RiskApp
RiskApp is a Dutch security-compliance platform that uses AI to build controls from frameworks such as SOC 2, ISO 27001 and NIS2, then has an agent gather audit evidence continuously from your existing security tools.
What is RiskApp?
RiskApp is a security-compliance platform built around one claim: most tools show that a control exists, RiskApp sets out to show that it actually works. It is published by RiskApp B.V. in The Hague and RiskApp, Inc. in New York, and it speaks to CISOs and CTOs in start-ups, scale-ups and enterprises — the people, as the site puts it, for whom every other project stops the moment an audit begins.
The product runs in four steps. First, an automated control builder has the AI generate compliance controls straight from a chosen framework, with no manual mapping. Second, you connect the tools already in place; the homepage says this runs through RiskApp's own APIs. Third, you calibrate risk — define the organisation's risk appetite and tune the scoring so that compliance lines up with the business instead of fighting it. Fourth, and this is the differentiator RiskApp leads with, agentic audit evidencing: an AI agent reads your technical stack, pulls the relevant data, maps it to each framework automatically and keeps it current, so evidence is ready before an auditor asks for it.
Framework coverage on display is wide — SOC 2, ISO 27001, NIS2, NIST, PCI DSS, GDPR, HIPAA, plus a broader claim of any framework. The Platform page names fourteen connectors together with the control category each one feeds: GitLab, Microsoft Defender for Cloud, SolarWinds, Veracode, ServiceNow, Okta, Black Duck, Imperva, Snyk, RiskRecon, GitHub Secret Scanning, Invicti, SonarQube and SecurityScorecard, spanning SAST, DAST, SCA, secret scanning, CSPM, CMDB, MFA, DDoS and supply-chain risk. The homepage adds GitHub, AWS and Checkmarx.
The problems it names are the familiar ones: audits that swallow the calendar, fragmented data, point-in-time certification, static checklists, screenshots passed off as proof, and requirements too vague to map onto real security.
What you cannot do is try it. There is no sign-up, no trial and no published price — every route on the site leads to a demo, a quote and a white-glove roll-out alongside the founders.
What it does
- Generate compliance controls automatically from a framework, with no manual mapping
- Collect audit evidence continuously through an AI agent that reads your existing tools
- Centralise the requirements of several frameworks in a single place
- Measure whether a technical control actually works, not merely that it exists
- Connect an existing security stack through APIs
- Calibrate risk scoring against the organisation's own risk appetite
- Track the chain of custody behind every risk acceptance
When to use RiskApp / When not to
A quick filter to help you decide if RiskApp is the right fit.
When to use RiskApp
- Security and engineering teams preparing a first SOC 2, ISO 27001 or NIS2 certification and tired of assembling evidence by hand
- CISOs and CTOs whose every other project stops the moment an audit begins
- Organisations whose security stack is already well tooled — GitLab, GitHub, AWS, Microsoft Defender, Snyk, SonarQube, Veracode, Okta — but whose findings sit in silos
- Start-ups and scale-ups starting their first certification journey without dedicated compliance headcount
- Buyers comfortable with a sales-led cycle: a demo, a quote, then a white-glove roll-out alongside the founders
When not to use RiskApp
- Anyone who wants a published price and a self-service purchase: nothing is listed, everything runs through a quote
- Teams that want to try before speaking to a salesperson — there is no free plan, no free trial and no sign-up anywhere on the site
- Organisations with no technical stack to connect: the value rests entirely on integrations with existing security tools
- Compliance functions outside security — HR, financial or product-quality compliance are out of scope
- Buyers who need written commitments before a conversation: no terms of service, no DPA, no named subprocessor list and no trust page are published
How to use RiskApp
A typical end-to-end flow, from setup to results.
