Nudge Security
Nudge Security, Inc. ·www.nudgesecurity.com· As of: 2026-07-30
Work through this tool with an AI
Our verdict
If you do not know which AI services hold access to your company data, you can neither answer a customer question about AI use nor keep a register. That is falling behind, not getting ahead. The inventory itself sets nobody apart: the competitor next door produces the same list in the same week. An edge only appears from what a company decides once it has the list, and no tool does that part.
Evidence:Prices, floor price, definition of an active account, paid add-on modulesOpen sourceEncryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storageOpen sourceYear founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customersOpen sourceNamed providers Stripe and Google, no subprocessor list, no statement on storage location, no standard contractual clauses namedOpen sourcePer-resource search queries capped at 100 results per page, no documented endpoint for a full exportOpen source
Who it fits
Solo
not suitable
Below 150 active accounts the vendor charges a flat 750 US dollars a month. With a handful of accounts you can see the same granted permissions for free in the Google Workspace or Microsoft 365 admin console.
Mid-market
suitable
From roughly 150 accounts the price of five US dollars per active account becomes proportionate, and that is exactly the size at which management stops knowing who signed up for which AI service. Below that threshold you pay the flat fee and therefore several times more per head.
Enterprise
suitable with caveats
Above 2,500 accounts you negotiate an enterprise agreement and the price stops being public. The heavier issue: the vendor does not publicly document the storage location and keeps no open subprocessor list. Every corporate privacy office asks for both in the first meeting.
Buy, switch or build
Off-the-shelf
Security suite with a network or endpoint sensor
The classic answer to shadow IT sits in network traffic or on the endpoint and therefore sees more than sign-up activity alone. In exchange it costs a rollout project, a round with the works council and, as a rule, an enterprise contract with a minimum commitment. For a company of 100 to 300 people that is a far more expensive route to the same list.
AI-native
Browser layer that sees prompts rather than sign-ups
A newer class sits as an extension in the browser and logs what staff type into a language model. That answers the data-leakage question more precisely but raises the co-determination question to another level, because workplace behaviour is being recorded. Nudge Security ships a browser extension of its own, yet the core of its detection remains the trail left in the mailbox.
Build it yourself
Pull the permission list from the admin API yourself
Google Workspace and Microsoft 365 expose granted OAuth permissions through their admin APIs. A script that writes those lists into a table every week costs one to two days and delivers the hard core of the answer: which service holds which rights on which mailboxes. What it misses are services someone signed up for with a work address without OAuth, the history before the first run, and the part that engages staff and cleans up.
Our advice
- Solo: Do it yourself. The floor price bears no relation to the number of accounts.
- Mid-market: Buy once you pass 150 accounts. Below that, run the script and keep a fixed monthly slot.
- Enterprise: Buying is defensible, but settle storage location, subprocessors and tenant-level logging in writing before signing.
Who is behind it
Staying power: Funded
The vendor is freshly funded but young. Five years since founding, not quite four years in market and a customer count in the low hundreds do not add up to established. The Series A of November 2025 carries operations for the foreseeable future but is no substitute for demonstrated profitability.
- Founded and launched: Founded in 2021, platform on the market since October 2022, based in Austin, TexasYear founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customersOpen source · As of 2026-07-30
- Funding: USD 22.5 million Series A dated 18.11.2025, led by Cerberus Ventures, with Ballistic Ventures, Forgepoint Capital and Squadra VenturesYear founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customersOpen source · As of 2026-07-30
- Customer count: just under 200 customers, vendor figure as of 18.11.2025Year founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customersOpen source · As of 2026-07-30
- Assurance: SOC 2 Type II per the vendor's own trust page; the first published audit, in 2022, was a Type 1 reportEncryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storageOpen source · As of 2026-07-30
- Legal entity: Nudge Security, Inc.; service address in Las Vegas, Nevada; venue per the terms of service is Massachusetts. No company registration number is publicly retrievable.nudgesecurity.com/legal/terms-and-conditionsOpen source · As of 2026-07-30
Cost of leaving: Low
The tool holds no data you need back, it only reads along. You revoke the read-only grant in Google Workspace or Microsoft 365 and you are out, with no migration and no data handover. What you lose is the accumulated history. The API documents no full-export endpoint, only search queries capped at 100 results per page. Anyone who wants to keep the inventory pulls it page by page before cancelling.
