Kontolink ApS

Denmark · owned by Independent (Denmark) · app.kontolink.com · 12 vendors

Kontolink is a Danish fintech/accounting software company that provides cloud-based bookkeeping and accounting automation tools primarily for small and medium-sized businesses. The platform connects bank transactions with accounting systems, enabling automated reconciliation and financial reporting. It is designed to simplify compliance with Danish accounting standards.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 3

12 direct vendors, 193 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Kontolink ApS demonstrates medium migration readiness. The company's internal tech stack is a significant strength, featuring a cloud-based SaaS architecture, a modern SPA/PWA framework (likely React or Angular), and extensive API integrations for Open Banking/PSD2 and Danish accounting platforms (e-conomic, Dinero). This modern, API-driven, and cloud-oriented foundation suggests a high technical capability for migrating to new environments or refactoring services. However, several critical unknowns and potential complexities reduce the overall readiness. The vendor lock-in risk is explicitly stated as 'Unknown,' which is a major concern; high lock-in could make migration prohibitively complex and costly. Similarly, data residency requirements are unknown, a crucial factor for a financial services company operating within the EU, potentially imposing strict geographical constraints on data movement. Financial stability data is also unavailable, which is vital for assessing the company's capacity to fund a significant migration project. While Kontolink uses 'Danish financial compliance tooling,' the regulatory environment, including the undetermined applicability of NIS2, adds a layer of complexity that must be thoroughly assessed before migration. The contradiction of 'Total Vendors: 0' with 'Total Services: 15' and diverse vendor geographies means the exact number of distinct vendors is unknown, preventing a direct assessment of vendor concentration for migration complexity. Despite a strong technical foundation, these substantial unknowns regarding vendor relationships, data residency, and financial capacity place Kontolink ApS in the medium readiness category.

Compliance

9 in-scope frameworks identified; showing 3.

eIDAS — Assessment Required

eIDAS (Regulation (EU) No 910/2014) and the upcoming eIDAS 2.0 regulation govern electronic identification and trust services across the EU. For Kontolink, eIDAS is relevant if the platform uses electronic signatures, electronic seals, or electronic invoicing with trust service providers. Risk is Low because: (1) eIDAS compliance is typically handled through integration with certified trust service providers rather than direct certification; (2) the primary obligation is to use qualified trust services where required; (3) Danish NemID/MitID integration (the national eID system) is the primary authentication mechanism for Danish digital services.

Evidence: https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation, https://www.digst.dk/digital-identitet/mitid/, https://esignature.ec.europa.eu/efda/tl-browser/

GDPR (source) — Assessment Required

Kontolink ApS is headquartered in Denmark, an EU member state, making GDPR unconditionally applicable. As a financial/accounting SaaS platform, Kontolink processes highly sensitive personal data including financial records, transaction data, business owner information, employee payroll data, and accountant credentials — all of which constitute personal data under GDPR Article 4. The risk level is High because: (1) financial data is among the most sensitive categories processed at scale; (2) Danish Datatilsynet (the DPA) is an active enforcement authority with a track record of issuing fines; (3) SaaS platforms acting as both data controllers and data processors face dual compliance obligations; (4) any breach involving financial personal data triggers mandatory 72-hour notification under Article 33; (5) non-compliance fines can reach €20M or 4% of global annual turnover under Article 83(5).

Evidence: https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679, https://www.datatilsynet.dk/afgoerelser-domme-og-udtalelser/afgoerelser, https://app.kontolink.com

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework but is increasingly required by enterprise customers of SaaS/cloud providers, particularly those in financial services. As a financial accounting SaaS platform, Kontolink's enterprise and mid-market customers (accountants, businesses) may contractually require SOC 2 Type II reports as part of vendor due diligence. Risk is Medium because: (1) absence of SOC 2 certification can be a commercial barrier and a trust signal gap; (2) financial data processed by Kontolink makes security assurance critical; (3) Danish and EU enterprise customers increasingly request SOC 2 or equivalent (ISAE 3402) reports; (4) no public SOC 2 report has been identified, which may indicate non-certification.

Evidence: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services, https://app.kontolink.com

Financials

Three-year financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report