Clerk, Inc.

United States · owned by Independent (United States) · clerk.com · 59 vendors

Clerk is a developer-focused authentication and user management platform purpose-built for modern web frameworks such as React, Next.js, and Remix. It provides drop-in components, APIs, and SDKs that allow developers to quickly add sign-up, sign-in, and user profile management to their applications. The company is backed by venture capital and serves developers and businesses looking to offload identity infrastructure.

Resilience scores

Disruption prediction

Clerk, Inc. has an estimated 11% probability of disruption in the next 6 months.

24 of Clerk, Inc.'s 59 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 4 categories; runs on 59 sub-vendors.

Insights

Last updated 2026-08-11 · revision 8

59 direct vendors, 416 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Clerk, Inc. demonstrates high migration readiness, primarily driven by its modern and cloud-native oriented tech stack. The use of Next.js, TypeScript, React, and platforms like Vercel strongly suggests a modular, API-driven architecture, which is highly conducive to re-platforming or re-hosting efforts. Their adoption of key technologies such as OAuth 2.0, OpenID Connect, JWT, and various authentication methods (Passkeys, SAML, MFA) indicates a well-architected system capable of integrating with diverse environments, further simplifying migration. However, several factors introduce complexity. The regulatory environment, with probable compliance requirements for SOC 2, GDPR, CCPA, and potential NIS2 applicability, means any migration must meticulously address data privacy, security, and residency. The likelihood of offering 'Global data residency options' also necessitates a migration strategy that can maintain these capabilities, potentially requiring multi-region deployments and careful data transfer planning. Regarding vendor relationships, the data presents an inconsistency with 'Total Vendors: 0' alongside 'Total Services: 98' and diverse 'Vendor HQ Countries'. Interpreting the geographic diversity of vendor HQs (7 unique countries) as representative of their service providers, this diversity generally reduces vendor lock-in risk compared to a concentrated vendor base. However, the actual number of vendors and the complexity of contracts are unknown, making a precise assessment of vendor lock-in challenging. The lack of publicly disclosed specific financial figures also makes it difficult to assess their financial capacity to fund a potentially large-scale migration. Despite these complexities and unknowns, the inherent flexibility and modern nature of their core technology stack position Clerk well for future migration initiatives.

Compliance

5 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

No public evidence of ISO 27001 certification was found on Clerk's website or legal pages. ISO 27001 is an internationally recognized information security management standard. While Clerk has achieved SOC 2 Type 2 (which covers similar ground), ISO 27001 is a separate certification often required by enterprise customers, particularly in Europe. The absence of a publicly disclosed ISO 27001 certificate represents a medium risk for enterprise sales into regulated industries and EU markets where ISO 27001 is commonly required. The risk is Medium rather than High because Clerk's SOC 2 Type 2 certification demonstrates a mature security posture, and ISO 27001 may be in progress or available under NDA.

Evidence: https://clerk.com/legal, https://clerk.com

GDPR (source) — Partially Compliant

Clerk, Inc. is a US-headquartered company that explicitly processes personal data of EU/EEA, UK, and Swiss residents through its authentication and user management platform. The company has taken meaningful compliance steps: it has published a GDPR Supplemental Notice, appointed VeraSafe as its EU/UK Article 27 representative, certified to the EU-US Data Privacy Framework (DPF), and published a Data Processing Agreement (DPA). However, as a US-based company transferring EU personal data to the USA, ongoing compliance obligations (data subject rights, lawful basis documentation, sub-processor management) require continuous monitoring. The risk is Medium rather than High because Clerk has demonstrably implemented key GDPR mechanisms, but full compliance cannot be independently verified without a formal audit. Enforcement risk is real given the scale of personal data processed (authentication data for potentially millions of end users).

Evidence: https://clerk.com/legal/gdpr, https://clerk.com/legal/dpa, https://clerk.com/legal/dpf, https://clerk.com/legal/subprocessors, https://clerk.com/legal/privacy, https://clerk.com/legal

CCPA — Compliant

Clerk, Inc. is headquartered in San Francisco, California, and is directly subject to CCPA/CPRA. Clerk has publicly stated CCPA compliance on its homepage and published a CCPA Supplemental Notice. The company provides a 'Do Not Sell/Share My Info' contact (privacy@clerk.com) and a Cookie Manager. As a California-based company processing personal data of California residents at scale, CCPA compliance is mandatory and Clerk has taken documented steps to comply. Risk is Low given the public compliance attestation and published supplemental notice.

Evidence: https://clerk.com/legal/ccpa, https://clerk.com/legal/privacy, https://clerk.com, https://clerk.com/legal

Financials

Three-year financials

Financial Resilience Score: 8/10

Clerk is a well-capitalized private SaaS company with approximately $105M in cumulative funding raised across Series A ($15M, March 2023), Series B ($30M, January 2024), and Series C ($50M, October 2025). With a lean team of ~100 employees, this provides multiple years of runway even at elevated burn rates. The company's blue-chip investor base — including Andreessen Horowitz, CRV, Madrona, Menlo Ventures, Anthropic's Anthology Fund, Georgian, and Stripe — signals strong ongoing access to capital. Operating traction is exceptional: managed users grew from ~1 million in March 2023 to over 200 million by October 2025 (roughly a 200× increase in ~2.5 years) across more than 15,000 applications. This scale, combined with disciplined headcount growth, is often indicative of high revenue per employee in a SaaS infrastructure model. However, since Clerk is private and does not disclose revenue, EBIT, gross margin, burn rate, or net retention, conventional financial-statement analysis is not possible, and the resilience assessment relies on funding and traction proxies rather than audited financials. Key structural risks include intense competition (Auth0/Okta, AWS Cognito, Firebase, Supabase Auth, WorkOS, NextAuth), concentration in the JavaScript/React ecosystem, a generous free tier that pressures low-end gross margin, and a speculative bet on emerging 'Agent Identity' for AI. Private-company liquidity risk also remains for employees and early investors.

Key strengths: ~$105M cumulative funding raised through Series C (October 2025), Blue-chip investor base including a16z, CRV, Madrona, Menlo Ventures, Anthropic's Anthology Fund, Georgian, and Stripe, Managed users grew ~200× from 1M to 200M+ between March 2023 and October 2025, 15,000+ applications served, including notable customers like Browserbase, Inngest, Upstash, OpenRouter, Cartesia, Lean ~100-person team implying strong revenue per employee potential, SOC 2 Type 2 and CCPA compliance supporting enterprise upsell, Product expansion beyond authentication into billing, multi-tenancy, and Agent Identity

Risk factors: No public disclosure of revenue, EBIT, equity, gross margin, or burn rate, Intense competition from Auth0/Okta, AWS Cognito, Firebase Auth, Supabase Auth, WorkOS, and open-source alternatives, Generous free tier (50,000 monthly retained users) pressures low-end gross margin, Concentration in the JavaScript/React ecosystem creates framework-shift risk, Risk of auth being bundled into frameworks like Next.js or Supabase, Speculative commercial upside from early-stage 'Agent Identity' bet (IETF standards still in progress), Private-company liquidity risk for employees and early investors

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report