Offline · No install · Open source

Risk analysis,
from inherent to residual

A standalone, methodology-agnostic risk-analysis editor: define your grid, enter risks and controls, and visualize the shift from inherent to residual risk — matrices, trajectories, action plan and report. The whole analysis fits in a single open .rae.json file.

🔒 No data ever leaves your computer 📄 Single HTML file 🌍 EN · FR · IT ⚖️ MIT license
risk-analysis-editor.html
Features

The whole risk-analysis cycle

Configure the grid, identify and score, treat, visualize, track and publish — without leaving the tool.

🔒

Standalone & offline

A single HTML file, no dependency, no server. Open the analysis with a double-click; nothing leaves your computer.

🎛️

Methodology-agnostic

Tailored grid: free axes and levels, product / sum / cell-by-cell matrix scoring, criticality zones, custom fields.

📉

Above-standard visualization

Inherent/residual matrices and arrowed trajectories, multiple layouts, manual placement, PNG and SVG exports.

📄

Open format

The .rae.json is documented and validated by a JSON schema. CSV import/export, plus Word and Excel exports generated locally.

🔎

Filtering & customization

Filters propagated along links, a shareable view via plain URL, register columns that show/reorder and are saved.

Tracking & deliverable

Action plan (timeline, kanban, by owner), progress and overdue tracking, printable report ready to share.

Use cases

One tool, several roles

The same generic core serves very different approaches, with ready-to-use templates.

DPO

DPIA — CNIL PIA method

Run the risk part of a data protection impact assessment: feared events, severity × likelihood, existing and planned controls.

  • Ready-to-use DPIA template
  • 4×4 grid in the CNIL spirit
  • Report to attach to the file
CISO · Analyst

EBIOS RM · ISO 27005

Score, treat and visualize your risk scenarios. Start from a template and adapt the grid to your scale.

  • EBIOS RM and ISO 27005 templates
  • Sources, assets, effects as custom fields
  • Before / after trajectories
Quality · Project · Compliance

Your own method

A fully configurable probability × severity matrix, without the weight of an enterprise GRC suite.

  • Tailored grid and criticalities
  • Custom fields (10 types)
  • Sharing via a single file
Demos

Open a complete analysis in one click

Two fictional demo analyses, ready to explore in your browser.

EBIOS RM

Information system

An EBIOS RM–inspired risk analysis: risk sources, scenarios, controls and trajectories.

12 risks · 11 controls Open the demo
DPIA · CNIL PIA

Occupational health service

A data protection impact assessment: feared events, controls and report.

12 risks · 12 controls Open the demo
🔒 Your data never leaves your computer.

No account, no server, no upload — even the Word and Excel exports are generated in your browser.

Ready to try?

Open the app, or download the single file to work offline.