- Start from the contact form: every call to action on the site — BOOK A DEMO, Talk to a Founder, Get a quote — leads to the same page
- Set the goals: agree which frameworks you need a certification or report for, then work backwards to the security programme
- Sit through the platform walkthrough, where compliance automation and agentic audit evidencing are demonstrated
- Close the meeting with a Q&A and a customised roadmap of next steps
- Ask for a quote, since there is no published price list to work from
- Once onboarded, let the AI build your compliance controls from the frameworks you selected
- Connect your existing tools; the homepage states that this runs through RiskApp's APIs
- Define your risk appetite and calibrate the risk scoring to match it
- Let the agent gather evidence from the stack, map it to each framework and keep it current
- Reach the team by email at yo@riskapp.com, or by phone on +1 (708) 408-7098 or +31 6 18048869
Pros & Cons
Pros
- A sharp, defensible angle — proving that controls work rather than that they exist
- Evidence collection that is automated and continuous, presented as always current and organised
- Fourteen named and categorised connectors, which makes the integration promise checkable rather than generic
- Broad framework coverage on display, NIS2 included, which is still uncommon
- Risk scoring calibrated to the organisation's own appetite instead of an imposed score
- A white-glove approach with direct access to the founders
- An EU-established publisher, an explicit GDPR claim and a structured privacy policy with retention periods in figures
Cons
- No public pricing at all: no plan, no currency, no entry point — everything runs through a quote
- Neither a free plan nor a free trial is mentioned anywhere on the site
- No terms of service: the footer link points at a dead anchor and the expected page does not resolve
- No API documentation, although the homepage claims you connect your tools through RiskApp's APIs
- No customer-facing DPA, no named subprocessor list, no trust or security page and no stated hosting country
- A very thin site — six pages, no blog, no case studies, no documentation, and a single customer testimonial repeated three times
- Visible signs of a site left unattended: an inert submit button, dead legal links, a copyright frozen at 2025 and a November 2024 privacy policy still describing the earlier application-security product
Pricing & Plans
No pricing is published. RiskApp has no pricing page, and the site directs every visitor towards a quote instead: the homepage carries a Get a quote section, and the recurring calls to action are BOOK A DEMO and Talk to a Founder. No permanent free plan, no free trial, no credits and no entry-level tier are mentioned anywhere on the site. The commercial model is therefore sales-led, and neither a starting price nor a currency can be established without contacting the vendor directly.
Data, GDPR & hosting
A consolidated view of how RiskApp handles your data.
GDPR overview
GDPR compliance is claimed in plain words, twice over: RiskApp states that it processes and stores personal data in accordance with the EU General Data Protection Regulation and applicable local privacy laws. The policy lists the rights it recognises — access, rectification, erasure, restriction, portability and objection to processing based on legitimate interests — and gives one channel to exercise them, privacy@riskapp.com. No Article 27 representative is designated, which is consistent, since the main publisher RiskApp B.V. is established in the Netherlands under registration number 91638577, alongside a sister entity, RiskApp, Inc., in New York. No data protection officer is named. Standard contractual clauses, transfers outside the EU and hosting locations are never mentioned. The policy carries a date: last updated November 2024.
Who owns the data?
RiskApp splits its role in two, and says so explicitly. For data collected through its website, RiskApp is the controller. For data processed inside the RiskApp Platform, its customers are the controllers and RiskApp acts only as a processor on their behalf. The practical consequence is spelled out: an end user who wants to exercise rights over data held in the platform must approach the relevant customer — typically their own employer — rather than RiskApp, which offers privacy@riskapp.com only as a fallback channel. Ownership of the security data pushed into the platform therefore stays with the customer organisation, and so does the authority to decide what happens to it.
Reuse rights
No terms of service are published, so nothing defines what an end user may do with data taken back out of the platform. What the privacy policy does set out is RiskApp's own use. Personal data is collected to deliver products and services, give access to the platform, websites and apps, answer customer enquiries, send newsletters with consent, meet legal obligations, secure the offices through access control and camera monitoring, and run research and feedback collection with prior consent. The categories collected include contact details, identification details, camera footage, call recordings and correspondence kept for training and quality purposes, and platform usage data such as IP addresses, browser types, pages visited and session details. The legal bases invoked are contractual necessity, legitimate interests for marketing, product improvement and customer service, consent for promotional material, and legal obligations. Sharing is limited to what service delivery or the law requires — IT and hosting providers, marketing and analytics partners, and legal authorities — all of it covered, the policy says, by data processing agreements. One silence deserves attention: nowhere does RiskApp state whether customer data is used to train AI models, and no opt-out is offered.
