Nudge Security
Nudge Security, Inc. ·www.nudgesecurity.com· As of: 2026-07-30
Our verdict
If you do not know which AI services hold access to your company data, you can neither answer a customer question about AI use nor keep a register. That is falling behind, not getting ahead. The inventory itself sets nobody apart: the competitor next door produces the same list in the same week. An edge only appears from what a company decides once it has the list, and no tool does that part.
Who it fits
Solo
not suitable
Below 150 active accounts the vendor charges a flat 750 US dollars a month. With a handful of accounts you can see the same granted permissions for free in the Google Workspace or Microsoft 365 admin console.
Mid-market
suitable
From roughly 150 accounts the price of five US dollars per active account becomes proportionate, and that is exactly the size at which management stops knowing who signed up for which AI service. Below that threshold you pay the flat fee and therefore several times more per head.
Enterprise
suitable with caveats
Above 2,500 accounts you negotiate an enterprise agreement and the price stops being public. The heavier issue: the vendor does not publicly document the storage location and keeps no open subprocessor list. Every corporate privacy office asks for both in the first meeting.
Buy, switch or build
Off-the-shelf
Security suite with a network or endpoint sensor
The classic answer to shadow IT sits in network traffic or on the endpoint and therefore sees more than sign-up activity alone. In exchange it costs a rollout project, a round with the works council and, as a rule, an enterprise contract with a minimum commitment. For a company of 100 to 300 people that is a far more expensive route to the same list.
AI-native
Browser layer that sees prompts rather than sign-ups
A newer class sits as an extension in the browser and logs what staff type into a language model. That answers the data-leakage question more precisely but raises the co-determination question to another level, because workplace behaviour is being recorded. Nudge Security ships a browser extension of its own, yet the core of its detection remains the trail left in the mailbox.
Build it yourself
Pull the permission list from the admin API yourself
Google Workspace and Microsoft 365 expose granted OAuth permissions through their admin APIs. A script that writes those lists into a table every week costs one to two days and delivers the hard core of the answer: which service holds which rights on which mailboxes. What it misses are services someone signed up for with a work address without OAuth, the history before the first run, and the part that engages staff and cleans up.
Our advice
- Solo: Do it yourself. The floor price bears no relation to the number of accounts.
- Mid-market: Buy once you pass 150 accounts. Below that, run the script and keep a fixed monthly slot.
- Enterprise: Buying is defensible, but settle storage location, subprocessors and tenant-level logging in writing before signing.
Who is behind it
Staying power: Funded
The vendor is freshly funded but young. Five years since founding, not quite four years in market and a customer count in the low hundreds do not add up to established. The Series A of November 2025 carries operations for the foreseeable future but is no substitute for demonstrated profitability.
- Founded and launched: Founded in 2021, platform on the market since October 2022, based in Austin, Texas · Source · As of 2026-07-30
- Funding: USD 22.5 million Series A dated 18.11.2025, led by Cerberus Ventures, with Ballistic Ventures, Forgepoint Capital and Squadra Ventures · Source · As of 2026-07-30
- Customer count: just under 200 customers, vendor figure as of 18.11.2025 · Source · As of 2026-07-30
- Assurance: SOC 2 Type II per the vendor's own trust page; the first published audit, in 2022, was a Type 1 report · Source · As of 2026-07-30
- Legal entity: Nudge Security, Inc.; service address in Las Vegas, Nevada; venue per the terms of service is Massachusetts. No company registration number is publicly retrievable. · Source · As of 2026-07-30
Cost of leaving: Low
The tool holds no data you need back, it only reads along. You revoke the read-only grant in Google Workspace or Microsoft 365 and you are out, with no migration and no data handover. What you lose is the accumulated history. The API documents no full-export endpoint, only search queries capped at 100 results per page. Anyone who wants to keep the inventory pulls it page by page before cancelling.