Regulation and data
| Data processing agreementdocumented, no condition attached: Auftragsverarbeitungsvertrag öffentlich abrufbar und ohne weitere Bedingung Bestandteil des Vertrags; oder er entfällt nachvollziehbar begründet, weil kein Anbieter Kundendaten verarbeitet.documented, tied to a condition: Vertrag existiert, ist aber an einen Tarif gebunden, nur nach Anfrage einsehbar oder allein in den Nutzungsbedingungen geregelt statt als eigenes Dokument.documented, but unfavourable: Kein Auftragsverarbeitungsvertrag im üblichen Sinn: entweder weil der Anbieter für das Kerngeschäft eigenständig Verantwortlicher ist und stattdessen eine andere Konstruktion gilt, oder weil öffentlich offen bleibt, ob überhaupt einer angeboten wird.open on a point that decides usability: Weder ein Vertrag noch ein dokumentierter Weg zu einem Vertrag; der Einkauf hätte nichts, worauf er sich stützen kann. | documented, tied to a conditionavailable, to be requested through the trust centertrust.nudgesecurity.comOpen sourceThe trust center lists a data processing agreement alongside the master services agreement and the privacy policy as an available document. The text is not openly readable and is handed out on request.As of 2026-07-30 |
|---|---|
| Storage locationdocumented, no condition attached: EU-Speicherort ohne Zusatzkosten und ohne Tarifbindung, oder der Ort ist vollständig selbst bestimmbar, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: EU-Speicherort möglich, aber an einen Tarif, einen gesondert zu aktivierenden Zusatz oder einen Umzug in eine getrennte Umgebung gebunden; oder die EU-Region ist nicht die Voreinstellung.documented, but unfavourable: Kein EU-Speicherort, der Ort ist aber eindeutig benannt, sodass die Folgen bewertbar sind.open on a point that decides usability: Der Speicherort ist öffentlich nicht benannt oder vom Kunden nicht steuerbar, sodass sich die Verarbeitung nicht verorten lässt. | open on a point that decides usabilityunclearEncryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storageOpen sourceThe vendor names Amazon Web Services as infrastructure but no region. Neither the trust page nor the privacy policy states whether inventory data sits in the EU or in the United States. No region choice is offered anywhere.As of 2026-07-30 |
| Subprocessorsdocumented, no condition attached: Vollständige öffentliche Liste der Unterauftragnehmer mit Zweck und Land; oder es gibt keine, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Liste existiert und ist benannt, aber nur nach Anfrage oder nach Zugang zu einem Vertrauensportal einsehbar, oder sie nennt Zweck und Land nicht vollständig.documented, but unfavourable: Keine geführte Liste; namentlich stehen nur einzelne Dienste in der Datenschutzerklärung, überwiegend solche der eigenen Website.open on a point that decides usability: Weder eine Liste noch eine Nennung der Verarbeiter des Produkts, und kein dokumentierter Weg, sie zu erfahren. | documented, but unfavourableno public listNamed providers Stripe and Google, no subprocessor list, no statement on storage location, no standard contractual clauses namedOpen sourceThe privacy policy names only Stripe for payments and Google for web analytics, plus generic categories such as hosting and communication providers. Who else processes customer data is stated nowhere in public.As of 2026-07-30 |
| Third-country transferdocumented, no condition attached: Keine Übermittlung in ein Drittland, oder die Übermittlung findet statt und die Grundlage ist benannt und im Vertrag verankert, etwa Standardvertragsklauseln, Angemessenheitsbeschluss oder EU-US-Datenschutzrahmen.documented, tied to a condition: Übermittlung findet statt, eine Grundlage ist genannt, aber ohne Zuordnung, welcher Empfänger auf welcher Grundlage arbeitet.documented, but unfavourable: Übermittlung findet statt und die eigenen Unterlagen widersprechen sich, oder die genannte Grundlage bezieht sich erkennbar nur auf einen Randbereich wie die Marketing-Website.open on a point that decides usability: Übermittlung findet erkennbar statt und eine Grundlage wird nirgends genannt. | open on a point that decides usabilityunclearNamed providers Stripe and Google, no subprocessor list, no statement on storage location, no standard contractual clauses namedOpen sourceThe vendor is based in the United States, so a transfer to a third country takes place. On what legal basis is not stated in the public documents. Standard contractual clauses or certification under the EU-US framework are not mentioned in the privacy policy.As of 2026-07-30 |
