conova communications GmbH
Austria · www.conova.com · 30 vendors
conova communications GmbH is an Austrian IT service company and data center operator. It specializes in carrier-neutral colocation, network services, secure infrastructure solutions, and hybrid cloud solutions. The company serves enterprises, service providers, and public sector organizations, operating multiple data centers in Austria.
Resilience scores
- Digital Sovereignty: 30
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Broadcom Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- Veeam Software Group GmbH — Technology — United States
- and 29 more
Services catalogue
4 services in catalogue across 3 categories; runs on 30 sub-vendors.
- RcodeZero DNS
- Web Hosting
- Conova DNS Hosting
Insights
Last updated 2026-08-14 · revision 2
30 direct vendors, 272 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 4
- Sweden: 1
- United States: 18
Subvendors by controlling owner country (sample)
- Germany: 8
- Bulgaria: 1
- Unknown: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
conova communications GmbH exhibits a high degree of migration readiness, primarily driven by its extensive expertise and service offerings in hybrid cloud environments and public cloud integration. Products like 'TopServer Managed Microsoft Azure,' 'TopOperations for Hybrid Cloud,' 'TopConnect Datacenter' (for Azure, AWS, GCP), and 'TopConnect for Microsoft Azure ExpressRoute' demonstrate strong capabilities in managing and connecting to major public cloud platforms. The company's internal tech stack includes modern components such as Kubernetes (for TopContainer service), VMware vSphere, and integration with Microsoft Azure, AWS, and GCP, indicating a forward-looking and adaptable infrastructure. Their consulting services explicitly cover 'cloud migration' and 'hybrid cloud architecture,' showcasing a strategic focus and capability to guide complex transitions. The offering of 'TopAI LLM' hosted in their secure Austrian data centers, with an emphasis on data sovereignty, suggests an understanding of advanced cloud-native workloads and data residency considerations. While the 'Total Vendors: 0' data point is contradictory to the listed vendor geographic diversity, the presence of vendors from 9 unique countries suggests a degree of vendor diversity that would likely mitigate severe vendor lock-in, even if the exact number of unique vendors is not provided. The absence of specific regulatory environment details and financial stability data introduces some unknowns, but the robust technical capabilities, strategic service offerings, and consulting expertise strongly position conova for successful cloud migrations. The company's focus on containerization and managed services for public cloud platforms further enhances its readiness for modern, agile migration strategies.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is a US-origin voluntary framework developed by the AICPA for service organizations (particularly cloud and managed service providers) to demonstrate controls over security, availability, processing integrity, confidentiality, and privacy. conova is a significant managed IT services and cloud services provider, making SOC 2 highly relevant from a customer assurance perspective — particularly for international or US-linked enterprise customers. The risk level is Medium because: (1) no SOC 2 report has been found in public sources; (2) European companies in this sector often rely on ISO 27001 as the equivalent assurance framework rather than SOC 2; (3) the absence of SOC 2 may limit conova's ability to serve US-market customers or multinational enterprises that require SOC 2 attestation; (4) however, conova's ISO 27001 certification and Cyber Trust Austria Label provide substantial equivalent assurance for European customers.
Evidence: https://www.conova.com/zertifizierungen/, https://www.conova.com/cyber-trust-label-austria/
GDPR (source) — Compliant
conova is an Austrian-based data center and managed IT services provider, making GDPR (locally implemented as DSGVO) universally applicable. The company processes extensive personal data including employee data, customer data, biometric access control data (for data center entry), video surveillance data, and marketing data. The risk level is Medium rather than Low because: (1) conova explicitly states in its privacy policy that it has NOT appointed a Data Protection Officer (DPO), citing that it is not legally obligated to do so — however, given the scale and sensitivity of data processing (biometric data, video surveillance, large-scale IT infrastructure for many enterprise clients), this determination warrants scrutiny; (2) the company uses third-party processors including US-based entities (Google, HubSpot, Microsoft, Apple, Amazon) where data transfers to the US carry residual risk post-Schrems II; (3) the company processes biometric data (Art. 9 GDPR special category) for data center access control. Mitigating factors include a comprehensive, detailed privacy policy referencing all relevant GDPR articles, a dedicated privacy contact (datenschutz@conova.com), and clear data retention schedules. Austrian DPA (Datenschutzbehörde) enforcement is active.
