RiskFinder logo
Report Generation · Operations Supply

RiskFinder

RiskFinder is a Danish SaaS platform structuring risk assessments, emergency plans, printable action cards and exercises for utilities and other critical operations, with AI-drafted action cards and exercise scenarios and documentation for Danish and EU preparedness rules.

Active GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is RiskFinder?

RiskFinder is a Danish software platform for beredskab - emergency preparedness - and business continuity, published by RiskFinder ApS. Its stated purpose is to pull preparedness work out of scattered documents, spreadsheets and competing versions and hold it in one structure that a technician in the plant room and a director in the boardroom can both read.

The work follows five stages that feed each other. A risk and vulnerability assessment, known locally as a ROS, runs in four parts - scope and assets, scenarios, probability against consequence, then vulnerability - and produces a 5x5 risk matrix. From it the platform calculates a critical limit for each asset: how long an outage is tolerable before the consequence becomes critical, four hours for the main pump used as the worked example on the site. Those results carry into a seven-section emergency plan built on the SAMSIK template, with crisis organisation, activation levels, versioning and approval. The plan in turn becomes action cards: short numbered procedures for a single incident at a single location, exported as PDF and meant to be printed and laminated, with the version number, revision date, responsible role and escalation path visible on the card itself. Exercises close the loop, tabletop or full-scale, ending in observations, a maturity score and improvement actions assigned to named owners with deadlines. A fifth track covers continuity proper: critical processes, dependencies, RTO and MTPD, then recovery plans, supplier risk, insurance documentation and physical security.

AI appears in two places, both of them drafting: action cards generated from the organisation's own risk assessment and context, and exercise scenarios built on the same material with timed injects. The vendor's own line is that it automates the process, not the knowledge, and the customer edits every draft before it is printed or played.

Everything is mapped to Danish and European rules - BEK 260 under Energistyrelsen, NIS2, CER and DORA - with the tier required for each requirement shown openly, and the methodology described as ISO 22301 compatible. The first audience is district heating, electricity distribution and water, then industry and other critical operations. The interface is Danish only.

What it does

  • Run a four-part risk and vulnerability assessment (ROS) ending in a 5x5 risk matrix
  • Calculate how long each critical asset or process can be down before the consequence turns critical
  • Build a seven-section emergency plan with crisis organisation, activation levels and approval
  • Create, version and print action cards for one incident at one specific location
  • Plan, run and evaluate tabletop or full-scale exercises with AI-generated scenarios
  • Map critical processes, dependencies, RTO and MTPD, then the recovery plans behind them
  • Export a compliance documentation pack for the regulator, an auditor or an insurer
Audience

When to use RiskFinder / When not to

A quick filter to help you decide if RiskFinder is the right fit.

When to use RiskFinder

  • Danish district heating, electricity distribution and water utilities that must document their preparedness to Energistyrelsen under BEK 260
  • Operations and safety managers at industrial sites running several plants or locations
  • Compliance and risk officers working through NIS2, CER or DORA obligations
  • Small preparedness teams with no full-time continuity function, since the entry tier is built around a single user
  • Executive teams that need auditable evidence that plans, roles and exercises are kept current

When not to use RiskFinder

  • Organisations outside Denmark that need an English-language interface, because the platform itself is Danish only
  • Teams that want to sign up and get started on their own: there is no self-service checkout, no free plan and no free trial
  • Buyers who need a published price before agreeing to a sales conversation
  • Engineering teams looking for a public API or ready-made integrations with the systems they already run
  • Procurement processes that require ISO 27001 or SOC 2 evidence and a signed data processing agreement
Get started

How to use RiskFinder

A typical end-to-end flow, from setup to results.

  1. Book the 20-minute walkthrough from the site, or ask to be called back; RiskFinder answers within one working day
  2. Agree on a tier - Basis, Plus or Premium - since there is no self-service sign-up
  3. Go through onboarding, which is simple, guided or tailored depending on that tier
  4. Have your operations specialists answer the guided questions on equipment, tolerable downtime, dependencies and capacity
  5. Let the platform calculate the critical limit for each asset and process
  6. Review the ranked list and decide what to mitigate, accept or analyse further
  7. Build the emergency plan section by section, assigning roles and activation levels
  8. Create an action card: pick the incident and the location, write the short steps in order, assign the responsible role
  9. Approve, export to PDF and print the card for the site where the incident can actually happen
  10. Schedule an exercise, use the AI-generated scenario, then log observations and improvement actions with owners and deadlines
Quick read

Pros & Cons

Pros

  • One unbroken chain from risk to action - assessment, plan, action card, exercise and documentation in the same tool, with data reused between them
  • Regulatory mapping is explicit down to the individual requirement, and states which tier is needed to cover it
  • Action cards are built for the field: printed, laminated, versioned and usable when the systems are down
  • AI is confined to drafting, with human editing kept in the loop by design rather than by policy alone
  • Direct access to the founder's expertise is part of every tier instead of a separate consulting contract
  • Clear data ethics commitments: customer ownership, no resale, and no training on customer data without an explicit agreement
  • Genuinely free entry points: a 60-second plan test with no login or email, a BEK 260 level check and a Word template

