Cal.com
United States · cal.com · 22 vendors
Cal.com is an open-source and cloud-based scheduling platform that provides infrastructure for managing appointments, meetings, and bookings efficiently. It offers customizable booking workflows, calendar integrations, and API tools for individuals, teams, and businesses. The company aims to connect a billion people by 2031 through calendar scheduling.
Resilience scores
- Digital Sovereignty: 91
- Digital Resilience: 8
- Financial Resilience: 6
Disruption prediction
Cal.com has an estimated 21% probability of disruption in the next 6 months.
15 of Cal.com's 22 vendors monitored for disruptions.
Technology vendors
- Clerk, Inc. — Technology — United States
- HubSpot, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 28 more
Services catalogue
2 services in catalogue across 2 categories; runs on 22 sub-vendors.
- Cal.com
- Hermes360
Insights
Last updated 2026-05-23 · revision 8
22 direct vendors, 279 subvendors
Direct vendors by controlling owner country (sample)
- United States: 20
- Denmark: 1
- Netherlands: 1
Subvendors by controlling owner country (sample)
- Taiwan: 1
- Switzerland: 2
- India: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Cal.com exhibits very high migration readiness due to its exceptionally modern, flexible, and cloud-native technology stack. The use of Next.js, Node.js, TypeScript, Docker, and a monorepo architecture (Turborepo) signifies a highly portable and containerized application environment. Their existing support for deployment across multiple major cloud providers (Vercel, AWS, GCP, Azure) demonstrates inherent architectural flexibility and significantly reduces infrastructure-level vendor lock-in. The open-source nature of their platform (AGPL / EE License) further enhances migration readiness, offering transparency and control over the codebase, which is a key factor in facilitating migrations for both Cal.com and its clients. From a regulatory perspective, Cal.com's strong compliance with GDPR, HIPAA, SOC 2 Type II, and ISO 27001 indicates that robust data governance and security frameworks are already in place. These established controls are crucial for ensuring compliance is maintained during any migration effort. Data residency requirements are addressed by their privacy policy and, importantly, by offering self-hosted options, which allows organizations to maintain full control over their data's physical location, a significant advantage for clients with strict data localization needs. The primary unknown factor is the lack of financial data, which prevents an assessment of Cal.com's capacity to fund large-scale internal migration initiatives if required. While the vendor data is ambiguous ("Total Vendors: 0" vs "Total Services: 60" and "Vendor HQ Countries" in 4 locations), the overall technical architecture, multi-cloud support, and open-source model inherently suggest a low internal vendor lock-in risk for their core platform, and high flexibility for their users' migration strategies.
Compliance
5 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
Cal.com explicitly states SOC 2 Type II certification on their security page and offers SOC 2 reports for download. As a cloud-based SaaS provider handling customer data, SOC 2 compliance is critical and they demonstrate strong compliance. Low risk due to established certification and regular auditing processes.
Evidence: https://cal.com/security
HIPAA (source) — Compliant
Cal.com explicitly states HIPAA certification on their security page and serves healthcare and telehealth sectors. They handle Protected Health Information (PHI) through their scheduling platform for healthcare clients. Medium risk due to the complexity of maintaining HIPAA compliance across their platform and ensuring all healthcare integrations meet requirements.
Evidence: https://cal.com/security, https://cal.com/scheduling/healthcare, https://cal.com/scheduling/telehealth
ISAE 3000 (source) — Assessment Required
ISAE 3000 applies to assurance services and assurance reporting. While Cal.com doesn't explicitly mention ISAE 3000 compliance, they do provide assurance through SOC 2 Type II reports and other compliance certifications. Medium risk as they may need ISAE 3000 for certain enterprise clients requiring specific assurance standards, though their existing SOC 2 compliance may be sufficient for most use cases.
Evidence: https://cal.com/security
Financials
Three-year financials
- 2024:
- 2023: equity $25M
- 2022: revenue $1M, equity $7.4M
Financial Resilience Score: 6/10
Cal.com is a privately held, VC-backed open-source SaaS company with approximately $32M+ in cumulative equity funding from top-tier investors including Sequoia Capital, OSS Capital, a16z, and Bain Capital Ventures. The strong investor base provides credibility and runway, and the company benefits from a capital-light, fully remote operating model and a large open-source community (30,000+ GitHub stars) that lowers customer acquisition costs. Product diversification across self-serve SaaS, Teams/Organizations, Enterprise, Platform/Atoms developer SDK, and the new Cal.ai voice agent provides multiple monetization vectors. However, the company has not publicly disclosed audited financials, revenue, EBIT, or equity in numeric form, limiting visibility into actual financial health. Like most early-stage VC-backed SaaS, Cal.com is almost certainly unprofitable and burning cash. It competes directly against Calendly (~$200M+ ARR) plus large incumbents like Microsoft Bookings, Google Appointments, and HubSpot Meetings. Structural dependencies on Google/Microsoft calendar APIs and the open-core tension between free self-hosting and paywalled features add risk. The mid-range score reflects strong backing balanced against unprofitability, competitive pressure, and limited financial transparency.
Key strengths: Strong VC backing (~$32M+ raised) from Sequoia, OSS Capital, a16z, Bain Capital Ventures, Large open-source community with 30,000+ GitHub stars driving organic growth, Diversified product surface: SaaS, Enterprise, Platform/Atoms SDK, Cal.ai, Capital-light fully remote operating model with no physical offices, Strong brand momentum and public transparency via Open Startup page
Risk factors: Entrenched competition from Calendly (~$200M+ ARR) and incumbents (Microsoft, Google, HubSpot), Likely unprofitable with ongoing monthly burn typical of VC-backed SaaS, Structural dependence on Google and Microsoft calendar APIs, Open-core tension between free self-hosting and paywalled enterprise features, No audited financials limiting creditor/partner due-diligence, Key-person concentration in two highly public founders
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.