Conversion Bridge

United States · conversionbridge.com · 11 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-08-14 · revision 2

11 direct vendors, 96 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Conversion Bridge demonstrates a relatively high level of migration readiness, primarily due to its modern and cloud-friendly internal tech stack. **Strengths:** The company utilizes Next.js for its frontend and PostgreSQL for its database (hosted via Supabase), both of which are widely adopted, open-source, and highly portable technologies. Its application hosting on Railway, a modern platform-as-a-service (PaaS), suggests a likely containerized or easily containerizable architecture, which significantly simplifies migration to other cloud environments. The use of standard, API-driven SaaS solutions like Stripe for payments, SendGrid for email, Sentry for error tracking, and Cloudflare for CDN, means these components are generally decoupled and can be integrated into new environments with relative ease. The geographic diversity of its vendors (6 unique countries) also suggests a reduced risk of vendor-specific regional issues impacting a migration. **Weaknesses:** Critical unknowns include data residency requirements, which, if strict, could introduce significant complexity and cost to any migration effort. The absence of data on financial stability (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially large-scale migration. While the tech stack is modern, the specific 'Vendor Lock-in Risk' is unknown, and reliance on PaaS solutions like Railway and Supabase, while beneficial for development, can introduce some level of platform-specific lock-in compared to a pure Infrastructure-as-a-Service (IaaS) approach. The regulatory environment is also unspecified, which could present unforeseen compliance challenges during a migration.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognized information security management standard relevant to any organization handling personal or sensitive data. Converly processes OAuth tokens, personal data from form submissions, and customer account data. No ISO 27001 certification has been publicly disclosed. Risk is Medium because: (1) the company handles sensitive credentials (OAuth tokens for Google/Meta ad accounts) that, if compromised, could cause significant harm to customers; (2) ISO 27001 is increasingly expected by enterprise customers and in regulated markets; (3) the company's small size means it may lack the resources for full ISMS implementation; (4) however, the described security controls (AES-256, TLS, RBAC, code review) suggest some security awareness, even if not formally certified.

Evidence: https://converly.io/privacy-policy

ePrivacy Directive — Assessment Required

Converly's core service involves deploying tracking scripts on customer websites and reading advertising cookies (Facebook _fbp, _fbc; Google gclid). The ePrivacy Directive (and its national implementations) requires prior informed consent for non-essential cookies and tracking technologies. Risk is Medium because: (1) Converly's tracking script reads advertising cookies set by third parties (Meta, Google) — these are non-essential cookies requiring consent; (2) The company has a cookie policy but the adequacy of consent mechanisms on customer websites is the responsibility of the website operator; (3) Converly itself (as a SaaS platform) must also comply with ePrivacy for its own website's cookie usage; (4) The EU is moving toward the ePrivacy Regulation which will strengthen these requirements.

Evidence: https://converly.io/cookie-policy, https://converly.io/privacy-policy, https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22019-processing-personal-data-under-article-6_en

CPRA — Assessment Required

Converly's privacy policy explicitly references CCPA/CPRA rights, indicating the company acknowledges potential applicability. The CCPA/CPRA applies to for-profit businesses that: (1) have annual gross revenues exceeding $25M; OR (2) buy, sell, or share personal information of 100,000+ California consumers or households annually; OR (3) derive 50%+ of annual revenues from selling/sharing personal information. As a global SaaS platform processing form submission data from websites worldwide (including California-based visitors), Converly likely processes personal data of California residents. Risk is Medium because: (1) the company explicitly acknowledges CCPA/CPRA in its privacy policy; (2) the nature of the service (processing form submissions from websites globally) means California residents' data is almost certainly processed; (3) however, the company's small size may mean it falls below the $25M revenue threshold; (4) the company explicitly states it does not sell personal information, which addresses a key CCPA/CPRA obligation.

Evidence: https://converly.io/privacy-policy, https://oag.ca.gov/privacy/ccpa

Financials

Three-year financials

Financial Resilience Score: 6/10

Converly (formerly Conversion Bridge) is a bootstrapped, founder-owned micro-SaaS with no external debt, no VC pressure, and self-described profitability. The subscription-based revenue model (US$19–$49+/month tiers) provides predictable recurring MRR, and the lean cost base with only ~4 named team members implies minimal fixed overhead. The absence of outside investors means founders retain full control of cash flow and there is no dilution or burn-rate pressure. However, resilience is constrained by extreme key-person risk (2–4 individuals, with the founder concurrently running another SaaS called Attributer), platform-dependency risk on Google/Meta/LinkedIn/TikTok ad APIs, and a crowded competitive landscape including free alternatives like Google Tag Manager. Privacy and regulatory shifts (GDPR, CCPA, cookie deprecation, iOS ATT) could compress the addressable market. With no disclosed liquidity buffer, ARR, or customer count, independent verification of financial strength is not possible. The score reflects a moderate resilience profile typical of a profitable indie-SaaS but with meaningful concentration and dependency risks.

Key strengths: Bootstrapped with zero outside investors, Self-described profitable operations, Recurring subscription SaaS revenue model, Lean cost base with ~4 team members, Broad integration catalog reducing single-platform dependence for customers, Scalable cloud-hosted delivery with low capex

Risk factors: Extreme key-person risk with only 2-4 named individuals, Founder concurrently runs a separate SaaS (Attributer), Platform-dependency on Google/Meta/LinkedIn/TikTok ad APIs, Crowded competitive space with free alternatives (Google Tag Manager, Zapier, Segment), Privacy/regulatory risk from GDPR, CCPA, cookie deprecation, iOS ATT, No disclosed liquidity buffer or runway, Single-product concentration (~100% one product)

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report