Bombora
United States · bombora.com · 16 vendors
Resilience scores
- Digital Sovereignty: 63
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Sage Intacct — Technology — United States
- and 15 more
Services catalogue
2 services in catalogue across 1 category; runs on 16 sub-vendors.
- Bombora
- Company Surge® Intent Data
Insights
Last updated 2026-08-04 · revision 2
16 direct vendors, 230 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- United States: 10
- United Kingdom: 2
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Poland: 1
- Belgium: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Bombora exhibits a very high level of migration readiness, largely due to its highly modern and cloud-native internal tech stack. The extensive use of technologies like Kubernetes and Docker indicates a strong adoption of containerization and microservices architectures, which are fundamental enablers for seamless cloud migration and hybrid cloud strategies. The presence of cloud data platforms such as Snowflake and Google BigQuery, along with infrastructure-as-code tools like Terraform, further suggests that Bombora is either already significantly migrated or possesses the foundational elements for efficient and agile migration to cloud environments. The use of Python, Java, and Scala, combined with big data and machine learning frameworks (Apache Spark, TensorFlow), points to a sophisticated and adaptable development environment. While the tech stack is a major strength, the assessment is limited by the lack of data concerning financial stability (which impacts the ability to fund migration efforts), specific regulatory environments, and data residency requirements. These factors could introduce complexities or constraints during a migration. The 'Vendor Lock-in Risk' is explicitly stated as unknown. Although 'Total Vendors: 0' is provided, the existence of 'Total Services: 20' from vendors across 6 countries suggests a moderate level of vendor relationships. Without details on the number of distinct vendors or contract complexities, a precise assessment of vendor lock-in is challenging, but the modern tech stack suggests a high degree of architectural flexibility that could mitigate potential vendor lock-in challenges.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Bombora is a US-headquartered B2B data broker and intent data provider that explicitly processes personal data of individuals located in the EEA, UK, and Switzerland, as confirmed by its own Privacy Policy (last updated February 6, 2026), which includes a dedicated 'EEA/UK Supplemental Privacy Notice.' The company collects and processes a wide range of personal data including IP addresses, device identifiers, email addresses, behavioral/engagement data, geolocation, and professional information from EEA residents. As a data broker operating at scale — processing 'billions of consumption events per month' — the risk of non-compliance is elevated. Bombora relies on IAB TCF v2.2 (Transparency and Consent Framework) as a consent mechanism (Vendor ID 163), which has faced regulatory scrutiny across the EU. The company uses a third-party EEA representative (Lionheart Squared, Dublin) rather than an in-house DPO, which may be insufficient given the scale of processing. Fines under GDPR can reach €20M or 4% of global annual turnover. The risk level is High due to the volume and sensitivity of data processed, the complexity of the data broker model, and ongoing EU regulatory scrutiny of adtech and intent data companies.
Evidence: https://bombora.com/privacy-policy/, https://bombora.com/privacy-philosophy/, https://bombora.com/opt-out/, https://preferences.bombora.com/privacy, https://bombora.com/cookie-statement/
CPRA — Partially Compliant
Bombora is headquartered in New York but operates nationally and processes personal data of California residents at scale. The company is explicitly subject to CCPA/CPRA as a data broker. Bombora's Privacy Policy includes a dedicated 'CA Privacy Rights' section and acknowledges selling personal information categories including identifiers, personal information, protected classification characteristics, internet activity, and geolocation data. As a data broker, Bombora is required to register with the California Privacy Protection Agency (CPPA). The company provides opt-out mechanisms and CCPA metrics reporting. Risk is High because: (1) Bombora's core business model involves selling/sharing personal data — the highest-risk CCPA activity; (2) CPRA introduced enhanced rights and enforcement; (3) the CPPA has increased enforcement activity; (4) data broker registration requirements under AB 1202 and the new Delete Act (SB 362, effective 2024) impose additional obligations. CCPA metrics are published at the URL referenced in the Privacy Policy.
