ConsentPro

United States · www.consentpro.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 10 sub-vendors.

Insights

Last updated 2026-08-15 · revision 2

10 direct vendors, 191 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ConsentPro exhibits a high level of migration readiness, primarily due to its modern and API-driven technology stack. The internal tech stack includes cloud-native platforms such as Vercel, Cloudflare, Auth0, and Stripe, which are inherently designed for flexibility and portability. The extensive use of APIs, including the Consent Pro API, Webflow API, and Webflow Localization API, suggests a modular architecture that would facilitate easier decoupling and re-platforming during a migration. The company's strong focus on regulatory compliance, evidenced by SOC 2 Type 2 compliance and products built for GDPR/CCPA, means that compliance considerations are likely well-understood and integrated, simplifying this aspect of a migration. However, several factors introduce uncertainty. Data residency requirements are not specified, which could introduce significant complexity if specific geographic data storage mandates exist. Financial stability data (revenue concentration, growth history) is missing, making it difficult to assess the company's capacity to fund a potentially costly migration. The vendor lock-in risk is unknown, and while vendor geographic diversity is present, the reliance on 16 services could present challenges if these services are deeply integrated and difficult to replace without significant effort.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

ConsentPro (operated by Finsweet Inc.) is a US-based SaaS company that explicitly processes personal data of EU/EEA residents as a core part of its business model. As a Consent Management Platform (CMP), it stores consent logs from EU website visitors on behalf of its customers, making it both a data controller (for its own customer data) and a data processor (for end-user consent records). The company markets GDPR compliance as its primary value proposition, which creates heightened regulatory scrutiny — any non-compliance would be reputationally catastrophic and legally exposed. While Finsweet has published an EU & Swiss Privacy Policy, a Data Processing Addendum (DPA), and a dedicated GDPR/ePrivacy notice, the company is US-based with infrastructure on Vercel and Cloudflare, raising data transfer concerns under GDPR Chapter V (Schrems II). The risk is High because: (1) the product's core function is consent management, making GDPR the central regulatory framework; (2) cross-border data transfers from EU to US require valid transfer mechanisms (SCCs or adequacy decisions); (3) enforcement by EU DPAs against CMPs has intensified (e.g., IAB TCF enforcement by Belgian DPA); (4) no DPO appointment has been publicly confirmed; (5) the company's size and global customer base amplify exposure.

Evidence: https://finsweet.com/legal/gdpr-and-eprivacy-notice-for-finsweet-products, https://finsweet.com/legal/data-processing-addendum, https://finsweet.com/legal/eu-swiss-privacy-policy, https://finsweet.com/legal/subprocessors, https://finsweet.com/legal/privacy-policy, https://consentpro.com, https://finsweet.com/company/security

ePrivacy Directive — Partially Compliant

The ePrivacy Directive (and its national implementations across EU member states) is the primary regulatory framework that ConsentPro's product is specifically designed to address. As a Consent Management Platform (CMP), ConsentPro helps its customers comply with ePrivacy requirements for cookie consent. However, ConsentPro itself must also comply with ePrivacy as a data processor/controller. The risk is High because: (1) ePrivacy is the core regulatory driver for ConsentPro's entire product existence; (2) enforcement has intensified across EU member states (France CNIL, Germany DSK, Italy Garante, Belgium APD); (3) ConsentPro processes consent signals and cookie data from EU users, making it directly subject to ePrivacy obligations; (4) the pending ePrivacy Regulation (replacing the Directive) may impose stricter requirements; (5) IAB TCF enforcement actions against CMPs have set precedent for direct CMP liability.

Evidence: https://finsweet.com/legal/gdpr-and-eprivacy-notice-for-finsweet-products, https://consentpro.com, https://finsweet.com/legal/data-processing-addendum

US State Privacy Laws — Assessment Required

As of 2025, over 20 US states have enacted comprehensive privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, Florida FDBR, Washington My Health MY Data Act, etc.). ConsentPro/Finsweet Inc. is a US-based company serving customers across all US states. The company's Privacy Policy acknowledges 'U.S. State privacy rights' broadly but does not enumerate specific state law compliance. The risk is Medium because: (1) the patchwork of state laws creates compliance complexity; (2) ConsentPro's product already supports geolocation-based consent banners, suggesting awareness; (3) enforcement is still maturing in most states; (4) the company's size and data processing activities may trigger applicability thresholds in multiple states.

Evidence: https://finsweet.com/legal/privacy-policy, https://finsweet.com/legal/california-do-not-sell-my-info-notice, https://consentpro.com

Financials

Three-year financials

Financial Resilience Score: 5/10

ConsentPro is a product line owned by Finsweet, a privately held US Webflow agency founded in 2016. Because Finsweet is private and has no SEC filings, no revenue, EBIT, equity, cash, or debt figures are publicly available, making independent solvency and scale assessment impossible. The score reflects moderate qualitative resilience balanced against total financial opacity. On the positive side, Finsweet has an approximately 10-year operating history within the Webflow ecosystem, a diversified product portfolio (Consent Pro, Wized, Components, Attributes, CMS Bridge, Client-First, Extension, Finsweet+) plus an agency services line with blue-chip clients including Dropbox, GitHub, Vanta, WeTransfer, Webflow itself, Blue Cross, Aura, and Lithia Motors. The company holds SOC 2 Type 2 certification (via Vanta), and the consent-management category benefits from regulatory tailwinds from GDPR, CCPA/CPRA, and expanding state privacy laws. Consent Pro's Webflow-native positioning creates a defensible niche moat versus larger horizontal CMPs. On the negative side, the business is heavily platform-dependent on Webflow, faces competition from at least 7 direct CMP competitors (OneTrust, Usercentrics, Didomi, CookieYes, CookieScript, Axeptio, Adopt), uses a lifetime-license pricing model that pulls revenue forward while creating ongoing support obligations, and carries typical small private-company key-person risk. Regulatory exposure exists if the CMP fails to properly block trackers.

Key strengths: Approximately 10-year operating history since 2016, Diversified product portfolio and agency services line within parent Finsweet, Blue-chip agency clients (Dropbox, GitHub, Vanta, WeTransfer, Webflow, Blue Cross, Aura, Lithia Motors), SOC 2 Type 2 certified via Vanta, Regulatory tailwind from GDPR, CCPA/CPRA, and state privacy laws, Webflow-native niche positioning creates defensible moat, Claimed 91-97% employee retention rate

Risk factors: Zero financial transparency - no revenue, EBIT, equity, or headcount disclosed, Platform-dependency risk on Webflow ecosystem, Competitive density with 7+ direct CMP competitors, many far larger and better funded, Lifetime-license pricing model pulls revenue forward without recurring revenue, Small-team/founder-led private-company key-person risk, Regulatory/legal exposure if trackers not properly blocked under GDPR/CCPA

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report