Regulation and data
| Data processing agreement | available, to be requested through the trust centerThe trust center lists a data processing agreement alongside the master services agreement and the privacy policy as an available document. The text is not openly readable and is handed out on request.Source · As of 2026-07-30 |
|---|---|
| Storage location | unclearThe vendor names Amazon Web Services as infrastructure but no region. Neither the trust page nor the privacy policy states whether inventory data sits in the EU or in the United States. No region choice is offered anywhere.Source · As of 2026-07-30 |
| Subprocessors | no public listThe privacy policy names only Stripe for payments and Google for web analytics, plus generic categories such as hosting and communication providers. Who else processes customer data is stated nowhere in public.Source · As of 2026-07-30 |
| Third-country transfer | unclearThe vendor is based in the United States, so a transfer to a third country takes place. On what legal basis is not stated in the public documents. Standard contractual clauses or certification under the EU-US framework are not mentioned in the privacy policy.Source · As of 2026-07-30 |
| Training on customer data | unclearNone of the public documents states whether the collected inventory and usage data feed the training of the vendor's models. The product analyses mailbox metadata with machine learning, so the question belongs in contract negotiations.no source given · As of 2026-07-30 |
| Retention and deletion | for as long as the account exists, full deletion by the customer possibleThe privacy policy ties retention to having an open account. The trust page adds that customers can fully erase their data and that email is not permanently stored. No retention period in days, for backups in particular, is named.Source · As of 2026-07-30 |
| Certifications | SOC 2 Type II per the vendor; the trust center additionally shows badges for GDPR, CCPA and HIPAANo ISO 27001 certificate is named anywhere. The Type II claim appears on the vendor's own page without an audit date or auditor; the only dated publication, from 2022, concerns a Type 1 report. Badges for GDPR and HIPAA are self-declarations, not certificates.Source · As of 2026-07-30 |
| EU AI Act, Article 50 | unclearThe vendor makes no public statement about its own duties under the European AI Regulation. The tool helps maintain a register of AI services in use, which supports your own duty and is not a commitment by the vendor.no source given · As of 2026-07-30 |
| Audit logging | unclearThe trust page mentions access logging for the vendor's own infrastructure. Whether the customer receives an auditable log of access and changes within their own tenant, and in which plan, is not publicly substantiated.Source · As of 2026-07-30 |
What it really costs
Entry price
Below 150 active accounts, a flat 750 US dollars a month. From 150 to 2,500 accounts, five US dollars per active account per month. Above that, an enterprise agreement on request. A free trial exists; the pricing page does not state its length.
Source · As of2026-07-30
What gets expensive
In three places. First, the vendor counts every licensed mailbox, including guests, contractors, distribution lists and shared mailboxes, so the invoice runs higher than the headcount suggests. Second, the two sharpest capabilities, reviewing app-to-app integrations and hardening configuration, are paid add-ons with no public price. Third, above 2,500 accounts the price disappears into negotiation entirely.
What it displaces
- Hand-maintained spreadsheet of tools in use
- Company-wide email asking who uses what
Interfaces
- Read-only connection to Google Workspace or Microsoft 365
- REST API for accounts, applications, users, OAuth grants and events
- Browser extension for endpoints
At Convios: Not used by us
Not in use. At the size of a one-person operation the floor price of 750 US dollars a month applies, and granted permissions can be read directly in the admin console.
Evidence
- 1.Prices, floor price, definition of an active account, paid add-on modules · As of 2026-07-30
- 2.Encryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storage · As of 2026-07-30
- 3.Year founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customers · As of 2026-07-30
- 4.Named providers Stripe and Google, no subprocessor list, no statement on storage location, no standard contractual clauses named · As of 2026-07-30
- 5.Per-resource search queries capped at 100 results per page, no documented endpoint for a full export · As of 2026-07-30
Last reviewed: 2026-07-30byDr. Oliver Gausmann, Convios GmbH
Details out of date? Let us know.