AdOpt
Brazil · goadopt.io · 13 vendors
AdOpt is a platform that provides privacy compliance solutions for businesses. It offers cookie management and consent solutions to help companies comply with various international data protection regulations such as GDPR, LGPD, and CCPA. The platform ensures transparency for users regarding data collection and manages consent records.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 5
- Financial Resilience: 5
Technology vendors
- HubSpot, Inc. — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 10 more
Services catalogue
1 service in catalogue across 1 category; runs on 13 sub-vendors.
- AdOpt
Insights
Last updated 2026-08-19 · revision 7
13 direct vendors, 245 subvendors
Direct vendors by controlling owner country (sample)
- United States: 11
- Belgium: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Cyprus: 1
- Bulgaria: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
AdOpt demonstrates medium migration readiness, largely due to a modern and adaptable internal tech stack. The use of Next.js, React, and Strapi CMS provides a strong foundation for cloud-native deployments, containerization, and microservices architectures, facilitating technical migration. However, several factors present significant challenges. Strict data residency requirements under LGPD (and potentially GDPR if EU data is processed) will heavily influence cloud provider and region selection, potentially limiting options and increasing complexity. The 'Assessment Required' status for GDPR, SOC2, and ISO 27001 indicates that a migration project would likely need to address these compliance gaps, adding scope and cost. The company's 100% revenue concentration by product and geography, coupled with null growth history, suggests potential financial constraints that could impact the funding and execution of a large-scale migration. The vendor situation, with 'Total Vendors: 0' but 25 services and low geographic diversity, implies either high vendor lock-in if services are from a few providers, or high complexity if many services are unmanaged, both of which could complicate migration efforts.
Compliance
10 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is relevant to AdOpt as a SaaS provider handling sensitive consent data for 50,000+ websites. Risk is Medium because: (1) AdOpt processes consent records containing personal data (IP addresses, browser identifiers, user consent choices) at scale, requiring robust information security management; (2) enterprise clients (Nike, LEGO, Bradesco Seguros, Caixa Econômica Federal) may require ISO 27001 certification as part of vendor qualification; (3) without ISO 27001, AdOpt's information security posture cannot be independently verified; (4) as a privacy technology company, the reputational damage from a security breach would be particularly severe; (5) however, ISO 27001 certification is resource-intensive and many SaaS startups of AdOpt's size (founded 2020) have not yet pursued it.
Evidence: https://goadopt.io, https://www.iso.org/standard/27001, https://goadopt.io/plans/
ANPD Regulatory Framework — Assessment Required
The ANPD is Brazil's data protection authority responsible for enforcing LGPD. AdOpt, as a major CMP provider in Brazil serving 50,000+ websites, is directly within ANPD's regulatory scope. Risk is High because: (1) ANPD has been increasingly active in issuing guidance, conducting investigations, and applying sanctions since 2021; (2) AdOpt processes consent data for millions of Brazilian internet users across its client base; (3) as a data processor for thousands of Brazilian companies, AdOpt's compliance posture directly affects its clients' LGPD compliance; (4) ANPD issued its Cookie Guidelines in October 2022, directly impacting AdOpt's product requirements; (5) no evidence of ANPD registration, formal compliance assessment, or DPO appointment was found publicly.
Evidence: https://www.gov.br/anpd/pt-br, https://goadopt.io/blog/anpd-cookies-guia-orientativo-cookies-protecao-dados-pessoais/, https://goadopt.io/blog/lgpd-lei-geral-de-protecao-de-dados/
LGPD — Partially Compliant
LGPD is AdOpt's core business domain — the company was founded specifically to help other organizations comply with LGPD. As a data processor and controller operating in Brazil, AdOpt itself is directly subject to LGPD (Lei 13.709/2018). The risk level is High because: (1) AdOpt processes personal data of Brazilian users on behalf of 50,000+ client websites, making it both a controller and a processor under LGPD; (2) as a CMP provider, AdOpt stores consent records containing personal data (IP addresses, browser identifiers, timestamps) for all end-users of its clients' websites; (3) enforcement by ANPD (Autoridade Nacional de Proteção de Dados) is actively increasing, with fines up to 2% of annual revenue or BRL 50 million per infraction; (4) AdOpt's own website demonstrates LGPD compliance tooling (cookie banner, DPO notifications, opt-out portal), suggesting awareness but no independent third-party audit evidence was found confirming full organizational compliance beyond the product layer; (5) as a SaaS platform processing consent data at scale, any breach or non-compliance would be highly visible and reputationally damaging. Status is 'Partially Compliant' because AdOpt visibly implements LGPD-required mechanisms (cookie consent, DPO role, data subject request portal) but no formal ANPD audit, third-party LGPD compliance certification, or public DPO appointment disclosure was found.
Evidence: https://goadopt.io, https://goadopt.io/blog/lgpd-lei-geral-de-protecao-de-dados/, https://www.gov.br/anpd/pt-br, https://goadopt.io/blog/cookies-e-lgpd/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 5/10
AdOpt (GO ADOPT, LLC) is a privately held US-LLC-structured, Brazil-focused SaaS startup in the consent management platform space, founded in 2020. No public financial statements are available because the company is a private LLC not subject to SEC disclosure requirements, and no Brazilian S.A. filings exist. Therefore, financial resilience must be assessed qualitatively rather than quantitatively. On the positive side, the company operates a recurring SaaS revenue model with predictable ARR characteristics, boasts a diversified customer base including major Brazilian corporates (Caixa Econômica Federal, Bradesco Seguros, OLX, Centauro, Exame, Governo do Rio de Janeiro) and global brands (Nike, LEGO, Reebok, Kipling, Crocs, Remax), and benefits from strong regulatory tailwinds from LGPD enforcement in Brazil and expanding US state privacy laws. The company holds valuable certifications as a Google CMP Partner and IAB Europe TCF 2.2 registered vendor, has reached 50,000+ websites globally, and has a low capital intensity business model. However, significant risks exist: the company competes against much larger, better-funded players like OneTrust, Cookiebot (Usercentrics), Didomi, Osano, and TrustArc; its aggressive pricing (US$12-29/month) suggests low ARPU and heavy dependence on volume; there is FX mismatch risk between USD pricing and BRL costs; the business is entirely dependent on continued privacy law enforcement; and no funding rounds have been publicly disclosed, making cash runway resilience unverifiable. The score of 5 reflects balanced qualitative positives against unknown financial fundamentals.
Key strengths: Recurring SaaS revenue model with annual and monthly subscriptions (20% annual discount), Diversified blue-chip client base including Caixa Econômica Federal, Bradesco Seguros, OLX, Nike, LEGO, Regulatory tailwinds from LGPD enforcement and expanding US state privacy laws, Google CMP Partner and IAB Europe TCF 2.2 registered vendor certifications, 50,000+ websites using the platform globally, High G2 ratings including #1 'Easiest to Use' in CMP category, Low capital intensity SaaS cost structure
Risk factors: Small player competing against much larger CMPs (OneTrust, Cookiebot, Didomi, Osano, TrustArc), Low ARPU with aggressive pricing (US$12-29/month) suggesting volume dependence, FX exposure between USD pricing and likely BRL cost base, Business entirely dependent on continued privacy regulation enforcement, No disclosed funding rounds - cash runway resilience cannot be verified, Founder / key person risk typical for small startups, No management team disclosed publicly
Revenue by product/service
- Consent Management Platform (Business/Pro/Enterprise SaaS): 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.