# Nudge Security

> Shows which AI and SaaS services are actually in use across a company, and what access rights those services hold on company data, without anyone having to survey the staff.

- Vendor: Nudge Security, Inc.
- Canonical URL: https://www.convios.com/en/toolbox/nudge-security
- Language version: https://www.convios.com/de/werkzeugkasten/nudge-security
- Area: Governance & security · Cluster: AI usage visibility
- Role: Off-the-shelf product · Origin: Established, AI retrofitted
- As of: 2026-07-30 · Reviewed: 2026-07-30 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: If you do not know which AI services hold access to your company data, you can neither answer a customer question about AI use nor keep a register. That is falling behind, not getting ahead. The inventory itself sets nobody apart: the competitor next door produces the same list in the same week. An edge only appears from what a company decides once it has the list, and no tool does that part.

## Suitability by company size

- Solo: not suitable — Below 150 active accounts the vendor charges a flat 750 US dollars a month. With a handful of accounts you can see the same granted permissions for free in the Google Workspace or Microsoft 365 admin console.
- Mid-market: suitable — From roughly 150 accounts the price of five US dollars per active account becomes proportionate, and that is exactly the size at which management stops knowing who signed up for which AI service. Below that threshold you pay the flat fee and therefore several times more per head.
- Enterprise: suitable with caveats — Above 2,500 accounts you negotiate an enterprise agreement and the price stops being public. The heavier issue: the vendor does not publicly document the storage location and keeps no open subprocessor list. Every corporate privacy office asks for both in the first meeting.

## Vendor staying power

Funded: The vendor is freshly funded but young. Five years since founding, not quite four years in market and a customer count in the low hundreds do not add up to established. The Series A of November 2025 carries operations for the foreseeable future but is no substitute for demonstrated profitability.

- Founded and launched: Founded in 2021, platform on the market since October 2022, based in Austin, Texas (source: https://www.nudgesecurity.com/press/nudge-security-raises-22-5m-series-a-to-secure-workforce-ai-and-saas, as of 2026-07-30)
- Funding: USD 22.5 million Series A dated 18.11.2025, led by Cerberus Ventures, with Ballistic Ventures, Forgepoint Capital and Squadra Ventures (source: https://www.nudgesecurity.com/press/nudge-security-raises-22-5m-series-a-to-secure-workforce-ai-and-saas, as of 2026-07-30)
- Customer count: just under 200 customers, vendor figure as of 18.11.2025 (source: https://www.nudgesecurity.com/press/nudge-security-raises-22-5m-series-a-to-secure-workforce-ai-and-saas, as of 2026-07-30)
- Assurance: SOC 2 Type II per the vendor's own trust page; the first published audit, in 2022, was a Type 1 report (source: https://www.nudgesecurity.com/trust-center, as of 2026-07-30)
- Legal entity: Nudge Security, Inc.; service address in Las Vegas, Nevada; venue per the terms of service is Massachusetts. No company registration number is publicly retrievable. (source: https://www.nudgesecurity.com/legal/terms-and-conditions, as of 2026-07-30)

## Cost of leaving

Low: The tool holds no data you need back, it only reads along. You revoke the read-only grant in Google Workspace or Microsoft 365 and you are out, with no migration and no data handover. What you lose is the accumulated history. The API documents no full-export endpoint, only search queries capped at 100 results per page. Anyone who wants to keep the inventory pulls it page by page before cancelling.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | available, to be requested through the trust center — The trust center lists a data processing agreement alongside the master services agreement and the privacy policy as an available document. The text is not openly readable and is handed out on request. | partially evidenced | 2026-07-30 |
| Storage location | unclear — The vendor names Amazon Web Services as infrastructure but no region. Neither the trust page nor the privacy policy states whether inventory data sits in the EU or in the United States. No region choice is offered anywhere. | not evidenced | 2026-07-30 |
| Subprocessors | no public list — The privacy policy names only Stripe for payments and Google for web analytics, plus generic categories such as hosting and communication providers. Who else processes customer data is stated nowhere in public. | partially evidenced | 2026-07-30 |
| Third-country transfer | unclear — The vendor is based in the United States, so a transfer to a third country takes place. On what legal basis is not stated in the public documents. Standard contractual clauses or certification under the EU-US framework are not mentioned in the privacy policy. | not evidenced | 2026-07-30 |
| Training on customer data | unclear — None of the public documents states whether the collected inventory and usage data feed the training of the vendor's models. The product analyses mailbox metadata with machine learning, so the question belongs in contract negotiations. | not evidenced | 2026-07-30 |
| Retention and deletion | for as long as the account exists, full deletion by the customer possible — The privacy policy ties retention to having an open account. The trust page adds that customers can fully erase their data and that email is not permanently stored. No retention period in days, for backups in particular, is named. | partially evidenced | 2026-07-30 |
| Certifications | SOC 2 Type II per the vendor; the trust center additionally shows badges for GDPR, CCPA and HIPAA — No ISO 27001 certificate is named anywhere. The Type II claim appears on the vendor's own page without an audit date or auditor; the only dated publication, from 2022, concerns a Type 1 report. Badges for GDPR and HIPAA are self-declarations, not certificates. | partially evidenced | 2026-07-30 |
| EU AI Act, Article 50 | unclear — The vendor makes no public statement about its own duties under the European AI Regulation. The tool helps maintain a register of AI services in use, which supports your own duty and is not a commitment by the vendor. | partially evidenced | 2026-07-30 |
| Audit logging | unclear — The trust page mentions access logging for the vendor's own infrastructure. Whether the customer receives an auditable log of access and changes within their own tenant, and in which plan, is not publicly substantiated. | not evidenced | 2026-07-30 |

