{
  "summary": "First tracked release of Allod DAM (Digital Asset Manager) - a self-hosted vendor governance and supply-chain visibility platform. Tracks a system inventory across owner, category, criticality, contract/license dates, and GDPR RoPA (processing role, DPA status, sub-processors, third-country transfers). Vendor security posture is continuously assessed via around 23 automated probes (TLS, DNS/mail authentication, security headers, SBOM presence, company registry data) and scored against the CSF SEAL v1.2.1 sovereignty framework across 8 weighted objectives - strategic, legal, data & AI, operational, supply chain, technology, security, and environmental. Imports and tracks published SBOMs (SPDX/CycloneDX) and vendor OSCAL documents (component-definition and system-security-plan). Discovers shadow IT and uncatalogued internal tools directly from Allod SWG's observed traffic. Named, admin-configured review-cycle templates - interval, contract-renewal, license-renewal, or manual triggers - drive a scheduled reassessment workflow, and SCIM v2 keeps user and group state synced from the customer's own identity provider. This release adds a formal Risk Register: risks are automatically opened and kept current from sovereignty scores, missing DPAs, absent SBOMs, and approaching contract or license expiries, each with likelihood/impact scoring, a mitigate/accept/transfer/avoid treatment workflow, time-boxed risk acceptance, and residual-risk tracking - without ever overriding a decision a human has already made on an entry."
}
