Nudge Security

Security for AI Cloud SecurityIdentity AccessGovernance Risk Compliance also known as Nudge Security, Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2021
Last updated 2026-08-27

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Russell Spitler and Jaime Blasco created the AlienVault Open Threat Exchange before founding Nudge Security in 2021. The company sells IT and security teams an inventory of the SaaS and AI apps employees sign up for on their own. It finds them in the automated mail those apps send into Microsoft 365 and Google Workspace. Two granted U.S. patents cover that email method. The browser and app-connection paths added later carry no patent in the reviewed record, so its exclusive asset covers the oldest path. Microsoft and Google control the mail that path reads, so the method depends on continued access to workspaces they own. Its customer numbers are its own, and the newest outside figure in the reviewed sources is Omdia's just over 50 paying enterprises in October 2023.

Sourced Details

Description Nudge Security finds the SaaS and AI applications, accounts, and OAuth integrations employees adopt on their own, scores the risk each one carries, and sends the responsible employee an automated prompt to fix the unsafe setting. [f1]
Founded 2021 [f2]
HQ Austin, Texas, United States [f2]
Latest funding Series A, $22.5M, November 2025 [f2]

Products

Product What it does
Nudge Security Inventories SaaS and AI apps, identities, and integrations from workspace email, browser, and app connections, then surfaces posture findings and routes remediation to app owners.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Nudge Security inventories AI tools in use, discovers agents employees build on platforms such as Microsoft Copilot Studio, watches what employees send to AI chatbots, and surfaces the OAuth grants that give AI tools access to business data. These capabilities are mapped to the AI Defense Matrix. [f3]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Nudge Security builds an inventory of the SaaS applications and accounts employees create, monitors app configurations and OAuth grants for risky settings, and drives single sign-on coverage and offboarding for those accounts. These capabilities are mapped to the Cyber Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 25 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Nudge Security names its buyer, IT and security teams running Microsoft 365 or Google Workspace, and states the problem plainly. Omdia calls shadow IT a direct consequence of the success of SaaS, while the numbers that size the pain are the company's own research carried by Dark Reading. [s17, s18, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Two granted U.S. patents describe the discovery mechanism, heuristic pattern analysis over incoming mail combined with machine learning. Omdia separately assessed how the read-only mailbox connection works and where it stops, which is technical assessment from outside the vendor. [s16, s22, s17]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 AI capability arriving inside ordinary business applications is a credible enabler, dated by the November 2025 raise and by the OAuth and browser-extension agents announced in July 2026 for select customers. Buyer-side evidence is review ratings: 31 G2 reviews syndicated onto the AWS Marketplace listing, plus the Gartner and G2 ratings the company posts on its own pages, 4.7 out of 5 and 5 out of 5. Named customer stories sit on those same pages. Ratings on two platforms are one kind of demand evidence, not two. [s11, s23, s19, s1]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 SecurityWeek and Omdia both record that Spitler and Blasco created and operated the AlienVault Open Threat Exchange, and an RSAC speaker profile names two earlier startups Blasco founded in web application security, source code analysis, and incident response. CRN and Omdia place Spitler as AlienVault's senior product lead through its 2018 sale to AT&T. [s12, s17, s21, s13]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Six named customer stories sit on the company's own pages alongside Reddit's security chief speaking on the record in the funding release, and the AWS Marketplace listing carries 31 reviews syndicated from G2. The one paying-customer count from an independent source is Omdia's just over 50 paying enterprises, published in October 2023, so the company measures its own current scale. [s10, s9, s19, s17]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A $22.5 million Series A in November 2025 is proportional to a company that took a $7 million seed in April 2022, and SecurityWeek puts the total raised close to $30 million. The growth behind it, tripled recurring revenue two years running and nearly 200 customers, is the company's own measurement with no revenue or margin disclosed. [s11, s9]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Omdia classified the product as SaaS security and governance, and CRN placed it in the software and AI security governance market. The company's own product page still positions it by name against SaaS security management vendors, and its homepage names a coined term for the segment it sells into, which is placement that needs vendor explanation. [s17, s13, s2, s1]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Microsoft and Google hold the mailboxes the patented discovery reads, which puts the input data inside platforms already adjacent to the buyer. Omdia points to the discovery approach as what differentiates the company, and the reviewed record shows no cross-customer data asset behind it. [s17, s16, s1]
Business Risks The patented discovery method depends on continued read access to Microsoft 365 and Google Workspace, which Microsoft and Google control…
  • The patented discovery method depends on continued read access to Microsoft 365 and Google Workspace, which Microsoft and Google control.
  • The two granted patents cover email-based discovery, and the reviewed record documents no patent protection for the newer browser and app-connection channels.
  • Customer-scale claims come from the company, so traction could prove thinner than the published reference list suggests.
  • No source in the reviewed record reports the customer base after 2023, so a stalled account base would stay out of the public record for some time.
  • The company states it does not block or limit access to SaaS applications, so buyers who want that control could treat Nudge Security as a discovery feed and buy blocking elsewhere.
  • Omdia records that the mailbox method cannot see an account an employee creates with a personal webmail address, so a workforce that routes around corporate mail would shrink the inventory.
Problem & Market Employees adopt SaaS and AI applications faster than a central IT team can record them, and Nudge Security sells the inventory that closes that gap. The buyers are IT and security teams at companies running Microsoft 365 or Google Workspace who have no single list of what their people signed up for. Omdia calls shadow IT a direct consequence of the success of SaaS, which places the problem independently of the vendor. The numbers that size it are the company's own. Dark Reading carried a Nudge Security finding that organizations averaged six AI tools in use, and that is coverage of the company's data rather than an independent measurement. The timing argument is that AI capability now sits inside ordinary business applications, so governing AI use means governing the whole application estate. That framing dates to the November 2025 funding round, and the OAuth and browser-extension agents announced in July 2026 for select customers extend it. Buyers do face more applications to govern, though the reviewed evidence carries the company's account of demand rather than an outside measure of it…

