Bright Bird A/S
Denmark · owned by Bernhoft Global Invest ApS (Denmark) · www.brightbird.com · 3 vendors
Bright Bird is a Danish strategic risk management and risk advisory firm headquartered in Hørsholm, Denmark. The company specializes in personalized risk assessment, operational planning, and execution of mitigation strategies, using intelligence-cycle-inspired methodologies to identify and address risks across diverse domains. It serves clients across the Nordic region and operates an additional office in Mykolaiv Oblast, Ukraine.
Resilience scores
- Digital Sovereignty: 33
- Digital Resilience: 4
Technology vendors
- Dandomain A/S — Technology — Denmark
- Netlify, Inc. — Technology — United States
- Squarespace, Inc. — Technology — United States
Insights
Last updated 2026-09-13 · revision 3
3 direct vendors, 72 subvendors
Direct vendors by controlling owner country (sample)
- United States: 2
- Belgium: 1
Subvendors by controlling owner country (sample)
- United States: 40
- United Kingdom: 3
- Sweden: 3
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Bright Bird A/S demonstrates medium migration readiness. A significant advantage is the simplicity of its current internal tech stack, primarily consisting of Squarespace for website hosting and CMS. This means there are no complex legacy systems, on-premise infrastructure, or monolithic applications to untangle, which can significantly reduce the technical complexity and scope of a potential migration. However, migrating from a proprietary platform like Squarespace would involve re-platforming and content migration rather than a straightforward lift-and-shift, requiring development effort. Key challenges to migration readiness stem from a lack of critical information: there is no verifiable data on regulatory requirements (e.g., NIS2 compliance) or data residency requirements, which are crucial for planning a compliant and legally sound migration strategy. Furthermore, the absence of verifiable financial stability data makes it difficult to assess the company's capacity to fund a significant migration project. While the vendor data is inconsistent, if we assume they rely on a small number of vendors for their 5 services, this could indicate a degree of vendor lock-in, particularly with Squarespace for their website, which might complicate switching providers or integrating new solutions. The lack of existing cloud-native or containerized architectures means a migration would likely be a greenfield adoption of modern cloud practices, which offers flexibility but also requires new expertise and investment.
Compliance
7 in-scope frameworks identified; showing 3.
Danish Security Industry Regulation — Assessment Required
Denmark's Private Security Act (Vagtvirksomhedsloven, Consolidated Act No. 112 of 11 January 2016, as amended) regulates private security companies operating in Denmark. The Act requires licensing for companies providing guarding, surveillance, and personal protection services. Bright Bird A/S explicitly offers executive protection services (referenced in their Ukraine page as part of their service suite). If executive protection is provided in Denmark or by Danish-registered entities, a license from the Danish National Police (Rigspolitiet) is required. Risk is HIGH because: (1) operating without the required license is a criminal offense; (2) the company's website explicitly references executive protection as a service; (3) no evidence of licensing was found; (4) the Sikkerhedsbranchen (Danish Security Industry Association) partnership suggests awareness of the regulatory environment, but membership does not substitute for licensing.
Evidence: https://www.brightbird.com, https://www.brightbird.com/ukraine, https://www.retsinformation.dk/eli/lta/2016/112, https://www.sikkerhedsbranchen.dk, https://www.politi.dk/vagtvirksomhed
GDPR (source) — Assessment Required
GDPR is universally applicable to Bright Bird A/S as a Danish-registered company headquartered in Hørsholm, Denmark — a full EU member state. The company processes personal data across multiple categories: (1) client personal data (business delegates, VIP executives, delegation members) gathered during travel risk advisory and executive protection engagements; (2) employee/contractor data in both Denmark and Ukraine; (3) sensitive due diligence data including background checks, financial ties, and reputational assessments on individuals (as evidenced by their Enhanced Due Diligence service for the defense company in Ukraine); (4) potentially special-category data related to security assessments. The risk level is HIGH because: (a) the company handles particularly sensitive personal data — background checks and financial network mapping of individuals constitute high-sensitivity processing under GDPR Articles 5–9; (b) data transfers to Ukraine (a non-EEA third country) require specific legal mechanisms under GDPR Chapter V (SCCs or other transfer tools), and Ukraine's war context adds operational complexity; (c) no public evidence of a Data Protection Officer (DPO) appointment, privacy policy, or GDPR compliance documentation was found on the website; (d) the Danish Data Protection Authority (Datatilsynet) is an active enforcement body with a track record of investigations; (e) non-compliance fines can reach €20M or 4% of global annual turnover.
Evidence: https://www.brightbird.com, https://gdpr-info.eu/, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Anti-Money Laundering — Assessment Required
The Danish Anti-Money Laundering Act (Hvidvaskloven, Act No. 930 of 6 September 2019, implementing EU's 5th AML Directive) may apply to Bright Bird A/S depending on the exact nature of its due diligence services. If the company provides trust or company services, or if its due diligence services are provided to financial institutions as part of their AML/KYC obligations, AML registration with Finanstilsynet or Erhvervsstyrelsen may be required. Risk is MEDIUM because: (1) the company's enhanced due diligence services are explicitly described as supporting compliance and reputational risk assessments — a function closely related to AML/KYC; (2) if clients are financial institutions using Bright Bird's due diligence as part of their AML obligations, Bright Bird may itself be subject to AML obligations as a 'person carrying out activities' under the Act; (3) operating in Ukraine (a high-risk jurisdiction for money laundering) increases AML scrutiny.
Evidence: https://www.brightbird.com, https://www.finanstilsynet.dk/en, https://www.retsinformation.dk/eli/lta/2019/930, https://www.fatf-gafi.org/en/countries/detail/Denmark.html
Financials
Three-year financials
- 2025: gross profit DKK 1.15M, EBIT DKK -3.13M, equity DKK 2.50M
- 2024: gross profit DKK -1.00M, EBIT DKK -5.94M, equity DKK 5.12M
- 2023: gross profit DKK -17.1K, EBIT DKK -33.6K, equity DKK -45.2K
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.