RiskApp logo
Privacy Security · Security Code Scanning

RiskApp

RiskApp is a Dutch security-compliance platform that uses AI to build controls from frameworks such as SOC 2, ISO 27001 and NIS2, then has an agent gather audit evidence continuously from your existing security tools.

GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is RiskApp?

RiskApp is a security-compliance platform built around one claim: most tools show that a control exists, RiskApp sets out to show that it actually works. It is published by RiskApp B.V. in The Hague and RiskApp, Inc. in New York, and it speaks to CISOs and CTOs in start-ups, scale-ups and enterprises — the people, as the site puts it, for whom every other project stops the moment an audit begins.

The product runs in four steps. First, an automated control builder has the AI generate compliance controls straight from a chosen framework, with no manual mapping. Second, you connect the tools already in place; the homepage says this runs through RiskApp's own APIs. Third, you calibrate risk — define the organisation's risk appetite and tune the scoring so that compliance lines up with the business instead of fighting it. Fourth, and this is the differentiator RiskApp leads with, agentic audit evidencing: an AI agent reads your technical stack, pulls the relevant data, maps it to each framework automatically and keeps it current, so evidence is ready before an auditor asks for it.

Framework coverage on display is wide — SOC 2, ISO 27001, NIS2, NIST, PCI DSS, GDPR, HIPAA, plus a broader claim of any framework. The Platform page names fourteen connectors together with the control category each one feeds: GitLab, Microsoft Defender for Cloud, SolarWinds, Veracode, ServiceNow, Okta, Black Duck, Imperva, Snyk, RiskRecon, GitHub Secret Scanning, Invicti, SonarQube and SecurityScorecard, spanning SAST, DAST, SCA, secret scanning, CSPM, CMDB, MFA, DDoS and supply-chain risk. The homepage adds GitHub, AWS and Checkmarx.

The problems it names are the familiar ones: audits that swallow the calendar, fragmented data, point-in-time certification, static checklists, screenshots passed off as proof, and requirements too vague to map onto real security.

What you cannot do is try it. There is no sign-up, no trial and no published price — every route on the site leads to a demo, a quote and a white-glove roll-out alongside the founders.

What it does

  • Generate compliance controls automatically from a framework, with no manual mapping
  • Collect audit evidence continuously through an AI agent that reads your existing tools
  • Centralise the requirements of several frameworks in a single place
  • Measure whether a technical control actually works, not merely that it exists
  • Connect an existing security stack through APIs
  • Calibrate risk scoring against the organisation's own risk appetite
  • Track the chain of custody behind every risk acceptance
Audience

When to use RiskApp / When not to

A quick filter to help you decide if RiskApp is the right fit.

When to use RiskApp

  • Security and engineering teams preparing a first SOC 2, ISO 27001 or NIS2 certification and tired of assembling evidence by hand
  • CISOs and CTOs whose every other project stops the moment an audit begins
  • Organisations whose security stack is already well tooled — GitLab, GitHub, AWS, Microsoft Defender, Snyk, SonarQube, Veracode, Okta — but whose findings sit in silos
  • Start-ups and scale-ups starting their first certification journey without dedicated compliance headcount
  • Buyers comfortable with a sales-led cycle: a demo, a quote, then a white-glove roll-out alongside the founders

When not to use RiskApp

  • Anyone who wants a published price and a self-service purchase: nothing is listed, everything runs through a quote
  • Teams that want to try before speaking to a salesperson — there is no free plan, no free trial and no sign-up anywhere on the site
  • Organisations with no technical stack to connect: the value rests entirely on integrations with existing security tools
  • Compliance functions outside security — HR, financial or product-quality compliance are out of scope
  • Buyers who need written commitments before a conversation: no terms of service, no DPA, no named subprocessor list and no trust page are published
Get started

How to use RiskApp

A typical end-to-end flow, from setup to results.