Employees adopt SaaS and AI applications faster than a central IT team can record them, and Nudge Security sells the inventory that closes that gap. The buyers are IT and security teams at companies running Microsoft 365 or Google Workspace who have no single list of what their people signed up for.

Omdia calls shadow IT a direct consequence of the success of SaaS, which places the problem independently of the vendor. The numbers that size it are the company's own. Dark Reading carried a Nudge Security finding that organizations averaged six AI tools in use, and that is coverage of the company's data rather than an independent measurement.

The timing argument is that AI capability now sits inside ordinary business applications, so governing AI use means governing the whole application estate. That framing dates to the November 2025 funding round, and the OAuth and browser-extension agents announced in July 2026 for select customers extend it. Buyers do face more applications to govern, though the reviewed evidence carries the company's account of demand rather than an outside measure of it. [s17, s18, s1, s11, s23]

Product Capabilities Nudge Security finds applications by reading the automated mail that SaaS providers send. The product connects to the customer's Microsoft 365 or Google Workspace accounts with read-only access, and two granted U.S. patents describe heuristic pattern analysis over that mail combined with machine learning. Two newer discovery paths now sit beside the patented one. A browser extension passively observes employees creating agents in Cursor, Zapier, Retool, and similar tools, and connected apps pull agent inventories from Salesforce Agentforce, Microsoft Copilot Studio, and other agent-building platforms. The company calls agent discovery a research preview. TechCrunch reported at the 2022 launch that the product uncovered SaaS assets without browser extensions or API integrations, so the mechanism has broadened since. Past discovery, the product monitors application configurations and the integrations attached to them, and it publishes security profiles covering a large catalog of SaaS vendors. Remediation runs through an automated message to the employee who owns the app, and the company states it does not block or limit access to SaaS applications. Agents announced in July 2026 for select customers analyze OAuth grants and browser extensions and hand the decision to a person…

Nudge Security finds applications by reading the automated mail that SaaS providers send. The product connects to the customer's Microsoft 365 or Google Workspace accounts with read-only access, and two granted U.S. patents describe heuristic pattern analysis over that mail combined with machine learning.