Data retention & training
Hosting summary
RiskApp publishes nothing about where customer data is hosted. No country, no region and no cloud provider is named for the platform, and there is no trust or security page. The privacy policy mentions IT and hosting providers only as a category of third party, without naming a single one, and never refers to transfers outside the EU or to standard contractual clauses. The only anchor available is the publisher itself: RiskApp B.V. is established in The Hague under registration number 91638577, and the policy claims processing in accordance with the GDPR, which implies an EU footprint without documenting one. The marketing site is served from an Amazon anycast CDN node in the United States, but that describes the brochure rather than the platform and says nothing about where customer data would sit. Anyone carrying a data residency requirement should treat hosting location as an open question to settle in writing before signing.
Things to keep in mind
Risks and trade-offs to weigh before adopting RiskApp.
- No customer-facing DPA and no named subprocessor list — for a tool that ingests an organisation's security findings, that is the most notable gap of all
- No hosting country or region is stated anywhere, so the jurisdiction covering your security data cannot be established before a contract
- The site never addresses whether customer data is used to train AI models, in either direction, and documents no opt-out
- RiskApp publishes no certification of its own: SOC 2, ISO 27001 and NIS2 are the frameworks it helps customers cover, not attestations it holds — an easy confusion to make on a compliance vendor's homepage
- The privacy policy dates from November 2024 and still describes the earlier application-security product, so the legal commitments may cover a scope different from what is being sold today
- Several implementation details point to a site left unattended: an inert submit button, dead legal links, displayed email addresses whose links target a different domain, and a US phone number linking to a Dutch one
- Automated evidence can breed a false sense of assurance: an always-green dashboard still needs a human to ask whether the control being evidenced is the right control
Setup & Integrations
Technical difficulty
Moderate, and not self-service. There is no sign-up: access runs through a demo and a quote. Roll-out means connecting existing security tools through APIs, so you need administrative access and credentials on each one — GitLab, GitHub, AWS, Microsoft Defender, Snyk, SonarQube and the rest. RiskApp claims the mapping itself is automatic, with the AI generating controls straight from the frameworks, and offers a white-glove roll-out. One calibration step stays on your side: defining risk appetite and tuning the scoring. No public technical documentation exists, so the real effort cannot be assessed in advance.
Deployment
Integrations
Behind RiskApp
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does RiskApp actually do?
What is agentic audit evidencing?
Which compliance frameworks are covered?
Which tools does RiskApp connect to?
How much does RiskApp cost?
Is RiskApp GDPR compliant?
Does RiskApp train AI models on customer data?
Where is customer data hosted?
Who is behind RiskApp?
Is there a documented API?
Should you pick RiskApp?
RiskApp arrives with a genuinely sharp proposition on a crowded market: not another checklist that confirms a control has been declared, but a platform that sets out to prove the control works, every day, from evidence pulled straight out of your own stack. The four-step path — build controls from the framework, connect the tools, calibrate risk, then let an agent evidence it all — is coherent, and the fourteen named and categorised connectors make the integration promise checkable rather than decorative. Coverage extends to NIS2, which few competitors advertise, and the publisher is EU-established with a structured privacy policy that puts figures on retention.
The other side of the ledger is substantial and mostly about silence. No price, no plan, no terms of service, no API documentation, no customer-facing DPA, no named subprocessors and no stated hosting country — for a vendor selling compliance rigour, those are conspicuous absences. The site itself is six pages deep, with one testimonial repeated three times, a privacy policy from November 2024 that still describes the earlier application-security product, a copyright frozen at 2025 and a contact form whose submit button leads nowhere.
That last point matters more than a cosmetic complaint. No product access of any kind is reachable — no sign-up, no login, no application subdomain — and the record therefore carries unknown rather than active as its lifecycle status, because an off-site source states the company stopped operating in November 2025. The idea is good and the framing is right. Before spending time on a demo, ask the publisher one question first: is the service still being operated?
- Choosing a selection results in a full page refresh.
- Opens in a new window.