On-device risk assessment · Windows 10 / 11 · UK-tuned

On-device risk assessment · Windows 10 / 11 · UK-tuned

Four questions most firms
can’t answer about their own PCs

Four questions most firms
can’t answer about their own PCs

Where is the sensitive data? Which apps are exploitable? Would you pass Cyber Essentials today? Is Windows actually hardened? PCRiskPro answers all four in one scan, in plain English — on the machine in front of you. It even reads scanned paperwork and photos of documents. Your files never leave the building.

Signed by PCRiskpro Limited

/

No account needed

/

Nothing uploaded

/

Free forever, no card

PCRiskPro
pcriskpro
digital risk assessment
🖥SAMPLE-LAPTOP
Last scan: 28 Jul 17:45
Protected
Enterprise Licence
Help
Settings
Dashboard
Data Discovery
App Security
Cyber Essentials
System Security
🗀 Scan Folders
◫ Choose Files
🗝 Key Locations
97 files ready to scan from C:/…/Client_Files
Start Scan
🔒 Sensitive Data
🔍 Text Search
⚙ Scan Rules
All Patterns
Detects personal, financial, credential, and compliance-sensitive data.
⬆ Export
🗑 Clear All
Scanningcustomer_contacts.xlsx
Scan complete — 97 files (5.9 MB) in C:/…/Client_Files ·54 with sensitive data· Rule: All Patterns (35) · ⏱ 35s · ⚡ 2.8 files/s
Last scan: 28 Jul 2026, 17:45
⇅ Filter & Sort
Sensitive Files
0
of 97 scanned
Critical & High
0
21 critical · 31 high
Top Category
Identity documents
26 findings
Riskiest folder
C:\…\Foreign_IDs
16 files
Files Scanned
0
of 97 supported · 54 with PII · 43 clean
View breakdown →
Compliance readiness
GDPR Partial
PCI-DSS Pass
UK DPA 2018 Partial
Cyber Essentials Fail
View details →
Detailed Evidence
File-level findings for review, validation, and export
Document
Findings
Data Types Found
Severity ▼
Verification
us_customers.csv
4 matches
Email Address, Street Address
MEDIUM
Manual check needed
customer_contacts.xlsx
11 matches
Email Address, UK Mobile Phone, UK Postcode
MEDIUM
Review suggested
Scanned_20260618-1744.pdf
3 matches
UK Driving Licence, Street Address, UK Postcode
HIGH
Review suggested
statement_1998_page1.tif
3 matches
UK IBAN, Bank Account Number, UK Bank Sort Code
HIGH
Verified
sa_passport_attached.txt
1 match
Foreign Passport Number
HIGH
Verified
right_to_work_bulgarian_staff.txt
1 match
Foreign Passport Number
HIGH
Verified
driving licence application.txt
2 matches
UK Driving Licence, Street Address
HIGH
Review suggested
DVLA_letter_03_2026.txt
1 match
UK Driving Licence
HIGH
Verified
driver_licence_application_review.txt
1 match
UK Driving Licence
HIGH
Verified
driving_licence_morgan.txt
1 match
UK Driving Licence
HIGH
Verified
Point it at a folder. It finds the sensitive data you forgot you had.
PCRiskPro
pcriskpro
digital risk assessment
🖥SAMPLE-LAPTOP
Last scan: 28 Jul 17:45
Protected
Enterprise Licence
Help
Settings
Dashboard
Data Discovery
App Security
Cyber Essentials
System Security
🗀 Scan Folders
◫ Choose Files
🗝 Key Locations
97 files ready to scan from C:/…/Client_Files
Start Scan
🔒 Sensitive Data
🔍 Text Search
⚙ Scan Rules
All Patterns
Detects personal, financial, credential, and compliance-sensitive data.
⬆ Export
🗑 Clear All
Scanningcustomer_contacts.xlsx
Scan complete — 97 files (5.9 MB) in C:/…/Client_Files ·54 with sensitive data· Rule: All Patterns (35) · ⏱ 35s · ⚡ 2.8 files/s
Last scan: 28 Jul 2026, 17:45
⇅ Filter & Sort
Sensitive Files
0
of 97 scanned
Critical & High
0
21 critical · 31 high
Top Category
Identity documents
26 findings
Riskiest folder
C:\…\Foreign_IDs
16 files
Files Scanned
0
of 97 supported · 54 with PII · 43 clean
View breakdown →
Compliance readiness
GDPR Partial
PCI-DSS Pass
UK DPA 2018 Partial
Cyber Essentials Fail
View details →
Detailed Evidence
File-level findings for review, validation, and export
Document
Findings
Data Types Found
Severity ▼
Verification
us_customers.csv
4 matches
Email Address, Street Address
MEDIUM
Manual check needed
customer_contacts.xlsx
11 matches
Email Address, UK Mobile Phone, UK Postcode
MEDIUM
Review suggested
Scanned_20260618-1744.pdf
3 matches
UK Driving Licence, Street Address, UK Postcode
HIGH
Review suggested
statement_1998_page1.tif
3 matches
UK IBAN, Bank Account Number, UK Bank Sort Code
HIGH
Verified
sa_passport_attached.txt
1 match
Foreign Passport Number
HIGH
Verified
right_to_work_bulgarian_staff.txt
1 match
Foreign Passport Number
HIGH
Verified
driving licence application.txt
2 matches
UK Driving Licence, Street Address
HIGH
Review suggested
DVLA_letter_03_2026.txt
1 match
UK Driving Licence
HIGH
Verified
driver_licence_application_review.txt
1 match
UK Driving Licence
HIGH
Verified
driving_licence_morgan.txt
1 match
UK Driving Licence
HIGH
Verified
Point it at a folder. It finds the sensitive data you forgot you had.

