Captcha.eu

Austria · www.captcha.eu · 21 vendors

Captcha.eu, operated by Captcha GmbH, provides an invisible, GDPR-compliant bot protection service. It uses advanced behavioral analysis, machine learning, and crypto-challenges to secure websites, forms, and login screens from bots and spam without requiring user interaction or tracking.

Resilience scores

Disruption prediction

Captcha.eu has an estimated 21% probability of disruption in the next 6 months.

10 of Captcha.eu's 21 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 21 sub-vendors.

Insights

Last updated 2026-08-14 · revision 6

21 direct vendors, 278 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Captcha.eu exhibits medium-to-low migration readiness. On the positive side, the core product's API-driven architecture and its design for seamless migration from existing CAPTCHA solutions (for customers) suggest an underlying modular and flexible technical foundation. The use of a decentralized edge infrastructure also points to a modern, distributed system that could be adaptable. However, significant challenges severely constrain migration readiness. A primary hurdle is the explicit and critical data residency requirement: all services are 'Hosted in Austria' as a core feature for GDPR compliance and data sovereignty. This severely limits options for migrating to cloud providers or regions outside the EU, increasing complexity and potential costs. The complete absence of financial data also makes it impossible to assess the company's capacity to fund a substantial migration effort. While GDPR compliance is strong, the 'Assessment Required' status for NIS2, SOC2, and ISO 27001 indicates that any migration would need to carefully consider and potentially address these additional regulatory and certification requirements, adding further complexity. The 'Vendor Lock-in Risk: Unknown' and the contradictory vendor data ('Total Vendors: 0' versus listed vendor countries) also introduce uncertainty regarding potential dependencies, although the implied geographic diversity of vendors (7 countries) could be a mitigating factor if managed effectively.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Austrian law via NISG 2024) is potentially applicable to Captcha.eu as a digital service provider in the cybersecurity sector. The company provides bot-protection and challenge-response authentication services — a form of managed security service — which may qualify it as a 'managed security service provider' (MSSP) under NIS2 Annex I (Essential Entities) or as a 'digital provider' under Annex II (Important Entities). The key uncertainty is company size: Captcha GmbH appears to be a small company (likely fewer than 50 employees based on its pricing tiers and structure as a GmbH under Krone Multimedia group), which would place it below NIS2's medium-enterprise threshold (50+ employees OR €10M+ turnover). However, if assessed as part of the Krone Multimedia group, consolidated size thresholds may apply. Risk is Medium because: (1) cybersecurity providers are explicitly referenced in NIS2; (2) the Austrian NIS2 transposition (NISG 2024) may have specific provisions; (3) non-compliance penalties under NIS2 can reach €10M or 2% of global turnover for essential entities.

Evidence: https://www.captcha.eu/impressum__en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&&Gesetzesnummer=10007517

EU Cybersecurity Act — Assessment Required

The EU Cybersecurity Act established ENISA's permanent mandate and created a European cybersecurity certification framework. As a cybersecurity service provider, Captcha GmbH may be subject to or benefit from EU cybersecurity certification schemes (e.g., EUCS — European Union Cloud Scheme). Currently, no mandatory certification requirements apply to CAPTCHA/bot-protection services under the CSA, but this may change as the EU develops sector-specific certification schemes. Risk is Low because no mandatory certification currently applies, but the regulatory landscape is evolving.

Evidence: https://www.captcha.eu/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019R0881

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for information security management systems (ISMS). As a cybersecurity service provider, Captcha GmbH's core business proposition is security — making ISO 27001 certification both highly relevant and commercially important. The absence of a publicly disclosed ISO 27001 certification is a notable gap for a company marketing itself as a security solution to enterprise clients including a national bank (OeNB), a national railway (ÖBB), and insurance companies. Risk is Medium because: (1) lack of ISO 27001 may undermine enterprise credibility; (2) regulated-sector clients may require it as a vendor prerequisite; (3) the company's small size may make full ISMS implementation challenging but not impossible; (4) non-certification does not constitute regulatory non-compliance but represents a significant commercial and reputational risk.

Evidence: https://www.captcha.eu/, https://www.captcha.eu/impressum__en/

Financials

Three-year financials

Financial Resilience Score: 5/10

Captcha GmbH is a recently established Austrian SaaS company (registered 2022-2023, commercial launch 2024) offering GDPR-compliant CAPTCHA/bot-protection services. As a small/micro Austrian GmbH, it benefits from reduced UGB disclosure obligations, meaning no revenue, EBIT, or equity figures are publicly available. This makes independent financial assessment difficult. However, qualitative indicators suggest moderate resilience: the company has secured an impressive roster of blue-chip and public-sector reference customers including ÖBB (Austrian Federal Railways), Österreichische Nationalbank, A1 Telekom, GRAWE, Bauer Media Group, and DGUV. The company's positioning as an EU-hosted, GDPR-compliant alternative to US-based CAPTCHA services (Google reCAPTCHA, Cloudflare Turnstile) aligns with structural regulatory tailwinds post-Schrems II and the EU Data Act. Its recurring SaaS revenue model provides predictable cash flow, and low operational complexity (small team, Austria-hosted infrastructure) keeps costs manageable. Key risks include early-stage scale with likely limited equity cushion, intense competition from well-funded incumbents (many offering free alternatives), low entry pricing (€8.90/month) requiring successful upselling, and customer concentration risk given the relatively small anchor customer base. The score of 5 reflects the balance between strong strategic positioning and reference customers against early-stage financial opacity and competitive pressures.

Key strengths: GDPR-compliant EU-hosted positioning aligned with Schrems II and EU Data Act tailwinds, Blue-chip and public-sector reference customers (ÖBB, OeNB, A1 Telekom, GRAWE, Bauer Media, DGUV), Recurring SaaS subscription revenue model with predictable cash flow, Low operational complexity with Austria-hosted infrastructure and small team, Two-founder managing-director structure providing clear accountability, Active content marketing/SEO growth strategy targeting reCAPTCHA replacement

Risk factors: Early-stage company with likely limited equity cushion, Intense competition from well-funded incumbents including free alternatives (Google reCAPTCHA, Cloudflare Turnstile, hCaptcha), Low entry pricing (€8.90/month starter) requires successful upselling to higher tiers, Customer concentration risk with relatively small anchor customer base, No published financial disclosures makes credit assessment difficult, Key-person risk with only two managing directors/likely founders, No visible external funding announcements - unclear if bootstrapped or funded

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report