Two newer discovery paths now sit beside the patented one. A browser extension passively observes employees creating agents in Cursor, Zapier, Retool, and similar tools, and connected apps pull agent inventories from Salesforce Agentforce, Microsoft Copilot Studio, and other agent-building platforms. The company calls agent discovery a research preview. TechCrunch reported at the 2022 launch that the product uncovered SaaS assets without browser extensions or API integrations, so the mechanism has broadened since.

Past discovery, the product monitors application configurations and the integrations attached to them, and it publishes security profiles covering a large catalog of SaaS vendors. Remediation runs through an automated message to the employee who owns the app, and the company states it does not block or limit access to SaaS applications. Agents announced in July 2026 for select customers analyze OAuth grants and browser extensions and hand the decision to a person. [s16, s22, s7, s14, s8, s23, s2]

Competitive Positioning Nudge Security competes in a crowded stretch of the SaaS security market, and its own product page names Wing Security, Grip Security, Valence Security, Push Security, and Lumos as companies focused on SaaS security management. That is the company's account of its field rather than an outside one. Omdia named Grip Security and Push Security as vendors focused on the discovery side of SaaS security when it assessed the company in 2023, and it placed BetterCloud, Zluri, and Torii HQ in a separate group that starts from licence management. Grip starts by inspecting identities and credentials rather than mailbox contents. Microsoft and Google pose a different kind of competitive question than the specialists. Both control the workspace mail the patented discovery reads, so the method depends on continued access to platforms they own…

Nudge Security competes in a crowded stretch of the SaaS security market, and its own product page names Wing Security, Grip Security, Valence Security, Push Security, and Lumos as companies focused on SaaS security management. That is the company's account of its field rather than an outside one.

Omdia named Grip Security and Push Security as vendors focused on the discovery side of SaaS security when it assessed the company in 2023, and it placed BetterCloud, Zluri, and Torii HQ in a separate group that starts from licence management. Grip starts by inspecting identities and credentials rather than mailbox contents.

Microsoft and Google pose a different kind of competitive question than the specialists. Both control the workspace mail the patented discovery reads, so the method depends on continued access to platforms they own. [s2, s17, s16, s1]

Go-to-Market & Traction Nudge Security sells through a self-serve trial alongside sales-assisted enterprise contracts. Its pricing page publishes a flat monthly rate for small teams with no per-seat math, a per-user rate that scales with headcount above that, and custom contracts with volume pricing above that band. The unit is the active Google Workspace or Microsoft 365 account, the same mailbox the discovery engine reads, and a free trial starts without a credit card or a sales conversation. Named references sit on the company's own pages. The customer stories page carries KarmaCheck, Stravito, Watershed, GLAAD, gridX, and Wallace Plese + Dreher, and Reddit's security chief is quoted by name in the November 2025 funding announcement. The AWS Marketplace listing carries 31 reviews syndicated from G2, which is buyer testimony hosted outside its own pages. Omdia recorded just over 50 paying enterprises in a report published in October 2023, and no later outside figure appears in the reviewed sources, so the customer base the company now claims carries no outside measurement…

Nudge Security sells through a self-serve trial alongside sales-assisted enterprise contracts. Its pricing page publishes a flat monthly rate for small teams with no per-seat math, a per-user rate that scales with headcount above that, and custom contracts with volume pricing above that band. The unit is the active Google Workspace or Microsoft 365 account, the same mailbox the discovery engine reads, and a free trial starts without a credit card or a sales conversation.

Named references sit on the company's own pages. The customer stories page carries KarmaCheck, Stravito, Watershed, GLAAD, gridX, and Wallace Plese + Dreher, and Reddit's security chief is quoted by name in the November 2025 funding announcement. The AWS Marketplace listing carries 31 reviews syndicated from G2, which is buyer testimony hosted outside its own pages.

