Back to changelog

SOC 2 Compliance

Subscribe to all Changelog posts via RSS to stay updated on everything we ship at Nudge Security.

Now, Nudge Security helps you triage and prioritize apps at the scale of modern SaaS and AI adoption by automatically assigning each app a business criticality tier (Low, Medium, High, or Critical) based on the data it typically handles.

‍

An app’s data access represents what’s at stake if the app is compromised. Nudge Security uses a proprietary model to infer the data types each AI or SaaS vendor typically handles. Next, each data type is classified by sensitivity, and business criticality is set based on the highest data sensitivity tier. With this update, which is now in open beta, you can:

  • Automatically triage every app in your environment based on its potential impact to your business.
  • Filter your inventory by 27 distinct data types, with no manual research required.
  • Tailor data sensitivity tiers to match your organization's data governance model (Settings > Risk). Business criticality recalculates automatically, except where you've set a tier manually.
  • Surface certain security posture findings only for Critical and High tier apps.

View business criticality tiers and data types within your app inventory, or within any app overview. Note: Previously tagged data types aren't lost. They now live under Data Types (Legacy), separate from the new, automatically populated Data Types field.

‍

New to Nudge Security? Start a 14-day free trial to see what data your apps can access.

You can now export a log of every administrative action taken in Nudge Security, so you have a clear record of who changed what and when. It captures events like OAuth revocations (including the reason), role changes, field and setting updates, app connect and disconnect events, and more. From there, export the log as a CSV.

​

Head to Settings > Audit event to view and export the audit log.

​

New to Nudge Security? Start a 14-day free trial to gain visibility and control over your SaaS estate.

You can now see exactly where your security posture has compliance gaps and act on them, with findings mapped to SOC 2, NIST CSF 2.0, ISO 27001, HIPAA, and OWASP Top 10 Agentic AI Security.

​

With it, you can:

  • Filter findings by compliance framework to see every control violation across your SaaS estate at a glance.
  • Drill into any finding to see the specific controls it violates and follow guided remediation from the same panel.
  • Export an audit-ready report with compliance framework and control columns included.

​

Head to Security Posture Findings to review your compliance posture.

​

New to Nudge Security? Start a 14-day free trial to map your SaaS risks to compliance requirements.

We’ve just released a new automated playbook to make running SOC 2 access reviews with Nudge Security even easier. 

‍

Now, customers and free trial users can:


  • Capture and classify all in-scope SOC 2 assets, starting with smart app categorization to speed up your process.
  • Easily identify users associated with your SOC 2 assets and verify that they still need access on a regular basis.
  • Generate a print-ready report of your SOC 2 access review to demonstrate a repeatable process for auditors.

‍

Here’s an interactive tour of the new feature:

‍

‍

For a closer look, read the release blog post here.

See what you've been missing.