TM Risk logo
Report Generation · Workflow Automation

TM Risk

Bulgarian-language platform for workplace risk assessment. It pairs 5x5 matrix and Fine-Kinney scoring with AI-drafted hazards and controls that a human assessor reviews, then issues versioned, publicly verifiable documents and tracks every corrective measure to its deadline.

Active GDPR compliant Subscription No public API Verified by Guidaio
Overview

What is TM Risk?

TM Risk is a Bulgarian occupational health and safety platform that turns workplace risk assessment into a structured, auditable workflow. Its terms of service call the product TM Risk Assessment, and it is aimed squarely at HSE teams and safety consultants working in Bulgarian.

The product supports the two scoring approaches most widely used across Europe. The classic 5x5 matrix multiplies severity by probability and suits most workplaces. Fine-Kinney computes R = P x E x C from probability, exposure and consequence scales, and the vendor recommends it for industry, construction and energy, where finer differentiation of risk is needed; a worked example on the homepage reaches 6 x 10 x 15 = 900, class V, unacceptable risk. Either method can be used on its own, or both across different assessments.

Artificial intelligence intervenes only as a drafting aid, and the vendor is insistent on the point. Once the assessor has described the site, the job position, the activities, the equipment and the chemical agents, and answered role questionnaires, the system proposes hazards, control measures and scores. Nothing is recorded without approval: the assessor selects, edits or rejects each suggestion. AI output is presented as a draft, never as legal advice, a safety certification or a guarantee of compliance.

Around that core sits the record-keeping the discipline actually demands. Work is organised as company, branch and job position, with templates for recurring roles and copying between sites. Each risk carries measures with a named owner, a deadline, a status, attached evidence and reminders as deadlines approach. Access follows roles - administrator, HSE manager, assessor, auditor - scoped by company and branch, over a full audit trail. Documents are issued as dated, signed versions, exported to PDF against a monthly quota, and each may carry a QR code or link to a public verification page that exposes limited metadata only, never the risk register, the measures or the evidence.

Consultants can assess external client companies through a dedicated structure and permission set. Free public resources - Fine-Kinney and matrix calculators, a readiness checklist and a CSV template - are available without an account.

What it does

  • Score workplace risks with either the 5x5 matrix or the Fine-Kinney method
  • Generate AI suggestions for hazards, control measures and scores from job context
  • Review, edit or reject every AI suggestion before it enters the assessment
  • Produce dated, signed, versioned assessment documents and export them to PDF
  • Assign corrective measures with an owner, deadline, status and supporting evidence
  • Monitor validity, high-risk positions and overdue measures from a single dashboard
  • Publish a QR code or link letting third parties verify a document's validity
Audience

When to use TM Risk / When not to

A quick filter to help you decide if TM Risk is the right fit.

When to use TM Risk

  • In-house HSE teams running assessments across several companies, branches and job positions
  • Safety consultants and occupational medicine providers assessing third-party client companies
  • Employers in industry, construction and energy who need Fine-Kinney's finer risk differentiation
  • Bulgarian organisations that must produce risk documentation defensible before the labour inspectorate
  • Managers who need corrective measures traced to a named owner, a deadline and documented evidence

When not to use TM Risk

  • Teams working in any language other than Bulgarian, the only interface language offered
  • Buyers who need a published price before trialling, since no rate is disclosed anywhere
  • Organisations expecting an API or developer integration, as none exists
  • Anyone seeking a substitute for employer duties, site inspections or competent professional judgement
  • Workflows handling sensitive medical or biometric data, which the platform is explicitly not designed for
Get started

How to use TM Risk

A typical end-to-end flow, from setup to results.

  1. Register at the sign-up page; no payment card is required to start
  2. Create an assessment by choosing the company, branch, workplace and validity period
  3. Select the scoring method, either the 5x5 matrix or Fine-Kinney, and name the responsible person
  4. Describe the activity: tasks, equipment, chemical agents and any site-specific context
  5. Answer the job-position questionnaires so the AI receives a richer, more specific context
  6. Review the AI's proposed hazards, control measures and scores one by one
  7. Accept, edit or reject each suggestion; nothing is stored until you approve it
  8. Assign each measure an owner, a deadline and a status, then attach the supporting evidence
  9. Generate a document version, which draws on the plan's monthly quota, and download the PDF
  10. Share the verification link or QR code, and track validity and overdue measures from the dashboard
Quick read

Pros & Cons

Pros

  • Two recognised assessment methods, matrix and Fine-Kinney, available in the same product
  • Human control over AI output is explicit, documented and enforced in the workflow
  • Complete chain from assessment to measures, evidence, versioned document and public verification
  • EU hosting announced in Frankfurt and Dublin, with a subprocessor list published in full
  • Unusually thorough legal documentation, including a dedicated AI notice and safety disclaimer
  • Free calculators, checklist and CSV template usable without an account
  • Native Bulgarian interface and content, uncommon in this segment

