Skip to content
Second Key Security

Shadow IT and Shadow AI Discovery

An inventory of the apps and AI tools your team already uses, including the ones nobody approved.

Cadence
Monthly
Pricing
Scoped to your environment after the assessment.
Family
Identity and access

The problem

Teams sign up for SaaS apps and AI tools with a work email and a credit card. Company data ends up in tools security never reviewed, and nobody has the list.

What you get

How it works

  1. Step 1: Connect read-only sources

    Sign-in and app connection records from your identity provider, plus any other sources you choose.

  2. Step 2: Agents build the inventory

    Apps and AI tools matched to the people and teams using them.

  3. Step 3: An expert reviews the risk

    Each unapproved tool judged on the data it can reach.

  4. Step 4: You approve any change

    You decide what stays, and we draft the follow-up for your approval. Every approval is logged.

Access we need

  • Read-only access to sign-in and app assignment data in your identity provider
  • Read-only access to third-party app connections (OAuth grants) in Google Workspace or Microsoft 365

What we never do

  • We never read the contents of email or files.
  • We never block or remove a tool; that decision is yours.

The full access model is on the security and trust page.

Questions about Shadow IT and Shadow AI Discovery?

Tell us what you run and what you need, and we will reply with next steps.