Changelog

Subscribe to all Changelog posts via RSS to stay updated on everything we ship at Nudge Security.

See your organization's risk posture at a glance with our new risk dashboard, built automatically from the business criticality tiers and residual risk scores Nudge Security calculates for every app in your inventory. Nudge continuously monitors risk across your environment, so both those scores and your dashboard stay current as things change.

​

With it you can:

  • See your risk posture at a glance, with tiles for apps assessed, business-critical apps, overall residual risk, and apps missing approval.
  • Track risk over time, with a trend chart you can filter down to just your business-critical apps.
  • Find where risk concentrates, with a matrix mapping business criticality against residual risk, and click into any cell to see the exact apps behind it.
  • Jump to what needs attention first with a table ranking your highest-risk apps.

​

Head to Dashboards > Risk to explore the dashboard.

​

New to Nudge Security? Start a 14-day free trial to see your SaaS risk posture at a glance.

You can now see how far passkey adoption has spread across your organization, and where those passkeys are actually stored, in the new Passkey usage dashboard. Nudge Security's browser extension already detects passkeys as employees create and use them, and the new dashboard turns that data into an auditable, organization-wide view.

​

With it you can:

  • See your passkey adoption rate and the top apps your users log into with a passkey.
  • See where passkeys are stored, by provider, with a toggle between number of passkeys and number of users.
  • Check whether passkeys can survive a lost device and whether the user was verified at login.

You can also see passkey usage for individual employees on their user details page.

​

The dashboard populates from the Nudge Security browser extension. Head to Dashboards > Passkey usage to explore your data.

​

New to Nudge Security? Start a 14-day free trial to see where your passkeys live.

You can now catch sensitive data before it reaches an AI tool.

​

When the browser extension detects sensitive data like PII, secrets, or financial info in an AI conversation, an in-browser nudge shows the employee exactly what was found and lets them redact it in one click, or justify sending it. Optionally turn on enforcement and redaction becomes the only way to send, so unredacted sensitive data never leaves the browser.

​

Head to Settings > In-browser nudges to turn on sensitive data nudges and choose whether to enforce redaction.

​

New to Nudge Security? Start a 14-day free trial.

AI conversation monitoring now detects sensitive data shared in Amazon Quick Suite, Amazon's agentic AI platform. When someone enters secrets, PII, financial data, or health data into an Amazon Quick chat, Nudge Security flags it.

​

Configure detection in your Browser Extension Settings. To learn more, see AI conversation monitoring.

​

New to Nudge Security? Start a 14-day free trial to detect and respond to AI data risks.

Nudge Security now discovers AI agents your team builds on Amazon Quick, AWS's agentic AI platform, right from the browser.

​

Every agent flows into your AI agents inventory under Identities, where you'll see its creator, components, risk insights, and more.

​

This is available as part of the AI agent discovery research preview. Ensure you have browser-based agent discovery turned on in your browser extension settings.

​

Not yet in the research preview? Request access from the AI Agents tab under Identities, or start a 14-day free trial if you're new to Nudge Security.

You can now enforce that everyone logs in to Nudge Security through your configured SSO provider.

‍

When you turn on login restrictions, other sign-in methods, like Sign in with Google and Sign in with Microsoft, are disabled for your organization. Every login then runs through your IdP, like Okta, and inherits its MFA, conditional access, and deprovisioning controls.​

‍

Head to Settings > Organization to set up login restrictions.

​

New to Nudge Security? Start a 14-day free trial to see and secure everything running across your SaaS estate.

You can now export a log of every administrative action taken in Nudge Security, so you have a clear record of who changed what and when. It captures events like OAuth revocations (including the reason), role changes, field and setting updates, app connect and disconnect events, and more. From there, export the log as a CSV.

​

Head to Settings > Audit event to view and export the audit log.

​

New to Nudge Security? Start a 14-day free trial to gain visibility and control over your SaaS estate.

Nudge Security calculates inherent and residual risk scores for every SaaS and AI vendor in your environment, mapped to a Low, Medium, High, or Critical level and updated continuously as risk factors change. These new scores complement business criticality tiers, which signal potential impact rather than current risk.

‍

Inherent risk reflects your risk before accounting for any controls you've put into place, whereas residual risk includes those controls. Nudge Security provides a transparent breakdown of the factors driving each score, including risk factors associated with each vendor's own security posture, internal risk factors based on your organization’s deployment and usage, and compensating controls you have in place to mitigate risk. With these scores, which are now in open beta, you can:

  • Get risk context for the long tail of apps other tools miss. Every SaaS and AI app gets a score on Day One, no vendor cooperation required.
  • Account for internal risk factors. Capture easily-overlooked risk factors like critical downstream connections and AI agents that can act through the app.
  • Continuously monitor risk. Instead of a one-time snapshot, scores recalculate automatically as risk factors change, from new MCP server connections to vendor breach disclosures.
  • Know what to fix next. See recommended actions ranked by projected residual risk reduction.

View and filter risk scores within your app inventory, or head to any app overview and click the Risk tab to see risk scores and recommended actions.

‍

New to Nudge Security? Start a 14-day free trial to see your real vendor risk exposure.

‍

Now, Nudge Security helps you triage and prioritize apps at the scale of modern SaaS and AI adoption by automatically assigning each app a business criticality tier (Low, Medium, High, or Critical) based on the data it typically handles.

‍

An app’s data access represents what’s at stake if the app is compromised. Nudge Security uses a proprietary model to infer the data types each AI or SaaS vendor typically handles. Next, each data type is classified by sensitivity, and business criticality is set based on the highest data sensitivity tier. With this update, which is now in open beta, you can:

  • Automatically triage every app in your environment based on its potential impact to your business.
  • Filter your inventory by 27 distinct data types, with no manual research required.
  • Tailor data sensitivity tiers to match your organization's data governance model (Settings > Risk). Business criticality recalculates automatically, except where you've set a tier manually.
  • Surface certain security posture findings only for Critical and High tier apps.

View business criticality tiers and data types within your app inventory, or within any app overview. Note: Previously tagged data types aren't lost. They now live under Data Types (Legacy), separate from the new, automatically populated Data Types field.

‍

New to Nudge Security? Start a 14-day free trial to see what data your apps can access.

Today we are announcing two new AI agents to assess risk across your OAuth grants and browser extensions. Each one draws on the context Nudge Security already has to analyze what it discovers, return a plain-language verdict, and resolve the risk.

  • The OAuth Grant Risk Analyst: Designed to review new OAuth grants as Nudge Security discovers them and resolve overly permissive and high-risk ones, either by automatically revoking access or by nudging the OAuth grantor to remove it, all with the right human-in-the-loop oversight from the security team.
  • The Browser Extension Risk Analyst Agent: Addresses the sprawling risk of third-party browser extensions that employees install. It's built to inspect the artifacts and metadata behind installed browser extensions and flag the ones that are malicious, compromised, risky or otherwise don't do what they claim, and orchestrate disable and uninstall workflows.

Take action on the AI agents' findings using Nudge Security's existing controls, like revoke, nudge, and disable, while keeping a human in the loop.

‍

Our new AI agents are currently available to select customers. Join the waitlist. Read our blog to learn more.