Changelog

Subscribe to all Changelog posts via RSS to stay updated on everything we ship at Nudge Security.

AI conversation monitoring now detects sensitive data shared in Amazon Quick Suite, Amazon's agentic AI platform. When someone enters secrets, PII, financial data, or health data into an Amazon Quick chat, Nudge Security flags it.

Configure detection in your Browser Extension Settings. To learn more, see AI conversation monitoring.

New to Nudge Security? Start a 14-day free trial to detect and respond to AI data risks.

Nudge Security now discovers AI agents your team builds on Amazon Quick, AWS's agentic AI platform, right from the browser.

Every agent flows into your AI agents inventory under Identities, where you'll see its creator, components, risk insights, and more.

This is available as part of the AI agent discovery research preview. Ensure you have browser-based agent discovery turned on in your browser extension settings.

Not yet in the research preview? Request access from the AI Agents tab under Identities, or start a 14-day free trial if you're new to Nudge Security.

You can now enforce that everyone logs in to Nudge Security through your configured SSO provider.

When you turn on login restrictions, other sign-in methods, like Sign in with Google and Sign in with Microsoft, are disabled for your organization. Every login then runs through your IdP, like Okta, and inherits its MFA, conditional access, and deprovisioning controls.​

Head to Settings > Organization to set up login restrictions.

New to Nudge Security? Start a 14-day free trial to see and secure everything running across your SaaS estate.

You can now export a log of every administrative action taken in Nudge Security, so you have a clear record of who changed what and when. It captures events like OAuth revocations (including the reason), role changes, field and setting updates, app connect and disconnect events, and more. From there, export the log as a CSV.

Head to Settings > Audit event to view and export the audit log.

New to Nudge Security? Start a 14-day free trial to gain visibility and control over your SaaS estate.

Nudge Security calculates inherent and residual risk scores for every SaaS and AI vendor in your environment, mapped to a Low, Medium, High, or Critical level and updated continuously as risk factors change. These new scores complement business criticality tiers, which signal potential impact rather than current risk.

Inherent risk reflects your risk before accounting for any controls you've put into place, whereas residual risk includes those controls. Nudge Security provides a transparent breakdown of the factors driving each score, including risk factors associated with each vendor's own security posture, internal risk factors based on your organization’s deployment and usage, and compensating controls you have in place to mitigate risk. With these scores, which are now in open beta, you can:

  • Get risk context for the long tail of apps other tools miss. Every SaaS and AI app gets a score on Day One, no vendor cooperation required.
  • Account for internal risk factors. Capture easily-overlooked risk factors like critical downstream connections and AI agents that can act through the app.
  • Continuously monitor risk. Instead of a one-time snapshot, scores recalculate automatically as risk factors change, from new MCP server connections to vendor breach disclosures.
  • Know what to fix next. See recommended actions ranked by projected residual risk reduction.

View and filter risk scores within your app inventory, or head to any app overview and click the Risk tab to see risk scores and recommended actions.

New to Nudge Security? Start a 14-day free trial to see your real vendor risk exposure.

Now, Nudge Security helps you triage and prioritize apps at the scale of modern SaaS and AI adoption by automatically assigning each app a business criticality tier (Low, Medium, High, or Critical) based on the data it typically handles.

An app’s data access represents what’s at stake if the app is compromised. Nudge Security uses a proprietary model to infer the data types each AI or SaaS vendor typically handles. Next, each data type is classified by sensitivity, and business criticality is set based on the highest data sensitivity tier. With this update, which is now in open beta, you can:

  • Automatically triage every app in your environment based on its potential impact to your business.
  • Filter your inventory by 27 distinct data types, with no manual research required.
  • Tailor data sensitivity tiers to match your organization's data governance model (Settings > Risk). Business criticality recalculates automatically, except where you've set a tier manually.
  • Surface certain security posture findings only for Critical and High tier apps.

View business criticality tiers and data types within your app inventory, or within any app overview. Note: Previously tagged data types aren't lost. They now live under Data Types (Legacy), separate from the new, automatically populated Data Types field.

New to Nudge Security? Start a 14-day free trial to see what data your apps can access.

Today we are announcing two new AI agents to assess risk across your OAuth grants and browser extensions. Each one draws on the context Nudge Security already has to analyze what it discovers, return a plain-language verdict, and resolve the risk.

  • The OAuth Grant Risk Analyst: Designed to review new OAuth grants as Nudge Security discovers them and resolve overly permissive and high-risk ones, either by automatically revoking access or by nudging the OAuth grantor to remove it, all with the right human-in-the-loop oversight from the security team.
  • The Browser Extension Risk Analyst Agent: Addresses the sprawling risk of third-party browser extensions that employees install. It's built to inspect the artifacts and metadata behind installed browser extensions and flag the ones that are malicious, compromised, risky or otherwise don't do what they claim, and orchestrate disable and uninstall workflows.

Take action on the AI agents' findings using Nudge Security's existing controls, like revoke, nudge, and disable, while keeping a human in the loop.

Our new AI agents are currently available to select customers. Join the waitlist. Read our blog to learn more.

You can now see every externally shared file, folder, and Shared Drive across your Google Workspace tenant in one view.

With it you can:

  • Spot what needs attention first, with risk insights that flag orphaned Shared Drives, shares to personal email, files owned by deactivated employees, and shares with no activity in 90 days.
  • Prioritize cleanup by domain, filtering to a specific external company to see everything shared with them.
  • Tighten or revoke access, with per-item actions and a confirmation that spells out the scope before anything changes.

Getting started takes a one-time setup: connect the new Google Drive connected app, with step-by-step instructions built into the product.

Head to Inventory > External File Shares to review your external shares.

New to Nudge Security? Start a 14-day free trial to uncover what's shared outside your organization.

You can now see exactly where your security posture has compliance gaps and act on them, with findings mapped to SOC 2, NIST CSF 2.0, ISO 27001, HIPAA, and OWASP Top 10 Agentic AI Security.

With it, you can:

  • Filter findings by compliance framework to see every control violation across your SaaS estate at a glance.
  • Drill into any finding to see the specific controls it violates and follow guided remediation from the same panel.
  • Export an audit-ready report with compliance framework and control columns included.

Head to Security Posture Findings to review your compliance posture.

New to Nudge Security? Start a 14-day free trial to map your SaaS risks to compliance requirements.

You can now create a Jira issue directly from a finding, so security work lands in the tool your team already tracks it in.

With it you can:

  • Create a ticket from any finding, pre filled from the finding detail and fix recommendations.
  • Map it to your workflow, setting the project, work type, priority, assignee, and reporter.
  • Keep both systems in sync, with a linked audit trail and auto close of the Jira ticket when the finding resolves in Nudge Security.

Admins can head to Settings > Ticketing to connect Jira.

New to Nudge Security? Start a 14-day free trial to route security findings into the tools your team already uses.