A board-grade risk register that stays on your machine — one HTML file, no server, no accounts, no upload.
RR-001, RR-002… per workspace, from a monotonic counter. Deleting a risk does not recycle its number, so a ref in last quarter's minutes still points at the same thing.pumapack export of every workspace, restored by drag-drop. PumaGRC2 findings arrive the same waySee Method for how these fit together and Keyboard for every shortcut.
A register turns vague worry into a ranked, owned list, so attention and budget go where the exposure actually is. The score is never the goal; the decision it drives is.
The matrix ranks and groups risks; it does not measure them. When a decision needs real numbers, move to loss frequency × loss magnitude estimated in ranges instead of pretending the grid is precise. The 5×5 lineage runs through NIST SP 800-30 Rev 1, ISO 31000 and COSO ERM; the quantitative path is FAIR — see Hubbard & Seiersen, How to Measure Anything in Cybersecurity Risk.
PumaRisk stores everything in your browser's sessionStorage under the pumarisk.* prefix — on this device, in this browser, and nowhere else. There is no server, no account, and nothing you type ever leaves your machine.
sessionStorage is tied to this specific browser on this specific device. Approximate ceiling is ~4.5 MB across all workspaces.
The topbar Export button writes a full backup of every workspace as .pumapack JSON. ⌘S / Ctrl+S writes the same full backup as a .json file. To restore, drag either file onto the window or use the topbar Import button.
Rule of thumb: export weekly. Drop the JSON in iCloud Drive, Dropbox, your Git repo — it's just a file.
⚠ Permanent. This erases every PumaRisk workspace, risk, preference, and theme stored in this browser. Export a backup first — there is no undo.
Still sure? Type DELETE EVERYTHING to finalize.
.json)PumaRisk is a lightweight, portable, offline quantitative risk register that runs entirely in your browser. Build a register, score and rank risks, and model treatment options, all from a single file.
This tool is provided as-is, with no warranties or guarantees. It is not professional advice. By using it you accept full responsibility for any outcomes that result from your use.
PumaWorx is a suite of offline, single-HTML productivity apps that run entirely in your local browser. The entire suite is a personal, open source vibecoding project.
This is an offline single-HTML app. No data goes to or from the internet after this page is loaded. No data you enter is ever transmitted to a server. Your risk register lives in your web browser's sessionStorage — on this device, in this browser, and nowhere else.
Your data is YOUR responsibility.
Clearing browser data, switching browsers, using private/incognito mode, or losing this device erases everything. Use Export in the top toolbar to save a .pumapack backup (or ⌘S for a .json backup) somewhere safe.
The full data-handling section is always available in Help — press ? or open it from the toolbar.