Where is the sensitive data? Which apps are exploitable? Would you pass Cyber Essentials today? Is Windows actually hardened? PCRiskPro answers all four in one scan, in plain English — on the machine in front of you. It even reads scanned paperwork and photos of documents. Your files never leave the building.
Signed by PCRiskpro Limited
/
No account needed
/
Nothing uploaded
/
Free forever, no card
13,451
files read in a single overnight scan
7,035
scanned PDFs it read with OCR along the way
6,261
items of personal data it found
0
scan failures — everything skipped was disclosed
42
built-in detection patterns, tuned for UK data
The first four figures are one real scan: a UK firm’s shared drive, run unattended overnight in July 2026 — 3 hours 59 minutes from start to finished report. Nobody there thought that much personal data was sitting on it.
What it checks
One scan, four answers
The four questions from the top of this page, answered on every device you point it at. There’s no console to stand up and no agent to deploy. You install it, pick a folder, and read the report.
Data Discovery
01
Where is your sensitive data, exactly?
Passport scans, payroll spreadsheets, bank details, NHS and NI numbers — we find them inside PDFs, Office files, Outlook messages, photos, and the pre-2007 legacy formats everyone has forgotten about. Every finding comes back with the full file path, a severity and a confidence level, so you know exactly which file to open first.
OCR on scans & photos
.doc .xls .ppt
.msg .eml
App Security
02
Which installed apps are exploitable?
We check every app you’ve installed against the public vulnerability databases and rank what we find by confidence. A direct hit on software you actually run never gets buried under speculative dependency noise.
NVD
OSV.dev
CISA KEV ransomware flag
Cyber Essentials
03
Would you pass Cyber Essentials today?
We walk all five control themes against the current technical requirements — firewalls, secure configuration, user access control, malware protection and security update management — then give you a readiness score and name the exact controls holding you back.
5 control themes
Assessor-ready HTML report
System Security
04
Is the Windows build actually hardened?
Eleven configuration checks most tools skip: Secure Boot, TPM, BitLocker, Credential Guard, SMBv1, UAC, ransomware protection, RDP exposure, the guest account, password policy and screen lock. Where one is switched off, we tell you what it actually exposes.
11 hardening checks
No agent, no console
How it works
Install, point, hand over the report
STEP 01
Install the signed build
One code-signed Windows installer from PCRiskpro Limited. You don’t register a tenant, you don’t create an account, and nothing is left running in the background once you’re done.
STEP 02
Point it at a folder
Pick a folder, a synced OneDrive or SharePoint library, or a network share. Before it starts, PCRiskPro tells you what it’s found and roughly how long this is going to take. Then it runs the security and compliance checks alongside the data scan.
STEP 03
Export something you can send
One report you can actually send — HTML, Excel, CSV or JSON, with an executive summary, evidence table, remediation plan and scan coverage. It’s written to your own disk, and it’s client-ready as exported — consultants and MSPs can hand it over as-is or fold the evidence into their own reporting.
Anatomy of a finding
A list of pattern matches isn’t a risk assessment
So we don’t hand you one. Every finding says what we found, why it matters in regulatory terms, and what to do about it, in order. The person who has to fix it shouldn’t need somebody to translate the report for them first. The card shown here is a representative example — real exported reports are linked in the Verify section below.
✓
Every detection in Data Discovery, Cyber Essentials and System Security gets a what / why / how card.
✓
Fix something, mark it fixed, and it stays fixed on the next scan. You show progress instead of re-arguing the same findings every quarter.
✓
We’d rather miss an edge case than cry wolf. Bank account numbers, driving licences and passport numbers all need supporting context before we report them at all.
✓
Run the same scan twice — even from two different machines — and you get identical findings. That determinism is locked in by automated tests on every release.
Critical
Data Discovery
+5 pts when fixed
payroll_master_2019.xlsx
C:\Users\a.hussain\Documents\HR_Archive\
What we found
17 UK National Insurance numbers and 9 sort code and account number pairs in a single unencrypted workbook.
Why this matters
Personal financial data held outside the encrypted finance share. Reportable to the ICO if this device is lost or stolen, and in scope for your UK GDPR Article 30 record of processing.
How to remediate
1
Move the file into Finance / Encrypted /
2
Restrict permissions to the Finance group only
3
Mark as fixed in PCRiskPro and re-scan to confirm
Owner
Finance lead
Effort
Under 15 minutes
Framework
UK GDPR Art. 30
On-device by architecture
A data discovery tool that never sees your data
Scanning, OCR, scoring and report generation all happen on the machine being assessed. There’s no SaaS account to create, no bucket to grant us access to, and no third-party processor agreement to get past your DPO before you’re allowed to start.
Your DPO is going to ask what we send. So here’s the complete list — not a summary of it, the actual list.
Never leaves the device
✓
File contents and extracted text
✓
OCR output from scans and photographs
✓
Findings, matched values and file paths
✓
Risk scores and generated reports
✓
The scan database, held in your user profile
The only outbound traffic
→
Application names and version numbers, sent to the public NVD, OSV.dev and CISA KEV databases to look up known vulnerabilities
→
A signed vulnerability-database update, downloaded from our release channel only when you ask for one
That’s everything. No file names, no file contents, no user identifiers, no scan results. If it ever changes, it changes in the release notes first.
Frameworks
Built for the audits you actually face
Tuned for UK regulatory baselines and certification pathways, not a generic global default that flags every American phone number it trips over.
DPA 2018
UK GDPR / DPA 2018
Article 30 register cues, ICO breach scoping and subject access request workflows. UK identifier patterns — NHS numbers, National Insurance, sort codes, postcodes — with US locale patterns switched off by default, because you don’t need the noise.
