ConsenSys

United States · infura.io · 14 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 14 sub-vendors.

Insights

Last updated 2026-07-12 · revision 1

14 direct vendors, 224 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ConsenSys exhibits very high migration readiness, primarily driven by its highly modern and cloud-native internal technology stack. The company already utilizes multiple major cloud providers (AWS, GCP, Azure), demonstrating existing cloud adoption and expertise. The widespread use of containerization (Kubernetes, Docker) and infrastructure as code (Terraform) ensures portability and automated deployment, significantly streamlining any migration efforts. Their adoption of modern programming languages (Go, Java, Node.js, TypeScript) and open-source technologies (PostgreSQL, Redis, Kafka, Prometheus, Grafana) further reduces technical lock-in to proprietary solutions. The absence of specified data residency requirements simplifies migration planning by removing geographical constraints on data storage. Key challenges and unknowns include the lack of information on financial stability (revenue, growth history), which could impact the funding of large-scale migration projects. The regulatory environment is also unspecified, potentially introducing unforeseen compliance complexities. While the internal tech stack suggests low technical lock-in, the 'Vendor Lock-in Risk' is explicitly 'Unknown', and the contradictory vendor data makes it difficult to assess potential contractual lock-in with service providers for the 19 identified services.

Compliance

9 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 Directive (EU) 2022/2555 includes 'digital infrastructure' and 'digital providers' (including cloud computing services, online marketplaces, online search engines, and managed ICT services) as covered entities. Infura operates as a critical blockchain API/RPC infrastructure provider — a digital infrastructure service upon which thousands of EU-based decentralized applications, financial services, and developers depend. ConsenSys/Infura almost certainly exceeds the NIS2 size thresholds (50+ employees, €10M+ turnover) given its global scale and venture funding history. However, formal classification as an 'Essential Entity' or 'Important Entity' under NIS2 depends on EU member state implementation and whether blockchain RPC infrastructure is explicitly categorized. The risk is Medium because: (1) NIS2 applicability is highly probable but not yet definitively confirmed through public regulatory classification; (2) Non-compliance with NIS2 can result in fines up to €10M or 2% of global annual turnover for essential entities; (3) EU regulators are actively expanding digital infrastructure oversight.

Evidence: https://infura.io, https://consensys.io/security, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

CPRA — Partially Compliant

ConsenSys explicitly addresses California residents in its Privacy Notice with a dedicated US State Privacy supplemental section. The company confirms it does not sell personal information, provides opt-out rights for sharing (targeted advertising), and supports Global Privacy Control (GPC). Risk is Medium because: (1) ConsenSys acknowledges sharing personal data with third-party ad providers for advertising purposes, which may constitute 'sharing' under CPRA; (2) The company's use of Google Analytics, Google Tag Manager, HubSpot, Segment, and LinkedIn for advertising creates CPRA exposure; (3) Enforcement by the California Privacy Protection Agency (CPPA) is active and increasing.

Evidence: https://consensys.net/privacy-policy, https://globalprivacycontrol.org/

SOC 2 (source) — Assessment Required

Infura is a cloud-based API and blockchain node service provider serving enterprise and developer customers globally, including major clients such as MetaMask, Uniswap, Coinbase, Reddit, Brave, Compound, and Polygon. Enterprise customers of cloud service providers routinely require SOC 2 Type II reports as part of vendor due diligence. The absence of a publicly disclosed SOC 2 report creates vendor risk for enterprise customers and represents a competitive disadvantage. Risk is Medium because: (1) Enterprise customers may require SOC 2 as a contractual prerequisite; (2) Lack of SOC 2 may indicate gaps in security controls documentation; (3) The blockchain infrastructure sector is increasingly subject to enterprise security requirements.

Evidence: https://infura.io, https://consensys.io/security, https://status.infura.io/

Financials

Three-year financials

Financial Resilience Score: 6/10

Consensys is a privately held blockchain software company with no publicly disclosed audited financials, making a definitive resilience assessment difficult. However, the company entered the crypto downturn with substantial cash reserves after raising US$450M in March 2022 at a US$7B valuation from tier-1 investors including Microsoft, Temasek, SoftBank Vision Fund 2, and ParaFi Capital. This strong balance sheet, combined with category-leading products (MetaMask and Infura) and a diversified Ethereum stack portfolio, supports medium-term resilience. However, revenue is highly cyclical and correlated with crypto market volumes, particularly MetaMask swap fees (historically 0.875%). Multiple rounds of layoffs in 2023 (~20% in January, ~11% in October) and mid-2024 (~20%) indicate meaningful margin pressure post-bull-market. Regulatory risk (SEC Wells Notice in April 2024, later dropped; EU MiCA) and rising competition from Alchemy, QuickNode, Phantom, and embedded wallet providers add uncertainty. The score reflects strong strategic positioning and funding offset by opaque financials, cyclical revenue, and structural cost pressures.

Key strengths: US$450M Series D raised March 2022 at US$7B valuation, Tier-1 investor base (Microsoft, Temasek, SoftBank, ParaFi), Category-leading products: MetaMask (dominant self-custody wallet) and Infura (top-2 Ethereum RPC provider), Diversified Ethereum stack: consumer, developer infra, L2 (Linea), staking, enterprise, Founder-led by Ethereum co-founder Joseph Lubin, Recurring/usage-based revenue streams

Risk factors: Revenue highly correlated with crypto market cycles and ETH price volatility, Regulatory overhang (SEC, EU MiCA), Multiple rounds of layoffs 2023-2024 indicating margin pressure, Growing competition from Alchemy, QuickNode, Phantom, Coinbase Wallet, No public financial disclosure limits transparency for counterparties, Heavy concentration on Ethereum ecosystem

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report