Skip to main content

TPRM Release Notes - 2026-SEP-23

Hyperproof TPRM Advanced

There were no updates for TPRM Advanced in this release.

Hyperproof Vendor Management

There were no updates for Hyperproof Vendor Management in this release.

Hyperproof TPRM Core

TPRM Core to Hyperproof Risk Register integration

Risks identified through TPRM Core can now be created directly in the Hyperproof Risk Register, centralizing vendor and organizational risk in one place.

Questionnaire document type for AI-based assessments

Vendors can now upload pre-filled questionnaires as a dedicated document type. This unlocks AI-based assessments generated directly from vendor-submitted questionnaire content.

Addressed issues

Re-assessment schedules

Several issues affecting how re-assessment dates are calculated have been resolved:

  • Criticality Tier is now filterable in the "For Vendors" section of schedules and reminders. It was previously hidden after a prior update, preventing customers from setting different cadences by criticality (e.g., 12 months for Critical/High and 24 months for Medium/Low).

  • "External posture rating changed" trigger fixed - It was incorrectly firing on Criticality Tier changes instead of the vendor's external posture rating.

  • Multi-rating updates are now evaluated consistently - When one action changes several vendor ratings at once, all matching rules are triggered based on the final state, removing timing-dependent inconsistencies.

  • Renewal date changes now start the reassessment cycle, regardless of source - Imports, the public API, and Hyperproof sync now trigger reassessment correctly.

  • Date/number filter matching corrected - Exact-match date and numeric filters were being compared as text and could silently fail to match.

  • Broken filters are now displayed, not silently ignored - If a filter references a deleted or hidden field, the schedule/reminder will flag it instead of quietly matching "all vendors."

Rule-based TPRM Core reminders

Rule-based reminders (reassessment, renewal, and document expiry) were not being sent despite appearing fully configured. The underlying scheduling issue has been fixed, and affected organization data will be backfilled so configured reminders begin dispatching on their set cadence.

Note for rollout: Because reminders have never run historically, the first dispatch after backfill may include an accumulated backlog of overdue reminders. Backfill is being staged on an organization-by-organization basis to monitor behavior.

Risk monitoring for imported vendors

Risk monitoring now runs automatically for vendors added via import, matching the behavior already in place for manually added vendors.

Vendor catalog view persists

The Vendor Catalog remembers your last-used view (Card or List) across page refreshes and future visits, instead of always resetting to Card View.


Did this answer your question?