CE / CE+
Cyber Essentials & CE Plus
We assess all five control themes against the current technical requirements. Export the report and hand it to your assessor as pre-audit evidence — before you pay for the assessment and find out the hard way.
PCI-DSS
PCI-DSS scope identification
Find cardholder data — primary account numbers, track data, issuer identification numbers — sitting outside the cardholder data environment. It’s the first step in any honest SAQ-D or Level 4 merchant pre-assessment.
PCRiskPro prepares you for Cyber Essentials and Cyber Essentials Plus. Certificates are issued by IASME-accredited certification bodies, and CE Plus requires assessment by an independent assessor. PCRiskPro Limited is not affiliated with, endorsed by, or accredited by NCSC or IASME.
Where it fits
How this differs from what you’ve probably already got
PCRiskPro is the discovery layer of enterprise data-loss prevention — the part that answers “where is our data?” — without the platform around it. Enterprise discovery deployments run to tens of thousands of pounds a year and months of onboarding; 2026 contract data puts the median around $88,000 a year. PCRiskPro answers the same first question in minutes, on the device, with UK patterns the big suites don’t ship.
Where your data is processed
On the device
In your Microsoft cloud tenant
On the device
Time to a first result
Minutes after install
Weeks — licensing tiers, scanner setup, policy tuning
Not designed to answer this
OCR of scanned images at rest
Included, every edition
Metered per page, routed through the cloud
No
Outlook .msg and .eml files
Read directly, plus pre-2007 Office formats
Not inspected by the at-rest scanner
No
UK sort codes out of the box
Built in
No built-in pattern — custom work required
No
Cyber Essentials evidence pack
Report built for assessors
No
No
Pricing shape
Published flat tiers — free to start
Per user, per month, plus metered add-ons
Bundled with the OS licence
What PCRiskPro deliberately doesn’t do: sit in the background intercepting email, uploads and USB copies. That’s an enforcement platform — Microsoft Purview being the obvious one — a different tool at a different price, and for many smaller firms the map is all they ever need. If you conclude you do need the platform, take PCRiskPro’s findings into that rollout: you’ll scope Purview tighter and pay for less of it.
Who it’s for
Whichever seat you’re sitting in
Three very different jobs end up asking the same question. Here’s where PCRiskPro fits into each of them.
You run the business
You’ve been handed “sort out Cyber Essentials”
On top of your actual job, probably. Start with one folder on one machine tonight. See what’s really there, find out how far off certification you are, and decide what it’s worth to you before you spend anything at all.
Free Edition · no card · no time limit
You look after other people’s estates
You need this to work across client sites
Run it site by site with nothing to stand up centrally and nothing left behind on a client machine afterwards. Reports come out client-ready — evidence, coverage and remediation plan included — and pricing is published flat tiers: no per-seat maths, no seat minimums, no quote to find out what it costs.
You sign off other people’s compliance
Your name goes on the report, not ours
Evidence you can defend in front of a client: full file paths, severities, confidence levels, the regulatory reasoning behind every finding, and a coverage table showing exactly what was examined and what wasn’t. Export it and attach it to your own report.
HTML · Excel · CSV · JSON
Verify us
You’ve never heard of us. Don’t trust us — verify us.
We’re new, and we’re asking you to run an executable on a machine that holds your payroll. You’d be mad to simply take our word for it. So here’s everything you need to check us out yourself: signature, hash, VirusTotal, company number, and real sample output you can read before you install a thing.
The installer is code-signed, and you can prove it
Every release is signed as PCRiskpro Limited with an organisation-validated certificate whose private key is held in a cloud HSM, and RFC 3161 timestamped. Our build pipeline verifies the signature after signing and fails the build if it doesn’t validate, so an unsigned installer can’t ship even by accident. Every release also has to clear more than 2,900 automated tests, a dependency vulnerability audit and a vulnerability-database freshness check before it can be built at all.
PS> check the signature before you run it
Get-AuthenticodeSignature .\PCRiskPro_Setup.exe | Format-List *
PS> and confirm the hash matches the one on the download page
Get-FileHash .\PCRiskPro_Setup.exe -Algorithm SHA256
Windows may still show a SmartScreen prompt. Every new publisher starts with no download reputation, whatever certificate they hold — that is Microsoft’s system working as designed, and it clears as installs accumulate. Verify the signature and the hash instead of trusting the absence of a warning.
OV certificate
RSA 4096
HSM-held key
RFC 3161 timestamp
SHA-256 published
A real company, on the public record
Entity
PCRiskPro Limited
Registered
England & Wales
Company no
17035916
Office
20 Wenlock Road, London N1 7GU
Support
support@pcriskpro.com
Read the output before you install anything
Real reports exported from a test corpus — unedited except that device and user names are masked. Read one first and decide whether it’s worth twenty minutes of your evening.
Scan one folder tonight. Decide about us afterwards.
The Free Edition is the full detection engine on local folders — no card, no time limit, no nag screens. It counts every finding and shows the first 20 in full detail: enough to know exactly where you stand before you spend a penny. And if it finds nothing you didn’t already know about, you’ve lost twenty minutes.
Free forever, no card · Windows 10 / 11 · ~170 MB code-signed installer · upgrade only when you need wider scope
Included, free forever
✓
Scan any local folder on this device
✓
More than 40 built-in patterns / 35 active by default
✓
OCR for images and scanned PDFs
✓
Legacy Office: .doc, .xls, .ppt
✓
Cyber Essentials and configuration checks
Paid tiers add
+
Full detail on every finding, not just the first 20
+
Report exports in HTML, Excel, CSV and JSON
+
Personal and business cloud scope — OneDrive, SharePoint, network shares
+
Remediation tracking across re-scans