lets you choose what happens to the proposed draft (create as standalone, create as a new version of an existing directive, or discard) and what happens to the impacted existing directive (no change, or deprecate) independently
- Approved directive content is never mutated in place. Every content change creates a new draft v2 row that links to v1, and v1 stays effective for AI Review until v2 is approved — at which point v1 auto-deprecates in the same request
- AI explanations are substantively richer: a 2–3 sentence "Why v{N}" rationale on every version recommendation, plus a "Show full AI analysis" disclosure that expands to a 4–6 sentence chain-of-thought walkthrough so you can verify the reasoning before approving
- When a new version materially changes the scope of an existing directive (e.g. AS/400-specific → all legacy modernization), the AI now suggests a fitting v2 title with a one-click "Use this title" apply button
- Comparisons between existing and new content are easier to read — the diff renders sentence-rewrites as block-level delete-then-insert pairs while keeping inline word-level marks for small edits, so heavy rewrites read as prose instead of token salad
- Saves through this flow write a comment to both the new and impacted directives, with the source KB entry referenced — visible in the Comments panel on each directive's detail page
- Smaller polish across the screen: dynamic v{N} labels (no more "v2" when the existing is already v3), confidence badges with explicit "Low/Medium/High confidence" labels and tooltips, internal token-overlap scores no longer leaked into user-facing prose, and a clear banner if AI semantic analysis is temporarily unavailable so deterministic match results are honestly labelled
- Relationship analysis cost now appears on the AI Usage page as its own row alongside Directive Gen and Doc Extract, so per-workspace AI spend is fully attributable
May 8, 2026
Framework picker upgrades on the Directives page and AI Review
- Directives page now has a strict, multi-select framework picker — pick "Custom" and/or one or more installed frameworks, and the list shows only directives from those buckets (no more silent mixing of custom directives into a framework view)
- AI Architecture Review now scopes one review to one framework: pick "Workspace custom directives" (the new default) or a specific framework, and the directive count, categories, and types update to match
- Both surfaces now agree on what "belongs to" a framework — fixing a bug where the Directives list and AI Review reported different directive counts for the same framework
May 8, 2026
Cleaner experience after scheduling a workspace deletion
- Deleting the workspace you were currently signed into no longer blocks you from listing or switching to your other workspaces
- Workspaces scheduled for deletion now show a clear "Scheduled for deletion" badge in the workspace switcher; clicking one opens its Danger Zone so you can cancel deletion in one click
- API error responses are no longer cached by the browser, so transient errors clear immediately on retry instead of sticking until you clear cookies
May 7, 2026
Framework Compliance view for AI Review results and findings
- AI Review results now group findings by compliance framework (ISO 27001, GDPR, etc.) with a toggle to switch back to the previous verdict-grouped layout
- Each finding in AI Review shows its full framework → clause → directive trail so you can see exactly which normative requirement it relates to
- Finding detail modal now shows the framework and clause context above the finding metadata
- New Framework Compliance Report option in Reports — select a framework and download a CSV covering clause-by-clause coverage, gaps, and finding detail
May 4, 2026
Workspace usage limits now match your plan
- Fixed the Workspace Usage panel showing the wrong storage cap on Pro, Team, and Enterprise plans — limits now match exactly what's listed on the pricing card
May 4, 2026
Free workspace inactivity flow
- Free workspaces now auto-restore on return — signing in cancels a pending archive instead of leaving the workspace blocked
- Added a second pre-archive email so every archive is preceded by two warnings, with at least 48 hours between the final notice and the archive itself
May 1, 2026
General Availability
- Knowledge Base for curating architecture standards, best practices, and reference materials
- AI-generated directives — principles, decisions, and guardrails extracted from your knowledge base
- Directive lifecycle with draft, review, approval, and deprecation stages
- Architecture Sessions with AI-powered review against approved directives
- Findings Management with severity levels, AI confidence scores, and a full remediation lifecycle
- Dashboard & Analytics with real-time KPIs across projects and findings
- Document Management with versioning, backed by Cloudflare R2
- Reports & Compliance with Markdown and PDF exports
- Multi-tenant workspaces with strict data isolation and per-workspace branding
- Role-based access control and SSO-ready identity management