Omdia recorded just over 50 paying enterprises in a report published in October 2023, and no later outside figure appears in the reviewed sources, so the customer base the company now claims carries no outside measurement. [s4, s10, s9, s19, s17]

Team & Credibility Russell Spitler and Jaime Blasco founded Nudge Security in 2021 after senior roles at AlienVault and AT&T Cybersecurity. SecurityWeek and Omdia both record that the pair created and operated the AlienVault Open Threat Exchange, an open threat-intelligence community, and CRN records that Spitler joined AT&T through the 2018 acquisition of AlienVault, where his last title was senior vice president of product. The record reaches back further for Blasco. An RSAC speaker profile tied to a 2019 presentation describes him as a security researcher whose work on emerging threats is frequently cited in the general press, and it names two earlier startups he founded in web application security, source code analysis, and incident response. Omdia records 13 years at AlienVault ending as vice president and chief scientist. The founding idea reached outside security for its method. TechCrunch reported at launch that the company worked with Aaron Kay, a psychology professor at Duke University, on applying psychology research to the product, which is an unusual input for a security tool and explains the company name. The bench has widened since. A leader with 20 years of go-to-market experience at security companies now runs global sales, marketing, product success, and revenue operations, and another joined after holding the chief technology officer position at TruSTAR, which Splunk acquired in 2020…

Russell Spitler and Jaime Blasco founded Nudge Security in 2021 after senior roles at AlienVault and AT&T Cybersecurity. SecurityWeek and Omdia both record that the pair created and operated the AlienVault Open Threat Exchange, an open threat-intelligence community, and CRN records that Spitler joined AT&T through the 2018 acquisition of AlienVault, where his last title was senior vice president of product.

The record reaches back further for Blasco. An RSAC speaker profile tied to a 2019 presentation describes him as a security researcher whose work on emerging threats is frequently cited in the general press, and it names two earlier startups he founded in web application security, source code analysis, and incident response. Omdia records 13 years at AlienVault ending as vice president and chief scientist.

The founding idea reached outside security for its method. TechCrunch reported at launch that the company worked with Aaron Kay, a psychology professor at Duke University, on applying psychology research to the product, which is an unusual input for a security tool and explains the company name.

The bench has widened since. A leader with 20 years of go-to-market experience at security companies now runs global sales, marketing, product success, and revenue operations, and another joined after holding the chief technology officer position at TruSTAR, which Splunk acquired in 2020. [s12, s17, s21, s13, s14, s3]

Trust Readiness Nudge Security runs a trust center on SafeBase at trust.nudgesecurity.com, which lists CCPA, HIPAA, SOC 2, and GDPR under compliance, and its own trust page states the company holds SOC 2 Type II. No ISO 27001 certification appears on those pages or elsewhere in the reviewed sources. The trust center is the assurance surface a buyer at this price point has, and the reviewed record names no regime that mandates this product class. The design limits email retention and human access. The vendor states it keeps no permanent copy of email and grants no human access, and it describes the service as less invasive than a spam filter. The pricing FAQ adds that a customer can delete its account and all data and revoke workspace access at any time…

Nudge Security runs a trust center on SafeBase at trust.nudgesecurity.com, which lists CCPA, HIPAA, SOC 2, and GDPR under compliance, and its own trust page states the company holds SOC 2 Type II.

No ISO 27001 certification appears on those pages or elsewhere in the reviewed sources. The trust center is the assurance surface a buyer at this price point has, and the reviewed record names no regime that mandates this product class.

The design limits email retention and human access. The vendor states it keeps no permanent copy of email and grants no human access, and it describes the service as less invasive than a spam filter. The pricing FAQ adds that a customer can delete its account and all data and revoke workspace access at any time. [s6, s5, s4]

Competitors Grip Security, Push Security, Valence Security, Wing Security, Lumos…
Company Relationship Note Compare
Grip Security competes with Omdia named Grip Security as a vendor focused on the discovery side of SaaS security, starting by inspecting identities and credentials rather than mailbox contents. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Push Security competes with Omdia named Push Security among the vendors focused on the discovery side of SaaS security. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Valence Security competes with Nudge Security's own product page lists Valence Security among the companies focused on SaaS security management. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Wing Security competes with Nudge Security's own product page lists Wing Security among the companies focused on SaaS security management.
Lumos competes with Nudge Security's own product page lists Lumos among the companies focused on SaaS security management.

