Axiomatics AB
Sweden · www.axiomatics.com · 12 vendors
Axiomatics AB is a leading provider of runtime, fine-grained authorization solutions, utilizing attribute-based access control (ABAC) for applications, data, APIs, and microservices. The company's Orchestrated Authorization strategy helps enterprises implement Zero Trust security for critical security implementations. They enable organizations to manage access to sensitive digital assets for enterprises and government agencies.
Resilience scores
- Digital Sovereignty: 25
- Digital Resilience: 7
- Financial Resilience: 5
Disruption prediction
Axiomatics AB has an estimated 10% probability of disruption in the next 6 months.
7 of Axiomatics AB's 12 vendors monitored for disruptions.
Technology vendors
- 6sense — Technology — United States
- Google LLC — Technology — United States
- HubSpot, Inc. — Technology — United States
- and 9 more
Services catalogue
3 services in catalogue across 3 categories; runs on 12 sub-vendors.
- Logging and observability
- Personal Data Processing
- Policy-based access control
Insights
Last updated 2026-07-30 · revision 7
12 direct vendors, 180 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Bulgaria: 1
- France: 1
Subvendors by controlling owner country (sample)
- Canada: 6
- United Kingdom: 4
- South Korea: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Axiomatics AB exhibits a medium level of migration readiness. A significant strength is their core product architecture, which heavily leverages modern, cloud-native principles such as Microservices Authorization, Policy-as-Code, REST APIs, and API Gateway Integration. This indicates a strong internal capability and mindset for adopting cloud environments and modern deployment strategies. The acquisition by Leonardo S.p.A. is also likely to provide the necessary financial resources to fund significant migration initiatives. However, several challenges exist. The most prominent are the complex data residency and sovereignty requirements stemming from GDPR, their EU headquarters, US subsidiaries, and potential defense-related contracts post-acquisition. These factors will necessitate meticulous planning for data placement and compliance in any cloud migration scenario. Furthermore, the pending or unconfirmed status of critical cybersecurity certifications (SOC2, ISO 27001) and the required NIS2 assessment will add complexity and potential delays to a migration, as these would likely need to be addressed as part of or immediately following the transition. The internal use of WordPress, while not central to their product, might require specific modernization or migration strategies. Lastly, the 'Vendor Lock-in Risk' remains unknown, which could present unforeseen challenges if key vendor contracts are difficult to transition or terminate.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
GDPR applies with HIGH confidence as Axiomatics AB is headquartered in Sweden (EU member state) and processes personal data of employees, customers, and website visitors. Non-compliance can result in fines up to 4% of annual turnover or €20M. As a cybersecurity company handling sensitive authorization data, the risk is elevated. Their privacy policy demonstrates GDPR compliance awareness with data subject rights, lawful basis documentation, and DPO contact information.
Evidence: https://axiomatics.com/privacy-policy
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for a cybersecurity company like Axiomatics. Their COO led ISO certification programs, suggesting organizational commitment to information security management. For a company providing authorization and access control solutions to Global 1000 customers, ISO 27001 certification would be expected for competitive positioning and customer requirements.
Evidence: https://axiomatics.com/about-us
NIS2 (source) — Assessment Required
NIS2 applicability requires detailed assessment. Axiomatics provides cybersecurity services and authorization solutions which could classify them as 'digital service providers' under NIS2 Important Entities if they exceed size thresholds (50+ employees or €10M+ turnover). With 60+ employees and Global 1000 customers, they likely meet size criteria. However, specific NIS2 sector classification needs verification. Non-compliance could result in significant penalties and operational restrictions.
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 5/10
Axiomatics AB presents a mixed financial resilience picture that is heavily constrained by the opacity inherent to its private company status. On the positive side, the company has demonstrated remarkable longevity — over 15 years of continuous operation in a competitive niche market — which strongly implies a stable, recurring revenue base anchored by multi-year enterprise and government contracts. Its recognition in KuppingerCole and Gartner analyst reports as a leadership-positioned PBAM vendor further validates its market durability and product credibility. The company's venture capital backing from Paladin Capital Group, while indicative of growth-stage ambitions, also raises the possibility of historical operating losses — a common profile for VC-funded software companies prioritising growth over near-term profitability. Without access to audited Bolagsverket filings, it is impossible to confirm whether Axiomatics has achieved sustainable profitability, what its leverage position looks like, or how its cash position has evolved over time. This opacity materially limits any quantitative resilience assessment. The announced acquisition by Leonardo S.p.A. — a large, publicly listed Italian defence and aerospace conglomerate — is the single most significant resilience factor in the near term. It eliminates funding risk, provides access to a well-capitalised parent's balance sheet, and opens cross-sell opportunities into defence and government markets globally. However, it simultaneously introduces integration risk, potential product roadmap disruption, and workforce uncertainty that are characteristic of post-acquisition transitions. The company's niche positioning, while a strength in terms of specialisation and customer stickiness, also implies scale constraints relative to larger IAM competitors such as SailPoint, Ping Identity, and Saviynt. Customer concentration risk is a meaningful concern given the implied small total customer count. The growing competitive landscape — with new entrants like PlainID, Styra/OPA, Cerbos, and Permit.io — adds further pressure. On balance, a score of 5 reflects a viable but opaque business whose resilience is currently propped up by the Leonardo acquisition rather than independently verifiable financial strength.
Key strengths: 15+ years of continuous operation in a competitive niche market, implying stable customer base, Fortune 1,000 and government customers providing multi-year recurring contract revenue, Strategic acquisition by Leonardo S.p.A. eliminates near-term funding and liquidity risk, Leadership positioning in KuppingerCole and Gartner PBAM analyst reports, Strong partner ecosystem with Deloitte, Accenture, CrowdStrike, MuleSoft, and Splunk, Tailwinds from Zero Trust architecture adoption, GDPR/HIPAA compliance, and AI governance demand, Venture capital backing from Paladin Capital Group supporting growth investment
Risk factors: Complete financial opacity due to private company status — revenue, EBIT, equity, and margins are unconfirmed, VC-backed history implies possible historical operating losses and uncertain path to profitability, Small scale relative to larger IAM competitors (SailPoint, Saviynt, Ping Identity, ForgeRock), Customer concentration risk given niche positioning and implied small total customer count, Post-acquisition integration risk with Leonardo S.p.A. — potential product roadmap and workforce disruption, Increasing competitive pressure from new FGA/PBAM entrants (PlainID, Styra/OPA, Cerbos, Permit.io), No public debt or equity markets access; historical reliance on VC funding rounds
Revenue by geography
- Rest of World: 0%
- North America (United States): 0%
- Europe (Scandinavia and broader EU): 0%
Revenue by product/service
- Maintenance and Support Contracts: 0%
- Professional Services and Implementation Support: 0%
- Software Licenses and/or SaaS Subscriptions (Orchestrated Authorization / XACML Platform): 0%
Workforce by country
- Sweden: 0
- United States: 0
- Total (estimated): 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.