TM Risk
Bulgarian-language platform for workplace risk assessment. It pairs 5x5 matrix and Fine-Kinney scoring with AI-drafted hazards and controls that a human assessor reviews, then issues versioned, publicly verifiable documents and tracks every corrective measure to its deadline.
What is TM Risk?
TM Risk is a Bulgarian occupational health and safety platform that turns workplace risk assessment into a structured, auditable workflow. Its terms of service call the product TM Risk Assessment, and it is aimed squarely at HSE teams and safety consultants working in Bulgarian.
The product supports the two scoring approaches most widely used across Europe. The classic 5x5 matrix multiplies severity by probability and suits most workplaces. Fine-Kinney computes R = P x E x C from probability, exposure and consequence scales, and the vendor recommends it for industry, construction and energy, where finer differentiation of risk is needed; a worked example on the homepage reaches 6 x 10 x 15 = 900, class V, unacceptable risk. Either method can be used on its own, or both across different assessments.
Artificial intelligence intervenes only as a drafting aid, and the vendor is insistent on the point. Once the assessor has described the site, the job position, the activities, the equipment and the chemical agents, and answered role questionnaires, the system proposes hazards, control measures and scores. Nothing is recorded without approval: the assessor selects, edits or rejects each suggestion. AI output is presented as a draft, never as legal advice, a safety certification or a guarantee of compliance.
Around that core sits the record-keeping the discipline actually demands. Work is organised as company, branch and job position, with templates for recurring roles and copying between sites. Each risk carries measures with a named owner, a deadline, a status, attached evidence and reminders as deadlines approach. Access follows roles - administrator, HSE manager, assessor, auditor - scoped by company and branch, over a full audit trail. Documents are issued as dated, signed versions, exported to PDF against a monthly quota, and each may carry a QR code or link to a public verification page that exposes limited metadata only, never the risk register, the measures or the evidence.
Consultants can assess external client companies through a dedicated structure and permission set. Free public resources - Fine-Kinney and matrix calculators, a readiness checklist and a CSV template - are available without an account.
What it does
- Score workplace risks with either the 5x5 matrix or the Fine-Kinney method
- Generate AI suggestions for hazards, control measures and scores from job context
- Review, edit or reject every AI suggestion before it enters the assessment
- Produce dated, signed, versioned assessment documents and export them to PDF
- Assign corrective measures with an owner, deadline, status and supporting evidence
- Monitor validity, high-risk positions and overdue measures from a single dashboard
- Publish a QR code or link letting third parties verify a document's validity
When to use TM Risk / When not to
A quick filter to help you decide if TM Risk is the right fit.
When to use TM Risk
- In-house HSE teams running assessments across several companies, branches and job positions
- Safety consultants and occupational medicine providers assessing third-party client companies
- Employers in industry, construction and energy who need Fine-Kinney's finer risk differentiation
- Bulgarian organisations that must produce risk documentation defensible before the labour inspectorate
- Managers who need corrective measures traced to a named owner, a deadline and documented evidence
When not to use TM Risk
- Teams working in any language other than Bulgarian, the only interface language offered
- Buyers who need a published price before trialling, since no rate is disclosed anywhere
- Organisations expecting an API or developer integration, as none exists
- Anyone seeking a substitute for employer duties, site inspections or competent professional judgement
- Workflows handling sensitive medical or biometric data, which the platform is explicitly not designed for
How to use TM Risk
A typical end-to-end flow, from setup to results.