Add analyzed competitors to compare them side by side with Nudge Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Nudge Security does specialized engineering to infer which applications an employee signed up for from the automated mail those applications send, and two granted U.S. patents document the method. Those patents are the exclusive asset the record evidences, and they cover the oldest of the three discovery paths the product ships. The vendor security profiles it publishes sit in a public directory, so that research is not exclusive to paying customers. Customers connect the product and run the workflows, so what they buy is software rather than an operator who owns the outcome. A customer that cancels takes back the offboarding and access reviews the product automates. Omdia named Grip Security and Push Security as discovery-focused alternatives, so a buyer has a like-for-like comparison.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 The customer connects the product, sets the policies, and runs the workflows, paying a published rate per active workspace account for capabilities rather than for an operator who owns the outcome.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 A departing customer takes back the offboarding playbook and the periodic access reviews the product automates, along with the accumulated historical inventory. That is data history and learned workflow friction rather than a mechanism that forces a rebuild. The cited record does not size the migration, and the pricing FAQ says a customer can delete its account and all data at any time.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The company holds SOC 2 Type II and runs a SafeBase trust center, assurance a funded competitor can obtain through ordinary enterprise-market preparation, and no reviewed source shows a regulation that mandates this product class.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Inferring application use from heuristic patterns in automated mail combined with machine learning, then extending that inventory across agent platforms and browsers, is specialized work two granted U.S. patents document.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Omdia puts the sweet spot at companies with 500 to 5,000 employees in a highly distributed environment, and the published bands run from small teams up to a negotiated agreement, so the evidenced buyer is mid-market with IT governance rather than a regulated enterprise or a government.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The product reads from the workspace and business applications and publishes an API, so it is a platform with application features rather than a path other systems must route through.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 Two granted U.S. patents assigned to Nudge Security cover the email-analysis discovery method, which is retained intellectual property the cited record evidences rather than infers, and a funded rival would need time and effort to design around it. The vendor security profiles sit in a public directory, so the published research is not the asset here.
Strategic Market Segmentation Nudge Security's published pricing puts the product within reach of midsize IT and security teams. The pricing page charges a flat monthly rate for small teams with no per-seat math, a per-user rate that scales with headcount above that, and custom contracts with volume pricing beyond that band. Omdia put the sweet spot at companies with 500 to 5,000 employees in a highly distributed environment, selling into IT and security teams. The segment is defined by a shared condition rather than by an industry, and the company describes customers spanning software, financial services, healthcare, biotechnology, and entertainment. The assurance package matches that segment. The trust page states the company holds SOC 2 Type II, which is the assurance surface a midsize buyer has before connecting a product to its mail. The trust center lists CCPA, HIPAA, SOC 2, and GDPR, and the record names no regime that requires more for this product class…

Nudge Security's published pricing puts the product within reach of midsize IT and security teams. The pricing page charges a flat monthly rate for small teams with no per-seat math, a per-user rate that scales with headcount above that, and custom contracts with volume pricing beyond that band.

Omdia put the sweet spot at companies with 500 to 5,000 employees in a highly distributed environment, selling into IT and security teams. The segment is defined by a shared condition rather than by an industry, and the company describes customers spanning software, financial services, healthcare, biotechnology, and entertainment.

The assurance package matches that segment. The trust page states the company holds SOC 2 Type II, which is the assurance surface a midsize buyer has before connecting a product to its mail. The trust center lists CCPA, HIPAA, SOC 2, and GDPR, and the record names no regime that requires more for this product class.

Product Capabilities & AI Advantages The distinctive capability is discovery through automated email…

The distinctive capability is discovery through automated email. Two granted U.S. patents describe heuristic pattern analysis over incoming mail combined with machine learning, which lets the product find applications an employee signed up for through the mail the application itself sent.

Two further discovery paths now run beside it. Connected apps pull agent inventories from Salesforce Agentforce, Microsoft Copilot Studio, and other agent-building platforms, while a browser extension passively observes employees creating agents in Cursor, Zapier, Retool, and similar tools. The company calls agent discovery a research preview. The patents describe email-based discovery, and the reviewed record documents no patent covering the newer channels, so the exclusive part of the discovery system is its oldest path.