| Training on customer datadocumented, no condition attached: Vertraglich oder in der Datenschutzerklärung ausdrücklich ausgeschlossen, mit Erstreckung auf die eingesetzten Modellanbieter; oder es gibt keine Datenübertragung an einen Anbieter.documented, tied to a condition: Ausschluss ab einem bestimmten Tarif, oder die Zusage steht nur auf einer Dokumentationsseite statt im Vertrag, oder die Frage stellt sich für das Werkzeug sachlich kaum und der Anbieter schweigt dazu.documented, but unfavourable: Nutzung ist die Voreinstellung und nur ein Widerspruch beendet sie; oder der Anbieter trainiert eigene Modelle auf bereinigten Kundendaten.open on a point that decides usability: Keine Aussage, obwohl das Werkzeug KI-Funktionen auf Kundeninhalten betreibt. | open on a point that decides usabilityunclearNone of the public documents states whether the collected inventory and usage data feed the training of the vendor's models. The product analyses mailbox metadata with machine learning, so the question belongs in contract negotiations.no source given · As of 2026-07-30 |
| Retention and deletiondocumented, no condition attached: Löschfristen nach Vertragsende beziffert und die Löschung oder Rückgabe zugesagt; oder die Fristen bestimmt der Betreiber selbst, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Löschung ist zugesagt, die Fristen sind aber nur teilweise beziffert, oder Sicherungskopien sind ausdrücklich ausgenommen.documented, but unfavourable: Nur der Grundsatz der Erforderlichkeit ohne jede Frist nach Vertragsende, oder Fristen sind allein für Randbereiche wie Website-Protokolle genannt.open on a point that decides usability: Keine Aussage zu Aufbewahrung und Löschung. | documented, tied to a conditionfor as long as the account exists, full deletion by the customer possibleEncryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storageOpen sourceThe privacy policy ties retention to having an open account. The trust page adds that customers can fully erase their data and that email is not permanently stored. No retention period in days, for backups in particular, is named.As of 2026-07-30 |
| Certificationsdocumented, no condition attached: Mehrere anerkannte Nachweise, benannt mit Norm, Fassung und Geltungsbereich, und bezogen auf den Anbieter selbst.documented, tied to a condition: Ein anerkannter Nachweis für den Anbieter belegt, der Bericht aber nur auf Anfrage, oder der Nachweis hängt an einem Tarif, oder der Geltungsbereich bleibt teilweise offen.documented, but unfavourable: Nur pauschale Nennung ohne Norm-Fassung und Geltungsbereich, oder bloße Selbstauskunft, oder die Nachweise gehören dem Infrastrukturanbieter statt dem Anbieter, oder der Prüfzeitraum ist erkennbar veraltet, oder die eigenen Angaben widersprechen sich.open on a point that decides usability: Kein Nachweis genannt und keine Sicherheits- oder Vertrauensseite vorhanden. | documented, but unfavourableSOC 2 Type II per the vendor; the trust center additionally shows badges for GDPR, CCPA and HIPAAEncryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storageOpen sourceNo ISO 27001 certificate is named anywhere. The Type II claim appears on the vendor's own page without an audit date or auditor; the only dated publication, from 2022, concerns a Type 1 report. Badges for GDPR and HIPAA are self-declarations, not certificates.As of 2026-07-30 |
| EU AI Act, Article 50documented, no condition attached: Der Anbieter macht eine belegte Aussage, die die eigene Pflicht trägt, etwa Modelldokumentation und Zertifizierung nach ISO/IEC 42001; oder das Werkzeug enthält nachvollziehbar begründet kein KI-System im Sinne der Verordnung.documented, tied to a condition: Der Anbieter äußert sich zur Verordnung oder ordnet die eigene Funktion ein, eine benannte Zusage zu den Transparenzpflichten aus Artikel 50 fehlt aber; oder das Werkzeug enthält kein KI-System, das gegenüber Menschen auftritt, und der Anbieter schweigt.documented, but unfavourable: Das Produkt enthält KI-Funktionen, der Anbieter schweigt dazu oder trägt ein Selbstetikett ohne Nachweis; die Kennzeichnung ist vom Betreiber aber selbst setzbar.open on a point that decides usability: KI spricht im Produkt unmittelbar mit Endkunden und der Anbieter sagt zu Artikel 50 nichts; die Kennzeichnung lässt sich ohne Zusage des Anbieters nicht sicher setzen. | documented, tied to a conditionunclearThe vendor makes no public statement about its own duties under the European AI Regulation. The tool helps maintain a register of AI services in use, which supports your own duty and is not a commitment by the vendor.no source given · As of 2026-07-30 |
