Coinbase
United States · www.coinbase.com · 7 vendors
Resilience scores
- Digital Sovereignty: 86
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Google LLC — Technology — United States
- Netlify, Inc. — Technology — United States
- Zendesk, Inc. — Technology — United States
- and 4 more
Services catalogue
2 services in catalogue across 2 categories; runs on 7 sub-vendors.
- Personal Data Processing
- Wallet
Insights
Last updated 2026-09-13 · revision 1
7 direct vendors, 173 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Australia: 1
Subvendors by controlling owner country (sample)
- Romania: 1
- China: 1
- Italy: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Coinbase exhibits exceptionally high migration readiness, primarily driven by its cutting-edge, cloud-native, and containerized infrastructure. The extensive use of Kubernetes, Docker, and a microservices architecture (gRPC, Istio) across a multi-cloud environment (AWS, GCP) signifies an architecture built for portability and flexibility, minimizing technical lock-in. Automation tools like Terraform, Spinnaker, GitHub Actions, and Bazel further streamline potential migration efforts. The sophisticated data platform utilizing Snowflake, dbt, Airflow, and Hadoop/Spark also suggests a well-managed and adaptable data layer. The primary challenges and unknowns for migration readiness stem from the lack of specific data on regulatory environment details and data residency requirements, which could introduce complexity depending on the target environment. While "Vendor Lock-in Risk: Unknown" is stated, the highly diversified and open-source-leaning tech stack generally mitigates this. The absence of financial stability data also means the ability to fund large-scale migrations is not explicitly known, but the overall technical posture points to a very high degree of readiness for migration.
Compliance
14 in-scope frameworks identified; showing 3.
CPRA — Compliant
Coinbase is headquartered in San Francisco, California, and serves millions of California residents. CCPA/CPRA applies to businesses that: (1) have annual gross revenues exceeding $25M (Coinbase far exceeds this), (2) buy, sell, or share personal information of 100,000+ California consumers (Coinbase exceeds this), or (3) derive 50%+ of annual revenues from selling personal information. Coinbase clearly meets the applicability thresholds. The risk level is Medium because Coinbase has implemented CCPA-compliant privacy controls (evidenced by the 'Do Not Sell or Share My Personal Information' link on its website), but the CPRA's enhanced requirements (data minimization, sensitive personal information rights, expanded opt-out rights) require ongoing compliance maintenance.
Evidence: https://www.coinbase.com/legal/privacy, https://www.coinbase.com
ISO 27001 (source) — Assessment Required
ISO 27001 certification is increasingly expected for large financial technology companies operating globally. While Coinbase has not publicly confirmed ISO 27001 certification, its scale of operations (serving 100M+ verified users, managing billions in assets), global regulatory requirements, and institutional client base create strong incentives for certification. The risk level is Medium because: (1) ISO 27001 is not legally mandated for Coinbase's US operations, (2) SOC 2 Type II partially addresses similar information security controls, (3) however, EU regulators (particularly under DORA and MiCA) increasingly reference ISO 27001 as a benchmark, and (4) absence of certification may be a competitive disadvantage in enterprise/institutional markets.
Evidence: https://www.coinbase.com/security, https://hackerone.com/coinbase, https://investor.coinbase.com/sec-filings
ISAE 3000 (source) — Assessment Required
ISAE 3000 is relevant to Coinbase primarily in the context of non-financial assurance reporting (e.g., ESG/sustainability reports, privacy compliance attestations, or crypto asset proof-of-reserve reports). Coinbase has published Proof of Reserves reports and ESG disclosures that may involve ISAE 3000 or equivalent assurance standards. The risk level is Low because ISAE 3000 is not a legally mandated compliance framework for Coinbase's core operations, and non-compliance does not carry direct regulatory penalties.
Evidence: https://investor.coinbase.com/sec-filings, https://www.coinbase.com/blog
Financials
Three-year financials
- 2025: revenue USD 7.18B, EBIT USD 1.44B, equity USD 14.8B
- 2024: revenue USD 6.56B, EBIT USD 2.31B, equity USD 10.3B
- 2023: revenue USD 3.11B, EBIT USD -162M, equity USD 6.28B
Financial Resilience Score: 7/10
Coinbase has demonstrated strong financial recovery from the 2022 crypto winter, returning to GAAP profitability in 2023 and posting record profitability in 2024 with net income of approximately $2.58B and operating income of $1.31B. The company maintains a robust balance sheet with several billion dollars of cash, cash equivalents, and USDC on hand (typically $5-8B), providing substantial runway through potential downturns. Adjusted EBITDA was positive in every quarter of 2023 and 2024, indicating consistent operational profitability. A key strength is the structural shift in revenue mix: subscription & services revenue (staking, USDC interest, custody, blockchain rewards) grew from a small share pre-2022 to roughly 35% of revenue by 2024, meaningfully reducing dependency on cyclical trading fees. Coinbase's position as primary custodian for most U.S. spot Bitcoin ETFs provides recurring custody fees and reinforces its regulatory moat as one of the few large, U.S.-regulated public crypto exchanges. However, resilience is tempered by high cyclicality tied to crypto asset prices and trading volumes, ongoing regulatory overhang (including the SEC's June 2023 enforcement action), concentration in USDC-related interest income exposed to rates and Circle's market share, and competitive fee pressure from Robinhood, PayPal, Block, and offshore exchanges. The 2022 loss of $2.6B (including a ~$1.9B goodwill impairment) illustrates the magnitude of downside risk in bear cycles.
Key strengths: Return to GAAP profitability in 2023 and record profitability in 2024, Strong cash and USDC balance ($5-8B range), Diversified revenue mix with subscription & services at ~35% of revenue, Primary custodian for most U.S. spot Bitcoin ETFs, U.S. regulatory moat as one of few large public regulated crypto exchanges, Cost discipline via 2022-2023 headcount reductions, Positive adjusted EBITDA every quarter of 2023 and 2024
Risk factors: Revenue cyclicality tied to crypto prices and trading volumes, Regulatory overhang including SEC enforcement action from June 2023, USDC interest revenue concentration exposed to rates and Circle relationship, Staking regulatory uncertainty across jurisdictions, Operational and cyber risk concentration from custodying large ETF assets, Competitive fee pressure from Robinhood, PayPal, Block, and offshore exchanges
Revenue by geography
- United States: 80%
- International: 20%
Revenue by product/service
- Transaction Revenue: 61%
- Subscription & Services: 35%
- Other Revenue: 4%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.