AI is both the subject and the method here. The product inventories AI apps and agents as assets to govern, watches for sensitive data employees share with AI chatbots, and uses machine learning inside the discovery engine. Remediation stays human-in-the-loop, and agents announced in July 2026 for select customers analyze OAuth grants and browser extensions and hand the decision to a person.

Sales Engagement & Go-to-Market The company sells self-serve first and moves to sales for larger accounts…

The company sells self-serve first and moves to sales for larger accounts. A free 14-day trial runs without a credit card or a sales conversation and delivers an inventory after a setup the company describes as five minutes. Beyond the published bands the pricing page routes the buyer to a negotiated agreement.

Distribution reaches beyond direct selling in one documented way. AWS Marketplace carries a Nudge Security listing priced by the same active-account unit, which puts the product in a procurement channel outside the company's own sales process.

Reference selling is doing real work. The customer stories page publishes six named accounts, and Reddit's security chief speaks on the record in the funding announcement. What outsiders record is Omdia's figure of just over 50 paying enterprises in October 2023 and 31 reviews syndicated from G2 onto the marketplace listing.

Pricing Model Nudge Security publishes its pricing, which fits a self-serve sale…

Nudge Security publishes its pricing, which fits a self-serve sale. The unit is the active Google Workspace or Microsoft 365 account, the same mailbox the discovery engine reads, so a buyer pays by the surface the product actually covers.

The structure has three steps. A flat monthly fee covers small teams with no per-seat math, a per-user rate scales with headcount through the middle band, and estates above it move to custom contracts with volume pricing. Both published tiers state that all features are included, billed annually. The feature list marks configuration and integration posture management with a dollar symbol the page does not explain.

Charging per mailbox rather than per discovered application keeps the bill predictable as sprawl grows. Per-mailbox pricing also caps upside, because a customer whose application count triples pays the same as one whose count holds steady. The company does not let a buyer meter part of a domain, so the price tracks the whole workspace.

Product Delivery & Operations Nudge Security is software the customer connects and operates…

Nudge Security is software the customer connects and operates. Setup is a read-only connection to the workspace provider, with the browser extension and app connections added as the customer chooses.

The service runs on AWS using microservices and serverless components, with logical tenant separation and least-privileged access described on the trust page. Nothing in the reviewed sources describes an analyst team that operates the product on a customer's behalf or accepts responsibility for outcomes.

Where automation cannot close a finding, the product routes the work to a person. That last-mile step is a workflow the customer's own staff runs, and the agents announced in July 2026 keep a person in the decision rather than acting alone.

Earning Customers' Trust The company publishes a SafeBase trust center at trust.nudgesecurity.com, which lists CCPA, HIPAA, SOC 2, and GDPR under compliance, and its own trust page states it holds SOC 2 Type II. No ISO 27001 certification appears on those pages or elsewhere in the reviewed sources. The trust center is the assurance surface a buyer has, and the reviewed record names no regime that mandates this product class. Reading corporate mailboxes is a material trust consideration for this product. The trust page answers it by describing no permanent storage of email and no human access, the architecture section describes tenant separation on AWS, and the pricing FAQ says a customer can delete its account and all data and revoke workspace access at any time…

The company publishes a SafeBase trust center at trust.nudgesecurity.com, which lists CCPA, HIPAA, SOC 2, and GDPR under compliance, and its own trust page states it holds SOC 2 Type II.

No ISO 27001 certification appears on those pages or elsewhere in the reviewed sources. The trust center is the assurance surface a buyer has, and the reviewed record names no regime that mandates this product class.

Reading corporate mailboxes is a material trust consideration for this product. The trust page answers it by describing no permanent storage of email and no human access, the architecture section describes tenant separation on AWS, and the pricing FAQ says a customer can delete its account and all data and revoke workspace access at any time.

