Release notes

Product updates, fixes, and improvements from Deep Fathom.

Updates

28 updates
PlatformMixedv3.5.3

This is a stability release. It clears errors some of you hit after the recent framework upgrades, and adds no new features.

Compliance pages load without errors

Your dashboard, frameworks, controls, policies, and assessments open normally again. On some projects, those pages had started returning a permissions error after a framework upgrade and would fail to load rather than show partial data. The publisher identity and signing details behind the conflict stay private to the platform, so you get your access back without widening what anyone can see.

Readiness scores stay visible on carried-over projects

Projects still carrying a framework baseline from before your upgrade now show their last recorded readiness figures instead of failing to load. The platform treats those figures as stale and pairs them with live objective progress, so your team can keep working while the framework source is reviewed. Publishing and refreshing a score remain blocked on those projects — the platform won't certify a number it can't trace to a confirmed source, so nothing unverified reaches an assessor.

Also improved

  • Production releases now confirm their required database updates have fully applied before the new version starts serving your workspace, so a partly applied upgrade can't reach you.

  • Routine health checks between the platform and its database run clean again, which means genuine problems surface faster instead of being lost in false alarms.

Questions or feedback? Reply on this update and tell us where the workflow still needs work.

PlatformMixedv3.4.1

Framework updates now use a retained source of truth
Benthic now keeps the exact OSCAL source and compiled relationships behind a
framework installation. Updates no longer depend on whichever framework package
happens to be running at the time, making results more repeatable and easier to
explain.
Portable playbooks keep their meaning
Built-in frameworks, portable playbooks, profiles, and program levels now pass
through the same project-basis model. Their controls and relationships retain
stable source identities as content moves between projects or advances to a new
version.
Migration decisions are explicit
New bounded audit tools classify existing framework bindings and identify cases
whose original source cannot yet be proven. Those cases remain visible for
review instead of being silently inferred from today's package.
Also improved

  • Canonical OSCAL 1.2.2 catalogs can be retained from JSON or XML sources.

  • Framework and playbook updates share one dependency-ordered planning path.

  • Large fleet audits use stable, resumable pagination for safer operations.

  • Production origin access and release provenance checks are more tightly

enforced.

Questions or feedback? Reply on this update and tell us where the workflow still
needs work.

PlatformMixedv3.4.0

Coverage stays consistent during framework changes
Benthic now tracks framework-managed control content with stable identities and
explicit lifecycle decisions. This makes update plans deterministic and keeps
retired package content from being mistaken for current requirements.
Compliance changes are easier to verify
The release adds a durable history of framework-seeded control changes and
stronger checks around imports, replacements, and deletions. Platform operators
can verify each environment before and after an update with exact, repeatable
evidence.
Safer control mapping
Invalid mixed-scope control mappings are stopped before they can affect project
coverage. Existing valid control-level and objective-level mappings continue
unchanged.
Also improved

  • Framework update plans now explain why each item is added, retained, retired,

or refused.

  • Production receives the same validated application images that completed the

demo qualification path.

Questions or feedback? Reply on this update and tell us where the workflow still
needs work.

PlatformMixedv3.0.0
Featured image for v3.0.0 — From Kickoff to Assessment Day

Rehearse the assessment before it counts

You can now run a mock assessment on your project. Benthic reads your actual policies, procedures, and evidence, evaluates them against each assessment objective, and queues candidate findings for your triage — you decide which become real findings. New Pre-Assessment and Post-Assessment pages show where you stand, including a projected SPRS score.

A guided start for every new project

Project setup is now a guided path: choose your CMMC level at creation (Level 1 projects get exactly the right scope), work through a smarter environment interview, and launch from a kickoff hub that shows what to do next. You can also delegate document collection to the people who own the sources.

Compare SSP snapshots and export to Word

Compare any SSP snapshot against your working draft and see exactly what changed, field by field. When it's time to share, export the SSP as a Word document.

Shared responsibility in one matrix

A shared responsibility matrix now lives in your Scope workflow: record, objective by objective, whether you or a provider carries each responsibility. You can also import a provider's customer responsibility matrix and review it against your own entries.

Your work finds you

You're now notified when work is assigned to you, a review is requested, or a due date approaches, and a work digest email summarizes your open work per project. Tasks export to CSV when you need a list outside the platform.

Organization libraries and client workspaces

Workspace admins can now manage policies and procedures in an organization catalog and share them into projects — one canonical document, reused wherever it applies. Partner organizations can create and administer managed client workspaces, including handing ownership to the client when the engagement calls for it.

Also improved

  • Framework content updates now show release notes and a full preview so you can decide before applying.

  • AI drafting is sharper: it can draft individual SSP fields, suggest asset scope categorizations for your review, and accepted drafts now save immediately with real citations.

  • Document import lets you opt out of AI extraction at upload and clear a whole review queue in one click.

  • Deleted people no longer appear in assignment pickers, downloaded documents keep their filenames, and dozens of smaller fixes landed across dashboards and editors.

Questions or feedback? Reply on this update and tell us where the workflow still needs work.

PlatformMixedv2.2.0
Featured image for v2.2.0 — Upload Progress, Live Activity Stream & SSP Frontmatter Tabs

Upload Anything: see your runs progress
Document uploads and extractions now show a real-time progress timeline for every run, moving from queued, through running, to complete, with smarter retry and recovery if a step needs to be retried. Stuck or stale uploads no longer linger in an ambiguous state, and you can see exactly where each run is at any moment.
Live activity stream on every entity detail
Control, policy, asset, and other detail sheets now show a live activity stream of who did what, when, and to which field, instead of a single "Last updated at" timestamp. The feed updates as you edit, so review hand-offs and change traceability are visible without leaving the sheet.
SSP authoring covers more of the document
The System Security Plan now includes ESP CRM, Glossary, Milestones, Revision History, and Signatory Block sections you can fill in directly, with people and vendor links where they apply. Edits persist immediately, and the tabs replace the previous "future release" placeholders so SSP authoring covers more of the document in one place.
Also improved

  • Project dashboards and Coverage Explorer now scope their numbers to your folios, so when you're working a specific folio the metrics match the scope you're working in.

  • Onboarding handles interrupted setups more cleanly, and invitation acceptance no longer requires a separate email confirmation step.

  • Password reset now works for all account types, and the AI assistant has been stabilized after some users saw it intermittently fail to respond.

Questions or feedback? Reply on this update and tell us where the workflow still needs work.