Branch

United States · www.branch.io · 23 vendors

Branch is a technology company that provides a mobile linking and measurement platform. It offers deep linking and attribution solutions to help app developers and marketers acquire, engage, and measure user behavior across various devices and channels. The platform aims to optimize marketing ROI and create seamless, personalized user experiences.

Resilience scores

Disruption prediction

Branch has an estimated 11% probability of disruption in the next 6 months.

16 of Branch's 23 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 4 categories; runs on 23 sub-vendors.

Insights

Last updated 2026-08-11 · revision 1

23 direct vendors, 266 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Branch's migration readiness is bolstered by its existing cloud-based infrastructure on Amazon Web Services (AWS), which provides a flexible and scalable foundation for potential migrations. The use of REST APIs and Webhooks in its internal tech stack suggests a modular architecture, which typically facilitates easier migration compared to monolithic systems. Furthermore, the company's strong commitment to compliance, evidenced by SOC 2, ISO 27001, GDPR/CCPA infrastructure, and HIPAA BAA support, means it has established processes and expertise to handle regulatory requirements during a migration. Significant challenges and unknowns exist. There is no specified data residency requirement, which could introduce substantial complexity and cost if strict rules apply to customer data. Financial stability data (revenue concentration, growth history) is missing, making it difficult to assess the company's capacity to fund a potentially large-scale migration. The vendor relationship data is ambiguous; while "Total Vendors: 0" is stated, other details imply vendor relationships for 25 services across various countries. The actual number of distinct vendors and the associated lock-in risk remain unknown, which is a critical factor for migration planning. The tech stack does not explicitly mention containerization (e.g., Docker, Kubernetes) or a fully microservices architecture, which could indicate further modernization efforts might be needed to achieve optimal cloud-native readiness.

Compliance

13 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 (Assurance Engagements Other than Audits or Reviews of Historical Financial Information) is the international standard used for non-financial assurance reporting, including privacy and sustainability assurance. It is the international equivalent framework to SOC2 (which uses AT-C 205 in the US). Branch's AICPA logo on its security page suggests engagement with assurance frameworks. However, no explicit ISAE 3000 report or engagement was found in publicly accessible Branch documentation. Risk is Low because: (1) ISAE 3000 is not a mandatory regulatory requirement for Branch's industry or geography; (2) Branch's ISO certifications (particularly ISO 27001 and ISO 27701) provide equivalent or superior assurance for most purposes; (3) ISAE 3000 reports are typically requested by specific enterprise clients in certain jurisdictions (particularly Europe) rather than being universally required.

Evidence: https://www.branch.io/security/, https://legal.branch.io/saas/information-security-privacy-standards/

COPPA — Compliant

Branch explicitly addresses COPPA in its Privacy Policy and Terms & Conditions. Branch prohibits clients from providing data relating to children under 13 (or under 18 in certain jurisdictions) and provides SDK Privacy Controls to help clients comply with COPPA. Risk is Low because Branch has implemented contractual and technical controls to prevent COPPA-regulated data from entering its platform.

Evidence: https://legal.branch.io/saas/privacy-policy/, https://help.branch.io/developers-hub/docs/honoring-opt-out-of-processing-requests

ISO 27701 — Compliant

Branch holds ISO 27701 certification, which is the international standard for Privacy Information Management Systems (PIMS) and extends ISO 27001/27002 with privacy-specific controls. This certification is directly relevant to GDPR compliance and demonstrates a mature, audited privacy management program. Risk is Low because the certification is confirmed and publicly disclosed.

Evidence: https://www.branch.io/security/, https://www.iso.org/

Financials

Three-year financials

Financial Resilience Score: 6/10

Branch is a private, venture-backed SaaS company with substantial equity capital raised (~US$680M+ cumulatively) and a peak private valuation of ~US$4B set in February 2022. This capital base, combined with a scaled enterprise customer footprint (~100,000 brands, marquee logos including Instacart, Reddit, Shopify, Credit Karma), suggests meaningful runway and a defensible market position as one of the largest independent Mobile Measurement Partners alongside AppsFlyer. Recurring SaaS-style revenue, deep technology moats in cross-platform attribution, and integrations with 2,000+ partners create customer switching costs that support revenue stickiness. However, resilience is materially constrained by several factors. The 2022 valuation was set at the peak of the SaaS multiple cycle, and comparable MarTech/AdTech private valuations have contracted 40-70% since, exposing Branch to down-round risk. Publicly reported layoffs in 2022 and 2023 indicate active burn management rather than profitable operations. Structural headwinds from Apple's ATT/SKAdNetwork and Google's Privacy Sandbox shrink the attribution TAM, while competition from AppsFlyer, Adjust (AppLovin), Kochava, and Singular remains intense. Critically, no revenue, EBIT, or equity figures are publicly disclosed, preventing independent verification of profitability or cash burn — this opacity itself is a resilience concern for external stakeholders.

Key strengths: ~US$680M+ cumulative equity raised across Series A through F, ~US$4B post-money valuation (Feb 2022 Series F), Scaled enterprise customer base (~100,000 brands, 3.5B users), Marquee customer logos (Instacart, Reddit, Shopify, Credit Karma, Warner Bros. Discovery), 2,000+ platform/partner integrations creating switching costs, Diversified vertical exposure (retail, finance, health, travel, media, F&B), Product expansion into AI (Ivy) and CTV attribution

Risk factors: Down-round risk given 2022 peak-cycle US$4B valuation, Apple ATT/SKAdNetwork and Google Privacy Sandbox shrinking attribution TAM, Intense competition from AppsFlyer, Adjust (AppLovin), Kochava, Singular, Publicly reported workforce reductions in 2022 and 2023, No public disclosure of revenue, EBIT, gross margin, or cash burn, Platform/policy dependency on mobile OS ecosystem, Risk of disintermediation by Apple SKAN and Google native attribution

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report