Cons

  • No public pricing at all: the three tiers say contact us for a price or contact sales
  • No self-service sign-up, no permanent free plan and no announced free trial
  • The platform runs in Danish only, which in practice limits it to Danish-speaking organisations
  • No documented public API and no named third-party integration
  • No data processing agreement is mentioned and no ISO 27001 or SOC 2 certification is displayed
  • Neither terms and conditions nor a legal notice are published, so contract terms cannot be checked beforehand
  • A young and very small vendor: an ApS registered in 2024, one employee on the CVR register, around twenty companies helped
Pricing

Pricing & Plans

RiskFinder publishes no prices. The three tiers - Basis, Plus and Premium - are quoted on request, the first two marked contact us for a price and the third contact sales, so no entry amount and no currency can be stated. No permanent free plan and no free trial are announced. What is quantified publicly is capacity rather than cost: one, five or unlimited risk assessments a year, none, twenty or unlimited AI-generated action cards a year, and one, three or unlimited users. Several resources are free of charge: a Word emergency plan template, a 60-second plan test requiring no login or email, a BEK 260 level check and a 20-minute walkthrough.

Basis, Kom i gang med beredskab
  • 1 risk assessment a year
  • action card templates only
  • help getting started
  • 1 user
  • basic organisation profile
  • limited asset register view
  • simple onboarding. Price on request.
Premium, Det fulde beredskab
  • unlimited risk assessments
  • unlimited AI
  • full action cards
  • continuous sparring and review
  • unlimited users (the card advertises 5+)
  • tailored onboarding. Contact sales.
Shared by all three tiers
  • the requirement and documentation overview
  • contacts and locations. Exercise planning and evaluation
  • the exportable compliance documentation pack and supplier management start at Plus.
Special offers — Free editable Word emergency plan template sent by email, advertised as free and requiring no payment card · Free 60-second emergency plan test with no login, no email and no answers stored, plus a downloadable PDF version · Free BEK 260 level check: four questions returning an indicative level and the matching tier · Free 20-minute walkthrough with no obligation and no preparation, answered within one working day
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how RiskFinder handles your data.

GDPR overview

GDPR implementation is concrete, though modest in scope. The privacy policy, effective 1 February 2026, names RiskFinder ApS as controller, gives its legal bases (consent under Article 6(1)(a) and legitimate interest under Article 6(1)(f)), lists six data subject rights - access, rectification, erasure, restriction, portability and objection - and routes their exercise to emil@riskfinder.dk. The Danish supervisory authority, Datatilsynet, is named with its full address and telephone number. Analytics run only after consent, which can be withdrawn at any time from the footer. Established in Denmark, the company needs no Article 27 representative and designates none. No security certification is displayed: the data ethics policy of 16 July 2026 refers instead to the principles of the Danish D-maerket scheme and to the recommendations of Dataetisk Raad.

Who owns the data?

RiskFinder's data ethics policy states plainly that the data customers put into the platform belongs to the customer. The company undertakes never to resell customer data or personal data, and never to use it for purposes the customer has not consented to; customers can ask for their data to be handed over or deleted. For the personal data collected through the website itself, RiskFinder ApS is named as the controller, reachable at emil@riskfinder.dk or on +45 42 40 40 70. No terms and conditions are published anywhere on the site, so these commitments rest on the data ethics and privacy pages rather than on a contract a buyer can read before signing.

Reuse rights

Customers keep control of what they enter: the data ethics policy says their data can be handed over or deleted on request, and is never used for purposes they have not agreed to. Customer data is not used to train general AI models without an explicit agreement, which sets no training as the default while leaving a contractual door open. Website data is narrower in scope. The contact form collects a name, a work email, an optional phone number and company name, and the message itself; it serves to answer the enquiry, confirm receipt and improve the site from anonymised usage data, on the basis of consent and legitimate interest. Resend sends the emails, Cloudflare provides hosting, and PostHog analyses traffic only once analytics cookies have been accepted.

Data retention & training

Retention summary
The privacy policy keeps personal data only as long as the purpose requires, and sets one explicit limit: contact details are deleted at the latest 24 months after the last contact, unless a customer agreement has been signed. No retention period is published for the data customers put into the platform itself; the data ethics policy says instead that customers can have their data handed over or deleted on request, and states a minimisation principle of not collecting data just in case. Cookie lifetimes are published: two years for the Google Analytics _ga and _ga_S9FB5JPKTK cookies, 24 hours for _gid, one year for the PostHog cookie, and the consent choice held in localStorage until the visitor clears it.
Trains on customer data
No
Subprocessors disclosed
Yes
GDPR contact

Hosting summary

RiskFinder names Cloudflare as its hosting subprocessor in the privacy policy, and its security page places the site's API endpoints on Cloudflare Workers. DNS resolves to 188.114.97.3, an anycast Cloudflare address, so the United States geolocation attached to that IP says nothing about where data actually sits. On jurisdiction the site is explicit only about the website layer: PostHog analytics are stated to be hosted in the EU, and the cookie policy says analytics data is stored in the EU. The data ethics policy adds a stated preference - when choosing subcontractors for hosting, email and analytics, the company looks for processing within the EU. No specific hosting country is named for the customer data held in the platform itself, and no data centre location is published. The named subprocessors are Resend for email, Cloudflare for hosting and PostHog for analytics; the security page additionally lists GitHub and Google Analytics among third-party services RiskFinder does not operate. Read strictly, the EU claim rests on the analytics stack and a supplier selection policy rather than on a commitment about platform data.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting RiskFinder.