| Audit loggingdocumented, no condition attached: Nachvollziehbares Protokoll über Zugriffe und Änderungen in allen Tarifen enthalten, mit benannter Frist und Ausleitung in eigene Systeme; oder die Nachvollziehbarkeit liegt vollständig in eigener Hand, weil das Werkzeug im eigenen Betrieb läuft.documented, tied to a condition: Protokoll vorhanden, aber an einen höheren Tarif oder einen kostenpflichtigen Zusatz gebunden, oder die Ausleitung fehlt in den unteren Stufen; Reichweite und Frist sind benannt.documented, but unfavourable: Protokolle sind nur anbieterseitig beschrieben, oder Reichweite und Frist bleiben offen, sodass sich Nachweispflichten nicht planen lassen.open on a point that decides usability: Öffentlich nicht belegt, ob der Kunde überhaupt ein auswertbares Protokoll erhält. | open on a point that decides usabilityunclearEncryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storageOpen sourceThe trust page mentions access logging for the vendor's own infrastructure. Whether the customer receives an auditable log of access and changes within their own tenant, and in which plan, is not publicly substantiated.As of 2026-07-30 |
What it really costs
Entry price
Below 150 active accounts, a flat 750 US dollars a month. From 150 to 2,500 accounts, five US dollars per active account per month. Above that, an enterprise agreement on request. A free trial exists; the pricing page does not state its length.Prices, floor price, definition of an active account, paid add-on modulesOpen source
As of 2026-07-30
What gets expensive
In three places. First, the vendor counts every licensed mailbox, including guests, contractors, distribution lists and shared mailboxes, so the invoice runs higher than the headcount suggests. Second, the two sharpest capabilities, reviewing app-to-app integrations and hardening configuration, are paid add-ons with no public price. Third, above 2,500 accounts the price disappears into negotiation entirely.
What it displaces
- Hand-maintained spreadsheet of tools in use
- Company-wide email asking who uses what
Interfaces
- Read-only connection to Google Workspace or Microsoft 365
- REST API for accounts, applications, users, OAuth grants and events
- Browser extension for endpoints
Matching methods
- Regulatory Density TestThe test presupposes you know how far a rule reaches into your own house, and without a list of the AI services actually in use you can answer neither a customer question about AI use nor a register requirement.
- DORA AI Capabilities Model (Seven AI Capabilities)The assessment asks for a clear internal stance on AI, and measured shadow usage is the reality check on whether that stance holds in daily work at all.
Sources
- 1.Prices, floor price, definition of an active account, paid add-on modules (opens in a new tab)nudgesecurity.com/pricing · As of 2026-07-30
- 2.Encryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storage (opens in a new tab)nudgesecurity.com/trust-center · As of 2026-07-30
- 3.Year founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customers (opens in a new tab)nudgesecurity.com/… · As of 2026-07-30
- 4.Named providers Stripe and Google, no subprocessor list, no statement on storage location, no standard contractual clauses named (opens in a new tab)nudgesecurity.com/legal/privacy-policy · As of 2026-07-30
- 5.Per-resource search queries capped at 100 results per page, no documented endpoint for a full export (opens in a new tab)nudgesecurity.readme.io/reference/post_api-1-0-accounts-search · As of 2026-07-30
- 6.nudgesecurity.com/legal/terms-and-conditions (opens in a new tab)As of 2026-07-30
- 7.trust.nudgesecurity.com (opens in a new tab)As of 2026-07-30
Last reviewed: 2026-07-30 by Dr. Oliver Gausmann, Convios GmbH
Details out of date? Let us know.