ColleaiQ ApS
Denmark · owned by Independent (Denmark) · Colleaiq.dk · 12 vendors
ColleaiQ is a Copenhagen-based AI company that builds a neurosymbolic runtime for governed multi-agent AI, designed for regulated industries. Every agent action is bound to a symbolic policy layer, making decisions fully traceable to named rules and auditable by regulators. The platform is currently in production with a European manufacturer and is built for EU-sovereign, on-premises, or partner-managed deployments.
Resilience scores
- Digital Sovereignty: 33
- Digital Resilience: 7
- Financial Resilience: 4
Disruption prediction
ColleaiQ ApS has an estimated 17% probability of disruption in the next 6 months.
5 of ColleaiQ ApS's 12 vendors monitored for disruptions.
Technology vendors
- Billy — Technology — Denmark
- Google LLC — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 9 more
Insights
Last updated 2026-09-13 · revision 2
12 direct vendors, 194 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- Luxembourg: 1
- United States: 4
Subvendors by controlling owner country (sample)
- Germany: 6
- Belgium: 6
- Denmark: 18
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ColleaiQ ApS exhibits high migration readiness due to its highly modern and flexible technology stack. The architecture is described as "cloud-native" with "VPC / sovereign EU cloud tenants," supports "air-gapped and on-premises deployment," and offers "Partner-Managed / White-Label Deployment," indicating strong portability and adaptability across various environments. Their "LLM-agnostic" approach further reduces lock-in to specific AI models. The company's deep understanding and architectural focus on complex regulatory environments (GDPR, EU AI Act, NIS2 / DORA compliance, EU data sovereignty) means their systems are built with inherent flexibility to meet diverse compliance requirements, simplifying migration to other compliant infrastructures. The primary weakness affecting migration readiness is the lack of financial stability data (revenue concentration, growth history), which makes it difficult to assess the company's capacity to fund a significant migration effort. The "Vendor Lock-in Risk" is "Unknown," and the contradictory vendor data ("Total Vendors: 0" vs. "Total Services: 14" and vendor countries) makes it challenging to fully evaluate potential dependencies that could complicate migration. While their tech stack is highly flexible, the unknown aspects of vendor relationships could introduce unforeseen complexities.
Compliance
8 in-scope frameworks identified; showing 3.
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (CRA), which entered into force December 2024 with most obligations applying from December 2027, imposes mandatory cybersecurity requirements on products with digital elements placed on the EU market. ColleaiQ's AI agent orchestration platform is a software product with digital elements sold/licensed to EU customers. Risk is High because: (1) the CRA applies to software products placed on the EU market — ColleaiQ's platform is precisely such a product; (2) given its use in regulated/critical environments (manufacturing, cybersecurity), it may qualify as an 'important' or 'critical' product under CRA Annex I/II, requiring third-party conformity assessment; (3) CRA requires vulnerability handling, security-by-design, incident reporting to ENISA, and CE marking; (4) non-compliance penalties reach €15M or 2.5% of global annual turnover; (5) the company's architecture (signed rejections, policy versioning, audit trails) reflects security-by-design principles, but formal CRA conformity assessment has not been disclosed.
Evidence: https://colleaiq.dk/platform, https://colleaiq.dk/
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for information security management systems (ISMS). It is not legally mandated but is widely required by enterprise customers, particularly in regulated industries and the EU public sector, as a condition of vendor qualification. ColleaiQ processes sensitive customer operational data (manufacturing process data, AI agent traces, policy decisions) and positions itself as infrastructure for regulated work. Risk is Medium because: (1) no ISO 27001 certification has been disclosed; (2) enterprise and regulated-industry customers will demand it as the company scales; (3) ISO 27001 is the EU-preferred equivalent to SOC 2 and is commonly required in NIS2 supply-chain security assessments; (4) the company's architecture (access controls, audit trails, encryption, policy enforcement) is aligned with ISO 27001 Annex A controls, but formal certification requires an accredited third-party audit.
Evidence: https://colleaiq.dk/platform, https://colleaiq.dk/privacy
Danish Data Protection Act — Partially Compliant
The Danish Data Protection Act supplements GDPR with national specifications, including stricter rules on processing of sensitive data, employee data, and criminal records. As a Danish company, ColleaiQ is subject to this act in addition to GDPR. Risk is Medium for the same reasons as GDPR: the privacy programme is nascent (v1.0, June 2026), and as the company grows and processes more employee and customer data, Danish-specific requirements (e.g., employee data processing rules under §12) will become more material.
Evidence: https://colleaiq.dk/privacy, https://colleaiq.dk/
Financials
Three-year financials
- 2025: gross profit DKK 3.65K, EBIT DKK -6.04K, equity DKK 13.9K
Financial Resilience Score: 4/10
ColleaiQ ApS is a very early-stage Danish deep-tech startup, likely incorporated in 2024 or 2025, with no publicly retrievable financial statements at the time of research. As a first-year ApS under regnskabsklasse B, disclosures are typically minimal and limited to gross result, net result, equity, and total assets. No revenue, EBIT, or equity figures are confirmed. The company shows qualitative strengths that support resilience: a clear positioning in governed multi-agent AI aligned with EU regulatory tailwinds (AI Act, NIS2, DORA), a named production customer (ProPlast, a European manufacturer), and strong ecosystem support from DTU Skylab, SagaLabs, Copenhagen Fintech, Google for Startups, DIREC, Mikrolegat, and Scaleway. These affiliations typically provide grants, cloud credits, and non-dilutive support that extend runway. However, typical early-stage risks weigh on the score: likely pre-revenue or minimal revenue status, dependence on founder/angel/grant capital, an equity base likely close to the DKK 40,000 ApS minimum plus any seed premium, extreme customer concentration (one flagship customer), a small four-person team creating key-person risk, and an R&D-heavy neurosymbolic AI focus with burn likely running ahead of revenue. The competitive landscape (LangChain, CrewAI, Microsoft, Palantir AIP) is well funded.
Key strengths: Aligned with EU regulatory tailwinds (AI Act, NIS2, DORA), Named production customer (ProPlast, European manufacturer), Strong ecosystem support: DTU Skylab, SagaLabs, Copenhagen Fintech, Google for Startups, DIREC, Mikrolegat, Scaleway, Complete technical founding team (CEO, CTO, Head of Research, ML engineer), EU-sovereign positioning with on-prem/air-gapped deployment options
Risk factors: Likely pre-revenue or minimal revenue at seed stage, Customer concentration risk with one flagship manufacturing customer, Small team of four creates key-person risk on each co-founder, R&D-heavy deep-tech burn likely running ahead of revenue, Well-funded competition (LangChain, CrewAI, Microsoft, Palantir AIP), Equity base likely near DKK 40,000 ApS minimum plus seed premium, No public disclosure of funding rounds or investors
Revenue by geography
- Denmark/EU: 100%
Revenue by product/service
- ColleaiQ neurosymbolic runtime / governance kernel: 100%
Workforce by country
- Denmark: 4
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.