Code42

United States · www.code42.com · 18 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-08-15 · revision 2

18 direct vendors, 169 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Code42 exhibits exceptionally high migration readiness due to its highly modern and cloud-native internal tech stack. The extensive use of Amazon Web Services (AWS), containerization (Kubernetes, Docker), and microservices-oriented technologies (Apache Kafka, Apache Spark, Elasticsearch) indicates that their architecture is already designed for scalability, portability, and cloud environments. The adoption of infrastructure-as-code (Terraform) and robust CI/CD pipelines (Jenkins, GitHub) further streamlines deployment and management, making future migrations or architectural shifts significantly easier. The modern tech stack also implies a lower reliance on legacy, monolithic systems, which are typically major hurdles in migration. While the exact number of distinct vendors is unclear, the modern architecture suggests that potential vendor lock-in from the 20 services is likely manageable, as integrations are often API-driven and less proprietary. The primary limitations to a perfect score are the unknown factors: specific regulatory environment, data residency requirements, and financial stability, which could impact the funding and complexity of any major migration initiatives. The explicit "Vendor Lock-in Risk" is also unknown.

Compliance

7 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 certification is increasingly expected by enterprise customers, particularly those in regulated industries and EU-based organizations. For Code42, which handles sensitive insider threat data and employee behavioral telemetry, ISO 27001 provides a recognized framework for information security management. Risk is MEDIUM because: (1) lack of ISO 27001 certification is not legally mandated but creates competitive and contractual risk; (2) EU customers subject to GDPR and NIS2 often require ISO 27001 from their vendors; (3) Code42's product handles highly sensitive data making information security management critical; (4) no public ISO 27001 certificate was found in official sources, though this does not confirm absence of certification.

Evidence: https://www.code42.com/, https://www.iso.org/isoiec-27001-information-security.html

NIST Cybersecurity Framework — Assessment Required

The NIST Cybersecurity Framework is a voluntary framework widely adopted by US organizations for managing cybersecurity risk. As a cybersecurity company, Code42 would be expected to align its own security practices with NIST CSF. Risk is LOW because NIST CSF is voluntary and non-compliance does not carry direct legal penalties. However, alignment with NIST CSF is often required by enterprise customers and government contractors.

Evidence: https://www.code42.com/, https://www.nist.gov/cyberframework

GDPR (source) — Assessment Required

Code42 provides a SaaS-based insider threat and data loss prevention platform (Incydr) that monitors employee behavior, file movements, and endpoint activity. This inherently involves processing significant volumes of personal data — including employee behavioral data, file metadata, and endpoint telemetry — on behalf of its enterprise customers, many of whom are EU/EEA-based organizations. As a US-headquartered data processor serving EU customers, Code42 must comply with GDPR's Chapter V requirements for international data transfers (e.g., Standard Contractual Clauses), Article 28 Data Processing Agreements, and data subject rights obligations. Non-compliance risk is HIGH because: (1) the nature of the product (employee monitoring) is particularly sensitive under GDPR; (2) EU supervisory authorities have actively enforced against employee monitoring tools; (3) US-to-EU data transfers remain under scrutiny post-Schrems II; and (4) fines can reach €20M or 4% of global annual turnover.

Evidence: https://www.code42.com/, https://support.code42.com/hc/en-us/articles/14827671688087-Code42-security-and-compliance

Financials

Three-year financials

Financial Resilience Score: 6/10

Code42 is a private US cybersecurity software company with no public financial disclosures for FY2022–FY2024. The most recent reliable public revenue reference is approximately $100M from 2015 IPO-related filings that were subsequently withdrawn. Since then, the company has operated privately with backing from established investors including JMI Equity, Accel, and Split Rock Partners, and was reportedly combined with Mimecast (a Permira portfolio company) in 2024, effectively ending its independent existence. The company benefits from a recurring SaaS revenue model through its Incydr insider risk management product, which typically delivers high gross margins and strong customer retention economics. Long-term PE backing and the strategic combination with Mimecast suggest a stable capital base. However, the 2024 tie-up itself may indicate that standalone growth had plateaued. Intense competition from Microsoft Purview, Proofpoint, Forcepoint, DTEX, Varonis, and CrowdStrike, combined with a relatively narrow product portfolio, presents meaningful risks. Financial opacity limits rigorous counterparty analysis without direct NDA-based disclosure.

Key strengths: Well-funded PE backing from JMI Equity, Accel, Split Rock Partners, and now Mimecast/Permira, Recurring SaaS revenue model via Incydr subscriptions with high gross margins, Established brand in insider risk management with large installed customer base, Serves approximately 50,000 organizations worldwide, Product focus after divesting consumer CrashPlan business in 2017

Risk factors: Intense competition from Microsoft Purview, Proofpoint, Forcepoint, DTEX, Varonis, and CrowdStrike, Category consolidation suggested by 2024 Mimecast combination indicates standalone growth may have plateaued, Financial opacity with no audited public financials available, Narrow product portfolio compared with larger platform vendors, limiting cross-sell, Loss of independent existence following Mimecast combination in 2024

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report