13,451

files read in a single overnight scan

7,035

scanned PDFs it read with OCR along the way

6,261

items of personal data it found

0

scan failures — everything skipped was disclosed

42

built-in detection patterns, tuned for UK data

The first four figures are one real scan: a UK firm’s shared drive, run unattended overnight in July 2026 — 3 hours 59 minutes from start to finished report. Nobody there thought that much personal data was sitting on it.

What it checks

One scan, four answers

The four questions from the top of this page, answered on every device you point it at. There’s no console to stand up and no agent to deploy. You install it, pick a folder, and read the report.

Data Discovery

01

Where is your sensitive data, exactly?

Passport scans, payroll spreadsheets, bank details, NHS and NI numbers — we find them inside PDFs, Office files, Outlook messages, photos, and the pre-2007 legacy formats everyone has forgotten about. Every finding comes back with the full file path, a severity and a confidence level, so you know exactly which file to open first.

OCR on scans & photos

.doc .xls .ppt

.msg .eml

App Security

02

Which installed apps are exploitable?

We check every app you’ve installed against the public vulnerability databases and rank what we find by confidence. A direct hit on software you actually run never gets buried under speculative dependency noise.

NVD

OSV.dev

CISA KEV ransomware flag

Cyber Essentials

03

Would you pass Cyber Essentials today?

We walk all five control themes against the current technical requirements — firewalls, secure configuration, user access control, malware protection and security update management — then give you a readiness score and name the exact controls holding you back.

5 control themes

Assessor-ready HTML report

System Security

04

Is the Windows build actually hardened?

Eleven configuration checks most tools skip: Secure Boot, TPM, BitLocker, Credential Guard, SMBv1, UAC, ransomware protection, RDP exposure, the guest account, password policy and screen lock. Where one is switched off, we tell you what it actually exposes.

11 hardening checks

No agent, no console

How it works

Install, point, hand over the report

STEP 01

Install the signed build

One code-signed Windows installer from PCRiskpro Limited. You don’t register a tenant, you don’t create an account, and nothing is left running in the background once you’re done.

STEP 02

Point it at a folder

Pick a folder, a synced OneDrive or SharePoint library, or a network share. Before it starts, PCRiskPro tells you what it’s found and roughly how long this is going to take. Then it runs the security and compliance checks alongside the data scan.

STEP 03

Export something you can send

One report you can actually send — HTML, Excel, CSV or JSON, with an executive summary, evidence table, remediation plan and scan coverage. It’s written to your own disk, and it’s client-ready as exported — consultants and MSPs can hand it over as-is or fold the evidence into their own reporting.

