Centarro

United States · centarro.io · 18 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-08-15 · revision 1

18 direct vendors, 219 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Centarro exhibits high migration readiness, largely driven by its highly modern and flexible technology architecture. The existing adoption of Drupal PaaS Hosting indicates a strong foundation in cloud infrastructure, which significantly streamlines potential migrations. The embrace of headless/decoupled commerce, along with the use of modern APIs like GraphQL and JSON:API, and front-end frameworks such as React and Vue.js, means their systems are inherently modular and less monolithic, making components easier to migrate or re-platform independently. The open-source nature of Drupal Commerce also provides flexibility. While the 'Total Vendors: 0' data point is confusing given the mention of PaaS hosting, the geographic diversity of vendor HQs (7 countries) suggests a potentially diverse vendor ecosystem, which can reduce lock-in. However, the specific vendor lock-in risk remains unknown. The primary challenges and unknowns for migration readiness are the lack of financial stability data (which impacts the ability to fund a migration), and unspecified regulatory environment or data residency requirements, which could introduce complexities depending on the target environment. Despite these unknowns, the architectural choices position Centarro very well for future migrations.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

Centarro explicitly acknowledges GDPR applicability in its Privacy Policy and serves EU/EEA clients and website visitors, meaning it processes personal data of EU/EEA residents. The company relies on GDPR Article 49 derogations (consent, contract, legitimate interest) for EU-to-US data transfers rather than the more robust Standard Contractual Clauses (SCCs) or an adequacy decision. Article 49 derogations are intended for occasional, non-repetitive transfers — using them as a primary transfer mechanism for ongoing commercial operations is legally precarious and has been criticized by EU data protection authorities. No Data Protection Officer (DPO) appointment is disclosed. No record of SCCs, Binding Corporate Rules, or EU-US Data Privacy Framework certification is found. The Privacy Policy references GDPR Articles 13/14 disclosures, which is positive, but the transfer mechanism gap and absence of a DPO represent material compliance risks. Enforcement risk is elevated given active EU DPA enforcement against US-based companies processing EU data.

Evidence: https://www.centarro.io/privacy-policy, https://www.centarro.io/company

PCI DSS (source) — Assessment Required

Centarro develops and supports eCommerce platforms that process payment card transactions for 30,000+ merchants handling billions of dollars annually. While Centarro itself may not directly process, store, or transmit cardholder data (relying on payment processors like PayPal, Braintree, and Authorize.net), its role as a platform developer and support provider means it may have access to merchant environments that are in-scope for PCI DSS. The risk is medium because Centarro's liability depends on its specific role in the payment ecosystem and whether it is listed as a PCI DSS-compliant service provider.

Evidence: https://www.centarro.io/drupal-commerce/integrations, https://www.centarro.io/products/centarro-support

CPRA — Partially Compliant

Centarro's Privacy Policy explicitly references the California 'Shine the Light' law (Civil Code §1798.83) and provides opt-out rights for California residents. However, the Privacy Policy does not include a full CCPA/CPRA-compliant disclosure covering all required elements such as a 'Do Not Sell or Share My Personal Information' link, categories of personal information sold or shared, or a dedicated CCPA rights request mechanism. The risk is medium because Centarro is a B2B services company with limited direct consumer data collection, which may place it below CCPA thresholds (annual gross revenue over $25M, buying/selling/receiving/sharing personal information of 100,000+ consumers/households, or deriving 50%+ of revenue from selling personal information).

Evidence: https://www.centarro.io/privacy-policy

Financials

Three-year financials

Financial Resilience Score: 5/10

Centarro is a privately held US-based technology services company that does not disclose financial statements, making a precise quantitative resilience assessment impossible. Qualitatively, the company benefits from its position as the creator and principal maintainer of Drupal Commerce, giving it a defensible niche authority position. Its business model includes recurring Support and Development Retainers, which provide more predictable cash flow than pure project work, and it maintains a cost-efficient international structure with a US HQ in Greenville, SC and a development office in Pančevo, Serbia. However, resilience is constrained by structural headwinds. The business is entirely dependent on the Drupal ecosystem, whose market share has been declining relative to SaaS commerce platforms (Shopify, BigCommerce) and composable commerce stacks (commercetools, Medusa). As a small-to-mid-sized services boutique with an estimated 15-30 employees, Centarro faces concentration risk from potential loss of key retainer clients and talent risk given its reliance on a small pool of specialized Drupal Commerce engineers. The lack of published financials also limits external visibility into solvency and liquidity, warranting a mid-range resilience score.

Key strengths: Category authority as creator and principal maintainer of Drupal Commerce since 2009, Recurring revenue via Support and Development Retainers, Enterprise/blue-chip customer roster including Lush, Freitag, Obermeyer, Leica Geosystems, Irish Times Group, Cost-efficient international structure (US HQ + Serbia development office), Open-source community leverage with 2,000+ member Slack community, Strategic pivot toward higher-ticket B2B and vertical use cases

Risk factors: Ecosystem dependence on declining Drupal CMS market share, Small scale with concentration risk from potential loss of large retainer clients, Competitive pressure from SaaS commerce (Shopify, BigCommerce) and composable commerce (commercetools, Medusa), Talent risk due to reliance on small pool of specialized Drupal Commerce engineers, Opaque financials limiting external stakeholder visibility

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report