Licenses nobody used
You pay for entitlements collecting dust. Too many licenses go untouched, but without usage data, that waste stays hidden.
Source: Torii 2026 SaaS Benchmark, annual report
Built for cybersecurity and security software teams, from public regulatory sources and our own anonymised discovery data. How this works
Cybersecurity & security software
Torii discovers every SaaS and AI application your teams sign up for, including the ones bought on a card or running a free tier. For a company that sells trust, shadow IT and unmanaged AI are the gap you can least afford. Torii finds 878 apps on average, 58% of them shadow IT.*
Read-only. Two weeks. No endpoint agent.
*Torii internal discovery data, January to December 2025. Methodology.
Top companies trust Torii
“Once we integrated Torii, it blew our minds. We found apps we didn’t even know we were using – or paying for.”
See how AppsFlyer brought 300+ applications under management with Torii →
Three places, and only one of them shows up in your spend report.
You pay for entitlements collecting dust. Too many licenses go untouched, but without usage data, that waste stays hidden.
Source: Torii 2026 SaaS Benchmark, annual report
AI consumption cost is the expense you never saw coming. Now you're scrambling to build a plan without data.
Source: Torii 2026 SaaS Benchmark, year-over-year AI spend
Every departure should close every account. It rarely does. You keep paying for the seats, and the access stays open behind them.
Source: Torii 2026 SaaS Benchmark, annual report
Don’t overlook the cost of compliance.
Annually, then at every renewal
Trust Services Criteria, the point of focus under CC6.1: The entity identifies,
inventories, classifies, and manages information assets (for example, infrastructure,
software, and data).
CC9.2 adds vendors and business partners. Your auditor samples
that register once a year. Your customers read the subservice organisations named in the
report every time they renew.
AICPA 2017 Trust Services Criteria with Revised Points of Focus (2022).
Primary source →Continuous · 30 days’ notice
Standard Contractual Clauses, Module Two, Clause 9(a), Option 2: the importer has
general authorisation to engage sub-processors from an agreed list
, and must
notify any intended changes to that list
at least [X] in advance. AWS’s executed
SCCs fill that bracket with 30 days. You cannot give 30 days’ notice of a tool you found
late.
Commission Implementing Decision (EU) 2021/914. AWS notice period from its supplier page (updated 28 July 2026), retrieved 12 August 2026.
Primary source →Every enterprise deal
Microsoft’s Supplier Data Protection Requirements v12, March 2026, devotes Section K, requirements 51 to 63, to AI systems, and accepts an ISO 42001 certificate as validation. CSA added a Service Bill of Materials control in CCM v4.1 in January 2026. DataGrail: 63.6% of AI vendors don’t disclose their subprocessors in legal documentation.
Microsoft SSPA Data Protection Requirements v12 (§K). CSA Cloud Controls Matrix v4.1, 27 January 2026. DataGrail 2026 Privacy and AI Trends Report, 27 May 2026.
Primary source →Shared by all of them: a complete, current list of every third-party application and service in use, and what regulated or customer data each one touches.
Your auditor adds an owner and a data classification per asset, and reads the subservice organisations named in your report at every renewal. SOC 2 CC6.1 and CC9.2.
Your contract adds a subprocessor list you must keep current, with 30 days’ notice of any change. Standard Contractual Clauses, Module Two.
Your buyer’s AI programme adds every AI system and its subprocessors, disclosed by name. Microsoft SSPA Section K and CSA CCM v4.1.
None of these start with a policy. They all start with a list, and the list is the part nobody has.
Torii produces and maintains that list. It does not write your attestation or fill your audit workbook. It gives you the inventory those artefacts are built from, with an owner and a data classification per application, and keeps it current in the months between audits.
From Torii’s 2026 SaaS Benchmark, based on discovery between January and December 2025. We count applications found through browser activity, OAuth grants and direct sign-ups — not only those visible in spend or SSO — which is why these figures run higher than licence-based benchmarks.
Two weeks
Read-only discovery across browser activity, OAuth grants and direct sign-ups. No agent on endpoints, no policy change, no announcement to staff.
One week
You get the inventory with an owner and a data classification per application, plus the overlap map. This is the artefact your auditors and your customers' security reviews both draw from.
Then decide
Sanction, consolidate or retire — with the register as the input to that decision rather than the output of a survey.
Here’s what we promise.
We’ll get you up and running with a pilot project so you can verify results before signing a contract.
Two weeks, read-only, no endpoint agent, no change to user-facing systems. Nothing to unwind if you walk away.
Data deletion certified on termination, the same standard your own customers hold you to in a vendor security review.
Linked here, not gated behind a call.
Estimated annual recovery
Licence waste we would expect to surface in the first two weeks of discovery.
15 you would name. The other 3,560 is where most of the recovery hides.
Likely candidates in your stack
AI spend — not counted in the figure above
This is not waste and we’re not proposing you cut it. It’s the spend most likely to be running across several vendors at once, on consumption pricing, with no single owner and no single total.
A model, not a measurement. Built from published list pricing and typical attach rates, August 2026. Application names and logos are likely candidates in an estate of this size — not claims about any vendor, and no vendor endorsement is implied. Real discovery differs in both directions.
Pick your company size and drop your work email — we’ll match you with the right rep and send times that work.
Rachel Castan
Account Executive
You pick a time that works for you.
You have a 30-minute call with Rachel — get every question answered, see if it’s a good fit, and if so, map out a plan together.
Initiate a pilot project on your terms.
You get an inventory extract afterwards — whether or not you continue.