SaaS Risk Heatmap
A SaaS risk heatmap scores every application in your stack on two axes, how sensitive the data it holds is and how far a compromised account or OAuth grant would reach, then plots them so the ones that need SSO, MFA and offboarding automation first are obvious.
Last reviewed by the Radiatus Cloud team
Want this done for your business?
Radiatus delivers cloud, security & automation for growing teams.
The two axes
Data criticality is what the app holds: source code, customer records, payroll, or lunch orders. Access scope is blast radius: what else an attacker reaches after compromising one account or one integration token. Google Workspace scores five on both because it is usually the identity provider, so control of one admin account resets the password on every other app. The score is the product of the two, from 1 to 25, banded as Low under 6, Medium to 9, High to 15 and Critical from 16.
Why the pre-filled scores look the way they do
- GitHub: secrets committed to repositories and long-lived personal access tokens that skip MFA entirely.
- Salesforce: report exports and connected apps with API access; guest and community sharing rules are misconfigured often enough to have a name, the Ghost Sites problem.
- Slack: credentials and customer data pasted into channels, retained indefinitely and searchable by every member.
- Jira and Notion: unfixed vulnerabilities and runbooks written in plain language, one public-link toggle away from the internet.
Adding your own applications
Use the extra row to add anything not listed, with your own criticality and scope from 1 to 5. Be honest about scope: a payroll provider holds critical data but usually scores 2 on reach because it integrates with little else. A password manager or an SSO provider is the reverse case and should be 5 on scope regardless of what it stores.
What to do with the ranking
Everything scoring 10 or more should be behind single sign-on with MFA enforced, should have SCIM or an equivalent so that leavers are deprovisioned automatically, and should have its OAuth grants reviewed quarterly. Everything Critical also needs an admin-count audit; more than a handful of global admins on the identity provider is the single most common finding in SaaS security reviews. The heatmap is a prioritisation device, not an assessment, and it runs entirely in the browser with nothing saved.
Related tools
- Third-Party Risk Assessor — Assess vendor risk based on data access and type.
- Vendor Onboarding Checklist — Generate a security onboarding checklist tailored to the vendor type and the data they touch, so a SaaS holding PHI gets a BAA line and a hardware supplier gets commissioning steps.
- Access Control Matrix Generator — Generate role-based access control (RBAC) matrices for your application.
- Shadow AI Detector — Estimate unapproved AI usage in your org based on survey inputs.
Frequently Asked Questions
Why does Google Workspace rank above GitHub when GitHub holds our code?
Because Workspace is the identity provider. Compromise it and the attacker can reset the GitHub password too. Identity systems always score maximum on access scope.
How is the score calculated?
Data criticality multiplied by access scope, each from 1 to 5, giving 1 to 25. Bands are Low below 6, Medium 6 to 9, High 10 to 15, Critical 16 and above.
Is this a replacement for a vendor risk assessment?
No. It ranks which vendors to assess first. A proper assessment looks at the vendor's own controls, certifications and contract terms; the heatmap only looks at your exposure to them.
What is an OAuth grant and why does it matter here?
When a user clicks Allow on a third-party app that wants access to their Google or Slack account, that app receives a token that keeps working after the user changes their password. Unreviewed grants are a quiet way for data to leave.
Is my app list stored anywhere?
No. Selections and custom entries live in the page and are gone on reload.
Privacy & Security
Generated locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Third-Party Risk Assessor
BusinessAssess vendor risk based on data access and type.
Vendor Onboarding Checklist
BusinessGenerate a security onboarding checklist tailored to the vendor type and the data they touch, so a SaaS holding PHI gets a BAA line and a hardware supplier gets commissioning steps.
Access Control Matrix Generator
SecurityGenerate role-based access control (RBAC) matrices for your application.