RiskFinder
RiskFinder is a Danish SaaS platform structuring risk assessments, emergency plans, printable action cards and exercises for utilities and other critical operations, with AI-drafted action cards and exercise scenarios and documentation for Danish and EU preparedness rules.
What is RiskFinder?
RiskFinder is a Danish software platform for beredskab - emergency preparedness - and business continuity, published by RiskFinder ApS. Its stated purpose is to pull preparedness work out of scattered documents, spreadsheets and competing versions and hold it in one structure that a technician in the plant room and a director in the boardroom can both read.
The work follows five stages that feed each other. A risk and vulnerability assessment, known locally as a ROS, runs in four parts - scope and assets, scenarios, probability against consequence, then vulnerability - and produces a 5x5 risk matrix. From it the platform calculates a critical limit for each asset: how long an outage is tolerable before the consequence becomes critical, four hours for the main pump used as the worked example on the site. Those results carry into a seven-section emergency plan built on the SAMSIK template, with crisis organisation, activation levels, versioning and approval. The plan in turn becomes action cards: short numbered procedures for a single incident at a single location, exported as PDF and meant to be printed and laminated, with the version number, revision date, responsible role and escalation path visible on the card itself. Exercises close the loop, tabletop or full-scale, ending in observations, a maturity score and improvement actions assigned to named owners with deadlines. A fifth track covers continuity proper: critical processes, dependencies, RTO and MTPD, then recovery plans, supplier risk, insurance documentation and physical security.
AI appears in two places, both of them drafting: action cards generated from the organisation's own risk assessment and context, and exercise scenarios built on the same material with timed injects. The vendor's own line is that it automates the process, not the knowledge, and the customer edits every draft before it is printed or played.
Everything is mapped to Danish and European rules - BEK 260 under Energistyrelsen, NIS2, CER and DORA - with the tier required for each requirement shown openly, and the methodology described as ISO 22301 compatible. The first audience is district heating, electricity distribution and water, then industry and other critical operations. The interface is Danish only.
What it does
- Run a four-part risk and vulnerability assessment (ROS) ending in a 5x5 risk matrix
- Calculate how long each critical asset or process can be down before the consequence turns critical
- Build a seven-section emergency plan with crisis organisation, activation levels and approval
- Create, version and print action cards for one incident at one specific location
- Plan, run and evaluate tabletop or full-scale exercises with AI-generated scenarios
- Map critical processes, dependencies, RTO and MTPD, then the recovery plans behind them
- Export a compliance documentation pack for the regulator, an auditor or an insurer
When to use RiskFinder / When not to
A quick filter to help you decide if RiskFinder is the right fit.
When to use RiskFinder
- Danish district heating, electricity distribution and water utilities that must document their preparedness to Energistyrelsen under BEK 260
- Operations and safety managers at industrial sites running several plants or locations
- Compliance and risk officers working through NIS2, CER or DORA obligations
- Small preparedness teams with no full-time continuity function, since the entry tier is built around a single user
- Executive teams that need auditable evidence that plans, roles and exercises are kept current
When not to use RiskFinder
- Organisations outside Denmark that need an English-language interface, because the platform itself is Danish only
- Teams that want to sign up and get started on their own: there is no self-service checkout, no free plan and no free trial
- Buyers who need a published price before agreeing to a sales conversation
- Engineering teams looking for a public API or ready-made integrations with the systems they already run
- Procurement processes that require ISO 27001 or SOC 2 evidence and a signed data processing agreement
How to use RiskFinder
A typical end-to-end flow, from setup to results.
