What's New | July 2026

What's New | July 2026

Written By
9 min read

TLDR

Tidal Control's July 2026 release launches the Trust Center, a public page where organisations can transparently display their security and compliance posture with customisable visibility, custom domain support, and branded styling. Seven new integrations are added, covering Cloudflare, STACKIT, Hetzner Cloud, TOPdesk, Anthropic, OpenAI, and Claude Enterprise. Azure automated checks expand by 15 tests to near-complete Microsoft Cloud Security Benchmark coverage. The in-app AI assistant TidalBot now runs on Anthropic's Claude models.

Welcome back to the Tidal Product Update newsletter! It's August and half the team is on holiday, but we have a big update: the Trust Center has officially launched! A much-requested feature that lets you show on a public webpage how your organisation handles security and compliance in a transparent way. On top of that, we're once again expanding significantly with new cloud and AI integrations, additional Azure tests, and various improvements.

This release includes:

  • Trust Center
  • Seven new integrations
  • Expanded Azure tests
  • AI governance support for ISO 42001
  • External issue status
  • Vendor re-assessment and history
  • A faster, smarter in-app AI assistant
  • Bug fixes & improvements

For more information and visuals of these updates, visit the What's New section in your Tidal app.

Trust Center

Show on a single public page that your security and compliance are in place

The Trust Center has now launched. This much-requested feature gives you a public page where you can transparently show how your organisation handles security and compliance, perfect for building trust with customers and prospects without having to share individual documents every time.

We're not just launching a basic version. You can customise the Trust Center to your own liking with three different settings:

  • Decide how open you want your Trust Center to be. You keep full control over the visibility of your controls and documents. Share the page fully publicly, give partial access, or set it per component, so you show exactly as much as you want.
  • Host your Trust Center on your own domain, such as trust.yourcompany.com. Add the hostname in Tidal, prove ownership with a single CNAME record, and we take care of the rest, including issuing and renewing the TLS certificate. Available on request, contact us at support@tidalcontrol.com to enable it.
  • Show what you want, in your style. Choose which controls and categories you display with the new Category Cards layout: one card per category, with an icon, the control count, and a name preview. Visitors click through to view every control inside. Match the page to your branding with a custom text colour for the header using a hex value, so the page looks like yours, not ours.

Seven new integrations

Connect even more of your tech stack to Tidal

This month we're adding seven new integrations, with a strong focus on cloud and AI governance:

  • Cloudflare pulls in your account members, API tokens, roles, audit logs, and zone settings, and runs 12 continuous security checks, including MFA enforcement, API token expiry, minimum TLS version, Always Use HTTPS, DNSSEC, and WAF.
  • STACKIT pulls in your service accounts, projects, Kubernetes clusters, servers, storage buckets, and more, with 18 continuous security checks across IAM, Kubernetes, compute, storage, networking, and secrets management.
  • Hetzner Cloud pulls in your servers, firewalls, networks, load balancers, DNS zones, and certificates, and runs 24 continuous security checks across firewall rules, server hardening, network configuration, and access controls.
  • TOPdesk brings the same two-way workflow you already know from our existing Jira and Azure DevOps integrations. Create an Incident or Change (RFC) from a finding or task, or link an existing one by number, and sync the live status back into Tidal.
  • Anthropic, OpenAI, and Claude Enterprise help you stay in control of how your organisation uses AI, a key part of ISO 42001. They pull in members, workspaces, API keys, projects, and security settings such as SSO, data retention, and IP allowlisting.

Expanded Azure tests

Even broader coverage based on the Microsoft Cloud Security Benchmark

We've added 15 new automated security and compliance checks for your Azure environment. The scope of all the tests now almost fully covers the whole Microsoft Cloud Security Benchmark.

The new coverage includes identity and access controls (blocking legacy authentication, sign-in and user-risk policies, privileged roles), data protection (Key Vault soft-delete and RBAC, storage and disk encryption with customer-managed keys, Function App TLS/FTPS), containers and networking (AKS, network policy, and Azure AD integration), and governance (Azure Policy).

The results appear directly alongside your tests and evidence.

AI governance for ISO 42001

Manage responsible AI use in your organisation

Working towards ISO 42001, the standard for AI management? You can now classify documents under four new AI-specific types: AI system impact assessment procedure, AI system notice, AI system use guidelines, and AI data management procedure, each mapped to the relevant ISO 42001 controls.

Matching checks verify that each document exists and has been approved within the last year, so your AI governance evidence stays up-to-date.

External issue status synchronisation

See the live status of linked Jira, Azure DevOps and TOPdesk issues

Issues and tasks linked to a Jira, Azure DevOps or TOPdesk issue now show the live status as a badge in the issues and tasks overviews. You can filter the list by external issue status and use the new bulk sync action to refresh the status of several issues at once.

In addition, AI assistants connected via MCP can now also work with your external issue trackers. The MCP can create a Jira, Azure DevOps or TOPdesk issue from a task or issue, link an existing issue, and look up the projects, issue types, and users needed to do so.

Vendor re-assessment and history

Keep your vendor assessments current and transparent

You can now re-assess vendors on each review cycle and view the full assessment history in a dated list on the vendor detail page. Start a new assessment or continue a draft from the top panel. The workflow works the same way as risk re-assessments.

A faster, smarter in-app AI assistant

TidalBot now runs on Claude

The in-app AI assistant TidalBot now runs on Anthropic's Claude models, for sharper and more reliable answers about your compliance work. To keep the assistant responsive and fair for everyone, each organisation has a generous daily usage allowance, which resets the next day.

Bug fixes & improvements

This release also includes several bug fixes and improvements:

  • Trust Center controls are now correctly grouped by category, and existing controls without a category have been automatically backfilled
  • Read-only mode is now correctly enforced in assessment dialogs, so only authorised users see editable fields
  • Aikido tests for optional resource modules no longer fail incorrectly when they are empty
  • Google Cloud Platform: connecting multiple service accounts now works correctly, and when a Google API is disabled you now get a clear message
  • Google Workspace: issue fetching mobile device data fixed, and Drive sharing settings are now fetched correctly
  • The Aikido DAST authentication test now only considers your front-end domains
  • The controls page no longer crashes on old bookmarks or shared links with a corrupted filter, and now falls back neatly to the default view
  • Expired Azure credentials are now clearly flagged instead of failing silently
  • Images in documents are now embedded in the document itself, so approved documents render identically everywhere
  • Date-range filter added to the task and control overviews
  • TidalBot now answers questions correctly, instead of occasionally refusing or repeating the previous answer

Coming soon

A little sneak peek: an update to the Personnel module with the ability to sync users from IdPs (Google Workspace and Microsoft Entra ID), a vendor assessment expansion with Vendor Questionnaires, and more.

For questions, feel free to reach out by email or on LinkedIn. Want insight into your compliance status? Take the free quick scan. Prefer to speak with our compliance team? Book an introductory call.

Subscribe now for monthly updates: what's new at Tidal, framework news, and compliance resources.

By submitting your email you agree to our Privacy Policy.