Let’s talk about email privacy

‍

We have read-only API access to email in Google Workspaces and Microsoft 365.
We only look for machine-generated emails. We provide an audit trail of all emails accessed.
We analyze in memory and only store metadata, destroying workers after every job. 
No permanent storage of email
No human ever has access
Less invasive than a spam filter
What you'll get on Day One

A single read-only integration to Microsoft 365 or Google Workspace delivers your initial analysis—typically in under an hour.

‍

Grid of SaaS and AI app tiles representing complete inventory

Complete SaaS & AI inventory

Discover all SaaS apps, AI tools, users, and authentication methods—including shadow apps that network and endpoint controls typically miss, and apps added in the past.

OAuth integration risk scoring panel with high, medium, and low meters

OAuth and integration risks

See every OAuth grant and app-to-app integration across your SaaS estate, complete with risk scoring, scopes, context, and one-click revocation workflows.

Security posture finding card with severity badges and remediation guidance

Security posture findings with remediation guidance

Surface identity, access, and configuration risks across Microsoft 365 or Google Workspace—with clear steps to fix each issue.

Attack surface mapping illustration showing identity, tech context, and risk tables

SaaS attack surface mapping

See what attackers can see, including cloud infrastructure, repositories, domains, and supply chain dependencies.

SaaS spend insights illustration with cost-per-app card and historical spend

SaaS spend insights

Reveal unapproved paid apps, duplicate tooling, and up to two years of historical spend to support cost optimization decisions.

"Other providers expected us to manually configure dozens of individual app integrations before we could start seeing value... When I signed up for a trial with Nudge, we were up and running within an hour just by connecting to our IdP. We were seeing insights immediately."

- Chris Tuley, IT Specialist at KarmaCheck

Unlock deeper insights

Our initial analysis provides fast insights and time-saving automation to deliver immediate value. Add these optional integrations for deeper insights and more scalable governance.

‍

See Integrations
Connect your SSO provider.
⏱ 5 minutes

You can:

See which apps are (and aren't) in SSO
Gain more granular insights into app usage frequency
Prioritize SSO onboarding efforts with real usage data
Use our playbook to streamline SSO onboarding
Deploy the browser extension.
⏱ 10 minutes

You get:

AI conversation monitoring with sensitive data detection
Detection of weak or re-used passwords
Tracking of app login method and frequency to spot suspicious activity
Browser-based nudges to enforce your security policies
AI agent discovery for a growing list of AI platforms
Connect your critical apps.
⏱ 5 minutes per app

You get:

User access details like login activity and authentication methods
Instance details to track multiple tenants or workspaces
Third-party integrations like OAuth grants and API tokens
Continuous posture checks against app-specific best practices
Automated remediation workflows and progress tracking
Visibility from Every Angle
Discover AI & SaaS everywhere modern work happens.

Nudge Security is the system of record for employee technology use, and the foundation for changing behavior at scale.

“Nudge is now being used by Security, Workforce Productivity, and Finance as the record of what apps employees are using.”

Director of Workforce Productivity, Netflix

Nudge your workforce toward secure behaviors

Deliver guardrails when and where your work is happening.

Step

1

Connect Slack or Teams
Reach employees as they are working to request context on new apps, verify if apps are still in use, confirm app ownership, and more.
Step

2

Deploy the browser extension
Intervene in the moment risky behaviors are detected - password re-use, missing MFA, sensitive data sharing, unapproved app use, and more.
Step

3

Scale governance with automation
Run playbooks to automate collecting context on new apps, redirecting users to approved tools, delivering your AI acceptable use policy, and more.
"Some of these people don't respond to emails or tickets, but they responded to the damn nudge! It just works."

Manager of IT, Wallace Plese + Dreher

Enterprise-ready at no extra cost
Sign in with SSO

SSO tax be damned. Every Nudge Security customer can take advantage of SSO functionality to enable sign in with Okta at no extra cost.

Role-based access control

Vary the access needed by role, including granting every employee the ability to self-manage their SaaS footprints.

Public API

Extend Nudge data to the rest of your IT security stack including SecOps, ITSM, identity management, and more.

Dive in. What are you waiting for?

Join the 200+ security teams who've eliminated shadow AI and SaaS sprawl in their first week. Full access for two weeks. No credit card required.

Frequently asked questions

How much access does your email analysis actually require?

Just read-only API access to your Google Workspace or Microsoft 365 domain, granted by your administrator. Read-only means we can't modify or delete anything in a mailbox. In practice, that makes Nudge Security less permissive than the average spam filter or secure email gateway.

Are you reading our employees emails?