## Cost

- Entry: Below 150 active accounts, a flat 750 US dollars a month. From 150 to 2,500 accounts, five US dollars per active account per month. Above that, an enterprise agreement on request. A free trial exists; the pricing page does not state its length. (as of 2026-07-30)
- Where it gets expensive: In three places. First, the vendor counts every licensed mailbox, including guests, contractors, distribution lists and shared mailboxes, so the invoice runs higher than the headcount suggests. Second, the two sharpest capabilities, reviewing app-to-app integrations and hardening configuration, are paid add-ons with no public price. Third, above 2,500 accounts the price disappears into negotiation entirely.

## Three routes compared

### Security suite with a network or endpoint sensor

The classic answer to shadow IT sits in network traffic or on the endpoint and therefore sees more than sign-up activity alone. In exchange it costs a rollout project, a round with the works council and, as a rule, an enterprise contract with a minimum commitment. For a company of 100 to 300 people that is a far more expensive route to the same list.

### Browser layer that sees prompts rather than sign-ups

A newer class sits as an extension in the browser and logs what staff type into a language model. That answers the data-leakage question more precisely but raises the co-determination question to another level, because workplace behaviour is being recorded. Nudge Security ships a browser extension of its own, yet the core of its detection remains the trail left in the mailbox.

### Pull the permission list from the admin API yourself

Google Workspace and Microsoft 365 expose granted OAuth permissions through their admin APIs. A script that writes those lists into a table every week costs one to two days and delivers the hard core of the answer: which service holds which rights on which mailboxes. What it misses are services someone signed up for with a work address without OAuth, the history before the first run, and the part that engages staff and cleans up.

Recommendation by size:

- Solo: Do it yourself. The floor price bears no relation to the number of accounts.
- Mid-market: Buy once you pass 150 accounts. Below that, run the script and keep a fixed monthly slot.
- Enterprise: Buying is defensible, but settle storage location, subprocessors and tenant-level logging in writing before signing.

## Context

- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The test presupposes you know how far a rule reaches into your own house, and without a list of the AI services actually in use you can answer neither a customer question about AI use nor a register requirement.
- Implements method: [DORA AI Capabilities Model (Seven AI Capabilities)](https://www.convios.com/en/methods/dora-ai-capabilities) — The assessment asks for a clear internal stance on AI, and measured shadow usage is the reality check on whether that stance holds in daily work at all.
- Displaces: Hand-maintained spreadsheet of tools in use, Company-wide email asking who uses what

## Evidence

- Prices, floor price, definition of an active account, paid add-on modules — https://www.nudgesecurity.com/pricing (as of 2026-07-30)
- Encryption, operation on Amazon Web Services, SOC 2 Type II, customer-initiated deletion, no permanent email storage — https://www.nudgesecurity.com/trust-center (as of 2026-07-30)
- Year founded, market launch, Series A of 22.5 million US dollars dated 18 November 2025, investors, nearly 200 customers — https://www.nudgesecurity.com/press/nudge-security-raises-22-5m-series-a-to-secure-workforce-ai-and-saas (as of 2026-07-30)
- Named providers Stripe and Google, no subprocessor list, no statement on storage location, no standard contractual clauses named — https://www.nudgesecurity.com/legal/privacy-policy (as of 2026-07-30)
- Per-resource search queries capped at 100 results per page, no documented endpoint for a full export — https://nudgesecurity.readme.io/reference/post_api-1-0-accounts-search (as of 2026-07-30)
