CANDDi
United Kingdom · www.canddi.com · 15 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 4
- Financial Resilience: 6
Technology vendors
- Demandware — Technology — United States
- EasyDMARC Inc. — Cybersecurity — United States
- Open Source Matters, Inc. — Technology — United States
- and 12 more
Services catalogue
1 service in catalogue across 1 category; runs on 15 sub-vendors.
- CANDDi
Insights
Last updated 2026-07-22 · revision 1
15 direct vendors, 229 subvendors
Direct vendors by controlling owner country (sample)
- Croatia: 1
- Norway: 1
- Germany: 1
Subvendors by controlling owner country (sample)
- Netherlands: 3
- India: 1
- Czech Republic: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
CANDDi's migration readiness is assessed as low-to-medium, primarily due to the lack of explicit indicators for a modern, cloud-native architecture. The "Internal Tech Stack" is empty, and while "Key Technologies" are listed, there's no mention of containerization, microservices, or cloud-native principles, suggesting a potentially more monolithic or traditional setup that would require significant refactoring for cloud migration. The vendor landscape, assuming vendors exist for the 7 services despite the "Total Vendors: 0" contradiction, shows high geographic concentration, with all vendor HQ and owner countries being the United States. This could lead to vendor lock-in or complex dependencies, increasing the difficulty and cost of migrating away from these services or their underlying infrastructure. Data residency requirements are not specified, which could be an unknown challenge. Crucially, there is no available data on financial stability (revenue concentration, growth history) to assess the company's capacity to fund a potentially extensive migration effort.
Compliance
5 in-scope frameworks identified; showing 3.
Cyber Essentials — Assessment Required
Cyber Essentials is a UK government-backed certification scheme. While not legally mandatory for all companies, it is required for UK government contracts involving handling of personal data or sensitive information. For a SaaS company like CANDDi that processes personal data, Cyber Essentials certification is a strong market expectation and may be required by public sector customers. Risk is MEDIUM as it is not a legal requirement for private sector companies but represents a significant competitive and trust gap if absent.
Evidence: https://www.ncsc.gov.uk/cyberessentials/overview, https://www.ncsc.gov.uk/cyberessentials/search
PECR — Assessment Required
PECR is critically relevant to CANDDi's core product. CANDDi operates by placing tracking cookies/scripts on customers' websites to identify and profile visitors. PECR Regulation 6 requires informed consent before placing non-essential cookies on a user's device. The ICO has made cookie compliance a major enforcement priority. Risk is HIGH because: (1) CANDDi's tracking technology is the core of its product and directly subject to PECR; (2) the ICO has issued enforcement notices and fines for cookie consent violations; (3) if CANDDi's tracking script is deployed without proper consent mechanisms, both CANDDi and its customers face regulatory exposure; (4) the ICO's 2023 cookie sweep found widespread non-compliance across UK websites.
Evidence: https://ico.org.uk/for-organisations/guide-to-pecr/, https://ico.org.uk/for-organisations/guide-to-pecr/cookies-and-similar-technologies/, https://www.legislation.gov.uk/uksi/2003/2426/contents/made
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for Information Security Management Systems (ISMS). For a SaaS company like CANDDi that processes personal data of website visitors at scale, ISO 27001 certification is a strong market expectation and is often required by enterprise customers and in public sector procurement in the UK. Risk is MEDIUM because: (1) lack of ISO 27001 certification may limit CANDDi's ability to win enterprise contracts; (2) it is not legally mandated but is a recognised best-practice framework; (3) UK GDPR's requirement for 'appropriate technical and organisational measures' (Article 25/32) is often evidenced through ISO 27001 certification; (4) without certification, demonstrating GDPR compliance to regulators and customers is harder.
Evidence: https://www.canddi.com, https://www.iso.org/isoiec-27001-information-security.html, https://www.ncsc.gov.uk/cyberessentials/overview
Financials
Three-year financials
- null:
- null:
- null:
Financial Resilience Score: 6/10
CANDDi demonstrates reasonable qualitative financial resilience through its recurring-revenue SaaS model, which provides predictable cash flow relative to project-based businesses. The company has an established operating history of approximately 15 years, which is unusual longevity for a small MarTech vendor and implies sustainable unit economics. Its niche differentiation in individual-level visitor identification (versus competitors that only identify companies) is a defensible product angle, particularly for GDPR-compliant B2B use cases, and a diversified small-customer base reduces single-customer concentration risk. However, quantitative financials (revenue, EBIT, equity) are not publicly disclosed, as CANDDi qualifies for UK small-company reporting exemptions and files abridged accounts at Companies House. The company operates at small scale (likely under the audit threshold), making it more vulnerable to downturns or the loss of a few large accounts. It faces significant competitive pressure from well-funded competitors including Lead Forensics, Dealfront/Leadfeeder, ZoomInfo, Clearbit/HubSpot Breeze Intelligence, and Albacross. Additionally, privacy/regulatory risks (GDPR, PECR, cookie-consent rules) and structural headwinds from cookie deprecation and browser tracking restrictions (Safari ITP, Firefox ETP, Chrome privacy sandbox) constrain the visitor-tracking business model.
Key strengths: Recurring-revenue SaaS subscription model produces predictable cash flow, Established operating history of ~15 years implies sustainable unit economics, Niche differentiation in individual-level visitor identification is defensible, Diversified small-customer base reduces single-customer concentration risk
Risk factors: Small scale - revenues likely under UK audit threshold, vulnerable to downturns, Competitive pressure from well-funded competitors (Lead Forensics, Dealfront/Leadfeeder, ZoomInfo, Clearbit, Albacross), Privacy/regulatory risk from GDPR, PECR, and evolving cookie-consent rules, Limited public financial disclosure hampers external assessment of profitability, runway, and leverage, Cookie deprecation and browser tracking restrictions (Safari ITP, Firefox ETP, Chrome privacy sandbox) as structural headwind
Revenue by geography
- International: 0%
- United Kingdom: 0%
Revenue by product/service
- CANDDi SaaS Subscription (visitor identification platform): 100%
Workforce by country
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.