Candeno

Denmark · owned by Independent (Denmark) · candeno.dk · 18 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

18 direct vendors, 277 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Candeno exhibits medium migration readiness, but with significant unknowns. The company's internal tech stack relies on modern SaaS platforms like Webflow, Google Tag Manager, and HaileyHR. This indicates an existing comfort with cloud-based services and potentially less traditional on-premise legacy infrastructure to migrate. The mention of "AI-augmented development" suggests a forward-thinking approach to technology. However, a major impediment to assessing migration readiness is the lack of crucial data. There is no information on specific regulatory environments, data residency requirements, or the company's financial stability, all of which are critical for planning and funding a migration. The provided data states "Total Vendors: 0" but also "Total Services: 25" and vendor geographic details. Assuming Candeno utilizes 25 external services, the "Vendor Lock-in Risk" is explicitly unknown, which is a significant concern. While the number of services (25) might suggest a diverse vendor base, the actual level of lock-in with these services (e.g., contract complexity, data portability) is unquantified. If Candeno's core products are heavily integrated with or built upon platforms like Webflow, migrating to a different, potentially custom, cloud-native architecture could be a complex and costly undertaking due to platform-specific dependencies. The architecture of their core product (e.g., monolithic vs. microservices, containerization) is also not specified, making it difficult to gauge the technical effort required for migration.

Compliance

7 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

Risk is Medium and emerging. The EU AI Act entered into force in August 2024 with phased implementation through 2026-2027. Candeno's core product involves AI-powered matching algorithms that profile job seekers and match them with employers — this is explicitly identified as a 'high-risk AI system' under Annex III of the EU AI Act (Category 4: Employment, workers management and access to self-employment). High-risk AI systems in employment contexts require: conformity assessments, technical documentation, human oversight mechanisms, transparency to affected individuals, registration in the EU AI database, and post-market monitoring. This is a significant emerging compliance obligation that Candeno must proactively address.

Evidence: https://candeno.dk/, https://www.candeno.com/jobsogende/om-os, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

NIS2 (source) — Assessment Required

NIS2 risk is assessed as Low for Candeno at this time. The company operates in the HR-technology/digital recruitment sector, which does not fall within NIS2's Essential Entity sectors (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space) nor clearly within the Important Entity sectors (postal/courier, waste management, chemicals, food, manufacturing, digital providers). While Candeno is a digital platform/SaaS provider, NIS2's 'digital providers' category under Important Entities specifically covers online marketplaces, online search engines, and cloud computing services — Candeno's recruitment matching platform does not clearly fit these definitions. The company does serve public sector clients (municipalities, job centres), but this does not automatically bring it within NIS2 scope. Size threshold (50+ employees or €10M+ turnover) may be met given 40+ employees and Scandinavian operations, but sector classification is the primary determinant. Consequences of NIS2 non-compliance if applicable include fines up to €7M or 1.35% of global turnover for Important Entities. A formal legal assessment is recommended to confirm sector classification.

Evidence: https://www.candeno.com/jobsogende/om-os, https://www.cfcs.dk/en/cybersecurity/nis2/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

ISO 27001 (source) — Assessment Required

ISO 27001 risk is Medium for Candeno. The standard is not legally mandated but is highly relevant given: (1) Candeno processes large volumes of sensitive personal data (CVs, personality tests, employment histories) for 250,000+ users; (2) the company serves public sector clients (Danish municipalities, job centres) who may require ISO 27001 certification in procurement processes; (3) Danish public sector procurement increasingly references ISO 27001 or equivalent as a security baseline; (4) without certification, Candeno may face barriers in enterprise sales and public sector tenders. The risk is primarily commercial and reputational rather than regulatory, but given the sensitivity of data processed and the public sector client base, the likelihood of client-driven requirements is elevated. A data breach without ISO 27001 controls in place could also amplify GDPR enforcement risk.

Evidence: https://candeno.dk/, https://www.candeno.com/juridisk/privatlivspolitik, https://www.candeno.com/jobsogende/om-os

Financials

Three-year financials

Financial Resilience Score: 5/10

Candeno A/S is an early-stage Danish HR-tech/employment-platform company founded in 2020, serving primarily public-sector clients (municipalities, jobcentres, unemployment funds, educational institutions) across Denmark, Norway, and Sweden. The company benefits from a sticky public-sector customer base with multi-year framework agreements that typically provide predictable, recurring revenue. Its SaaS business model implies relatively low marginal costs at scale and attractive unit economics if growth continues. Reported customer satisfaction is high (95.78% CSAT), suggesting low churn risk on existing accounts. However, as a young private A/S under Danish Class B disclosure rules, financial transparency is very limited, and actual revenue, EBIT, and equity figures could not be retrieved in this session. Typical of HR-tech scale-ups, the company may not yet be profitable and could still be burning cash on growth. Public-sector procurement cycles are slow, tender losses to competitors (Jobindex, HeyJobs, Talentech, Emply, HR-ON) create renewal risk, and regulatory changes to Denmark's employment policy framework could reshape demand. The mid-range score reflects the tension between a resilient customer base and the opacity plus early-stage risks of the business.

Key strengths: Sticky public-sector customer base with multi-year framework agreements, Multi-country Nordic footprint (DK/NO/SE) reduces single-market dependency, High reported customer satisfaction (95.78% CSAT) suggests low churn, SaaS model with low marginal cost of serving additional users, Over 200,000 job seekers onboarded since 2020, Corporate conversion from ApS to A/S suggests scaling / capital raise

Risk factors: Early-stage company (founded 2020) with possible unprofitability and cash burn, Public-sector procurement cycles are slow and tender losses create renewal risk, Limited financial transparency under Danish Class B disclosure regime, Regulatory dependency on Danish employment policy reforms (beskæftigelsesindsats), Nordic competition from larger players (Jobindex, Workday, Talentech, Emply, HR-ON), Revenue concentration in public-sector clients

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report