Clock Software

Bulgaria · www.clock-software.com · 8 vendors

Clock Software develops and provides comprehensive software and hardware solutions for the hospitality industry. Their offerings include property management systems, online booking engines, channel managers, and restaurant point-of-sale systems. The company caters to independent hoteliers and small hotel groups globally.

Resilience scores

Disruption prediction

Clock Software has an estimated 27% probability of disruption in the next 6 months.

4 of Clock Software's 8 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 8 sub-vendors.

Insights

Last updated 2026-08-04 · revision 2

8 direct vendors, 132 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Clock Software exhibits strong migration readiness, primarily driven by its modern, cloud-native tech stack built on Amazon Web Services (AWS) and leveraging Google BigQuery. This foundation suggests a flexible and scalable environment conducive to migration. A significant strength is its 'Integrations Platform' featuring an open REST API and a marketplace connecting with over 100 third-party hospitality tools. This indicates a modular architecture and ease of integration/disintegration, which greatly simplifies the process of moving or re-platforming services. The use of multiple distinct vendors (AWS, Google, Adyen, HubSpot, Freshdesk, Zapier) also suggests a degree of vendor diversity, potentially reducing monolithic lock-in. However, several critical unknowns impact a higher readiness score: the absence of specified data residency requirements, lack of information on the regulatory environment (which can impose complex compliance hurdles during migration), and unknown financial stability (which affects the ability to fund a significant migration project). The explicit 'Vendor Lock-in Risk: Unknown' is also a notable factor, as reliance on major cloud providers and a single payment gateway, while operationally sound, can present challenges when considering a full migration away from these core services.

Compliance

7 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applies to Essential Entities and Important Entities in the EU. Clock Software is a cloud-based SaaS provider (hotel management software) headquartered in Bulgaria (EU). The relevant NIS2 category to assess is 'Digital Providers' under Annex II (Important Entities), which covers: online marketplaces, online search engines, and cloud computing service providers. Clock Software provides a cloud-based SaaS PMS (Property Management System) — this may qualify as a 'cloud computing service' under NIS2 Article 6(30) if it meets the definition. However, NIS2's 'cloud computing service' definition is narrow and primarily targets IaaS/PaaS/SaaS providers of general-purpose infrastructure. A vertical SaaS application (hotel management) may or may not be captured depending on Bulgarian national transposition. Additionally, the size threshold (50+ employees OR €10M+ turnover) is unconfirmed from public sources. Risk is Low because: (1) Clock Software is not in a clearly listed Essential Entity sector (energy, transport, banking, health, water, etc.); (2) as a vertical SaaS for hospitality, NIS2 applicability is genuinely uncertain and depends on national transposition; (3) even if applicable, the company has demonstrated security controls (TOMs in DPA Annex B) that partially address NIS2 requirements. Risk would escalate to Medium if size thresholds are confirmed and Bulgarian NIS2 transposition captures vertical SaaS providers.

Evidence: https://www.clock-software.com/data-processing-agreement, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new, https://www.clock-software.com

SOC 2 (source) — Assessment Required

Clock Software is a cloud SaaS provider processing sensitive personal data (hotel guest IDs, payment data, stay history) for 1,500+ hotel customers across 65 countries. SOC 2 is not a legal requirement but is a widely expected industry standard for cloud service providers, particularly when serving enterprise hotel groups and chains. Risk is Medium because: (1) the absence of a SOC 2 report may be a commercial barrier with enterprise hotel customers who require vendor SOC 2 attestation; (2) the company processes sensitive financial and personal data; (3) the company's DPA references security controls (Annex B) but these have not been independently audited; (4) US-based hotel customers (sky-us1, sky-us2 server regions) are particularly likely to require SOC 2 Type II reports. Risk is not High because SOC 2 is voluntary and the company has documented TOMs, and many SME SaaS providers operate without SOC 2.

Evidence: https://www.clock-software.com/data-processing-agreement, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services, https://www.clock-software.com/service-terms

GDPR (source) — Partially Compliant

Clock Software (operating entity: Klok AD, registered in Bulgaria, EU) is unambiguously subject to GDPR as both a Data Controller (for its own marketing/website visitors) and a Data Processor (for hotel guest personal data processed on behalf of hotel customers). The company has published a Privacy Policy, a Data Processing Agreement (DPA), and a Subprocessor list — all positive compliance signals. However, the status is 'Partially Compliant' rather than 'Compliant' because: (1) no independent third-party GDPR audit or DPO appointment has been publicly disclosed; (2) the Privacy Policy relies on broad consent language ('by disclosing any personal data to us you explicitly accept') which may not satisfy GDPR's granular consent requirements; (3) no Record of Processing Activities (RoPA) is publicly referenced; (4) no Data Protection Impact Assessment (DPIA) documentation is published; (5) the company processes highly sensitive hospitality data (passport/ID details, payment data, guest profiles) across 65 countries, increasing inherent risk. Risk is Medium rather than High because the company has clearly invested in GDPR infrastructure (DPA, subprocessor list, data subject rights section, breach notification procedures) and primary hosting is within the EEA (AWS Luxembourg, Google Cloud Ireland).

Evidence: https://www.clock-software.com/privacy-policy, https://www.clock-software.com/data-processing-agreement, https://www.clock-software.com, https://gdpr-info.eu/art-28-gdpr/, https://www.cpdp.bg

Financials

Three-year financials

Financial Resilience Score: 7/10

Clock Software demonstrates strong qualitative financial resilience despite the absence of disclosed quantitative financials. The company is bootstrapped, self-funded, and management explicitly claims profitability and independence from outside investors, meaning there is no external debt or VC/PE overhang that could create covenant pressure or forced growth. With a ~30-year operating history since 1996, the company has survived multiple economic shocks including the dot-com bust, the 2008 financial crisis, and — most importantly for a hospitality-focused vendor — the COVID-19 pandemic, which is a strong signal of underlying resilience. The SaaS/subscription model provides recurring, predictable cash flow, and high switching costs in the PMS category support customer retention. Geographic diversification across 65 countries reduces single-market exposure, and a broad product suite (PMS, POS, booking engine, payments, kiosk, guest portal) drives higher ARPU. However, the company is 100% exposed to the cyclical hospitality sector, competes against much larger, well-capitalized rivals (Oracle Opera, Mews, Cloudbeds, SiteMinder), and its deliberate avoidance of external capital limits M&A firepower and geographic acceleration. Key-person risk around the founder-CEO and limited financial transparency (private Bulgarian LLC with only statutory filings) also weigh on the score.

Key strengths: Bootstrapped and profitable per management, with no outside investors or external debt, Long operating history since 1996 (~30 years), including survival of COVID-19 hospitality shock, Diversified across 65 countries and 1,500+ hotel customers, Recurring SaaS subscription revenue model with high switching costs, Broad product suite (PMS, POS, booking engine, payments) increases ARPU and retention

Risk factors: 100% sector concentration in cyclical hospitality/hotel industry, Small scale versus well-funded global competitors (Oracle, Mews, Cloudbeds, SiteMinder), No external capital limits ability to fund large acquisitions or accelerated expansion, Key-person risk with founder-led leadership concentration, Financial opacity as a private Bulgarian LLC; no public disclosure of revenue, EBIT, or equity

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report