Brave Software, Inc.

United States · brave.com · 38 vendors

Brave Software, Inc. is a technology company that developed the privacy-focused Brave web browser, which blocks ads and trackers by default. The company also offers a private search engine, a cryptocurrency-based rewards system (Basic Attention Token - BAT), a crypto wallet, a VPN, and an AI assistant built into its browser.

Resilience scores

Disruption prediction

Brave Software, Inc. has an estimated 11% probability of disruption in the next 6 months.

18 of Brave Software, Inc.'s 38 vendors monitored for disruptions.

Technology vendors

Services catalogue

8 services in catalogue across 1 category; runs on 38 sub-vendors.

Insights

Last updated 2026-07-30 · revision 7

38 direct vendors, 270 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Brave Software exhibits a medium level of migration readiness. The company's modern and diverse tech stack, built on open-source foundations like Chromium and utilizing languages such as Rust and C++, provides a strong technical basis for adopting new cloud environments or re-platforming. This modularity and use of widely supported technologies suggest a good degree of architectural flexibility. However, significant challenges exist primarily in the regulatory and data governance domains. The 'Assessment Required' status for critical regulations like GDPR, SOC2, and ISO 27001, combined with unverified data residency practices, would introduce considerable complexity, cost, and time to any large-scale migration. These compliance and data sovereignty issues would require extensive legal and technical planning to ensure adherence in a new environment. While the geographic diversity of vendors is a positive, the reliance on specific infrastructure partners (e.g., 8x8 for Brave Talk, Guardian for Brave Firewall + VPN) could introduce vendor lock-in risks that would need careful management during a migration. The 'Unknown' vendor lock-in risk and the lack of financial stability data also add uncertainty to the feasibility and funding of a major migration project.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

Brave provides cloud-based services including Brave Sync (encrypted cloud storage via AWS), Brave Talk (video conferencing), Brave Firewall + VPN (powered by Guardian), Brave Leo AI (backend AI processing), and Brave Email Aliases (AWS-hosted). These services are classic candidates for SOC 2 Type II audits, which assess security, availability, processing integrity, confidentiality, and privacy controls. The risk is Medium because: (1) Brave's enterprise customers (via Group Policy installs) and B2B partners (Search API, Brave Ads) may require SOC 2 reports as part of vendor due diligence; (2) Absence of a SOC 2 report could be a commercial barrier for enterprise sales; (3) Brave's privacy-by-design architecture likely meets many SOC 2 criteria, but without a formal audit this cannot be confirmed. No SOC 2 report has been publicly disclosed.

Evidence: https://brave.com/privacy/browser/, https://brave.com/search/api/, https://brave.com/firewall-vpn/

ISO 27001 (source) — Assessment Required

ISO 27001 certification is relevant for Brave given its role as a technology company handling user data across multiple cloud services and its global user base of 117.6M monthly active users. The risk is Medium because: (1) Brave's privacy-by-design approach and technical security measures (encryption at rest and in transit, IP address stripping, minimal data retention) suggest a mature security posture that could support ISO 27001 certification; (2) However, no certification has been publicly disclosed; (3) Enterprise and B2B customers (Search API, Brave Ads) may require ISO 27001 as a vendor qualification criterion; (4) Without certification, Brave relies on self-attestation of security practices, which carries reputational and commercial risk.

Evidence: https://brave.com/privacy/browser/, https://hackerone.com/brave

CPRA — Compliant

Brave Software is headquartered in San Francisco, California, making CCPA/CPRA directly applicable. Brave has published a dedicated CCPA privacy notice, explicitly states it does not buy, sell, or share personal data about consumers, and enumerates all California consumer rights (right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive personal information, non-discrimination). The risk is Low because Brave's privacy-by-design architecture structurally aligns with CCPA/CPRA requirements — minimal data collection means minimal exposure. The California Privacy Protection Agency (CPPA) is identified as the relevant complaint authority.

Evidence: https://brave.com/privacy/ccpa/, https://brave.com/privacy/browser/, https://brave.com

Financials

Three-year financials

Financial Resilience Score: 6/10

Brave Software is a privately held US technology company that does not disclose audited financial statements, making rigorous financial assessment difficult. Third-party estimates suggest annual revenue in the range of ~US$50 million to US$100 million for 2023/2024, driven largely by Brave Ads and rapidly growing Brave Search API licensing to AI/LLM customers. The company has raised capital through multiple rounds including a ~$4.5M seed in 2016 and a ~$35M BAT token sale in 2017, providing some capital cushion. Strengths include strong user growth (from ~5M MAU in 2018 to 80+M in 2024), diversified revenue streams across advertising, search API, subscriptions, and wallet, and a strategically valuable independent search index that is increasingly monetized by AI companies. Founder credibility (Brendan Eich) and alignment with privacy regulatory tailwinds (GDPR, CCPA, DMA) further support the business. However, opacity of financials, competition from Chrome/Edge/Safari/Firefox, crypto exposure via BAT, ad-market cyclicality, and reported customer concentration in the Search API business create meaningful risks. The browser itself is free, so monetization depends entirely on ads, subscriptions, API, and wallet fees.

Key strengths: Strong user growth: ~80+ million MAU as of mid-2024, up from ~25M in 2020, Diversified revenue streams (Brave Ads, Search API, subscriptions, Wallet), Independent search index — strategically valuable for AI/LLM customers, Founder credibility (Brendan Eich, co-founder of Mozilla, creator of JavaScript), Privacy positioning aligned with regulatory tailwinds (GDPR, CCPA, DMA), Rapidly growing Brave Search API business since 2023 launch

Risk factors: Opaque financials — no audited statements publicly available, Competition from Google Chrome, Microsoft Edge, Apple Safari, Mozilla Firefox, DuckDuckGo, Crypto exposure via Basic Attention Token (BAT) — volatility and regulatory risk, Digital advertising market cyclicality, Customer concentration in Search API from small number of AI/LLM customers, Limited pricing power — browser is free, monetization dependent on ads/subs/API/wallet

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report