Demo:Celanin Due Diligence
Run due diligence on Demo:Celanin: monitor compliance and get alerts when suppliers, ownership or leadership change.
Denmark · owned by Independent (Denmark) · celanin.com · 10 vendors
Celanin ApS is the personal investment vehicle of Lars Neupart, a Danish business angel and cybersecurity entrepreneur based in Copenhagen. The company focuses on pre-seed investments in B2B SaaS and cybersecurity startups, primarily in Denmark, with 40+ investments made since 2017. Lars Neupart is also an active board member of the DanBAN co-investment fund and founder of Resiliate.io.
Resilience scores
- Digital Sovereignty: 40
- Digital Resilience: 4
- Financial Resilience: 6
Technology vendors
- Google LLC — Technology — United States
- Hosting.de GmbH — Germany
- Open-Xchange AG — Technology — Germany
- and 2 more
Insights
Last updated 2026-09-26 · revision 3
5 direct vendors, 60 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 2
- United States: 2
- Switzerland: 1
Subvendors by controlling owner country (sample)
- Switzerland: 1
- Canada: 2
- France: 3
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Celanin ApS demonstrates low to medium migration readiness. A key challenge is the medium vendor lock-in risk associated with its 4 vendors, which could complicate efforts to transition services or infrastructure. The regulatory environment, particularly the applicability of GDPR and the requirement for a NIS2 assessment, introduces significant compliance considerations that would need to be meticulously managed during any migration, potentially increasing complexity and cost. A major impediment to a higher readiness score is the complete absence of data regarding Celanin's internal tech stack (e.g., cloud-nativity, containerization, microservices adoption). Without this information, it is impossible to accurately gauge the technical effort and feasibility of a migration. Similarly, the lack of financial stability and growth history data prevents an assessment of the company's capacity to fund a substantial migration project. On a positive note, the absence of explicit data residency requirements offers some flexibility in selecting new infrastructure locations.
Compliance
4 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is a standard for assurance engagements other than audits or reviews of historical financial information. Its applicability would depend on specific client requests for assurance.
The risk of not having an ISAE 3000 report is low, as it is a specialized assurance report that would likely only be required by specific clients.
ISO 27001 (source) — Assessment Required
ISO 27001 is a voluntary information security standard. Its relevance depends on client expectations and the company's own risk management strategy.
While not mandatory, certification could be a competitive advantage. The risk of not having it is low unless required by clients, which is unknown.
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary compliance standard for service organizations, specifying how they should manage customer data. Applicability is driven by customer demand.
Similar to ISO 27001, the risk of not having a SOC 2 report is low unless specifically required by customers of their software development or consulting services.
Financials
Three-year financials
- 2025: gross profit DKK -116K, EBIT DKK -728K, equity DKK 7.81M
- 2024: gross profit DKK -226K, EBIT DKK -889K, equity DKK 13.4M
- 2023: gross profit DKK -221K, EBIT DKK -912K, equity DKK 13.7M
Financial Resilience Score: 6/10
Celanin ApS is a personal-investment holding vehicle whose economics are driven by small annual admin costs and episodic gains/losses from a concentrated portfolio of early-stage Danish/Nordic technology companies. Despite persistent operating losses (negative EBIT every year 2022-2025), the company maintains a substantial equity cushion of DKK 7.81M relative to its annual operating cash burn of under DKK 1M, meaning it can absorb many years of similar losses before depleting own funds. The FY2023 net profit of DKK +10.6M and FY2024's +2.90M demonstrate the vehicle's capacity for meaningful positive returns from portfolio exits and revaluations. However, resilience is tempered by significant equity erosion - from DKK 13.7M (2023) to DKK 7.81M (2025), a ~43% decline in two years. Earnings are highly volatile and event-driven, ranging from -DKK 6.28M (2022) to +DKK 10.6M (2023) to -DKK 592K (2025). Key-person dependency on Lars Neupart and concentration in illiquid, high-risk startup positions (with documented bankruptcies of MeetinVR ApS and CAVEA TECHNOLOGIES ApS in 2023) add further risk. Overall, the vehicle has adequate near-term buffer but faces structural challenges typical of a small holding company.
Key strengths: Substantial equity cushion of DKK 7.81M relative to sub-DKK 1M annual operating burn, Owner-operator alignment with 100% ownership by experienced tech/cyber-security entrepreneur, Historically capable of large positive returns (FY2023 net profit of +DKK 10.6M), Simple structure below audit thresholds (revision fravalgt), Improving EBIT trend (-1.45M → -912K → -889K → -728K)
Risk factors: Persistent operating losses every year 2022-2025, Equity erosion of ~43% over two years (DKK 13.7M to DKK 7.81M), Volatile bottom line swinging from -DKK 6.28M to +DKK 10.6M, Key-person dependency on sole director Lars Neupart, Concentration in illiquid early-stage startup positions with documented bankruptcies (MeetinVR, CAVEA TECHNOLOGIES), No revenue disclosure limiting transparency, Dependence on episodic portfolio exits for profitability
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.