Know your real vendor risk with inherent and residual risk scores, now in open beta
Nudge Security calculates inherent and residual risk scores for every SaaS and AI vendor in your environment, mapped to a Low, Medium, High, or Critical level and updated continuously as risk factors change. These new scores complement business criticality tiers, which signal potential impact rather than current risk.
‍
Inherent risk reflects your risk before accounting for any controls you've put into place, whereas residual risk includes those controls. Nudge Security provides a transparent breakdown of the factors driving each score, including risk factors associated with each vendor's own security posture, internal risk factors based on your organization’s deployment and usage, and compensating controls you have in place to mitigate risk. With these scores, which are now in open beta, you can:
- Get risk context for the long tail of apps other tools miss. Every SaaS and AI app gets a score on Day One, no vendor cooperation required.
- Account for internal risk factors. Capture easily-overlooked risk factors like critical downstream connections and AI agents that can act through the app.
- Continuously monitor risk. Instead of a one-time snapshot, scores recalculate automatically as risk factors change, from new MCP server connections to vendor breach disclosures.
- Know what to fix next. See recommended actions ranked by projected residual risk reduction.
View and filter risk scores within your app inventory, or head to any app overview and click the Risk tab to see risk scores and recommended actions.
‍
New to Nudge Security? Start a 14-day free trial to see your real vendor risk exposure.
‍



