Release Notes
What has changed in the Neostra platform, by month.
Neostra is updated continuously. This page summarises customer-visible changes. Dates are the month the change reached production.
August 2026
Assessments
- Assessment questions can be linked to Data Inventory objects when the Data Inventory module is enabled for your tenant.
- Brand and Process are now optional on assessments.
Data Inventory
- Custom attributes and metadata on Data Collection Sources and Data Subjects.
- Scan scope rules: include or exclude specific schemas, tables, and columns from a scan.
- Amazon S3 connections accept a custom endpoint URL.
July 2026
Security
- Tenant administrators can enforce two-factor authentication for all users. New tenants have enforcement on by default.
Privacy Rights Manager
- Intake form attachments upload as soon as they are selected.
- Task response attachments record who uploaded them.
Assessments
- Template questions can carry a default assignee. Assessments created from the template assign those questions automatically.
- "Answer Question" and "Start an Assessment" actions in assessment rules, including linking follow-up assessments back to the assessment that started them.
Consent Management
- "Send Email" action in collection point rules, with consent display names available as choices.
- The embed snippet copy dialog validates the script URL and integrity hash before you copy.
Data Inventory
- Scan schedules on an integration, with a Schedule tab showing the last scheduled scan status.
- A first full scan runs when a source is onboarded.
June 2026
Integrations
- Integration API for creating and reading privacy requests programmatically, with scoped API tokens managed under Integrations > API Tokens. See Integration API.
- Webhooks are now product-agnostic: one API configuration can be used from Privacy Rights Manager, Breach Management, and Assessments rules.
- Webhook retries with a configurable maximum, replay of failed deliveries, and an idempotency key on every call.
- Webhook secrets are stored encrypted and are write-only once saved.
- Delivery logs: filter by module, search by run or entity, and follow the lineage of a call. See Webhooks.
Consent Management
- Embed snippet with Subresource Integrity (SRI). See Cookie Consent Modal.
Breach Management
- Redesigned workflow builder with Details, Builder, and Rules tabs.
- "Call API" advanced action with custom headers and variable interpolation in email subject and body.
Assessments
- System DPIA templates are read-only, with scored export and import.
- Rule builder drawers and scored template preview.
Security
- Sessions now use short-lived tokens with automatic refresh and an explicit sign-out.
- Unified breadcrumb navigation across modules.
May 2026
Consent Management
- Preference center rules can trigger webhooks.
- Consent submissions record the regulation that applied to the visitor.
Governance
- Read-only mode for non-owners in the readiness assessment. Open the assessment directly from the dashboard.
Settings
- The data retention policy for request and consent records is shown in tenant settings.
Security
- Personal data captured in privacy requests is encrypted at rest.
April 2026
Consent Management
- Auto-blocker: third-party scripts, images, and iframes are held until the visitor consents to the category their vendor belongs to.
- IAB TCF v2 signal support.
- Re-solicitation: visitors are asked again when your published configuration changes.
- Banner rule conditions redesigned: Accepted All, Rejected All, or a specific category.
- Banner rules and preference center rules are configured separately.
- Cookie scanner ships with a library of well-known cookie classification rules and vendor-domain fallback for scripts and iframes.
- Monthly consent quota enforced per plan.
Security
- Account lockout after five failed sign-in attempts.
- Minimum password length raised to 14 characters.
Data Inventory
- Attribute type replaced with separate category and data type fields.
March 2026
Platform
- Initial release: Governance, Breach Management, Privacy Rights Manager, Data Inventory, Privacy Center, Consent Management, Assessments, and Privacy Notices.
- Multi-tenant with brand-level access control and role-based permissions.
- Audit log of user actions across modules.
- User interface available in more than 50 languages.
Was this page helpful?