Chevron Left
ALL RESOURCES
October 1, 2026

SurgeONE.ai v2.6.3: Workflow, Device Trust and Data Foundations for Modern Compliance

SurgeONE.ai v2.6.3 turns compliance from a paperwork burden into a connected, always-on system: configurable workflows, device-level security signals, and clean data feeding every supervisory process. Released in September 2026, this update spans four pillars of the platform, Compliance, Cyber, Data and AI Governance, and it is built around one idea: your teams should spend their time on decisions, not on chasing documents, devices and spreadsheets.

Below is what is new, how it works under the hood, and what it means for your firm.

Compliance: faster policy updates, smarter due diligence, workflows you configure yourself

Document redlining: from approved amendment to effective manual

The policy and procedures redlining workflow is now end to end. Reviewers compare tracked changes, approve or reject suggestions, edit drafts directly in the browser, and generate both a redline and a clean-copy Word document. Compliance AI reads the structure of your manual, places each approved amendment in the right section, and rewrites suggested language to match your firm's own terminology and tone. Every version carries draft and effective-date information and moves to an "In Effect" status on approval. Bulk decisions show progress as you go, and if document generation fails, you can rebuild it without starting over.

Why it matters: policy updates that once took days of copy-and-paste become a reviewable, auditable workflow.

RIA due diligence: intake to continuous monitoring in one module

The new RIA Due Diligence module covers structured intake, review, risk assessment, approval and ongoing monitoring for RIA firms and individual investment adviser representatives.

  • ‍Guided intake: firms and advisers complete workflows through shareable links, with secure adviser access.
  • AI pre-fill: Compliance AI populates profiles and checklists from public regulatory records, prior filings and uploaded documents, and adverse-media and web research support screening.
  • Risk-rated outcomes: each review receives a risk rating, findings and suggested remediation, ending in Approved, Approved with Conditions, Rejected or Appeal Pending.
  • Governance built in: committee review, exception and appeal workflows, and automatic setup of approved RIAs as child firms.
  • Scale: continuous monitoring, bulk import with trial runs, dashboards and reports.

Configurable forms and workflows

Much of this release puts configuration in administrators' hands, with no development work required.

  • Grid Answer Type: capture multiple records in a single form. Administrators build grids from questions in published, draft or archived forms, and users add, edit and delete grid records. Forms can also be hidden from end users while staying available for grid configuration and reuse.
  • Dynamic Form Reports: build tabular reports from published forms by choosing the form and fields, customizing display names, and exporting to Excel.
  • Region-based OBA approvals: route Outside Business Activity submissions to the right regional approval team, based on the submitter's assigned region and configurable regional user pools.
  • Employee Onboarding workflows: create reusable workflow templates with multiple stages, assign forms to stages, set progression rules, and bundle everything into onboarding packages assigned to users. New hires track progress in My Onboarding, and administrators monitor package, form and stage status. Stakeholders can review, approve, reject or return submissions.
  • Public and private comments: workflow stakeholders can add public comments, or private comments and attachments visible only to authorized internal users and never exposed to the submitter.
  • Custom fields on users: add text, number, currency, date, dropdown, multi-select, file-upload and location fields, plus repeatable groups and linked submissions, to the User Onboarding form. Fields appear on Add User and Edit User screens and carry over when a user is cloned.

Everyday admin, simplified

Administrators can now update a user's email address from Manage Users. The system sends a Set Password email to the new address, temporarily deactivates the user during the transition, and preserves all existing records, submissions and data. Users can also transfer assigned tasks, singly or in bulk, to another eligible user on the same team or designation, which keeps work moving when someone is out or overloaded.

Cyber: device trust and PII visibility, without exposing the data itself

Regulators increasingly expect firms to prove that devices are secured and sensitive data is controlled. v2.6.3 gives you both, with evidence you can show an examiner.

Cyber Agent for Windows and Mac

The new guided installer enrolls devices in minutes. Users pair a device with their work email and a six-digit one-time code, or administrators issue pre-paired installers. On Windows, signed silent deployment works through Intune, SCCM or Group Policy. On Mac, macOS 13 and later is supported on both Apple Silicon and Intel.

