Close

United States · close.com · 33 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 33 sub-vendors.

Insights

Last updated 2026-08-17 · revision 1

33 direct vendors, 278 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Close demonstrates high migration readiness due to its modern and flexible tech stack. **Strengths:** The use of Python, React, MongoDB, PostgreSQL, and AWS S3 indicates a contemporary and potentially cloud-native architecture. The presence of "Argo Workflows" suggests adoption of modern orchestration practices, likely involving containers and microservices, which significantly eases migration efforts. The comprehensive "Close REST API & Developer Platform" with OAuth 2.0, webhooks, and client libraries points to a highly modular and interoperable system, reducing the complexity of integrating with or migrating to new environments. The company's focus on "SOC 2 Type 2 compliance tooling" suggests established data governance and security practices that would support a structured migration. The lack of specified data residency requirements could offer flexibility in choosing migration targets. **Weaknesses:** The primary challenge for assessing migration readiness is the absence of critical financial data (revenue concentration, growth history), which makes it impossible to evaluate the company's financial capacity to fund a significant migration project. Specific details regarding the regulatory environment are also missing, which could introduce unforeseen compliance hurdles during migration. While vendor geographic diversity is noted, the "Total Vendors: 0" is contradictory, and the "Vendor Lock-in Risk" is unknown, making it difficult to fully assess potential dependencies and associated migration complexities, particularly with the explicit reliance on "Twilio (telephony infrastructure)" for a core service.

Compliance

7 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

The EU AI Act (Regulation 2024/1689) entered into force on August 1, 2024, with phased implementation through 2027. Close's AI agent 'Chloe' autonomously calls leads, qualifies prospects through real conversations, and books meetings — constituting an AI system that interacts with humans. Risk is Medium because: (1) Chloe makes autonomous outbound calls to individuals, which may qualify as a 'high-risk' or at minimum 'limited-risk' AI system under the EU AI Act; (2) Transparency obligations under Article 50 require that individuals be informed when interacting with an AI system (chatbots, voice agents); (3) Close serves EU customers, bringing Chloe's interactions with EU residents within scope; (4) The AI Act's general-purpose AI (GPAI) provisions may apply to underlying AI models used by Chloe; (5) Prohibited AI practices (Article 5) include subliminal manipulation — Close must ensure Chloe's sales tactics comply; (6) Full enforcement of high-risk AI provisions begins August 2026. Risk is not High because Chloe appears to be a sales automation tool rather than a system making consequential decisions about individuals (employment, credit, etc.).

Evidence: https://close.com/chloe, https://close.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689

ISO 27001 (source) — Assessment Required

No evidence of ISO 27001 certification was found on Close's official website or public documentation. Close's security page prominently features SOC2 Type 2 and GDPR compliance but does not mention ISO 27001. Close's GDPR page notes that sub-processors like AWS maintain 'SOC2 and/or ISO 27001 certifications' — implying Close itself may not hold ISO 27001. Risk is Low because: (1) Close already holds SOC2 Type 2, which provides comparable information security assurance for US-market customers; (2) ISO 27001 is more commonly required by European enterprise customers; (3) the absence of ISO 27001 may create friction with EU enterprise sales but does not represent a regulatory violation; (4) Close's customer base appears to be primarily SMB/mid-market where SOC2 is the dominant standard.

Evidence: https://close.com/security, https://close.com/gdpr

GDPR (source) — Compliant

Close is a US-headquartered SaaS CRM provider that explicitly serves EU/EEA customers and processes personal data of EU/EEA residents (leads, contacts, prospects stored in the CRM). Close has publicly declared GDPR compliance, appointed an independent Data Privacy Officer (DPO) and Chief Cybersecurity Officer (CCO), conducted a third-party gap analysis, and offers Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) for cross-border data transfers. Risk remains Medium rather than Low because: (1) Close acts as both a Data Controller and Data Processor, creating dual obligations; (2) the CRM stores large volumes of personal data (calls, emails, SMS, contact records) for thousands of customers globally; (3) GDPR enforcement has intensified across the EU with significant fines for SaaS providers; (4) the AI agent 'Chloe' introduces new data processing activities (automated calling, profiling, lead qualification) that may require additional DPIA assessments; and (5) sub-processor chain (AWS and others) must be continuously monitored. Self-declared compliance without a formal GDPR certification (which does not exist as an accredited standard) means ongoing vigilance is required.

Evidence: https://close.com/gdpr, https://close.com/security, https://resource-downloads.close.com/website/close-data-processing-scc-feb-2023.pdf

Financials

Three-year financials

Financial Resilience Score: 7/10

Close is a privately held, bootstrapped SaaS company that has publicly declared itself profitable since inception, with over a decade of operational history since its founding in 2013. The company has built a recurring revenue model with 11,500+ paying sales teams globally, a diversified customer base that reduces concentration risk, and a lean 100% remote workforce of approximately 100 employees keeping overhead low. Self-funding without significant venture dilution indicates sustainable unit economics and disciplined cash management. However, financial opacity is a major limitation — no audited statements, revenue figures, EBIT, or equity data are publicly disclosed, making external validation of profitability claims impossible. Third-party estimates place ARR in the ~$40-60M range but are unverified. The company operates in an intensely competitive CRM market against well-funded giants (Salesforce, HubSpot, Pipedrive) that can outspend on R&D and AI capabilities. Its SMB/startup customer focus creates churn sensitivity during macroeconomic downturns, and its small headcount may limit ability to compete in the accelerating AI arms race. Overall resilience appears healthy for its size, but the lack of transparency prevents a higher confidence rating.

Key strengths: Bootstrapped and self-funded with no reliance on venture debt or dilutive rounds, Recurring SaaS subscription revenue model with tiered pricing, 11,500+ paying sales teams providing diversified customer base, Over a decade of operating history (founded 2013) with proven unit economics, Self-declared profitability sustained across multiple years, Lean cost structure with 100% remote workforce (~100 employees), High customer satisfaction (4.7/5 on G2 across 2,000+ reviews), Public commitment to donate 1% of revenue to Stripe Climate signals cash confidence, Cumulative platform activity exceeding 2 billion sales conversations

Risk factors: Complete financial opacity — no audited statements or verified revenue figures, Highly competitive CRM market with well-funded incumbents (Salesforce, HubSpot, Pipedrive, Zoho), AI arms race exposure — large competitors can invest hundreds of millions in AI capabilities, Small headcount (~100) may limit R&D scaling versus competitors, Bootstrapped constraint limits firepower for marketing pushes or M&A during downturns, SMB/startup customer focus creates higher churn risk in economic downturns, Telecom/regulatory exposure from global calling/SMS (STIR/SHAKEN, TCPA, international rules), Dependence on new Chloe AI agent for future competitive positioning

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report