Day One Discovery
Nudge Security uncovers all shadow AI and SaaS sprawl on Day One with a patented discovery method competitors canât match.
No endpoint agents to deploy. No network taps to configure. No traffic to inspect.
Nudge Security uncovers all shadow AI and SaaS sprawl on Day One with a patented discovery method competitors canât match.
No endpoint agents to deploy. No network taps to configure. No traffic to inspect.
Nudge Security is the system of record for employee technology use, and the foundation for changing behavior at scale.


Director of Workforce Productivity, Netflix
Deliver guardrails when and where your work is happening.
Manager of IT, Wallace Plese + Dreher
SSO tax be damned. Every Nudge Security customer can take advantage of SSO functionality to enable sign in with Okta at no extra cost.
Vary the access needed by role, including granting every employee the ability to self-manage their SaaS footprints.
Extend Nudge data to the rest of your IT security stack including SecOps, ITSM, identity management, and more.
Just read-only API access to your Google Workspace or Microsoft 365 domain, granted by your administrator. Read-only means we can't modify or delete anything in a mailbox. In practice, that makes Nudge Security less permissive than the average spam filter or secure email gateway.
No. Nudge Security's patented email analysis engine looks only for machine-generated emails sent by SaaS providersâthings like account confirmations, password resets, and invoices. We never access outbound emails or emails sent between employees, and no human ever reads email content. Every analysis runs in memory on automated systems, and the content is destroyed immediately after processing.
You don't have to take our word for it. We keep a full record of every search query we run and every email identifier we analyze, and you can request that record at any time. Your email administrator can also review and verify our search activity directly from your Google Workspace or Microsoft 365 admin console.
We pull out the metadata that builds your SaaS inventoryâthings like app name, user account, OAuth grants, and timestampsâand discard the rest. All analysis happens on ephemeral, serverless workers that exist only for seconds, for the duration of the job. Once it's done, the worker and the email content it touched are both destroyed. Nothing is retained.
No. Setup is a single read-only connection to your email domain, typically five minutes of work for your administrator. There's nothing to install on endpoints and nothing running in employees' browsers.
Fast. Most organizations have a complete SaaS inventory within an average of 75 minutes of connecting, covering apps, accounts, OAuth grants, and even SaaS spend pulled from emailed invoices. From there, Nudge Security keeps scanning as new emails arrive, so you're notified as soon as new apps show up.
Many only scan email subject lines, which misses a lot. Nudge Security analyzes the full metadata of machine-generated emails and uses pattern recognitionânot just a list of known sendersâto identify SaaS providers. That means we can surface shadow accounts, email/password logins that never touch SSO, and brand-new tools (including AI apps) that haven't been added to anyone's catalog yet.
Yes, anytime. From the Settings tab in Nudge Security, you can delete all data and revoke access to your Microsoft 365 or Google Workspace domain. Your Microsoft or Google administrator can also remove the application directly from your admin console.
Visit the Nudge Security Trust Center for our SOC 2 Type 2 report and other compliance documentation, or reach out directly at [email protected] with any questions.
It's a lightweight extension you deploy to employees' browsers, tied to each person's identity. From there, it gives you real-time visibility into SaaS and AI usage, login and authentication activity, password hygiene, and data-sharing behaviorâand can nudge employees toward safer choices as they work, like flagging a weak password the moment they set it.
No. It's built to collect security-relevant signals only, not to monitor or surveil employees. It doesn't track keystrokes, browsing history for its own sake, or general web activityâit watches for specific events like logins, OAuth grants, file uploads, and AI tool use, and ignores everything else.
It picks up on app logins and account status, authentication methods (SSO, MFA), password strength and reuse, OAuth grants and API keys created from the browser, file uploads, and AI chatbot interactions. For AI conversations, it reports which tools are in use and, if enabled, flags when sensitive dataâlike credentials or financial informationâshows up in a prompt. You control which of these categories are active; not all of them are required.
No. The extension never sees or stores a plaintext password. It stores a SHA-256 cryptographic hash locally in the employee's browser, which is enough to flag weak or reused passwords without ever exposing the password itself.
Yes. It shows up in their browser's extension list (grayed out, so they can't remove it) and can be pinned to the toolbar if your admins choose. Employees can also get their own view into their SaaS footprint through individual access, which builds trust rather than a sense of being watched.
Chrome, Edge, Firefox, Brave, and AI-native browsers like ChatGPT Atlas, Comet, and Dia, on both Windows and Mac. Safari support is in active development.
Admins can push it organization-wide through an MDM or the Google Admin Console, or deploy it individually and share an install link with specific users. Updates ship automaticallyâa browser refresh is all it takes to pick up the latest version.
Yes. Every detection categoryâpassword checks, file upload monitoring, API key detection, AI conversation monitoring, personal account detection, and moreâcan be toggled on or off from your Nudge Security settings to match your organization's policies.
No. It's no more resource-intensive than any other browser extension your employees already use.
Only if it happens in the same managed browser session where an employee is logged in with corporate credentials. It doesn't track activity in a separate personal browser or profile, and it only looks forward from the point of deploymentânot historical browsing.