Truyo Product Release Version 9.7.0

New Features & Enhancements

Cookie Domain Group Visibility (16568)

    • Added the ability to view groups assigned to a cookie domain directly on the Consent > Domain tab, giving seamless visibility into group to domain mappings.

Cookie Domain Group Association and Dissociation (16569)

    • Added the ability to assign or remove groups from a cookie domain on the Consent > Domain tab, providing full control over group to domain assignments.

Cookie Domain Sub-Domain Limit Expansion (16572)

    • Added an API ability to configure up to 10 sub-domains per cookie domain in the Consent module, doubling the previous limit of 5 for greater flexibility.

Snowflake QuikLink: Key Pair Authentication Upgrade (16499)

    • Introduced RSA Key Pair Authentication in Snowflake QuikLink connections, replacing the deprecated Username/Password method to ensure stronger security and future-proof connectivity.

Attentive Mobile QuikLink: Subscriber Not Found Handling (16636)

    • Improved Attentive Mobile QuikLink to handle ‘Not Found’ responses for missing subscribers by marking tasks as Rejected instead of Error, preventing failures caused by API response variations.

QuikLink Auto-Recovery from Error State (16708)

    • Enabled QuikLink connectors in Error (E) state to automatically transition to Active (A) state upon a successful connection or scheduled task execution, reducing manual intervention and operational downtime.

Preference Center Analytics: Opt-Out Reason Reporting (16583)

    • Enabled reporting for Opt-Out reasons in Preference Center Analytics to help organizations analyze user opt-out trends.

Custom Organization Assessment Types (15572)

    • Enhanced Assessments with support for custom assessment types while maintaining compatibility with existing assessments and question workflows.

Missing Languages Support (16701)

    • Expanded multilingual coverage by adding Serbian Latin, Spanish LA, Spanish LATAM, Portuguese (Brazil), and Portuguese (Portugal) to the platform.

CSR Flow: Simultaneous Handling of Access & Abbreviated Right to Know Requests (16529)

    • Removed the restriction that blocked request type selection when an open request of a different type existed, enabling CSR agents to view and create both Access Requests and Abbreviated Right to Know requests simultaneously.

Preference Management Integration with Klaviyo CRM (15044)

    • Completed Klaviyo CRM preference management integration, enabling synchronized consent and preference data flow across marketing platforms.


Security Updates

Session Invalidation on Role Change or Account Update (15727)

    • Strengthened session management to automatically invalidate active user sessions when user details are updated, enforcing real-time session revocation and reducing the risk of unauthorized access with outdated privileges.

PHPSession Cookie Hardening with Secure and HttpOnly Flags (16707)

    • Resolved a security vulnerability by configuring the PHPSession cookie with Secure and HttpOnly flags, strengthening session security and reducing the risk of unauthorized access within the portal.

Privacy Portal Security Hardening (16534)

    •  Migrated the hardcoded WAF encryption secret key (used in both UI and API) to the Kubernetes Key Management System (KMS), enabling dynamic, organization-specific encryption key generation and management for improved security.


Infrastructure Updates

No infrastructure updates included in this release.


Bug Fixes

  • Resolved an issue where the SMTP password field appeared blank after saving Basic SMTP settings, ensuring the saved password is now correctly retained and displayed. (16245)
  • Resolved an issue where OAuth2 SMTP client secrets were stored and handled as plaintext instead of being encrypted at rest, ensuring they now follow the same encryption pattern as Basic Auth passwords. (16055)
  • Resolved an issue that prevented users from uploading CSV files for bulk operations. (16580)
  • Resolved an issue causing privacy requests with verification enabled to skip verification and incorrectly enter “InVerificationReview” status. (16574)

 


Hot Fixes Version-9.6.0

No hotfixes included in this release.

 


Upcoming Features

Multiple Data Subject Requests Using the Same Email Address
Support to submit multiple data subject requests using the same email address, with dedicated information fields, DOB collection, and clear data subject identification across request and task detail views.

Consent Audit Trail Enhancements
Logging GPC opt out events.

Ability to apply cookie plugin config changes to multiple domain plugins at once
Ability to apply cookie plugin changes like colors, fonts, content, translations, custom CSS, behavioral settings across multiple domain plugins in a single action.

Support for Oklahoma Computer Data Privacy Act (OCDPA)
Configurations to ensure client compliance with OCDPA as it comes into effect.

Support for Louisiana Consumer Privacy Act (LCPA)
Configurations to ensure client compliance with LCPA as it comes into effect.

Support for Vermont Data Privacy Act (VDPA)
Configurations to ensure client compliance with VDPA as it comes into effect.

Group Cleanup on User Account Deletion
Enhancement to automatically remove a user from all assigned groups on deleting the user and update group user counts accordingly.

Separate Configuration for Initial and Extension Due Dates
Ability to configure different initial and extension due dates.

Preference Management integration with Klaviyo CRM
Support for Preference Management integration with Klaviyo CRM