Help CenterRelease Notes

Release Notes

What has changed in the Neostra platform, by month.

Neostra is updated continuously. This page summarises customer-visible changes. Dates are the month the change reached production.

August 2026

Assessments

  • Assessment questions can be linked to Data Inventory objects when the Data Inventory module is enabled for your tenant.
  • Brand and Process are now optional on assessments.

Data Inventory

  • Custom attributes and metadata on Data Collection Sources and Data Subjects.
  • Scan scope rules: include or exclude specific schemas, tables, and columns from a scan.
  • Amazon S3 connections accept a custom endpoint URL.
July 2026

Security

  • Tenant administrators can enforce two-factor authentication for all users. New tenants have enforcement on by default.

Privacy Rights Manager

  • Intake form attachments upload as soon as they are selected.
  • Task response attachments record who uploaded them.

Assessments

  • Template questions can carry a default assignee. Assessments created from the template assign those questions automatically.
  • "Answer Question" and "Start an Assessment" actions in assessment rules, including linking follow-up assessments back to the assessment that started them.
  • "Send Email" action in collection point rules, with consent display names available as choices.
  • The embed snippet copy dialog validates the script URL and integrity hash before you copy.

Data Inventory

  • Scan schedules on an integration, with a Schedule tab showing the last scheduled scan status.
  • A first full scan runs when a source is onboarded.
June 2026

Integrations

  • Integration API for creating and reading privacy requests programmatically, with scoped API tokens managed under Integrations > API Tokens. See Integration API.
  • Webhooks are now product-agnostic: one API configuration can be used from Privacy Rights Manager, Breach Management, and Assessments rules.
  • Webhook retries with a configurable maximum, replay of failed deliveries, and an idempotency key on every call.
  • Webhook secrets are stored encrypted and are write-only once saved.
  • Delivery logs: filter by module, search by run or entity, and follow the lineage of a call. See Webhooks.

Breach Management

  • Redesigned workflow builder with Details, Builder, and Rules tabs.
  • "Call API" advanced action with custom headers and variable interpolation in email subject and body.

Assessments

  • System DPIA templates are read-only, with scored export and import.
  • Rule builder drawers and scored template preview.

Security

  • Sessions now use short-lived tokens with automatic refresh and an explicit sign-out.
  • Unified breadcrumb navigation across modules.
May 2026
  • Preference center rules can trigger webhooks.
  • Consent submissions record the regulation that applied to the visitor.

Governance

  • Read-only mode for non-owners in the readiness assessment. Open the assessment directly from the dashboard.

Settings

  • The data retention policy for request and consent records is shown in tenant settings.

Security

  • Personal data captured in privacy requests is encrypted at rest.
April 2026
  • Auto-blocker: third-party scripts, images, and iframes are held until the visitor consents to the category their vendor belongs to.
  • IAB TCF v2 signal support.
  • Re-solicitation: visitors are asked again when your published configuration changes.
  • Banner rule conditions redesigned: Accepted All, Rejected All, or a specific category.
  • Banner rules and preference center rules are configured separately.
  • Cookie scanner ships with a library of well-known cookie classification rules and vendor-domain fallback for scripts and iframes.
  • Monthly consent quota enforced per plan.

Security

  • Account lockout after five failed sign-in attempts.
  • Minimum password length raised to 14 characters.

Data Inventory

  • Attribute type replaced with separate category and data type fields.
March 2026

Platform

  • Initial release: Governance, Breach Management, Privacy Rights Manager, Data Inventory, Privacy Center, Consent Management, Assessments, and Privacy Notices.
  • Multi-tenant with brand-level access control and role-based permissions.
  • Audit log of user actions across modules.
  • User interface available in more than 50 languages.
Was this page helpful?