Once installed, the agent reports on disk encryption, antivirus, firewall, OS patches, screen lock, Wi-Fi, VPN, USB, password policy, logins and AI-tool activity. Every device receives a security score from 0 to 100 and a grade from A to F, so posture is visible at a glance.

Trust Gate: device posture as a sign-in signal

Trust Gate makes the device's security score part of the access decision. It integrates with Microsoft Entra, so a sign-in can be allowed, flagged or blocked based on how healthy the device is.

  • Guided remediation: users without an agent see an installation-required screen. Fix My Device walks them through remediation and recalculates the score afterward.
  • Operational flexibility: configure temporary access, exceptions and grace periods, with an emergency disable option.
  • Full visibility: the dashboard records Allowed, Flagged, Blocked, Agent Missing and Grace outcomes, and sign-in events can be exported for security monitoring.

AI Governance and Cyber filters on Policy Coverage

Policy Coverage now offers focused views for AI Governance and Cyber Compliance. Administrators can review applicable requirements, evidence, deficiencies and remediation by compliance topic, and assess coverage by requirement, control or regulation as Fully met, Partly met or Unproven. Compliance AI suggests policy-to-control mappings for your review. When no open gaps remain, you can generate and download an exam packet as a PDF, marked "Exam Ready."

PII at rest and in motion

The Cyber module now watches both sensitive data stored on devices and sensitive data leaving them, while keeping the actual values masked.

  • At rest: scanning identifies files containing sensitive data.
  • In motion: monitoring records channel, source, destination, website, method and, where supported, AI-tool involvement. It covers clipboard activity, USB and external-media transfers, and cloud-sync folders.
  • Privacy by design: pattern matching identifies PII without reading or storing the exact content. Only the data type, a masked value and a confidence score are reported. Actual sensitive values are never transmitted.
  • Governance guardrails: clipboard monitoring, upload scanning and device-wide monitoring require recorded legal and privacy sign-off before they are enabled.

PII Dashboard: one view of exposure

The PII Dashboard gives a firm-wide view of sensitive-data exposure across AI tools, web applications, desktop applications and other destinations. Consolidated across users, devices and branches, it lets you filter and drill down from organization-wide exposure to a single event, supporting investigation, decision management, monitoring and audit.

Data: connected systems and a clean foundation for surveillance

Good supervision depends on good data. v2.6.3 adds integrations that keep records current across systems and prepare trade data before it ever reaches a surveillance workflow.

  • Salesforce to SurgeONE sync: vendor and contact records synchronize automatically, so vendor profiles and their contacts stay current with Salesforce updates. Less manual entry and fewer data mismatches support vendor risk and due diligence workflows.
  • Advisor-operations to Salesforce sync: contacts, branch data and branch profile data flow into Salesforce automatically, with contacts linked to their branches. The organizational hierarchy is preserved for reporting and supervisory oversight.
  • FINRA Form U4 filing and retrieval: U4 registration and disclosure data, including Outside Business Activity disclosures, is filed and retrieved automatically and synchronized into SurgeONE for compliance and supervisory review. The integration supports FINRA registration and disclosure requirements, including Rule 3290 for OBAs.
  • Normalization and aggregation for trade surveillance: trade, account and representative data from multiple custodian and clearing sources is mapped into a common data model and aggregated into one unified dataset. Validation, de-duplication and exception handling run before data reaches surveillance workflows, and the clean output feeds downstream trade surveillance systems automatically. The result is less manual preparation and stronger support for FINRA Rule 3110 and related surveillance obligations.

What v2.6.3 means for your firm

v2.6.3 expands workflow configuration and due diligence in Compliance, adds device trust and PII monitoring in Cyber, and strengthens data synchronization, normalization and surveillance preparation in Data. Together, they help your firm update policies faster, onboard and monitor RIAs with confidence, secure the devices behind every sign-in, and trust the data behind every supervisory decision.

Ready to see it in action? Contact the SurgeONE.ai team to schedule a demo of v2.6.3 and learn how it fits your compliance program.

Author:  
SurgeONE Team