Crazy Egg

United States · www.crazyegg.com · 11 vendors

Crazy Egg is a web analytics tool that helps businesses understand user behavior on their websites. It provides visual reports such as heatmaps, scrollmaps, and A/B testing capabilities to optimize user experience and conversion rates. The platform aims to turn data into actionable strategies for improving online experiences.

Resilience scores

Disruption prediction

Crazy Egg has an estimated 11% probability of disruption in the next 6 months.

9 of Crazy Egg's 11 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 3 categories; runs on 11 sub-vendors.

Insights

Last updated 2026-05-26 · revision 8

11 direct vendors, 202 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Crazy Egg exhibits moderate to high migration readiness. A key strength is their existing use of 'Cloud-based Computing & Storage (Subprocessors)', indicating a modern infrastructure and familiarity with cloud environments, which significantly reduces the technical hurdle of a migration. Their consistent growth history suggests financial capacity to fund such initiatives. However, several factors introduce complexity. The regulatory environment, particularly GDPR compliance with its 'medium risk' for cross-border data transfers and the explicit data processing in the US with Standard Contractual Clauses for EU/EEA data, means any change in data processing location would require careful re-evaluation of legal frameworks and user consents. The unknown status of SOC2 and ISO 27001 certifications could necessitate significant effort to achieve compliance during or after a migration, especially for enterprise clients. The vendor relationship data is contradictory, stating 'Total Vendors: 0' but then listing vendor HQ countries. If Crazy Egg relies heavily on a few key subprocessors for its cloud infrastructure, there could be an unquantified 'Vendor Lock-in Risk' (currently unknown) that would need to be assessed and mitigated during a migration. The lack of specific details on containerization or microservices adoption in their tech stack also means potential architectural refactoring might be required depending on the target environment.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Crazy Egg is a US-based company that processes personal data of EU/EEA residents through their web analytics services. While they have implemented GDPR compliance measures including Standard Contractual Clauses for international transfers, privacy policy updates, and data processing agreements, the medium risk stems from the complexity of cross-border data transfers and the need for ongoing compliance monitoring. The company serves global clients and processes visitor data from EU residents, making GDPR applicable with moderate enforcement risk given their US location.

Evidence: https://www.crazyegg.com/privacy

SOC 2 (source) — Assessment Required

SOC2 is highly relevant for cloud-based analytics services like Crazy Egg, as they process customer data and provide SaaS services. The medium risk stems from the lack of publicly available SOC2 compliance information, which is concerning for a company handling customer data. Many enterprise clients expect SOC2 compliance from their vendors, and the absence of visible certification could indicate either non-compliance or poor transparency around security practices.

ISO 27001 (source) — Assessment Required

ISO 27001 is relevant for information security management, especially for a company processing customer data globally. The medium risk is due to the lack of publicly available ISO 27001 certification information. While not legally required, ISO 27001 certification demonstrates robust information security practices and is often expected by enterprise clients, particularly those in regulated industries.

Financials

Three-year financials

Financial Resilience Score: 6/10

Crazy Egg is a privately held US SaaS company that has been operating since 2006, indicating durable business viability over nearly two decades. The company demonstrates qualitative hallmarks of a resilient niche SaaS business: a large installed base of over 449,000 websites, a subscription-based recurring revenue model with tiered pricing ($29-$249/month plus enterprise plans), capital-light software-only operations, and apparent bootstrap/founder-controlled status implying disciplined cost management. Brand recognition in the CRO/heatmap category and G2 Leader awards in Winter 2025 further support customer satisfaction and retention. However, the financial resilience assessment is constrained by complete lack of financial transparency—no audited statements, SEC filings, or official disclosures of revenue, EBIT, or equity exist. Third-party estimates suggest revenue between US$10-30 million but these are unverified. The company faces significant competitive pressure from free alternatives like Microsoft Clarity and well-funded rivals like Hotjar/Contentsquare and FullStory, plus product commoditization risk as heatmap features become bundled into larger analytics platforms. Privacy regulation exposure (GDPR, CCPA) and small-scale R&D capacity relative to competitors limit defensive positioning. The score reflects qualitative strength balanced against significant competitive headwinds and zero financial visibility.

Key strengths: Long operating history since 2006 (nearly 20 years), Large installed base of 449,000+ websites providing diversified recurring revenue, SaaS subscription model with predictable MRR, Capital-light software-only operations with no inventory, Bootstrapped/founder-controlled with disciplined cost management, Strong brand recognition in CRO/heatmap category, G2 Leader awards Winter 2025 (Best Estimated ROI, Mid-Market Leader), No obvious customer concentration risk - long-tail SMB base

Risk factors: No financial transparency - no audited statements or SEC filings, Intense competition from free Microsoft Clarity offering, Competition from well-funded Hotjar/Contentsquare and FullStory, Product commoditization as heatmap features bundled into larger platforms, Privacy and regulatory exposure (GDPR, CCPA, browser cookie restrictions), Small to mid-size scale limits R&D and enterprise sales spending, Key-person risk with small founder-led leadership team, Pricing pressure in heatmap/session-recording category since 2020

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report