Evidence: https://www.conova.com/datenschutz/, https://www.conova.com/wp-content/uploads/2026/06/datenschutzerklaerung2-12.pdf, https://www.conova.com/
ISO 27001 (source) — Compliant
conova has maintained ISO 27001 certification continuously since 2013, covering the company and its data centers at Salzburg-Maxglan and Hallein. The certification is issued by TÜV Rheinland, a globally recognized and accredited certification body. The risk level is Low because: (1) the certification is current (renewed 2025, certificate downloadable from the website); (2) ISO 27001 requires regular surveillance audits and recertification every 3 years, demonstrating ongoing commitment; (3) the certification scope covers the company's core business operations and data center infrastructure; (4) the company actively promotes this certification as a key differentiator and customer assurance mechanism; (5) TÜV Rheinland is an internationally accredited certification body under DAkkS (German Accreditation Body). The combination of ISO 27001 and EN 50600 certifications represents best-in-class information security and data center operational standards.
Evidence: https://www.conova.com/zertifizierungen/, https://www.conova.com/wp-content/uploads/2025/09/ISO27001-Zertifikat_conova-DE-2025-inklAnlage.pdf, https://www.conova.com/wp-content/uploads/2025/06/ISO27001-Zertifikat_conova-DE-2025.jpg, https://www.conova.com/cyber-trust-label-austria/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
conova communications GmbH demonstrates solid qualitative financial resilience anchored by its 50% ownership by Salzburg AG, a Land Salzburg-controlled multi-utility that provides strategic backing, long-term capital access, and a stable anchor customer relationship. The company operates a recurring revenue model based on data-center housing, hosting, managed services, and cloud subscriptions with typically multi-year contracts, generating predictable cash flows. Its blue-chip Austrian customer base spans regulated and mid-large industrial segments including Porsche Informatik, XXXLutz, Raiffeisenverband, and Felbermayr Holding, providing revenue stability. The company's certification portfolio (ISO 27001, 27017, 27018, EN 50600, Cyber Trust Austria) and 'data sovereignty' positioning align well with EU regulatory tailwinds including NIS2, DORA, EU Data Act, and Schrems II, supporting sustained demand. Diversification across colocation, managed cloud, security (MDR/SOC), Microsoft 365 protection, backup, and emerging AI/LLM managed services further strengthens resilience. However, resilience is constrained by scale limitations as a regional Austrian mid-market player competing against hyperscalers (AWS, Azure, Google Cloud) and larger European MSPs, ongoing capital intensity for data-center build-out, geographic concentration in Austria, related-party customer concentration with parent Salzburg AG, and exposure to European energy prices. Exact financial figures could not be verified in this session, limiting quantitative assessment.
Key strengths: 50% ownership by Salzburg AG providing strategic backing and capital access, Recurring revenue model with multi-year contracted data-center and managed services, Blue-chip Austrian customer base across regulated and industrial segments, Comprehensive certification portfolio (ISO 27001/27017/27018, EN 50600, Cyber Trust Austria), Data sovereignty positioning aligned with EU regulatory tailwinds (NIS2, DORA, Schrems II), Diversified portfolio spanning colocation, cloud, security, and AI managed services, Steady organic expansion of data-center capacity since 2020
Risk factors: Scale disadvantage versus hyperscalers (AWS, Azure, Google Cloud) and larger MSPs, High capital intensity for data-center build-out (DC 4/5 Maxglan, DC 6/7 Hallein), Geographic concentration in Austria with limited international diversification, Related-party customer concentration risk with parent Salzburg AG, Talent competition for cloud, security, and AI engineers in Salzburg region, Energy price exposure for data-center operations, Margin pressure from hyperscaler cost per compute unit
Revenue by geography
- Austria: 95%
- Other DACH/Neighboring Countries: 5%
Workforce by country
- Austria: 150
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.