Anatomy of a finding

A list of pattern matches isn’t a risk assessment

So we don’t hand you one. Every finding says what we found, why it matters in regulatory terms, and what to do about it, in order. The person who has to fix it shouldn’t need somebody to translate the report for them first. The card shown here is a representative example — real exported reports are linked in the Verify section below.

Every detection in Data Discovery, Cyber Essentials and System Security gets a what / why / how card.

Fix something, mark it fixed, and it stays fixed on the next scan. You show progress instead of re-arguing the same findings every quarter.

We’d rather miss an edge case than cry wolf. Bank account numbers, driving licences and passport numbers all need supporting context before we report them at all.

Run the same scan twice — even from two different machines — and you get identical findings. That determinism is locked in by automated tests on every release.

Critical

Data Discovery

+5 pts when fixed

payroll_master_2019.xlsx

C:\Users\a.hussain\Documents\HR_Archive\

What we found

17 UK National Insurance numbers and 9 sort code and account number pairs in a single unencrypted workbook.

Why this matters

Personal financial data held outside the encrypted finance share. Reportable to the ICO if this device is lost or stolen, and in scope for your UK GDPR Article 30 record of processing.

How to remediate

1

Move the file into Finance / Encrypted /

2

Restrict permissions to the Finance group only

3

Mark as fixed in PCRiskPro and re-scan to confirm

Owner

Finance lead

Effort

Under 15 minutes

Framework

UK GDPR Art. 30

On-device by architecture

A data discovery tool that never sees your data

Scanning, OCR, scoring and report generation all happen on the machine being assessed. There’s no SaaS account to create, no bucket to grant us access to, and no third-party processor agreement to get past your DPO before you’re allowed to start.

Your DPO is going to ask what we send. So here’s the complete list — not a summary of it, the actual list.

Never leaves the device

File contents and extracted text

OCR output from scans and photographs

Findings, matched values and file paths

Risk scores and generated reports

The scan database, held in your user profile

The only outbound traffic

Application names and version numbers, sent to the public NVD, OSV.dev and CISA KEV databases to look up known vulnerabilities

A signed vulnerability-database update, downloaded from our release channel only when you ask for one

That’s everything. No file names, no file contents, no user identifiers, no scan results. If it ever changes, it changes in the release notes first.

Frameworks

Built for the audits you actually face

Tuned for UK regulatory baselines and certification pathways, not a generic global default that flags every American phone number it trips over.

DPA 2018

UK GDPR / DPA 2018

Article 30 register cues, ICO breach scoping and subject access request workflows. UK identifier patterns — NHS numbers, National Insurance, sort codes, postcodes — with US locale patterns switched off by default, because you don’t need the noise.

CE / CE+

Cyber Essentials & CE Plus

We assess all five control themes against the current technical requirements. Export the report and hand it to your assessor as pre-audit evidence — before you pay for the assessment and find out the hard way.

PCI-DSS

PCI-DSS scope identification

Find cardholder data — primary account numbers, track data, issuer identification numbers — sitting outside the cardholder data environment. It’s the first step in any honest SAQ-D or Level 4 merchant pre-assessment.

PCRiskPro prepares you for Cyber Essentials and Cyber Essentials Plus. Certificates are issued by IASME-accredited certification bodies, and CE Plus requires assessment by an independent assessor. PCRiskPro Limited is not affiliated with, endorsed by, or accredited by NCSC or IASME.

Where it fits

How this differs from what you’ve probably already got

PCRiskPro is the discovery layer of enterprise data-loss prevention — the part that answers “where is our data?” — without the platform around it. Enterprise discovery deployments run to tens of thousands of pounds a year and months of onboarding; 2026 contract data puts the median around $88,000 a year. PCRiskPro answers the same first question in minutes, on the device, with UK patterns the big suites don’t ship.

