RiskPilot Website FR GitHub

Product roadmap #

Delivered on 23 August 2026 #

  • AI-generated structured third-party risk using only visible scopes, assets and threats, with rationale, editable fields and separate confirmation;
  • AI-generated remediation action from eligible compliance gaps, with proposed priority, type and due date, user-selected owner and no invented evidence.

Delivered on 9 August 2026 #

  • compliance-assessment lifecycle from draft to archive with automatic active-result creation;
  • global and compliance copilots with consent, context preview, auditing and guided drafts;
  • corrected maturity radar, separate not-applicable items and entry lock after completion;
  • RBAC matrix protected by admin.roles with non-revocable super-administrator rights;
  • mutually exclusive navigation groups with automatic opening of the active section;
  • complete five-workshop EBIOS RM workflow with ordered independent validation;
  • dedicated NIS2 management view and organization-configurable RBAC matrix;
  • guided operational-record editing and readable structured-data presentation;
  • enriched annual and decision PDFs with summaries, rankings, maturity and appendices;
  • governed RGPD, NIS2, ISO/IEC 27001:2022 and EBIOS Risk Manager starter packs;
  • per-requirement maturity radar with strengths, weaknesses and remaining work;
  • native PDF exports for annual and decision reports;
  • encrypted, tenant-scoped Mistral, OpenAI, Gemini or compatible copilot settings;
  • stronger compliance-relationship validation and preservation of the stored business status for overdue actions.

Delivered on 1 August 2026 #

  • operational workspace for tasks, responsibilities, trajectories, questionnaires, campaigns and packs;
  • decision workspace for Security by Design, financial quantification, 360-degree views, governed reports, connectors and the TPRM portfolio;
  • experiments without automated decisions and a versioned internal library;
  • versioned analyses, governed artifacts, quality checks, comparison and approval;
  • annual reports, justified 0-to-5 cyber maturity and immutable exportable snapshots.

Delivered on 26 July 2026 #

The foundations of all four stages are available:

  1. explicit asset families and three specialized views;
  2. ticket, origin, type, frameworks, requirements and custom fields for actions;
  3. bidirectional action relationships with audit findings and compliance results;
  4. KPI/KRI definitions, time-series measurements, idempotency, batch import and CSV export.

The complete interface is also available in French and English according to the profile preference.

Increments still to industrialize #

Planned
  • extend closure blocking to every finding workflow;
  • complete time pagination and versioned measurement corrections;
  • service keys with read, write and administration scopes;
  • threshold alerts, notifications and accessible trend charts;
  • individual visible-column selection and richer specialized imports/exports.

Delivery rules #

Every increment must preserve reversible migrations, existing data, tenant isolation, RBAC, audit, server validation, responsive behavior, tests, API documentation and Docker checks. No public delivery date is promised.