Back to the blog
December 9, 2025

2025 in review: Our greatest hits for SaaS and AI security

SaaS sprawl and AI adoption surged in 2025, creating new security challenges. Here are the key product updates we delivered to help teams stay ahead.

As 2025 comes to a close, we’ve been reflecting on how quickly the landscape shifted this year. Workforce AI use matured faster than any of us expected—moving from one-off productivity helpers to interconnected agents embedded across the SaaS tools we all rely on. And with MCP servers linking those agents into business-critical systems, organizations suddenly needed new compensating controls just as quickly as they were adopting new capabilities.

‍

2025 was also a milestone year for us. We raised our Series A funding, giving us the fuel to accelerate our mission to secure the modern workforce without blocking productivity. As we head into 2026, we’re more energized than ever—and grateful to everyone who partnered with us along the way.

‍

Here’s a look back at what we accomplished together.

‍

‍

AI security: Built for the way teams actually work

If 2025 proved anything, it’s that AI security isn’t a separate category at all—it’s an extension of SaaS security. The surge of SaaS-delivered AI tools made this clearer than ever. Employees are adopting AI tools the same way they adopt SaaS tools, and those tools plug into the same browsers, the same identity systems, the same data flows, and the same supply chains.

‍

In other words, the risks aren’t new—they’re amplified. And the controls organizations need haven’t changed either. Real-time visibility, powerful automation, and active workforce participation remain the only scalable ways to secure the modern workplace.

‍

With that philosophy at the center, we invested heavily this year in capabilities to help customers discover, protect, and govern workforce AI use at scale. We released:

  • Deep visibility & control: Track AI tool usage, monitor daily active users, and detect sensitive data being shared with AI chatbots.
  • Expanded browser support: Including AI-native browsers like ChatGPT Atlas, Dia, and Perplexity’s Comet.
  • Real-time policy enforcement: Deliver your AI Acceptable Use Policy (AUP) the moment an employee accesses an AI tool and track acceptance rates directly in your dashboard.
  • Vendor evaluation summaries: Quickly review AI data training policies to streamline security reviews.
  • Governance playbooks: Pre-built workflows to help you operationalize your AI governance framework.

Read more about our approach to AI governance at scale →

‍

‍

Third-party risk: Unprecedented visibility

Third-party risk no longer ends with the vendors you contract with. It extends to the thousands of connections, plugins, and integrations your employees authorize every day, as well as the vendors in your vendors' supply chains.

‍

The Salesloft Drift breach was a prime example of a modern SaaS supply chain attack: The attackers gained access to Salesforce instances not by breaching Salesforce directly, but by leveraging stolen OAuth grants, bypassing MFA and exfiltrating data. These app-to-app access pathways are often unmonitored and forgotten, providing a hidden doorway for attackers.

‍

This year, we doubled down on helping you see and manage that expanding digital supply chain—without slowing down the business. We’ve given you:

  • Browser insights and interventions: Access risk findings, activity data, and real-time policy enforcement for every SaaS or AI app your employees use through our browser extension, with support for Google Chrome, Microsoft Edge, Brave, as well as AI browsers like ChatGPT Atlas, Dia, and Comet.
  • Expanded connected app support: Detect and resolve misconfigurations and identity risks through over a dozen new integrations, including Salesforce, Atlassian, Snowflake, ServiceNow, and more.
  • Instant vendor assessments: Access to more than 200,000 vendor security profiles, so you can quickly vet the tools your workforce adopts.
  • Expanded supply chain breach details: Identify which vendors were breached in an app’s supply chain, with rich context and historical breach insights.

Read more about third-party risk management with Nudge Security →

‍

‍

Identity governance: Streamlined & automated

Managing identities across a sprawling SaaS estate is a heavy lift. Accounts, credentials, and non-human identities continue to multiply—and manual workflows can’t keep up.

‍

This year, we focused on improving automation and visibility to ease that burden:

  • Non-human identity discovery: Monitor which MCP servers, API keys, OAuth grants, service accounts, and more are accessing your critical applications.
  • Automated offboarding: We enhanced our offboarding playbook to support suspended and archived users in Google Workspace and Microsoft 365, ensuring complete access revocation. Plus, you can now trigger offboarding directly via our API.
  • Weak password detection: Identify weak passwords and automatically nudge users to update them, reducing the risk of credential-based attacks.
  • Granular identity insights: Gain deeper context into user activity with new visibility into OS, browser type, and authentication methods (MFA, SSO, OAuth) for every login event——directly through our extension.

‍

‍

Product experience: Built for scale

Security operations should be seamless, not a bottleneck. That’s why we’ve invested deeply in usability, automation, and customization—so you can move faster and manage more without increasing manual work.

‍

This year, we delivered:

  • Microsoft Teams & multi-channel support: Reach employees where they work, with native Teams support and expanded Slack notification options.
  • Bulk actions & automation: Scale your operations with bulk nudging, automatic re-nudging for non-responsive users, and mass account updates.
  • Real-time visibility: Track engagement instantly with immediate nudge response alerts and exportable history logs.
  • Deep customization: Adapt the platform to your specific workflows with custom fields, notes, and flexible labeling.

Subscribe to our changelog and you’ll never miss an update.

‍

Cheers to a more secure 2026 🥂

These updates have empowered our customers to stay ahead of emerging risks, automate tedious workflows, and govern AI and SaaS adoption at scale—all without slowing down innovation. We’re proud to provide the real-time visibility and proactive controls modern IT and security teams need to protect their organizations while keeping the business moving forward.

‍

Thanks for being part of our journey this year. Here’s to a secure and innovative 2026!

Related posts

Report

Debunking the "stupid user" myth in security

Exploring the influence of employees’ perception
and emotions on security behaviors