Platform Strategy & Ecosystem Positioning Nudge Security behaves as a platform with application features rather than as infrastructure other systems depend on. It reads from Microsoft 365, Google Workspace, and a growing list of business applications, and it publishes an API, but nothing routes through it in the way traffic routes through a gateway. Its ecosystem reach is broadest on the discovery side. The company claims posture coverage across a very large catalog of SaaS and AI tools with or without an API integration, and it publishes vendor security profiles drawn from that catalog. The company publishes a public directory of those profiles. Open access puts the research in front of buyers who have not bought anything. It also means the published output is not exclusive to paying customers, and the reviewed sources establish no exclusive corpus behind it…

Nudge Security behaves as a platform with application features rather than as infrastructure other systems depend on. It reads from Microsoft 365, Google Workspace, and a growing list of business applications, and it publishes an API, but nothing routes through it in the way traffic routes through a gateway.

Its ecosystem reach is broadest on the discovery side. The company claims posture coverage across a very large catalog of SaaS and AI tools with or without an API integration, and it publishes vendor security profiles drawn from that catalog.

The company publishes a public directory of those profiles. Open access puts the research in front of buyers who have not bought anything. It also means the published output is not exclusive to paying customers, and the reviewed sources establish no exclusive corpus behind it.

Team & Execution Capability Russell Spitler and Jaime Blasco founded the company in 2021 out of AlienVault and AT&T Cybersecurity, where Blasco led the Alien Labs threat intelligence and data science unit. SecurityWeek and Omdia both record that the pair created and operated the AlienVault Open Threat Exchange, so the in-domain track record rests on published accounts rather than claimed ones. CRN and Omdia place Spitler as AlienVault's senior product lead through the 2018 sale to AT&T, and Omdia records 13 years at AlienVault for Blasco ending as vice president and chief scientist. An RSAC speaker profile tied to a 2019 presentation names two earlier startups Blasco founded in web application security, source code analysis, and incident response. The founding thesis borrowed from outside security. TechCrunch reported that the company worked with Aaron Kay, a psychology professor at Duke University, on applying psychology research to the product. That is an unusual input for a security product and it explains the name. The bench has widened since. A leader with 20 years of go-to-market experience at security companies now runs global sales, marketing, product success, and revenue operations, and another joined after holding the chief technology officer position at TruSTAR, which Splunk acquired in 2020…

Russell Spitler and Jaime Blasco founded the company in 2021 out of AlienVault and AT&T Cybersecurity, where Blasco led the Alien Labs threat intelligence and data science unit. SecurityWeek and Omdia both record that the pair created and operated the AlienVault Open Threat Exchange, so the in-domain track record rests on published accounts rather than claimed ones.

CRN and Omdia place Spitler as AlienVault's senior product lead through the 2018 sale to AT&T, and Omdia records 13 years at AlienVault for Blasco ending as vice president and chief scientist. An RSAC speaker profile tied to a 2019 presentation names two earlier startups Blasco founded in web application security, source code analysis, and incident response.

The founding thesis borrowed from outside security. TechCrunch reported that the company worked with Aaron Kay, a psychology professor at Duke University, on applying psychology research to the product. That is an unusual input for a security product and it explains the name.

