Meet your newest security analysts.

The OAuth Grant Risk Analyst and Browser Extension Risk Analyst review the risk sprawl no security team could manage by hand—and act on it, with human-in-the-loop approval every step of the way.

Join the waitlist

Risk sprawl, by the numbers

88

OAuth grants per employee on average—31 of them with data-level permissions.
Source: Nudge Security platform data

53%

of installed browser extensions can access sensitive enterprise data like passwords and page content.
Source: LayerX Enterprise Browser Extension Security Report, 2026

200,000+

vendor security profiles power every verdict our agents deliver—cutting manual vendor review by up to 90%.
Source: Nudge Security platform data

Research Preview

OAuth Grant Risk Analyst

Reviews every new OAuth grant the moment it's discovered: who requested it, their role, the vendor's security posture, and the scopes requested against what's typical, and against your own data-sharing policy. It catches what a simple risk score misses, like a brand-new hire creating a high-risk developer grant, because it looks at who created the grant, not just what it can do.

Evaluates requester role, vendor posture, and requested scopes in seconds, not 45 minutes
Delivers a clear verdict, plain-language explanation, and next step: review, monitor, or revoke
Orchestrates revocation or nudges the grantor directly to remove access
Keeps a human on the security team in the loop for every consequential call
Nudge Security SaaS asset discovery
Nudge Security SaaS asset discovery

Research Preview

Browser Extension Risk Analyst

Inspects an extension's artifacts and metadata alongside its marketplace listing to check whether what it actually does matches what it claims. When it finds a mismatch, like an extension quietly sending data to an undisclosed server, it rates the severity of what it found and acts on it.

Compares extension behavior against its marketplace listing and requested permissions
Flags malicious, compromised, or misrepresented extensions
Rates severity so your team knows exactly what to act on first
Automatically disables high-risk extensions and nudges stakeholders to complete uninstall

General Availability

Vendor Risk Analyst

Our original agent, shipped before "agentic" was the label everyone reached for. It draws on more than 200,000 vendor security profiles to evaluate new vendors automatically, pulling certifications, breach history, and compliance posture the moment a new tool shows up in your environment.

Pulls a vendor's security and compliance posture automatically, no manual lookups
Flags missing certifications, recent breach disclosures, and policy gaps
Cuts manual vendor review time by up to 90% for teams using it today
Surfaces a clear verdict your team can act on immediately
Nudge Security SaaS asset discovery

Get in line for early access.

Our new AI agents are rolling out to select customers first. Join the waitlist and we'll reach out as access opens up.