CircleScope

Denmark · owned by Independent (Denmark) · circlescope.dk · 8 vendors

CircleScope is a leading provider of AI-based computer vision and detection systems for tracking and identifying drones, vessels, birds, and other objects. Their flexible and modular systems serve defense, airports, power plants, offshore installations, and critical infrastructure. Solutions are built around their proprietary CircleScope Tracker Unit and software, configurable with Doppler radars, multi-sensor camera systems, and customer-specified equipment.

Resilience scores

Technology vendors

Insights

Last updated 2026-08-06 · revision 3

8 direct vendors, 135 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

CircleScope demonstrates medium migration readiness, scoring 60. A significant strength is the existing utilization of AWS services for data residency in the EU (Germany and Ireland), indicating prior experience with cloud infrastructure and a clear understanding of data residency requirements. The internal tech stack includes 'Standard Integration Interfaces (APIs)', suggesting a modular architecture that can facilitate easier integration and migration of components. The company's proactive approach to regulatory compliance (GDPR, ISO 27001 in progress) means that compliance requirements are understood, which is crucial for planning a migration. However, several factors temper the readiness score. The tech stack includes 'Embedded / Real-Time Operating Systems' and the products involve proprietary hardware, suggesting that a significant portion of their core detection systems may not be easily migratable to a purely cloud-native environment, potentially requiring a hybrid or edge computing strategy. Financial stability, including the ability to fund a substantial migration, is unknown due to missing revenue and growth data. Similar to resilience, the vendor relationship data is contradictory ('Total Vendors: 0' vs. 'Total Services: 11' and vendor geographic data). Assuming vendors exist, the 'Vendor Lock-in Risk' is unknown, and the number of distinct vendors providing 11 services is not specified, making it difficult to assess potential vendor lock-in challenges during migration. The combination of existing cloud usage and modularity is positive, but the hardware-dependent components, unknown financials, and vendor ambiguity present notable challenges for a comprehensive migration.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

CircleScope explicitly serves critical infrastructure sectors including defense, airports/airfields, power plants, wind parks, and offshore installations — all of which are covered under NIS2 Annex I (Essential Entities) and Annex II (Important Entities). As a technology/ICT provider supplying AI-based detection, identification, and tracking systems to these sectors, CircleScope likely qualifies as a digital provider or ICT service management entity under NIS2. Furthermore, their customers (airports, power plants) are themselves Essential Entities under NIS2, meaning supply chain security requirements flow down to CircleScope. Denmark transposed NIS2 into national law (Lov om sikkerhed i net- og informationssystemer). Non-compliance can result in fines up to €10M or 2% of global turnover for Important Entities, and €7M or 1.4% for others. The defense sector involvement also raises national security dimensions.

Evidence: https://circlescope.dk, https://www.cfcs.dk/en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

SOC 2 (source) — Assessment Required

CircleScope provides AI-based software and integrated systems to high-security clients including defense organizations and critical infrastructure operators. These clients typically impose stringent third-party security assurance requirements. SOC 2 Type II reports are increasingly demanded by enterprise and government clients as evidence of security controls. While SOC 2 is not legally mandated, the absence of a SOC 2 report may represent a commercial and reputational risk when bidding for contracts with security-conscious clients. Risk is medium rather than high because SOC 2 is voluntary and alternatives (ISO 27001) may satisfy client requirements.

Evidence: https://circlescope.dk

Danish Data Protection Act — Assessment Required

As a Danish company, CircleScope is subject to the Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended), which supplements GDPR with national specifications. This includes specific rules on employee data processing, CCTV/surveillance regulations, and processing of sensitive data. The Danish DPA (Datatilsynet) is an active enforcement authority with a track record of investigations and fines.

Evidence: https://circlescope.dk, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502

Financials

Financial Resilience Score: 5/10

CircleScope is a long-established Danish defense and security technology vendor, active since 2001, with a proprietary radar-and-AI tracking platform. The company operates in structurally growing end markets including counter-UAS, critical infrastructure protection, defense, airports, power plants, wind farms, and offshore installations. These segments are benefiting from increased European defense spending post-2022, NATO readiness initiatives, and rising demand for drone-defense capabilities. Qualitatively, the company's ~24 years of continuous operation in a specialised niche suggests business stability. Its proprietary IP (CircleScope Tracker Unit and software) rather than pure integration work typically supports higher margins. The modular, dual-use product design broadens the addressable market across military and civilian critical infrastructure. However, no public financial figures could be verified in this research session. The company almost certainly files as a small Danish ApS entity under reporting class B, meaning revenue may legally be omitted from filings. Key risks include customer concentration in project-driven defense sales, export-control exposure under EU dual-use regulations, and competitive pressure from well-funded Danish and international counter-drone entrants such as Terma, Weibel, Robin Radar, and MyDefence. Limited public financial transparency itself represents a due diligence risk for counterparties.

Key strengths: Long operating history since 2001 (~24 years), Proprietary core IP in Tracker Unit and AI software, Exposure to structurally growing defense and critical-infrastructure markets, Modular dual-use product design serving multiple end markets, Alignment with post-2022 European defense spending increases and counter-UAS demand

Risk factors: Small scale with likely lean headcount and lumpy project-driven revenue, Customer concentration risk from long defense sales cycles dominated by 1-2 government or prime-contractor customers, Export-control and geopolitical exposure under Danish and EU dual-use regulations, Competitive pressure from well-funded entrants (Terma, Weibel, Robin Radar, MyDefence), Limited public financial transparency due to abbreviated small-entity filings

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report