- Book the 20-minute walkthrough from the site, or ask to be called back; RiskFinder answers within one working day
- Agree on a tier - Basis, Plus or Premium - since there is no self-service sign-up
- Go through onboarding, which is simple, guided or tailored depending on that tier
- Have your operations specialists answer the guided questions on equipment, tolerable downtime, dependencies and capacity
- Let the platform calculate the critical limit for each asset and process
- Review the ranked list and decide what to mitigate, accept or analyse further
- Build the emergency plan section by section, assigning roles and activation levels
- Create an action card: pick the incident and the location, write the short steps in order, assign the responsible role
- Approve, export to PDF and print the card for the site where the incident can actually happen
- Schedule an exercise, use the AI-generated scenario, then log observations and improvement actions with owners and deadlines
Pros & Cons
Pros
- One unbroken chain from risk to action - assessment, plan, action card, exercise and documentation in the same tool, with data reused between them
- Regulatory mapping is explicit down to the individual requirement, and states which tier is needed to cover it
- Action cards are built for the field: printed, laminated, versioned and usable when the systems are down
- AI is confined to drafting, with human editing kept in the loop by design rather than by policy alone
- Direct access to the founder's expertise is part of every tier instead of a separate consulting contract
- Clear data ethics commitments: customer ownership, no resale, and no training on customer data without an explicit agreement
- Genuinely free entry points: a 60-second plan test with no login or email, a BEK 260 level check and a Word template
Cons
- No public pricing at all: the three tiers say contact us for a price or contact sales
- No self-service sign-up, no permanent free plan and no announced free trial
- The platform runs in Danish only, which in practice limits it to Danish-speaking organisations
- No documented public API and no named third-party integration
- No data processing agreement is mentioned and no ISO 27001 or SOC 2 certification is displayed
- Neither terms and conditions nor a legal notice are published, so contract terms cannot be checked beforehand
- A young and very small vendor: an ApS registered in 2024, one employee on the CVR register, around twenty companies helped
Pricing & Plans
RiskFinder publishes no prices. The three tiers - Basis, Plus and Premium - are quoted on request, the first two marked contact us for a price and the third contact sales, so no entry amount and no currency can be stated. No permanent free plan and no free trial are announced. What is quantified publicly is capacity rather than cost: one, five or unlimited risk assessments a year, none, twenty or unlimited AI-generated action cards a year, and one, three or unlimited users. Several resources are free of charge: a Word emergency plan template, a 60-second plan test requiring no login or email, a BEK 260 level check and a 20-minute walkthrough.
- 1 risk assessment a year
- action card templates only
- help getting started
- 1 user
- basic organisation profile
- limited asset register view
- simple onboarding. Price on request.
- 5 risk assessments a year
- 20 AI-generated action cards a year
- full action card creation and printing
- access to professional sparring
- 3 users
- full organisation profile and asset register
- guided onboarding. Price on request.
- unlimited risk assessments
- unlimited AI
- full action cards
- continuous sparring and review
- unlimited users (the card advertises 5+)
- tailored onboarding. Contact sales.
- the requirement and documentation overview
- contacts and locations. Exercise planning and evaluation
- the exportable compliance documentation pack and supplier management start at Plus.
Data, GDPR & hosting
A consolidated view of how RiskFinder handles your data.
GDPR overview
GDPR implementation is concrete, though modest in scope. The privacy policy, effective 1 February 2026, names RiskFinder ApS as controller, gives its legal bases (consent under Article 6(1)(a) and legitimate interest under Article 6(1)(f)), lists six data subject rights - access, rectification, erasure, restriction, portability and objection - and routes their exercise to emil@riskfinder.dk. The Danish supervisory authority, Datatilsynet, is named with its full address and telephone number. Analytics run only after consent, which can be withdrawn at any time from the footer. Established in Denmark, the company needs no Article 27 representative and designates none. No security certification is displayed: the data ethics policy of 16 July 2026 refers instead to the principles of the Danish D-maerket scheme and to the recommendations of Dataetisk Raad.
Who owns the data?
RiskFinder's data ethics policy states plainly that the data customers put into the platform belongs to the customer. The company undertakes never to resell customer data or personal data, and never to use it for purposes the customer has not consented to; customers can ask for their data to be handed over or deleted. For the personal data collected through the website itself, RiskFinder ApS is named as the controller, reachable at emil@riskfinder.dk or on +45 42 40 40 70. No terms and conditions are published anywhere on the site, so these commitments rest on the data ethics and privacy pages rather than on a contract a buyer can read before signing.
Reuse rights
Customers keep control of what they enter: the data ethics policy says their data can be handed over or deleted on request, and is never used for purposes they have not agreed to. Customer data is not used to train general AI models without an explicit agreement, which sets no training as the default while leaving a contractual door open. Website data is narrower in scope. The contact form collects a name, a work email, an optional phone number and company name, and the message itself; it serves to answer the enquiry, confirm receipt and improve the site from anonymised usage data, on the basis of consent and legitimate interest. Resend sends the emails, Cloudflare provides hosting, and PostHog analyses traffic only once analytics cookies have been accepted.
