ControlMap
United States · www.controlmap.com · 17 vendors
Resilience scores
- Digital Sovereignty: 71
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- BambooHR — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Google LLC — Technology — United States
- and 14 more
Services catalogue
1 service in catalogue across 1 category; runs on 17 sub-vendors.
- ControlMap
Insights
Last updated 2026-08-15 · revision 2
17 direct vendors, 215 subvendors
Direct vendors by controlling owner country (sample)
- Canada: 1
- Denmark: 1
- France: 1
Subvendors by controlling owner country (sample)
- United States: 157
- Spain: 2
- UK: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ControlMap exhibits high migration readiness, largely due to its existing multi-cloud infrastructure across AWS, Azure, and GCP. This indicates a modern, cloud-native approach and significant experience in managing diverse cloud environments, which are foundational for any migration effort. The company's multi-tenant SaaS architecture and 83+ REST API integrations suggest a modular and API-driven system, facilitating easier data and application portability. Their internal compliance with SOC 2 Type II and ISO 27001, coupled with product offerings like CMMC tooling and GovCloud hosting support, demonstrates a strong capability to navigate complex regulatory and security requirements during migration. The geographic diversity of their vendor base (5 countries) also suggests a reduced risk of vendor-specific geographic concentration impacting migration plans. Key challenges and unknowns include the lack of specified data residency requirements, which could introduce significant constraints on where data can be migrated. The absence of financial stability data (revenue concentration, growth history) also means the ability to fund large-scale migration initiatives cannot be fully assessed. While a modern architecture is implied, explicit confirmation of containerization or microservices adoption would further solidify the high readiness score.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
ScalePad has achieved SOC 2 Type II certification, which is the highest level of SOC 2 assurance, covering not just the design but the operating effectiveness of controls over a period of time. A public SOC 3 report is available for download, and the SOC 2 Type II report is available under NDA. The risk is Low because: (1) SOC 2 Type II has been independently audited and confirmed; (2) The certification explicitly covers ControlMap as one of the in-scope products; (3) The company uses its own ControlMap platform to manage its compliance program, demonstrating operational maturity; (4) Continuous compliance monitoring is built into their product and internal operations. The main residual risk is the annual renewal cycle — compliance must be maintained and re-audited periodically.
Evidence: https://www.scalepad.com/security, https://cdn.sanity.io/files/rss1jlb9/production/50f4890e5801807e4c91e4ca0da66a5f7d32539e.pdf, https://www.scalepad.com/security/scalepad-product-security-whitepaper.pdf
GDPR (source) — Partially Compliant
ScalePad (parent of ControlMap) explicitly acknowledges GDPR applicability in its Privacy Policy and DPA, has appointed a Privacy and Data Protection Officer, uses Standard Contractual Clauses (Model Clauses) for EEA/UK data transfers, and maintains a published DPA. However, as a Canadian-headquartered SaaS company serving global MSP clients — including those in the EU/EEA — it acts as both a data controller and data processor. The risk is Medium rather than High because the company has clearly invested in GDPR compliance infrastructure (DPA, SCCs, DPO, breach notification procedures), but full compliance cannot be independently verified without a third-party GDPR audit. The company's global MSP customer base means EU personal data is routinely processed, keeping ongoing compliance obligations elevated.
Evidence: https://www.scalepad.com/privacy, https://www.scalepad.com/dpa, https://www.scalepad.com/security, https://cdn.sanity.io/files/rss1jlb9/production/50f4890e5801807e4c91e4ca0da66a5f7d32539e.pdf
ISAE 3000 (source) — Assessment Required
ISAE 3000 (Assurance Engagements Other than Audits or Reviews of Historical Financial Information) is the international standard underpinning assurance reports such as SOC 2 (when performed under ISAE standards rather than AICPA AT-C Section 205). ScalePad has SOC 2 Type II and SOC 3 reports, which in the US context are performed under AICPA standards. For European or international clients, the equivalent assurance may be sought under ISAE 3000 or ISAE 3402. The risk is Low because: (1) The underlying controls are already independently audited via SOC 2 Type II; (2) ISAE 3000 is more relevant for European assurance contexts; (3) The company's existing SOC 2 and ISO 27001 certifications provide substantial equivalent assurance; (4) No evidence of ISAE 3000-specific engagements has been found, but this may simply reflect the company's primary market being North American MSPs.
Evidence: https://www.scalepad.com/security, https://cdn.sanity.io/files/rss1jlb9/production/50f4890e5801807e4c91e4ca0da66a5f7d32539e.pdf
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
ControlMap operates as a product line within ScalePad Software Inc., a private, PE-backed Canadian software group. Because no audited financials, SEC filings, or public disclosures exist, financial resilience must be assessed qualitatively. The business benefits from a recurring SaaS revenue model with per-client MSP pricing that provides revenue predictability, backing from Integrity Growth Partners (since 2021) providing capital for aggressive M&A, and cross-sell leverage into a 12,000+ MSP partner installed base. Structural tailwinds from mandatory compliance regimes (SOC 2, HIPAA, CMMC 2.0, NIST CSF 2.0, DORA) create a growing TAM. On the risk side, the lack of financial transparency prevents lenders, enterprise procurement, and outside investors from independently verifying liquidity, burn, or profitability. The parent executed 6+ acquisitions in 2023 alone, creating meaningful integration risk. Competitive pressure from better-funded GRC players (Vanta, Drata, Secureframe, Thoropass, Hyperproof) and eventual PE liquidity event pressure add uncertainty. Overall, the company appears to be a healthy mid-market SaaS scale-up but scores mid-range due to opacity and integration risk.
Key strengths: Recurring SaaS revenue model with per-client MSP pricing, Growth capital backing from Integrity Growth Partners since 2021, Cross-sell leverage into 12,000+ MSP Partner installed base, Structural regulatory tailwinds (SOC 2, HIPAA, CMMC 2.0, NIST CSF 2.0, DORA), SOC 2 Type II and ISO 27001 certifications supporting enterprise sales, Self-reported growth of 7 new Partners onboarded per day, Expanded to 63+ compliance frameworks and 83+ integrations
Risk factors: No public financial disclosures (revenue, EBIT, equity all undisclosed), Integration risk from 6+ acquisitions executed in 2023 alone, Well-funded competitors: Vanta, Drata, Secureframe, Thoropass, Hyperproof, Sprinto, Niche MSP-only channel dependence caps TAM vs broader GRC vendors, PE ownership concentration requiring eventual liquidity event, No auditable verification of self-reported partner/employee metrics
Revenue by geography
- North America (US + Canada): 0%
- International (Europe, APAC, other): 0%
Revenue by product/service
- Quoter: 0%
- ControlMap: 0%
- Backup Radar: 0%
- Cognition360: 0%
- Lifecycle Manager: 0%
Workforce by country
- Canada: 0
- Australia: 0
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.