Ukraine solidarity. Service offered free to Ukrainian businesses for as long as the war lasts. Request free access
01 / Simulator · actuarial order of magnitude

When will your next secret leak
happen ?

Rare events eventually happen. This simulator estimates, from a profile you enter on this page, the statistical probability that a secret leak will affect your organisation at one year, five years, ten years, and thirty years (a career).

- Saved profiles
- Most represented sector
- Median annual probability
- Without a password manager

No profiles saved yet · be the first.

02 / Simulator

Enter your profile,read your exposure.

The entire calculation runs in your browser. No data is sent to our servers unless you explicitly click “Save my result”.

Your profile

Current hygiene practices
Known incident in the past 5 years

Your estimated exposure

Annual probability

2,3 %

chance of a leak this year

Median horizon

14 years

until the next probable breach

Cumulative probability over time

Horizon Cumulative probability
Over 1 year 2,3 %
Over 5 years 11 %
Over 10 years 21 %
Over 30 years (career) 50 %

Download your PDF report or anonymously save your profile to contribute to aggregated statistics.

03 / Actuarial methodology

The formula,the weightings, the figures.

This page details the coefficients used, sources and limitations of the actuarial model. Everything is public, reproducible and open to discussion.

Actuarial propagation formula

The cumulative probability over N years is calculated from the independent annual probability P using the geometric distribution formula:

P_cumulative = 1 − (1 − P)^N

This formula assumes year-on-year independence · a reasonable assumption provided no incident has occurred, meaning no structural vulnerability has been revealed.

Annual P 5 years 10 years 30 years
0,1 %0,5 %1,0 %3,0 %
0,5 %2,5 %4,9 %14 %
1,0 %4,9 %9,6 %26 %
2,0 %9,6 %18 %45 %
5,0 %23 %40 %79 %

Key reading. An event with a 1% annual probability seems negligible in isolation, but represents a 26% probability over a 30-year career.

Weightings applied to the calculation

Sector baseline

Consulting & services: 2.0%. Tech & software, legal, other: 2.5%. Industry, public sector: 3.0%. Retail & e-commerce: 3.5%. Finance & banking: 4.0%. Healthcare: 4.5%. Figures smoothed over the last three editions of the Verizon DBIR, cross-referenced with average per-incident cost from IBM Cost of a Data Breach.

Size factor

Below 50 employees, the baseline is not adjusted. Beyond that, the increase is sub-linear on a decimal logarithm scale: an organisation of 1,000 people is not exposed 20× more than one of 50, but approximately 3.3×.

Hygiene multipliers

Generalised MFA: × 0.55 (approx. −45%). Password manager for entire team: × 0.65 (approx. −35%). Audit in the last 12 months: × 0.85 (approx. −15%). All three are multiplicative and therefore cumulative.

Prior incident

Incident in the last 5 years: × 1.6 (a past incident reveals an unaddressed structural vulnerability). No known incident: × 0.9. “Don't know”: × 1.05 (lack of incident awareness signals a detection gap).

04 / Use cases

Who isthis simulator, in practice.

Three typical profiles use this simulator in a professional context. In all three cases, the goal is to have a quantified, defensible benchmark for board meetings or auditor reviews.

CISO

Prepare a cyber budget

Converting an annual probability into cumulative exposure over five and ten years gives the board a figure comparable to the cost of a password manager or a PASSI audit.

DPO

Feed a PIA

A data protection impact assessment requires an “incident probability” component in the risk profile. The simulator result, together with the sources and methodology published on this page, constitutes a defensible benchmark.

Security buyer

Compare solutions

The simulator quantifies the exposure delta between a current state (no generalised MFA, no password manager) and a target state (all three boxes ticked).

05 / Tooling lever

Why a vaultchanges the actuarial picture.

A zero-knowledge B2B vault does not change your industry sector or team size. However, it acts on the three measurable hygiene multipliers: it shifts the annual probability by a factor of 0.3 to 0.5 on a comparable baseline.

Phishing via reused credentials

A secrets manager eliminates password reuse between professional and personal accounts. DBIR statistics show approximately 40% fewer identity-related incidents in organisations that have deployed an enterprise password manager.

Elimination of cleartext sharing

Emails, Slack, shared notes, CSV files · every cleartext transmission of a secret is an untracked exfiltration vector. A B2B vault replaces these flows with client-side encrypted sharing (zero-knowledge), with instant revocation and access logging.

Verifiable HMAC audit chain

Every access to a secret is sealed by HMAC-SHA-256 in an audit chain you can independently verify via a public CLI command · without relying on a proprietary binary.

06 / Sources and calibration

Public reports usedfor calibration.

The four following reports form the calibration dataset. All are public, annual and downloadable from their respective publishers.