PCRiskPro

Microsoft Purview

Business Premium + add-on

Built-in Windows tooling

Where your data is processed

On the device

In your Microsoft cloud tenant

On the device

Time to a first result

Minutes after install

Weeks — licensing tiers, scanner setup, policy tuning

Not designed to answer this

OCR of scanned images at rest

Included, every edition

Metered per page, routed through the cloud

No

Outlook .msg and .eml files

Read directly, plus pre-2007 Office formats

Not inspected by the at-rest scanner

No

UK sort codes out of the box

Built in

No built-in pattern — custom work required

No

Cyber Essentials evidence pack

Report built for assessors

No

No

Pricing shape

Published flat tiers — free to start

Per user, per month, plus metered add-ons

Bundled with the OS licence

What PCRiskPro deliberately doesn’t do: sit in the background intercepting email, uploads and USB copies. That’s an enforcement platform — Microsoft Purview being the obvious one — a different tool at a different price, and for many smaller firms the map is all they ever need. If you conclude you do need the platform, take PCRiskPro’s findings into that rollout: you’ll scope Purview tighter and pay for less of it.

Who it’s for

Whichever seat you’re sitting in

Three very different jobs end up asking the same question. Here’s where PCRiskPro fits into each of them.

You run the business

You’ve been handed “sort out Cyber Essentials”

On top of your actual job, probably. Start with one folder on one machine tonight. See what’s really there, find out how far off certification you are, and decide what it’s worth to you before you spend anything at all.

Free Edition · no card · no time limit

You look after other people’s estates

You need this to work across client sites

Run it site by site with nothing to stand up centrally and nothing left behind on a client machine afterwards. Reports come out client-ready — evidence, coverage and remediation plan included — and pricing is published flat tiers: no per-seat maths, no seat minimums, no quote to find out what it costs.

You sign off other people’s compliance

Your name goes on the report, not ours

Evidence you can defend in front of a client: full file paths, severities, confidence levels, the regulatory reasoning behind every finding, and a coverage table showing exactly what was examined and what wasn’t. Export it and attach it to your own report.

HTML · Excel · CSV · JSON

Verify us

You’ve never heard of us. Don’t trust us — verify us.

We’re new, and we’re asking you to run an executable on a machine that holds your payroll. You’d be mad to simply take our word for it. So here’s everything you need to check us out yourself: signature, hash, VirusTotal, company number, and real sample output you can read before you install a thing.

The installer is code-signed, and you can prove it

Every release is signed as PCRiskpro Limited with an organisation-validated certificate whose private key is held in a cloud HSM, and RFC 3161 timestamped. Our build pipeline verifies the signature after signing and fails the build if it doesn’t validate, so an unsigned installer can’t ship even by accident. Every release also has to clear more than 2,900 automated tests, a dependency vulnerability audit and a vulnerability-database freshness check before it can be built at all.

PS> check the signature before you run it

Get-AuthenticodeSignature .\PCRiskPro_Setup.exe | Format-List *

PS> and confirm the hash matches the one on the download page

Get-FileHash .\PCRiskPro_Setup.exe -Algorithm SHA256

Windows may still show a SmartScreen prompt. Every new publisher starts with no download reputation, whatever certificate they hold — that is Microsoft’s system working as designed, and it clears as installs accumulate. Verify the signature and the hash instead of trusting the absence of a warning.

OV certificate

RSA 4096

HSM-held key

RFC 3161 timestamp

SHA-256 published

A real company, on the public record

Entity

PCRiskPro Limited

Registered

England & Wales

Company no

17035916

Office

20 Wenlock Road, London N1 7GU

Support

support@pcriskpro.com

Read the output before you install anything

Real reports exported from a test corpus — unedited except that device and user names are masked. Read one first and decide whether it’s worth twenty minutes of your evening.

Scan one folder tonight. Decide about us afterwards.

The Free Edition is the full detection engine on local folders — no card, no time limit, no nag screens. It counts every finding and shows the first 20 in full detail: enough to know exactly where you stand before you spend a penny. And if it finds nothing you didn’t already know about, you’ve lost twenty minutes.

Free forever, no card · Windows 10 / 11 · ~170 MB code-signed installer · upgrade only when you need wider scope

Included, free forever

Scan any local folder on this device

More than 40 built-in patterns / 35 active by default

OCR for images and scanned PDFs

Legacy Office: .doc, .xls, .ppt

Cyber Essentials and configuration checks

Paid tiers add

+

Full detail on every finding, not just the first 20

+

Report exports in HTML, Excel, CSV and JSON

+

Personal and business cloud scope — OneDrive, SharePoint, network shares

+

Remediation tracking across re-scans