Cons

  • No price is published anywhere, and the pricing page the billing terms point to does not exist
  • The Starter, Professional and Business plans are named but carry no amounts or stated quotas
  • The four published contact channels sit on a domain that has never been registered
  • Bulgarian is the only interface language offered
  • No API, no developer documentation and no third-party integrations
  • Every legal document describes itself as a working draft awaiting review by a lawyer
  • No security certification is claimed and no position is published on model training
Pricing

Pricing & Plans

No price is publicly available. The subscription terms refer the reader to a pricing page, but that page does not exist: every candidate address returns the site's standard 404, and the 51-URL sitemap contains no such page. Three plans are named - Starter, Professional and Business - and paid plans are said to carry monthly document-generation quotas and AI features, with Business open to an individual agreement. Payment is handled by Stripe on a monthly or annual basis, prices are stated exclusive of VAT, and subscriptions renew automatically unless cancelled beforehand. The homepage advertises starting without a payment card, but neither a permanent free plan nor a dated free trial is ever named. No entry price, currency or billing unit can therefore be stated.

Plan 1
Starter
  • named in the subscription terms
  • no price or quota published
Plan 3
Business
  • named in the subscription terms
  • may be covered by an individual agreement
  • no price published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how TM Risk handles your data.

GDPR overview

The site claims GDPR compliance in a single homepage line and backs it with unusually detailed documentation dated 1 June 2026. The privacy policy names the data categories processed, and states legal bases explicitly: contract, legitimate interest for security and audit logs, legal obligation, consent for marketing and non-essential cookies, and customer instructions under a data processing agreement. It sets out rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority, with privacy@tmrisk.bg as the dedicated channel. A full subprocessor list is published, transfers outside the EEA are acknowledged under appropriate safeguards, and the platform states it is not intended for sensitive data or for children. A DPO or privacy lead is referred to generically, without a name or separate contact details, and no external audit or certificate is produced.

Who owns the data?

Customers keep ownership of their content. TM Risk takes only the rights it needs to host, process, display, generate, back up and support that content, and each party must protect non-public information obtained through the service. Roles are split: for the customer workspace the customer is the data controller and TM Risk acts as processor under a data processing agreement, whereas for account administration, billing, security, analytics and sales TM Risk may act as controller in its own right. Content can reach authorised users of the same customer, assigned measure owners, reviewers and the published subprocessors. Where a generated document carries a verification link, anyone holding it sees limited metadata.

Reuse rights

Nothing in the published terms grants the end user a right to reuse other parties' data. Customers may freely use and export their own content: assessments are generated as dated, signed document versions and downloaded as PDF, and re-downloading a version already generated does not consume additional quota. It is the customer, not the vendor, who decides whether to circulate a document, a QR code or a verification link, and that decision is framed as a responsibility rather than a permission. Reuse in the opposite direction is constrained: platform acceptance of a measure is a workflow status only, never legal confirmation that occupational safety obligations have been met, and AI output must be reviewed by a competent person before it enters any assessment or document.

Data retention & training

Retention summary
The vendor states no fixed period. Data is kept for as long as it is needed for the relevant purpose, the contract, a legal obligation, security or a dispute, which means retention is governed by purpose rather than by a published number of months or years. Accounting and tax records fall under a legal-obligation basis, while audit logs are retained on the grounds of legitimate interest in security, reliability and diagnostics. Users may request erasure or restriction, along with access, rectification, portability and objection, through the privacy channel given in the policy. No anonymisation practice and no post-termination deletion deadline are described. The policy in force is dated 1 June 2026.
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

The vendor states an EU hosting region, naming Frankfurt and Dublin. Five subprocessors are published with their purpose, data categories and transfer basis: Supabase for the database, authentication and file storage; Vercel for hosting, CDN and analytics; Stripe for payments and subscriptions; Resend for service email delivery; and OpenAI, reached through an AI Gateway, for generating suggestions. Supabase is listed as EU with standard contractual clauses where needed, while Vercel, Stripe, Resend and the AI provider are listed as EU/US under standard contractual clauses, so transfers outside the EEA are acknowledged rather than denied. The published DPAs of Supabase, Vercel and Stripe are linked directly. Customers are notified when a subprocessor is added or replaced, through an update to that page and by email where relevant to their plan. Card details are never stored by the vendor, being handled by Stripe. The country names Germany and Ireland are inferred from the two cities the vendor names, as the page itself states cities rather than countries.

Hosting countries
🇩🇩 Germany🇮🇪 Ireland
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting TM Risk.