Evidence: https://bombora.com/privacy-policy/, https://preferences.bombora.com/, https://bombora.com/opt-out/, https://bombora.com/wp-content/uploads/2026/07/CCPA-Databroker-2025-Reporting.pdf
EU-US Data Privacy Framework — Assessment Required
Bombora's Privacy Policy explicitly states that servers and facilities are operated in the United States and that personal data of EEA/UK residents is transferred internationally. The policy acknowledges that 'countries may have data protection laws that differ from those of your country.' However, the specific legal mechanism used for EEA-to-US data transfers (EU-US Data Privacy Framework certification, Standard Contractual Clauses, or Binding Corporate Rules) is not publicly disclosed. Risk is High because: (1) invalid transfer mechanisms could render all EEA data processing unlawful; (2) the EU-US DPF faces ongoing legal challenges (Max Schrems/NOYB); (3) failure to implement adequate transfer safeguards is a top GDPR enforcement priority.
Evidence: https://bombora.com/privacy-policy/, https://www.dataprivacyframework.gov/, https://bombora.com/privacy-philosophy/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Bombora is a privately held U.S. B2B Intent data company that does not disclose revenue, EBIT, or equity figures. Despite the lack of transparency, qualitative signals suggest a resilient business: the CEO reports near-100% annual customer retention, implying strong recurring revenue characteristics, and the company holds a category-leadership position recognized by Forrester as the 'gold standard' in the Q1 2025 Wave for B2B Intent Data Providers. Its Data Co-op — with 86% of data shared exclusively with Bombora and 1,743 new B2B sources added in 2024 — creates a defensible moat described by the CEO as 'impossible to replicate.' The company has scaled to approximately 160 employees over 10 years with what appears to be capital-efficient growth, given the modest publicly disclosed funding relative to its category leadership. Third-party estimates place revenue in the ~$50–100M range, though these are unverified. Broad partner integrations (The Trade Desk, LiveRamp, 6sense, Salesforce, HubSpot, LinkedIn, Adobe, Reddit, StackAdapt, Dun & Bradstreet) diversify distribution channels and reduce single-partner dependency. Offsetting these strengths are notable risks: no public financial transparency prevents independent verification of profitability or cash position; exposure to the cyclical B2B marketing/advertising spend cycle; rising privacy/regulatory pressure (GDPR, CCPA/CPRA, cookie deprecation); and structural risks from generative AI disrupting publisher partners that supply the Co-op. Competitive intensity is high, with better-capitalized players such as 6sense, Demandbase, ZoomInfo, and LinkedIn. Overall, the qualitative evidence supports a moderately strong resilience profile, but the absence of hard financial data caps confidence.
Key strengths: Category leadership recognized by Forrester as 'gold standard' (Q1 2025 Wave), Near-100% annual customer retention per CEO, Defensible Data Co-op moat with 86% exclusive data, Broad partner/integration footprint (50+ integrations), Product breadth beyond Intent (Identity, Digital Audiences, B2beacon), 10 years of operating history and capital-efficient growth, Multiple industry awards (Great Place to Work, G2 Leader, Stevie Award)
Risk factors: No public financial transparency — unverifiable revenue, profitability, or balance sheet, Dependence on cyclical B2B marketing/advertising spend, Privacy and regulatory risk (GDPR, CCPA/CPRA, cookie deprecation), Intense competition from better-capitalized rivals (6sense, Demandbase, ZoomInfo, LinkedIn), Generative AI disrupting publisher partners in the Data Co-op, Structural dependency on Data Co-op publisher retention
Revenue by geography
- APAC: 0%
- EMEA: 0%
- North America: 0%
Revenue by product/service
- B2B Digital Audiences: 0%
- Identity & Enrichment: 0%
- Company Surge Intent Data: 0%
- B2beacon Campaign Measurement: 0%
Workforce by country
- Australia: 0
- United States: 0
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.