Skip to main content

Changelog

Follow new updates and improvements to OneClickComply.

We’ve updated our privacy policy

We’ve updated our Privacy Notice, effective 18 June 2026.

The UK’s new data protection law, the Data (Use and Access) Act 2025 (DUAA), has come into force, so we’ve updated our notice to reflect it. We’ve also taken the chance to make how we handle your data clearer, which matters to us as a compliance company. Here’s what’s changed.

  • We’ve named our subprocessors. The old version listed vague categories like “cloud computing services”. The new one names the actual companies that process data for us and what each one does, so you can see exactly who’s involved.

  • We’ve updated our AI providers. We now use Anthropic (Claude), Google (Gemini) and Reducto, replacing OpenAI and Microsoft Azure. We’ve also spelled out that none of them are allowed to train their models on your content, and they can only hold it to provide the service to us.

  • We record and transcribe some calls and meetings, for example Ask an Auditor sessions and support calls.

  • We’ve changed how long we keep data. The old notice kept it for up to three months after an account closed. The new one keeps it for up to seven years, which we need to meet our legal, tax, accounting and limitation-period obligations.

  • New rights under the DUAA. You can now raise a data protection complaint with us directly and we’ll acknowledge it within 30 days, and we’ve set out your rights where a decision about you is made automatically.

  • We’ve been clearer on cookies and tracking, including session recording on the platform with sensitive fields like passwords masked, and we now honour Global Privacy Control signals.

There’s nothing you need to do. You can read the full notice here: OneClickComply.com/privacy. If you’ve any questions, email our privacy team at privacy@oneclickcomply.com.

Cyber Essentials 2026 is now available

We've added Cyber Essentials 2026, the latest edition of the Cyber Essentials certification, to the OneClickComply platform. This is a free upgrade, available to all customers already entitled to Cyber Essentials.

Why is this a separate standard?

On 27th April 2026, the Cyber Essentials certification requirements were updated. Because the self-assessment questionnaire has changed to reflect these new requirements, we've introduced Cyber Essentials 2026 as a separate standard in the platform. Unless you are currently in the process of being certified under the pre-27th April requirements, you should opt into the 2026 version, as it contains the updated questionnaire that applies to your assessment.

What's changed?

The 2026 edition updates the self-assessment questionnaire to reflect the latest Cyber Essentials requirements. Your controls, tasks, and evidence are identical across both editions - only the questionnaire has changed.

How do I enable the 2026 version?

If you haven't started Cyber Essentials yet, it's a normal one-click opt-in, just like adopting any other framework.

If you are already working through Cyber Essentials, a confirmation dialog will appear before you enable the 2026 version, explaining what to expect. Your existing controls, tasks, and evidence will all be copied across automatically, meaning you'll start at exactly the same readiness level you had in the previous version.

Will my existing work be affected?

No. Your previous edition remains completely untouched, and you can keep both running side by side. The copy happens once, at the point you enable 2026. After that, the two editions are fully independent. Changes in one will not affect the other.

Please reach out to our support team if you have any questions about this process.

Detect the critical NGINX Rift (CVE-2026-42945)

A critical heap buffer overflow just hit every standard NGINX build. And it's been sitting there since 2008.

Active exploitation is confirmed in the wild. The public PoC came out on disclosure day.

So we stepped in and just added detection for CVE-2026-42945 to our penetration testing module. You can access it here

Don’t have access to penetration testing? Drop us a message and one of our team will be happy to take you through how it can benefit and protect your business.

Earlier updates