No. Nudge Security's patented email analysis engine looks only for machine-generated emails sent by SaaS providers—things like account confirmations, password resets, and invoices. We never access outbound emails or emails sent between employees, and no human ever reads email content. Every analysis runs in memory on automated systems, and the content is destroyed immediately after processing.

How do we know what you're actually looking at?

You don't have to take our word for it. We keep a full record of every search query we run and every email identifier we analyze, and you can request that record at any time. Your email administrator can also review and verify our search activity directly from your Google Workspace or Microsoft 365 admin console.

What happens to the email data after it's analyzed?

We pull out the metadata that builds your SaaS inventory—things like app name, user account, OAuth grants, and timestamps—and discard the rest. All analysis happens on ephemeral, serverless workers that exist only for seconds, for the duration of the job. Once it's done, the worker and the email content it touched are both destroyed. Nothing is retained.

Does discovery require agents, network proxies, or browser extensions?

No. Setup is a single read-only connection to your email domain, typically five minutes of work for your administrator. There's nothing to install on endpoints and nothing running in employees' browsers.

How fast can we actually get visibility?

Fast. Most organizations have a complete SaaS inventory within an average of 75 minutes of connecting, covering apps, accounts, OAuth grants, and even SaaS spend pulled from emailed invoices. From there, Nudge Security keeps scanning as new emails arrive, so you're notified as soon as new apps show up.

How is this different from other vendors that say they do email-based discovery?

Many only scan email subject lines, which misses a lot. Nudge Security analyzes the full metadata of machine-generated emails and uses pattern recognition—not just a list of known senders—to identify SaaS providers. That means we can surface shadow accounts, email/password logins that never touch SSO, and brand-new tools (including AI apps) that haven't been added to anyone's catalog yet.

Can we revoke access or delete our data?

Yes, anytime. From the Settings tab in Nudge Security, you can delete all data and revoke access to your Microsoft 365 or Google Workspace domain. Your Microsoft or Google administrator can also remove the application directly from your admin console.

Where can we find more detail on your security and compliance program?

Visit the Nudge Security Trust Center for our SOC 2 Type 2 report and other compliance documentation, or reach out directly at [email protected] with any questions.

How does the Nudge Security browser extension work?

It's a lightweight extension you deploy to employees' browsers, tied to each person's identity. From there, it gives you real-time visibility into SaaS and AI usage, login and authentication activity, password hygiene, and data-sharing behavior—and can nudge employees toward safer choices as they work, like flagging a weak password the moment they set it.

Is it monitoring everything employees do in their browser?

No. It's built to collect security-relevant signals only, not to monitor or surveil employees. It doesn't track keystrokes, browsing history for its own sake, or general web activity—it watches for specific events like logins, OAuth grants, file uploads, and AI tool use, and ignores everything else.

What can the extension actually see?

It picks up on app logins and account status, authentication methods (SSO, MFA), password strength and reuse, OAuth grants and API keys created from the browser, file uploads, and AI chatbot interactions. For AI conversations, it reports which tools are in use and, if enabled, flags when sensitive data—like credentials or financial information—shows up in a prompt. You control which of these categories are active; not all of them are required.

Do you store our employees' actual passwords?

No. The extension never sees or stores a plaintext password. It stores a SHA-256 cryptographic hash locally in the employee's browser, which is enough to flag weak or reused passwords without ever exposing the password itself.

Will employees know the extension is installed?

Yes. It shows up in their browser's extension list (grayed out, so they can't remove it) and can be pinned to the toolbar if your admins choose. Employees can also get their own view into their SaaS footprint through individual access, which builds trust rather than a sense of being watched.

What browsers does it support?

Chrome, Edge, Firefox, Brave, and AI-native browsers like ChatGPT Atlas, Comet, and Dia, on both Windows and Mac. Safari support is in active development.

How is it deployed, and does it need to be manually updated?

Admins can push it organization-wide through an MDM or the Google Admin Console, or deploy it individually and share an install link with specific users. Updates ship automatically—a browser refresh is all it takes to pick up the latest version.

Can we control what the extension collects?

Yes. Every detection category—password checks, file upload monitoring, API key detection, AI conversation monitoring, personal account detection, and more—can be toggled on or off from your Nudge Security settings to match your organization's policies.

Does it slow down the browser?

No. It's no more resource-intensive than any other browser extension your employees already use.

Can it see activity outside of work, like personal browsing?

Only if it happens in the same managed browser session where an employee is logged in with corporate credentials. It doesn't track activity in a separate personal browser or profile, and it only looks forward from the point of deployment—not historical browsing.