CloudAMQP
Sweden · www.cloudamqp.com · 20 vendors
Resilience scores
- Digital Sovereignty: 5
- Digital Resilience: 9
- Financial Resilience: 7
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Statuspage (an Atlassian company) — Australia
- Stripe, Inc. — Financial Services — United States
- and 17 more
Services catalogue
3 services in catalogue across 3 categories; runs on 20 sub-vendors.
- Application Messaging
- Personal Data Processing
- RabbitMQ
Insights
Last updated 2026-08-04 · revision 2
20 direct vendors, 248 subvendors
Direct vendors by controlling owner country (sample)
- United States: 17
- Australia: 2
- Denmark: 1
Subvendors by controlling owner country (sample)
- Unknown: 2
- Brazil: 1
- Germany: 6
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
CloudAMQP demonstrates extremely high migration readiness, largely due to its existing operational model across 5 major cloud providers and 129 regions. This multi-cloud, multi-region deployment inherently signifies a highly automated, containerized, and likely microservices-oriented architecture, indicating exceptional portability and experience in deploying across diverse environments. Their flexible and modern tech stack, including the in-house developed LavinMQ with a single-binary deployment model, further supports ease of migration. Expertise in private connectivity (VPC peering, PrivateLink, Private Service Connect) is crucial for secure enterprise migrations. Furthermore, adherence to SOC 2 Type II, HIPAA, and GDPR compliance means many regulatory hurdles for data migration are likely already addressed. The primary unknowns are specific data residency requirements, which could introduce complexity for certain migration paths, and the detailed nature of the '16 services' from other vendors and their associated lock-in risks. However, their core infrastructure shows minimal lock-in to any single cloud provider, positioning them ideally for future migrations or adaptations.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
CloudAMQP explicitly states on its homepage that it is 'SOC 2 compliant by AICPA' and is 'constantly audited against the Security (common criteria) and Availability Trust Services Criteria.' This is a strong indicator of active, ongoing compliance with a recognized third-party audit framework. SOC 2 Type II audits are conducted by independent CPA firms and provide the highest level of assurance for cloud service providers. The risk is Low because the company has demonstrated commitment to continuous auditing, which significantly reduces the likelihood of undiscovered control failures. The explicit mention of both Security and Availability criteria is appropriate for a messaging infrastructure provider.
Evidence: https://www.cloudamqp.com, https://www.cloudamqp.com/legal/security_and_compliance.html
GDPR (source) — Compliant
CloudAMQP is headquartered in Sweden (EU/EEA) and operated by 84codes AB, a Swedish company. GDPR is universally applicable. The company explicitly self-declares GDPR compliance on its homepage and maintains a dedicated GDPR legal page (https://www.cloudamqp.com/legal/gdpr.html). As a cloud infrastructure provider processing customer data across 129 regions globally, the data flows are complex and involve international transfers, which elevates residual risk. However, the public declaration of compliance and the existence of documented legal policies reduce the likelihood of gross non-compliance. Risk is Medium rather than Low because the company acts as both a data controller (for customer account data) and a data processor (for message queue data), creating dual obligations that require ongoing diligence. Enforcement by the Swedish Authority for Privacy Protection (IMY) is active.
Evidence: https://www.cloudamqp.com, https://www.cloudamqp.com/legal/gdpr.html, https://www.cloudamqp.com/legal/legal_and_policies.html, https://www.cloudamqp.com/legal/security_and_compliance.html
HIPAA (source) — Compliant
CloudAMQP explicitly self-declares HIPAA compliance on its homepage. As a cloud messaging infrastructure provider, CloudAMQP can be used by healthcare customers to transmit Protected Health Information (PHI) through message queues, making it a potential Business Associate under HIPAA. The company's self-declaration indicates it offers Business Associate Agreements (BAAs) and has implemented the required administrative, physical, and technical safeguards. Risk remains Medium because HIPAA compliance for a cloud infrastructure provider is operationally complex — the company must ensure that all 129 regions/deployments where healthcare customers operate meet HIPAA standards, and ongoing compliance requires continuous monitoring. US HHS OCR enforcement is active against cloud service providers.
Evidence: https://www.cloudamqp.com, https://www.cloudamqp.com/legal/security_and_compliance.html, https://www.cloudamqp.com/legal/security_policy.html
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
CloudAMQP (84codes AB) demonstrates strong qualitative financial resilience despite the absence of publicly retrieved numerical figures in this research session. The business operates a recurring SaaS revenue model providing managed message-broker infrastructure, which is mission-critical to customers and carries high switching costs. Its blue-chip customer base includes Mozilla, Docker, Heroku, Salesforce, HP, KLM, DraftKings, and Shutterstock, spread across 100+ countries with 4,100+ customers and 31,000+ managed clusters. The capital-light operating model (infrastructure rented from hyperscalers) and lean team of ~48 employees suggests strong unit economics. The company has been bootstrapped since its founding in 2012 with no publicly disclosed venture funding, yet has sustained hiring and geographic expansion, strongly implying cash-generative operations and profitability. Founder Carl Hörberg still leads the company, providing continuity. The strategic development of LavinMQ, their in-house open-source broker, provides a hedge against RabbitMQ platform risk (now owned by Broadcom). Compliance certifications (SOC 2, GDPR, HIPAA) support upmarket enterprise sales. Key risks include underlying-technology concentration on RabbitMQ (Broadcom-owned), hyperscaler dependency for both infrastructure delivery and as competitive threats (Amazon MQ, Azure Service Bus, Google Pub/Sub), small absolute size versus hyperscaler competitors, and FX exposure with USD/EUR-denominated revenue against SEK-denominated Swedish salary costs. As a private, bootstrapped, founder-controlled entity, external governance and transparency are limited beyond statutory Swedish annual reports.
Key strengths: Recurring SaaS revenue model with high switching costs, Blue-chip diversified customer base (Mozilla, Docker, Heroku, Salesforce, HP, KLM), Capital-light operating model leveraging hyperscaler infrastructure, Bootstrapped since 2012 with no external funding, implying cash-generative operations, Founder-led continuity (Carl Hörberg still CEO), LavinMQ in-house open-source broker as strategic hedge against RabbitMQ platform risk, SOC 2, GDPR, and HIPAA compliance supporting enterprise sales, Global reach across 100+ countries and ~129 cloud regions
Risk factors: Underlying-technology concentration risk on RabbitMQ (Broadcom-owned), Hyperscaler dependency for infrastructure and as competing managed queue services, Small absolute size (~48 employees) versus hyperscaler competitors, FX exposure: USD/EUR revenue versus SEK salary costs, Private, bootstrapped, founder-controlled with limited external governance, Limited public financial disclosures beyond statutory Swedish annual report
Revenue by geography
- North America: 60%
- Europe: 30%
- Rest of World: 10%
Revenue by product/service
- CloudAMQP (Managed RabbitMQ/LavinMQ Hosting): 100%
Workforce by country
- Sweden: 30
- New Zealand: 5
- United States: 4
- Spain: 1
- Brazil: 1
- Hungary: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.