The bench has widened since. A leader with 20 years of go-to-market experience at security companies now runs global sales, marketing, product success, and revenue operations, and another joined after holding the chief technology officer position at TruSTAR, which Splunk acquired in 2020.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Nudge Security: SaaS and AI Security Platform official 2026-08-27
f2 SecurityWeek: Nudge Security Raises $22.5 Million in Series A Funding press 2026-08-27
f3 AI Defense Matrix Catalog: product entry for Nudge Security official 2026-08-27
f4 Nudge Security: SaaS Security Posture Management official 2026-08-27
Profile Analysis Sources (23)
Id Source Tier Accessed
s1 Nudge Security: SaaS and AI Security Platform official 2026-08-27
s2 Nudge Security: Product Overview official 2026-08-27
s3 Nudge Security: About Us official 2026-08-27
s4 Nudge Security: Pricing official 2026-08-27
s5 Nudge Security: Trust and Security official 2026-08-27
s6 Nudge Security Trust Center on SafeBase (unauthenticated fetch, 2026-08-27) official 2026-08-27
s7 Nudge Security: AI Agent Discovery official 2026-08-27
s8 Nudge Security: SaaS Security Posture Management official 2026-08-27
s9 Nudge Security: Raises $22.5M Series A to Secure Workforce AI and SaaS (November 2025) official 2026-08-27
s10 Nudge Security: Customer Stories official 2026-08-27
s11 SecurityWeek: Nudge Security Raises $22.5 Million in Series A Funding (published November 2025) press 2026-08-27
s12 SecurityWeek: Nudge Security Bags $7M Seed Round (published April 2022) press 2026-08-27
s13 CRN: 10 Cloud Computing Startup Companies To Watch In 2026 press 2026-08-27
s14 TechCrunch: Nudge Security emerges from stealth (published October 2022) press 2026-08-27
s15 Dark Reading: Nudge Security Launches Platform With Humans in Mind (published October 2022) press 2026-08-27
s16 Google Patents: US 11,799,884 B1, Analysis of user email to detect use of Internet services, assignee Nudge Security, Inc. regulatory 2026-08-27
s17 Omdia On the Radar: Nudge Security offers SaaS security with patented discovery and collaborative governance, by Rik Turner (23 October 2023) research 2026-08-27
s18 Dark Reading: Infosec Doesn't Know What AI Tools Orgs Are Using (published July 2023) press 2026-08-27
s19 AWS Marketplace: Nudge Security listing official 2026-08-27
s20 Nudge Security: Security Profiles directory (probe by unauthenticated fetch, 2026-08-27) official 2026-08-27
s21 RSAC Conference: Jaime Blasco expert profile and 2019 presentation record research 2026-08-27
s22 Google Patents: US 12,137,117 B2, Analysis of user email to detect use of internet services regulatory 2026-08-27
s23 Nudge Security: Unveils AI Agents to Mitigate Escalating Risks from Hidden OAuth Grants and Browser Extensions (July 2026) official 2026-08-27
Deep-Dive Sources (23)
Id Source Tier Accessed
s1 Nudge Security: SaaS and AI Security Platform official 2026-08-27
s2 Nudge Security: Product Overview official 2026-08-27
s3 Nudge Security: About Us official 2026-08-27
s4 Nudge Security: Pricing official 2026-08-27
s5 Nudge Security: Trust and Security official 2026-08-27
s6 Nudge Security Trust Center on SafeBase (unauthenticated fetch, 2026-08-27) official 2026-08-27
s7 Nudge Security: AI Agent Discovery official 2026-08-27
s8 Nudge Security: SaaS Security Posture Management official 2026-08-27
s9 Nudge Security: Raises $22.5M Series A to Secure Workforce AI and SaaS (November 2025) official 2026-08-27
s10 Nudge Security: Customer Stories official 2026-08-27
s11 SecurityWeek: Nudge Security Raises $22.5 Million in Series A Funding (published November 2025) press 2026-08-27
s12 SecurityWeek: Nudge Security Bags $7M Seed Round (published April 2022) press 2026-08-27
s13 CRN: 10 Cloud Computing Startup Companies To Watch In 2026 press 2026-08-27
s14 TechCrunch: Nudge Security emerges from stealth (published October 2022) press 2026-08-27
s15 Dark Reading: Nudge Security Launches Platform With Humans in Mind (published October 2022) press 2026-08-27
s16 Google Patents: US 11,799,884 B1, Analysis of user email to detect use of Internet services, assignee Nudge Security, Inc. regulatory 2026-08-27
s17 Omdia On the Radar: Nudge Security offers SaaS security with patented discovery and collaborative governance, by Rik Turner (23 October 2023) research 2026-08-27
s18 Dark Reading: Infosec Doesn't Know What AI Tools Orgs Are Using (published July 2023) press 2026-08-27
s19 AWS Marketplace: Nudge Security listing official 2026-08-27
s20 Nudge Security: Security Profiles directory (probe by unauthenticated fetch, 2026-08-27) official 2026-08-27
s21 RSAC Conference: Jaime Blasco expert profile and 2019 presentation record research 2026-08-27
s22 Google Patents: US 12,137,117 B2, Analysis of user email to detect use of internet services regulatory 2026-08-27
s23 Nudge Security: Unveils AI Agents to Mitigate Escalating Risks from Hidden OAuth Grants and Browser Extensions (July 2026) official 2026-08-27

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.