  1. Start from the contact form: every call to action on the site — BOOK A DEMO, Talk to a Founder, Get a quote — leads to the same page
  2. Set the goals: agree which frameworks you need a certification or report for, then work backwards to the security programme
  3. Sit through the platform walkthrough, where compliance automation and agentic audit evidencing are demonstrated
  4. Close the meeting with a Q&A and a customised roadmap of next steps
  5. Ask for a quote, since there is no published price list to work from
  6. Once onboarded, let the AI build your compliance controls from the frameworks you selected
  7. Connect your existing tools; the homepage states that this runs through RiskApp's APIs
  8. Define your risk appetite and calibrate the risk scoring to match it
  9. Let the agent gather evidence from the stack, map it to each framework and keep it current
  10. Reach the team by email at yo@riskapp.com, or by phone on +1 (708) 408-7098 or +31 6 18048869
Quick read

Pros & Cons

Pros

  • A sharp, defensible angle — proving that controls work rather than that they exist
  • Evidence collection that is automated and continuous, presented as always current and organised
  • Fourteen named and categorised connectors, which makes the integration promise checkable rather than generic
  • Broad framework coverage on display, NIS2 included, which is still uncommon
  • Risk scoring calibrated to the organisation's own appetite instead of an imposed score
  • A white-glove approach with direct access to the founders
  • An EU-established publisher, an explicit GDPR claim and a structured privacy policy with retention periods in figures

Cons

  • No public pricing at all: no plan, no currency, no entry point — everything runs through a quote
  • Neither a free plan nor a free trial is mentioned anywhere on the site
  • No terms of service: the footer link points at a dead anchor and the expected page does not resolve
  • No API documentation, although the homepage claims you connect your tools through RiskApp's APIs
  • No customer-facing DPA, no named subprocessor list, no trust or security page and no stated hosting country
  • A very thin site — six pages, no blog, no case studies, no documentation, and a single customer testimonial repeated three times
  • Visible signs of a site left unattended: an inert submit button, dead legal links, a copyright frozen at 2025 and a November 2024 privacy policy still describing the earlier application-security product
Pricing

Pricing & Plans

No pricing is published. RiskApp has no pricing page, and the site directs every visitor towards a quote instead: the homepage carries a Get a quote section, and the recurring calls to action are BOOK A DEMO and Talk to a Founder. No permanent free plan, no free trial, no credits and no entry-level tier are mentioned anywhere on the site. The commercial model is therefore sales-led, and neither a starting price nor a currency can be established without contacting the vendor directly.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how RiskApp handles your data.

GDPR overview

GDPR compliance is claimed in plain words, twice over: RiskApp states that it processes and stores personal data in accordance with the EU General Data Protection Regulation and applicable local privacy laws. The policy lists the rights it recognises — access, rectification, erasure, restriction, portability and objection to processing based on legitimate interests — and gives one channel to exercise them, privacy@riskapp.com. No Article 27 representative is designated, which is consistent, since the main publisher RiskApp B.V. is established in the Netherlands under registration number 91638577, alongside a sister entity, RiskApp, Inc., in New York. No data protection officer is named. Standard contractual clauses, transfers outside the EU and hosting locations are never mentioned. The policy carries a date: last updated November 2024.

Who owns the data?

RiskApp splits its role in two, and says so explicitly. For data collected through its website, RiskApp is the controller. For data processed inside the RiskApp Platform, its customers are the controllers and RiskApp acts only as a processor on their behalf. The practical consequence is spelled out: an end user who wants to exercise rights over data held in the platform must approach the relevant customer — typically their own employer — rather than RiskApp, which offers privacy@riskapp.com only as a fallback channel. Ownership of the security data pushed into the platform therefore stays with the customer organisation, and so does the authority to decide what happens to it.