- Register at the sign-up page; no payment card is required to start
- Create an assessment by choosing the company, branch, workplace and validity period
- Select the scoring method, either the 5x5 matrix or Fine-Kinney, and name the responsible person
- Describe the activity: tasks, equipment, chemical agents and any site-specific context
- Answer the job-position questionnaires so the AI receives a richer, more specific context
- Review the AI's proposed hazards, control measures and scores one by one
- Accept, edit or reject each suggestion; nothing is stored until you approve it
- Assign each measure an owner, a deadline and a status, then attach the supporting evidence
- Generate a document version, which draws on the plan's monthly quota, and download the PDF
- Share the verification link or QR code, and track validity and overdue measures from the dashboard
Pros & Cons
Pros
- Two recognised assessment methods, matrix and Fine-Kinney, available in the same product
- Human control over AI output is explicit, documented and enforced in the workflow
- Complete chain from assessment to measures, evidence, versioned document and public verification
- EU hosting announced in Frankfurt and Dublin, with a subprocessor list published in full
- Unusually thorough legal documentation, including a dedicated AI notice and safety disclaimer
- Free calculators, checklist and CSV template usable without an account
- Native Bulgarian interface and content, uncommon in this segment
Cons
- No price is published anywhere, and the pricing page the billing terms point to does not exist
- The Starter, Professional and Business plans are named but carry no amounts or stated quotas
- The four published contact channels sit on a domain that has never been registered
- Bulgarian is the only interface language offered
- No API, no developer documentation and no third-party integrations
- Every legal document describes itself as a working draft awaiting review by a lawyer
- No security certification is claimed and no position is published on model training
Pricing & Plans
No price is publicly available. The subscription terms refer the reader to a pricing page, but that page does not exist: every candidate address returns the site's standard 404, and the 51-URL sitemap contains no such page. Three plans are named - Starter, Professional and Business - and paid plans are said to carry monthly document-generation quotas and AI features, with Business open to an individual agreement. Payment is handled by Stripe on a monthly or annual basis, prices are stated exclusive of VAT, and subscriptions renew automatically unless cancelled beforehand. The homepage advertises starting without a payment card, but neither a permanent free plan nor a dated free trial is ever named. No entry price, currency or billing unit can therefore be stated.
- named in the subscription terms
- no price or quota published
- named in the subscription terms
- no price or quota published
- named in the subscription terms
- may be covered by an individual agreement
- no price published
Data, GDPR & hosting
A consolidated view of how TM Risk handles your data.
GDPR overview
The site claims GDPR compliance in a single homepage line and backs it with unusually detailed documentation dated 1 June 2026. The privacy policy names the data categories processed, and states legal bases explicitly: contract, legitimate interest for security and audit logs, legal obligation, consent for marketing and non-essential cookies, and customer instructions under a data processing agreement. It sets out rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority, with privacy@tmrisk.bg as the dedicated channel. A full subprocessor list is published, transfers outside the EEA are acknowledged under appropriate safeguards, and the platform states it is not intended for sensitive data or for children. A DPO or privacy lead is referred to generically, without a name or separate contact details, and no external audit or certificate is produced.
Who owns the data?
Customers keep ownership of their content. TM Risk takes only the rights it needs to host, process, display, generate, back up and support that content, and each party must protect non-public information obtained through the service. Roles are split: for the customer workspace the customer is the data controller and TM Risk acts as processor under a data processing agreement, whereas for account administration, billing, security, analytics and sales TM Risk may act as controller in its own right. Content can reach authorised users of the same customer, assigned measure owners, reviewers and the published subprocessors. Where a generated document carries a verification link, anyone holding it sees limited metadata.
Reuse rights
Nothing in the published terms grants the end user a right to reuse other parties' data. Customers may freely use and export their own content: assessments are generated as dated, signed document versions and downloaded as PDF, and re-downloading a version already generated does not consume additional quota. It is the customer, not the vendor, who decides whether to circulate a document, a QR code or a verification link, and that decision is framed as a responsibility rather than a permission. Reuse in the opposite direction is constrained: platform acceptance of a measure is a workflow status only, never legal confirmation that occupational safety obligations have been met, and AI output must be reviewed by a competent person before it enters any assessment or document.
