preloader
Our new platform is here - start free at app.foundationcybersecurity.com.au

Know the risks before you roll out a new app

Every term, someone asks the IT manager to approve a new app. A teacher wants a maths platform for Year 7. Marketing wants a new survey tool. Finance wants to move expenses to a SaaS product. Each one collects data, each one has a privacy policy nobody has read, and each one becomes your problem if it goes wrong.

App Risk Reporter, part of the Foundation platform, does the reading for you. Enter the app’s name, add its privacy policy or terms of service if you have them, and get a structured risk report covering privacy, security, compliance and data handling - in minutes, not weeks.

Who it’s for

  • Schools assessing edtech apps. Before a new learning platform goes anywhere near student data, run it through App Risk Reporter. The report covers age appropriateness, parental consent handling, data residency, and what the vendor actually does with student information.
  • Businesses assessing SaaS vendors. New CRM, file sharing tool, or AI service? Get a clear view of the vendor’s security posture and data practices before you sign, and keep the report on file as evidence of due diligence.
  • Anyone who owns vendor risk. If your cyber insurance renewal or board asks “how do you assess third-party apps?”, this gives you a documented, repeatable answer.

How it works

  1. Enter the app. Name the app and vendor, and add any notes about how you plan to use it.
  2. Upload documents if you have them. Privacy policies, terms of service, security whitepapers - anything the vendor has given you. If you don’t have them, that’s fine: the platform’s built-in web research finds the vendor’s public documentation for you.
  3. Get a structured report. The AI analyses the documents and research, and produces a report you can act on - and export to Word for your records or your leadership team.

What’s in a report

Each report gives you:

  • Risk scores by category - data privacy, security, compliance, data retention, vendor trust, and (for education) age appropriateness and educational value, rolled up into an overall risk rating of low, medium or high.
  • Critical issues and positive highlights - the things that need attention before rollout, and the things the vendor is doing well, in plain language.
  • Findings by area - what data the app collects and why, how it’s secured, which standards and regulations the vendor addresses (including the Australian Privacy Principles), and where the data lives.
  • Recommendations - immediate actions, what to monitor over time, policy updates to make, and questions to put back to the vendor.
  • Research summary - the sources found, including links to the vendor’s privacy policy, terms, and security documentation, so you can verify anything yourself.

Reports are private to your organisation, and colleagues on your team see the same report library - so the work one person does on an app is there for everyone.

Start free

Every free account includes 3 app risk reports, alongside the free Foundation Cyber Security Check assessment. No credit card required. Subscriptions add unlimited reports, Word exports, and team invitations - see pricing for details.

Create your free account and run your first report today, or contact us if you’d like a walkthrough first.