Data retention & training
Hosting summary
RiskFinder names Cloudflare as its hosting subprocessor in the privacy policy, and its security page places the site's API endpoints on Cloudflare Workers. DNS resolves to 188.114.97.3, an anycast Cloudflare address, so the United States geolocation attached to that IP says nothing about where data actually sits. On jurisdiction the site is explicit only about the website layer: PostHog analytics are stated to be hosted in the EU, and the cookie policy says analytics data is stored in the EU. The data ethics policy adds a stated preference - when choosing subcontractors for hosting, email and analytics, the company looks for processing within the EU. No specific hosting country is named for the customer data held in the platform itself, and no data centre location is published. The named subprocessors are Resend for email, Cloudflare for hosting and PostHog for analytics; the security page additionally lists GitHub and Google Analytics among third-party services RiskFinder does not operate. Read strictly, the EU claim rests on the analytics stack and a supplier selection policy rather than on a commitment about platform data.
Things to keep in mind
Risks and trade-offs to weigh before adopting RiskFinder.
- AI drafts of action cards and exercise scenarios can read as finished work; a plausible but wrong first step followed at three in the morning is a real safety risk, and the vendor expects the customer to edit them
- A tidy dashboard can produce a sense of preparedness that outruns reality on the ground - a completed plan is not a trained organisation
- Reusing data across modules saves work but propagates a single early mistake into the assessment, the plan, the cards and the documentation
- Documenting for the regulator can quietly become the goal, displacing the human judgement the vendor says it wants to protect
- Neither terms and conditions nor a data processing agreement are published, so contractual and subprocessing terms cannot be checked before committing
- Preparedness plans and critical infrastructure data are highly sensitive, and no ISO 27001 or SOC 2 certification is displayed to back the security claims
- Depending on a one-person vendor for continuity tooling is itself a continuity risk worth writing into the risk register
Setup & Integrations
Technical difficulty
Technically undemanding: a web application with PDF output, nothing to install, no integration or API to configure. The effort is organisational rather than technical, since the method depends on operations specialists answering guided questions about equipment, tolerable downtime, dependencies and capacity - which the vendor presents as a way to avoid long workshops and empty templates. There is no self-service sign-up, so onboarding runs with RiskFinder: simple on Basis, guided on Plus, tailored on Premium. Expect the real cost to be internal time from the people who know the plant, not IT work.
Deployment
Supported languages
Behind RiskFinder
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does RiskFinder actually do?
How much does RiskFinder cost?
Is there a free plan or a free trial?
What is an AI-generated action card?
What is a ROS risk assessment?
Which regulations does RiskFinder cover?
Is my data used to train AI models?
Which languages and platforms are supported?
Should you pick RiskFinder?
RiskFinder is a narrow tool that knows exactly how narrow it is. It was built for Danish preparedness obligations - BEK 260, NIS2, CER, DORA - and it maps its modules to those requirements one by one, which is a great deal more useful to a district heating utility than a generic risk register would be. The strongest part of the product is the least glamorous: action cards designed to be printed, laminated and used at three in the morning with the systems down, carrying their version number and escalation path on the card itself. The AI is deliberately modest, drafting action cards and exercise scenarios from the organisation's own risk assessment, with the customer editing before anything is printed or played.
The reservations are commercial and documentary rather than functional. Nothing about the price is public, there is no free plan, no trial and no way to sign up alone, so evaluating the tool means starting a sales conversation. The interface exists in Danish only. No terms and conditions, no legal notice and no data processing agreement are published, and no security certification is displayed - an awkward gap for a platform that holds emergency plans for critical infrastructure, even with an explicit data ethics policy and a well-run vulnerability disclosure page in its favour. The vendor is young and very small: an ApS registered in 2024 with one employee on the Danish register, and the industrial logos on the site are the founder's past experience, which the site itself takes care to say.
For a Danish utility or industrial operator facing a regulator, that trade is a reasonable one. For anyone else, the language and the pricing opacity will settle the question first.
- Choosing a selection results in a full page refresh.
- Opens in a new window.