Lutril vs Nudge Security
Nudge Security is a SaaS and AI security platform that discovers every app and agent from email metadata in hours and remediates through nudges to the people involved. Lutril discovers the same estate and then governs it: requests, reviews, lifecycle and an MCP proxy. Where each fits.
Short answer
Choose Nudge Security if your first problem is visibility: a five-minute, agentless deployment that lists every SaaS and AI tool from Google Workspace or Microsoft 365 email metadata, with published pricing and a strong AI-agent inventory, and you are comfortable remediating through nudges to app owners. Choose Lutril if you need the same discovery followed by enforcement: access reviews whose decisions execute, time-boxed requests approved in Slack, Teams or the app UI, HRIS-driven onboarding and offboarding, and an MCP proxy that applies policy to each agent tool call, hosted in the EU.
Where each one starts
Nudge Security
Deploy in five minutes, see all AI and SaaS in under two hours, scale risk remediation. Austin-based, founded in 2021, $22.5M Series A in November 2025. Discovery from email metadata and OAuth grants plus a browser extension; remediation through nudges to the people who own each app; published pricing with all features on every tier.
Lutril
Discovery from the same Google Workspace and Microsoft 365 signals, a Chrome extension and code scanning, then governance: requests in Slack, Teams and the app UI with automatic expiry, reviews that revoke, HRIS-driven lifecycle, and an MCP proxy with policy on every agent call and a global kill switch. Hosted in France, in French and English.
Capability by capability
| Capability | Nudge Security | Lutril |
|---|---|---|
| SaaS discovery from IdP sign-in and OAuth grants (Google Workspace, Microsoft 365) | YesEmail metadata discovery via Google Workspace or Microsoft 365 read-only API; OAuth grants; Okta integrationSource 3 | YesGoogle Workspace and Microsoft 365 sign-in signals and OAuth grants, from the day you connect |
| Browser extension for shadow IT and shadow AI discovery | YesExtension for Chromium, Edge and Firefox; logins, AI access, file uploadsSource 4 | YesChrome extension for the SaaS and AI tools that skip SSO |
| Access reviews whose keep-or-remove decisions execute the revocation | PartialNudges confirm accounts; changes routed to app owners for clean-up; OAuth grants auto-revokeSource 5 | YesDecisions execute in the connected tool; proof in the campaign export |
| Access requests and approvals in Slack | PartialApp directory request emails or Slack-messages the technical contact; provisioning not documentedSource 6 | YesRequests, approvals and expiry warnings in Slack |
| Access requests and approvals in Microsoft Teams | PartialNudges and notifications delivered in Teams; approvals in Teams not documentedSource 7 | YesSame flow in Microsoft Teams, and in the app UI |
| Just-in-time, time-boxed access that expires on its own | Not documented | YesOne hour to seven days; an approver can shorten, never extend; auto-revoked |
| Onboarding triggered by the HRIS | PartialBambooHR and Deel connected; aligns with HR offboarding events; HRIS-triggered provisioning not documentedSource 8 | YesLucca, PayFit and Eurécia native; other HRIS through the MCP endpoint |
| Offboarding that deprovisions across SaaS, including apps outside SSO | YesRevoke OAuth grants, automate password resets on unmanaged accounts, guided nudges elsewhereSource 8 | YesNative connectors plus a universal MCP endpoint for any tool with an API |
| Shadow AI discovery: AI tools and agents in use | YesAPI discovery (Agentforce, Copilot Studio, ChatGPT, n8n) plus browser discoverySource 9 | YesSign-in logs, mailbox scanning, Chrome extension and code scanning |
| AI agent registry with an accountable owner | YesSingle agent inventory with creator; owner can be assigned separatelySource 9 | YesOwner, model and scopes on every agent; offboarded like an employee |
| MCP proxy or gateway enforcing policy on agent tool calls | Not documentedFlags unauthenticated MCP connections as a risk signal | YesLutril MCP proxy: policy on every call, WORM log, global kill switch |
| Prompt-level DLP and redaction for LLM traffic | PartialDetects secrets, PII and PHI in AI prompts; alert, mask or store; blocking not documentedSource 10 | YesDetect and redact PII and secrets in prompts, per-model policy |
| EU hosting and a French-language product | Not documentedBuilt in AWS; no region or French UI stated | YesOVHcloud, France; product and documentation in French |
| Compliance evidence exports for SOC 2 and ISO 27001 | YesSOC 2 evidence: asset inventory, review actions, offboarding records; Drata integrationSource 11 | YesCampaign export with decisions and revocation proof, one link |
| Native integrations | Not documentedConnect unlimited apps; no figure published | YesMore than 55 native connectors plus the universal MCP endpoint |
| Published pricing | Yes$750 per month up to 150 users; $5 per user per month from 150 to 1,500Source 2 | Not offeredOn request |
Choose Nudge Security if
- You need a complete SaaS and AI inventory this week, with nothing to install and a price you can see.
- Your remediation model is people-driven: nudge the owner, confirm the account, revoke the grant.
- SaaS security posture (SSPM) and breach alerts matter more than access workflows.
Choose Lutril if
- Discovery is step one; you also need reviews that execute removals and requests that expire on their own.
- Onboarding and offboarding must run from the HRIS with accounts created and revoked, not nudged.
- AI agents need policy enforced on each MCP tool call, with a kill switch, rather than an inventory and risk flags.
- Your data must stay in the EU, or your team works in French.
Questions buyers ask
Is Nudge Security a shadow IT discovery tool or a governance tool?
Its own category is SaaS and AI security platform, or SSPM. Discovery and risk remediation through nudges are the core; access reviews route changes to app owners rather than executing them. Lutril covers the same discovery and adds the governance layer: reviews that revoke, time-boxed requests, HRIS lifecycle and an MCP proxy.
Which one finds more AI agents?
Nudge Security documents two discovery channels, API-based for platforms like Agentforce and Copilot Studio and browser-based for tools like Cursor, with an agent inventory and assignable owners. Lutril finds agents through sign-in logs, mailbox scanning, its Chrome extension and code scanning of GitHub and GitLab, then registers each one with an owner and governs its tool calls through the MCP proxy.
Does Nudge Security block sensitive prompts?
Its AI conversation monitoring detects secrets, PII and PHI in prompts and can alert, mask or store; blocking is not documented, and monitoring requires the browser extension. Lutril's prompt DLP can redact, mask or block per policy at the proxy layer.
How do the prices compare?
Nudge Security publishes $750 per month for up to 150 users and $5 per user per month from 150 to 1,500, all features included. Lutril prices on request, scoped to the people and agents governed. Compare on the outcome you need: an inventory with nudges, or an inventory with enforcement.
Sources
- 1Nudge Security homepageread on September 2, 2026
- 2Nudge Security pricingread on September 2, 2026
- 3Nudge Security FAQsread on September 2, 2026
- 4Nudge Security, browser extensionread on September 2, 2026
- 5Nudge Security, user access reviewsread on September 2, 2026
- 6Nudge Security, app directory and access requestsread on September 2, 2026
- 7Nudge Security changelog, Microsoft Teams integrationread on September 2, 2026
- 8Nudge Security, IT offboardingread on September 2, 2026
- 9Nudge Security, AI agent discoveryread on September 2, 2026
- 10Nudge Security, AI conversation monitoringread on September 2, 2026
- 11Nudge Security, SOC 2 complianceread on September 2, 2026
- 12Nudge Security press, Series Aread on September 2, 2026
- 13Nudge Security integrationsread on September 2, 2026
Lutril wrote this page. Facts about Nudge Security come from their public documentation as of September 2, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.