Reuse rights

No terms of service are published, so nothing defines what an end user may do with data taken back out of the platform. What the privacy policy does set out is RiskApp's own use. Personal data is collected to deliver products and services, give access to the platform, websites and apps, answer customer enquiries, send newsletters with consent, meet legal obligations, secure the offices through access control and camera monitoring, and run research and feedback collection with prior consent. The categories collected include contact details, identification details, camera footage, call recordings and correspondence kept for training and quality purposes, and platform usage data such as IP addresses, browser types, pages visited and session details. The legal bases invoked are contractual necessity, legitimate interests for marketing, product improvement and customer service, consent for promotional material, and legal obligations. Sharing is limited to what service delivery or the law requires — IT and hosting providers, marketing and analytics partners, and legal authorities — all of it covered, the policy says, by data processing agreements. One silence deserves attention: nowhere does RiskApp state whether customer data is used to train AI models, and no opt-out is offered.

Data retention & training

Retention summary
RiskApp keeps personal data only as long as the purpose it was collected for requires. Two figures are given as examples: marketing data is held for up to two years after your last interaction, and invoices for at least seven years to satisfy tax law. Nothing is stated about data processed inside the platform itself, where RiskApp acts as a processor — those periods are set by the customer organisation that controls the data. Beyond the right to erasure, exercised at privacy@riskapp.com, no deletion or anonymisation procedure is described. The policy is dated November 2024.
GDPR contact

Hosting summary

RiskApp publishes nothing about where customer data is hosted. No country, no region and no cloud provider is named for the platform, and there is no trust or security page. The privacy policy mentions IT and hosting providers only as a category of third party, without naming a single one, and never refers to transfers outside the EU or to standard contractual clauses. The only anchor available is the publisher itself: RiskApp B.V. is established in The Hague under registration number 91638577, and the policy claims processing in accordance with the GDPR, which implies an EU footprint without documenting one. The marketing site is served from an Amazon anycast CDN node in the United States, but that describes the brochure rather than the platform and says nothing about where customer data would sit. Anyone carrying a data residency requirement should treat hosting location as an open question to settle in writing before signing.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting RiskApp.

  • No customer-facing DPA and no named subprocessor list — for a tool that ingests an organisation's security findings, that is the most notable gap of all
  • No hosting country or region is stated anywhere, so the jurisdiction covering your security data cannot be established before a contract
  • The site never addresses whether customer data is used to train AI models, in either direction, and documents no opt-out
  • RiskApp publishes no certification of its own: SOC 2, ISO 27001 and NIS2 are the frameworks it helps customers cover, not attestations it holds — an easy confusion to make on a compliance vendor's homepage
  • The privacy policy dates from November 2024 and still describes the earlier application-security product, so the legal commitments may cover a scope different from what is being sold today
  • Several implementation details point to a site left unattended: an inert submit button, dead legal links, displayed email addresses whose links target a different domain, and a US phone number linking to a Dutch one
  • Automated evidence can breed a false sense of assurance: an always-green dashboard still needs a human to ask whether the control being evidenced is the right control
Setup

Setup & Integrations

Technical difficulty

Moderate, and not self-service. There is no sign-up: access runs through a demo and a quote. Roll-out means connecting existing security tools through APIs, so you need administrative access and credentials on each one — GitLab, GitHub, AWS, Microsoft Defender, Snyk, SonarQube and the rest. RiskApp claims the mapping itself is automatic, with the AI generating controls straight from the frameworks, and offers a white-glove roll-out. One calibration step stays on your side: defining risk appetite and tuning the scoring. No public technical documentation exists, so the real effort cannot be assessed in advance.

Deployment

Web app

Integrations

GitLab GitHub Microsoft Defender for Cloud AWS SolarWinds Veracode ServiceNow Okta Black Duck Imperva Snyk RiskRecon Invicti SonarQube SecurityScorecard Checkmarx
Company

Behind RiskApp

Company name
RiskApp B.V.
Founded
10/10/2023
Country of origin
🇳🇱 Netherlands
Headquarters
Wilhelmina van Pruisenweg 104, 2595 AN The Hague, The Netherlands
US office
169 Madison Ave STE 11902 New York, NY 10016
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