  • IBM Cost of a Data Breach Report (annual) · frequency and cost of incidents by company size and sector.
  • Verizon Data Breach Investigations Report (annual) · breakdown of incident vectors (phishing, employee departure, device theft, supplier compromise).
  • ENISA Threat Landscape Report (annual) · European threat landscape, NIS2 regulatory context.
  • ANSSI Cyber Threat Overview (annual) · figures calibrated to the French context and OIV sectors.

Assumed limits. This simulator is an order of magnitude, not an audit. It gives you a benchmark to decide whether a review of your secrets management is worthwhile. For a formal, documented audit of your architecture, consult an ANSSI-listed PASSI provider. ARDNTECH EI cannot be held liable for any decision made solely on the basis of this tool.

07 / FAQ

Questionsfrequently asked about the simulator.

The most frequently asked questions about how the simulator works, data privacy and the meaning of the probabilities produced.

Is my data sent to ARDNTECH?

No, unless you explicitly click “Save my result”. The entire calculation runs in your browser via a public Stimulus controller. No network call is triggered by simply moving the sliders or changing the checkboxes.

How are these probabilities calibrated?

The sector baseline coefficients come from the Verizon DBIR smoothed over three editions. The hygiene multipliers (MFA, password manager, annual audit) are calibrated from the same report's “controls effectiveness” appendix, cross-referenced with IBM Cost of a Data Breach data. Details are published in the Methodology section of this page.

What happens to my PDF report?

The PDF report is generated on demand server-side, streamed in response to your button click, and is neither stored nor indexed on the server. The HTTP header {Content-Disposition: attachment} forces direct download. You receive a self-contained PDF you can keep, share or attach to a risk dossier.

Why 30 years as the horizon?

30 years is the span of a professional career. It is the timeframe that makes actuarial propagation of an annual risk tangible: an event with a 2% annual probability reaches 45% cumulative probability over 30 years · a figure that resonates with a board of directors where “2% this year” remains abstract.

My sector is not listed, what should I choose?

Choose the sector closest in terms of attack surface and attacker targeting. A cybersecurity consultancy would choose “Consulting / services”. A fintech is better represented by “Finance / banking” than “Tech / software”.

Does a PASSI audit replace this simulator?

No, they serve different purposes. This simulator produces a statistical order of magnitude in seconds, without access to your information system. An ANSSI-listed PASSI audit produces a factual, documented assessment of your actual architecture, configurations and processes. The simulator may justify commissioning an audit; it does not replace one.

Does ARDNTECH store the saved profiles?

Only in anonymised form: headcount bracket (bucket “2–10”, “11–50”, etc.), normalised sector from the nine available, three hygiene booleans, incident history and the calculated result. No IP address, user agent or session identifier is retained.

How do I remove my profile from the aggregated stats?

As profiles are anonymised at source, there is no identifier that would allow us to locate yours among the aggregated data. If you wish to have the file containing your contribution deleted, contact us via the contact page: we will delete the corresponding JSONL file within 72 hours.

08 / To go further

Go deeper into each lever mentioned in the methodology: zero-knowledge architecture, HMAC audit chain, jurisdictional sovereignty, target sectors.

B2B vault France

For organisations seeking a vault hosted in mainland France, operated by a French-law company, with no American subcontractor in the data path.

Read the page

Verifiable HMAC audit chain

HMAC-SHA-256 sealing of every event in an audit chain independently verifiable via the CLI · without relying on a proprietary binary.

Read the page

Alternative to the Cloud Act

Why a vault hosted in France, with French capital, structurally escapes extra-European CLOUD Act requisitions.

Read the page

Security architecture

Detailed cryptographic choices: OpenPGP.js v6, Argon2id (RFC 9106), AES-256-GCM SEIPDv2, HMAC-SHA-256 RFC 2104. For CISOs and PASSI auditors.

Read the page

Industry verticals

Five B2B sectors prioritised: cybersecurity consulting, tech law firms, HDS healthcare, defence, energy and OIV. Each with its specific regulatory requirements.

Read the page

Pricing and plans

Free for life up to 3 users, Team plan at €4/seat/month, Business plan at €7/seat/month with 99.5% SLA, Enterprise on request.

Read the page
09 / Getting started

Turn the order of magnitude
into an action plan.

You now have a quantified estimate of your exposure. The next step is to deploy the only lever that shifts probability by 35 to 65% on measured vectors: a zero-knowledge B2B vault, hosted in France, auditable by your CISO.

Everything encrypted browser-side (zero-knowledge)
AGPL-3.0 code, fully auditable
Hosting in France, French jurisdiction
HMAC audit chain independently verifiable
Multi-organisation pivot account, strict partitioning