Data retention & training
Hosting summary
The vendor states an EU hosting region, naming Frankfurt and Dublin. Five subprocessors are published with their purpose, data categories and transfer basis: Supabase for the database, authentication and file storage; Vercel for hosting, CDN and analytics; Stripe for payments and subscriptions; Resend for service email delivery; and OpenAI, reached through an AI Gateway, for generating suggestions. Supabase is listed as EU with standard contractual clauses where needed, while Vercel, Stripe, Resend and the AI provider are listed as EU/US under standard contractual clauses, so transfers outside the EEA are acknowledged rather than denied. The published DPAs of Supabase, Vercel and Stripe are linked directly. Customers are notified when a subprocessor is added or replaced, through an update to that page and by email where relevant to their plan. Card details are never stored by the vendor, being handled by Stripe. The country names Germany and Ireland are inferred from the two cities the vendor names, as the page itself states cities rather than countries.
Things to keep in mind
Risks and trade-offs to weigh before adopting TM Risk.
- AI-drafted hazard lists invite rubber-stamping: the vendor's own terms warn that suggestions may be wrong, incomplete or unsuited to a specific workplace, yet accepting them wholesale is the fastest path through the tool
- A generated document can create false assurance; platform acceptance of a measure is only a workflow status, never confirmation that legal safety obligations have been discharged
- The four published contact addresses are on tmrisk.bg, a domain that has never been registered, so messages sent for privacy, security, billing or legal matters cannot be delivered
- Relying on the software may erode first-hand practice, since it cannot replace site inspections, worker consultation or competent professional judgement
- Risk prompts carry workplace and job detail to an external AI provider, and the vendor asks users not to enter worker names, medical data or identifiers that could easily be typed in by habit
- Public verification links are shareable by anyone holding them, so circulating a QR code exposes limited company metadata beyond the intended recipient
- No price is published and every legal document is self-declared a working draft, so commercial and contractual terms may change under a customer already committed to the platform
Setup & Integrations
Technical difficulty
Low. There is nothing to install: the product is a web application reached after registration, and no payment card is needed to start. The vendor claims a first activity can be entered in under ten minutes. The real effort is organisational rather than technical - defining the company, branch and job-position hierarchy, assigning roles and memberships, and choosing a scoring method before the first assessment. No API, connector or third-party integration has to be configured, and subscriptions are managed through the Stripe billing portal.
Deployment
Supported languages
Behind TM Risk
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Does the platform support more than one assessment method?
Does the AI make the final decision?
How are the two scoring methods calculated?
How do the document limits work?
Can external companies be assessed?
How is team access controlled?
What does the public verification link reveal?
What does TM Risk cost?
Which languages does the interface support?
Where is the data hosted and who processes it?
Should you pick TM Risk?
TM Risk is a narrow, deliberately unglamorous tool, and that is its strength. It does one job - occupational risk assessment - with the two methods practitioners actually use, and it wraps them in the record-keeping that makes an assessment defensible: versioned documents, measures tied to a named owner and a deadline, an audit trail, and a verification link a third party can check. The insistence that AI only ever drafts, and that a competent person decides, is stated in the terms, the privacy policy and a dedicated AI notice rather than merely implied. Transparency about subprocessors and EU hosting is well above what this segment usually offers.
The reservations are about maturity, not design. The product is visibly new: the Internet Archive holds no capture of the domain at all, the legal documents are dated June 2026 and each one describes itself as a working draft to be reviewed by a lawyer. Commercially it is opaque - the subscription terms send readers to a pricing page that has never been published, so three named plans carry no figures whatsoever. More awkwardly, all four advertised contact channels sit on a domain that was never registered, so mail to them cannot arrive; only the two personal addresses on the main domain are reachable.
The publisher is an established Bulgarian software company rather than a newcomer, which tempers the youth of the product itself. For a Bulgarian HSE team or consultancy, TM Risk looks like a credible way to replace scattered spreadsheets with a traceable process. Anyone outside that language market, or anyone needing a price before committing, will have to wait or ask.
- Choosing a selection results in a full page refresh.
- Opens in a new window.