  • AI drafts of action cards and exercise scenarios can read as finished work; a plausible but wrong first step followed at three in the morning is a real safety risk, and the vendor expects the customer to edit them
  • A tidy dashboard can produce a sense of preparedness that outruns reality on the ground - a completed plan is not a trained organisation
  • Reusing data across modules saves work but propagates a single early mistake into the assessment, the plan, the cards and the documentation
  • Documenting for the regulator can quietly become the goal, displacing the human judgement the vendor says it wants to protect
  • Neither terms and conditions nor a data processing agreement are published, so contractual and subprocessing terms cannot be checked before committing
  • Preparedness plans and critical infrastructure data are highly sensitive, and no ISO 27001 or SOC 2 certification is displayed to back the security claims
  • Depending on a one-person vendor for continuity tooling is itself a continuity risk worth writing into the risk register
Setup

Setup & Integrations

Technical difficulty

Technically undemanding: a web application with PDF output, nothing to install, no integration or API to configure. The effort is organisational rather than technical, since the method depends on operations specialists answering guided questions about equipment, tolerable downtime, dependencies and capacity - which the vendor presents as a way to avoid long workshops and empty templates. There is no self-service sign-up, so onboarding runs with RiskFinder: simple on Basis, guided on Plus, tailored on Premium. Expect the real cost to be internal time from the people who know the plant, not IT work.

Deployment

Web app

Supported languages

Danish
Company

Behind RiskFinder

Company name
RiskFinder ApS
Founded
26/03/2024
Country of origin
🇩🇰 Denmark
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
INFORMATION_NOT_FOUND
Support contact

Fundraising

No funding round has been announced by the company or found elsewhere
Innovationsfonden (Innovation Fund Denmark) backs RiskFinder through its InnoFounder programme, presented on the About page as validation of an innovative technology project with high growth potential; no amount is published

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does RiskFinder actually do?
It brings risk and vulnerability assessments, emergency plans, action cards, exercises and the supporting documentation into a single Danish platform, aimed first at utilities and other organisations with critical operations.
How much does RiskFinder cost?
No price is published. Basis and Plus are marked contact us for a price and Premium contact sales, so the amount and the currency are only disclosed in a sales conversation.
Is there a free plan or a free trial?
Neither is announced. What is free is the Word emergency plan template, the 60-second plan test, the BEK 260 level check and the 20-minute walkthrough.
What is an AI-generated action card?
According to the pricing FAQ, RiskFinder can draft a short step-by-step procedure from your risk assessment and your context, which you then edit and print. Basis includes none, Plus twenty a year, Premium unlimited.
What is a ROS risk assessment?
A structured review of the threats to your critical functions and equipment, guided through relevant threat scenarios in four parts. How many you may run per year depends on your tier.
Which regulations does RiskFinder cover?
BEK 260, NIS2, CER and DORA, with a table showing which module covers each requirement and from which tier. The site calls that overview indicative, and describes its methodology as ISO 22301 compatible.
Is my data used to train AI models?
The data ethics policy states that customer data is not used to train general AI models without an explicit agreement, and that the data customers put into the platform belongs to them.
Which languages and platforms are supported?
The platform runs in Danish only, as a web application; the English page on the site is presentational. No mobile app, public API or named third-party integration is documented.
Conclusion

Should you pick RiskFinder?

RiskFinder is a narrow tool that knows exactly how narrow it is. It was built for Danish preparedness obligations - BEK 260, NIS2, CER, DORA - and it maps its modules to those requirements one by one, which is a great deal more useful to a district heating utility than a generic risk register would be. The strongest part of the product is the least glamorous: action cards designed to be printed, laminated and used at three in the morning with the systems down, carrying their version number and escalation path on the card itself. The AI is deliberately modest, drafting action cards and exercise scenarios from the organisation's own risk assessment, with the customer editing before anything is printed or played.

The reservations are commercial and documentary rather than functional. Nothing about the price is public, there is no free plan, no trial and no way to sign up alone, so evaluating the tool means starting a sales conversation. The interface exists in Danish only. No terms and conditions, no legal notice and no data processing agreement are published, and no security certification is displayed - an awkward gap for a platform that holds emergency plans for critical infrastructure, even with an explicit data ethics policy and a well-run vulnerability disclosure page in its favour. The vendor is young and very small: an ApS registered in 2024 with one employee on the Danish register, and the industrial logos on the site are the founder's past experience, which the site itself takes care to say.

For a Danish utility or industrial operator facing a regulator, that trade is a reasonable one. For anyone else, the language and the pricing opacity will settle the question first.