No funding round, amount or institutional investor has been published by RiskApp B.V., and none is announced on the site
The About page lists six people under Investors & Advisory — Dimitri van Zantvliet (CISO, NS Dutch Railways), Mahdi Abdulrazak (CISO, SHV Energy), Seemant Seghal (founder and CEO, Breachlock), Rogier Fischer (co-founder and CEO, Hadrian), Dov Koplovsky (owner and CEO, NEWCOM Global) and Jesse Calderon (CFA, head of M&A at Flexera) — with no amount, no date and no distinction drawn between investor and adviser

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does RiskApp actually do?
It automates security compliance. RiskApp builds controls from your frameworks, connects to the tools you already run, and has an AI agent gather the evidence proving that those technical controls meet regulatory requirements such as SOC 2, ISO 27001 and HIPAA.
What is agentic audit evidencing?
It is RiskApp's term for evidence that stays current on its own. An AI agent connects to your tools, pulls the relevant data, maps it to your compliance frameworks automatically and keeps everything updated, so you are audit-ready instead of scrambling when an audit starts.
Which compliance frameworks are covered?
SOC 2, ISO 27001, NIS2, NIST, PCI DSS, GDPR and HIPAA are shown on the homepage, alongside a broader claim of support for any framework.
Which tools does RiskApp connect to?
The Platform page names fourteen connectors: GitLab, Microsoft Defender for Cloud, SolarWinds, Veracode, ServiceNow, Okta, Black Duck, Imperva, Snyk, RiskRecon, GitHub Secret Scanning, Invicti, SonarQube and SecurityScorecard. The homepage adds GitHub, AWS and Checkmarx. Be aware that the same list is repeated immediately below under a Coming soon label, so availability connector by connector is not established.
How much does RiskApp cost?
Nothing is published. There is no pricing page; the homepage offers a Get a quote section and the site's calls to action are BOOK A DEMO and Talk to a Founder. Neither a free plan nor a free trial is mentioned.
Is RiskApp GDPR compliant?
Compliance is claimed explicitly in the privacy policy, which lists the rights it recognises and gives privacy@riskapp.com as the channel to exercise them. The main publisher is established in the Netherlands. No external audit, certification or data protection officer is put forward to back the claim.
Does RiskApp train AI models on customer data?
The site never says, in either direction, and no opt-out is documented. Treat it as an open question to raise before signing anything.
Where is customer data hosted?
No country, region or cloud provider is named anywhere on the site, and there is no trust or security page. Hosting location is a question to settle in writing with the vendor.
Who is behind RiskApp?
Two entities appear in the footer of every page: RiskApp B.V. in The Hague, registered under number 91638577, and RiskApp, Inc. in New York. The About page names co-founders Matthew Fox and Rafael Carvalho and non-executive chairman Brian Gumbel, and states that the company was established in 2023.
Is there a documented API?
The homepage states that you connect your tools through RiskApp's APIs, but no documentation page exists on the site or on any subdomain, so the interface cannot be assessed from the outside.
Conclusion

Should you pick RiskApp?

RiskApp arrives with a genuinely sharp proposition on a crowded market: not another checklist that confirms a control has been declared, but a platform that sets out to prove the control works, every day, from evidence pulled straight out of your own stack. The four-step path — build controls from the framework, connect the tools, calibrate risk, then let an agent evidence it all — is coherent, and the fourteen named and categorised connectors make the integration promise checkable rather than decorative. Coverage extends to NIS2, which few competitors advertise, and the publisher is EU-established with a structured privacy policy that puts figures on retention.

The other side of the ledger is substantial and mostly about silence. No price, no plan, no terms of service, no API documentation, no customer-facing DPA, no named subprocessors and no stated hosting country — for a vendor selling compliance rigour, those are conspicuous absences. The site itself is six pages deep, with one testimonial repeated three times, a privacy policy from November 2024 that still describes the earlier application-security product, a copyright frozen at 2025 and a contact form whose submit button leads nowhere.

That last point matters more than a cosmetic complaint. No product access of any kind is reachable — no sign-up, no login, no application subdomain — and the record therefore carries unknown rather than active as its lifecycle status, because an off-site source states the company stopped operating in November 2025. The idea is good and the framing is right. Before spending time on a demo, ask the publisher one question first: is the service still being operated?