  • AI-drafted hazard lists invite rubber-stamping: the vendor's own terms warn that suggestions may be wrong, incomplete or unsuited to a specific workplace, yet accepting them wholesale is the fastest path through the tool
  • A generated document can create false assurance; platform acceptance of a measure is only a workflow status, never confirmation that legal safety obligations have been discharged
  • The four published contact addresses are on tmrisk.bg, a domain that has never been registered, so messages sent for privacy, security, billing or legal matters cannot be delivered
  • Relying on the software may erode first-hand practice, since it cannot replace site inspections, worker consultation or competent professional judgement
  • Risk prompts carry workplace and job detail to an external AI provider, and the vendor asks users not to enter worker names, medical data or identifiers that could easily be typed in by habit
  • Public verification links are shareable by anyone holding them, so circulating a QR code exposes limited company metadata beyond the intended recipient
  • No price is published and every legal document is self-declared a working draft, so commercial and contractual terms may change under a customer already committed to the platform
Setup

Setup & Integrations

Technical difficulty

Low. There is nothing to install: the product is a web application reached after registration, and no payment card is needed to start. The vendor claims a first activity can be entered in under ten minutes. The real effort is organisational rather than technical - defining the company, branch and job-position hierarchy, assigning roles and memberships, and choosing a scoring method before the first assessment. No API, connector or third-party integration has to be configured, and subscriptions are managed through the Stripe billing portal.

Deployment

Web app

Supported languages

Bulgarian
Company

Behind TM Risk

Company name
Ви Ел Криейт ЕООД
Founded
20/01/2017
Country of origin
🇧🇬 Bulgaria
Headquarters
бул. Братя Бъкстон 40, ет. 3, Офис 17, гр. София, България
UBO
Dimitar Nikolinov Lazarov
UBO country
🇧🇬 Bulgaria
Domain registrar country
🇧🇬 Bulgaria
Legal contact
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Does the platform support more than one assessment method?
Yes. Both the 5x5 matrix method and Fine-Kinney are built into the product, and a company can work with either one or with both across different assessments.
Does the AI make the final decision?
No. The AI only proposes hazards and control measures. The team reviews, edits and decides what goes into the assessment, and nothing is recorded without the assessor's approval.
How are the two scoring methods calculated?
The matrix method multiplies severity by probability on a 5x5 grid. Fine-Kinney computes R = P x E x C from probability, exposure and consequence scales, and returns a risk class.
How do the document limits work?
Each plan carries a monthly quota of generated documents. Downloading a version that has already been generated does not consume any additional quota.
Can external companies be assessed?
Yes. The platform supports target companies with a dedicated structure and permissions for the users who work on those assessments, which is how consultants serve their own clients.
How is team access controlled?
Access is tied to memberships and roles - administrator, HSE manager, assessor and auditor - so users only see the companies and functions they are entitled to, and all actions are recorded in an audit trail.
What does the public verification link reveal?
Only limited metadata: validity status, company or target company, branch and department, period, assessment date, validity end, version and activity. It never shows the risk register, the measures, the evidence, the user list or comments.
What does TM Risk cost?
No amount is published. Three plans are named - Starter, Professional and Business - billed through Stripe monthly or annually, with prices stated exclusive of VAT. The pricing page referenced by the billing terms is not online.
Which languages does the interface support?
Bulgarian only. The site, the product interface and all legal documentation are published in Bulgarian, and no other language is announced.
Where is the data hosted and who processes it?
The stated hosting region is the EU, in Frankfurt and Dublin. The published subprocessors are Supabase, Vercel, Stripe, Resend and OpenAI through an AI Gateway, some of which involve transfers outside the EEA under standard contractual clauses.
Conclusion

Should you pick TM Risk?

TM Risk is a narrow, deliberately unglamorous tool, and that is its strength. It does one job - occupational risk assessment - with the two methods practitioners actually use, and it wraps them in the record-keeping that makes an assessment defensible: versioned documents, measures tied to a named owner and a deadline, an audit trail, and a verification link a third party can check. The insistence that AI only ever drafts, and that a competent person decides, is stated in the terms, the privacy policy and a dedicated AI notice rather than merely implied. Transparency about subprocessors and EU hosting is well above what this segment usually offers.

The reservations are about maturity, not design. The product is visibly new: the Internet Archive holds no capture of the domain at all, the legal documents are dated June 2026 and each one describes itself as a working draft to be reviewed by a lawyer. Commercially it is opaque - the subscription terms send readers to a pricing page that has never been published, so three named plans carry no figures whatsoever. More awkwardly, all four advertised contact channels sit on a domain that was never registered, so mail to them cannot arrive; only the two personal addresses on the main domain are reachable.

The publisher is an established Bulgarian software company rather than a newcomer, which tempers the youth of the product itself. For a Bulgarian HSE team or consultancy, TM Risk looks like a credible way to replace scattered spreadsheets with a traceable process. Anyone outside that language market, or anyone needing a price before committing, will have to wait or ask.