Crunchr
Netherlands · www.crunchrapps.com · 13 vendors
Resilience scores
- Digital Sovereignty: 31
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- HubSpot, Inc. — Technology — United States
- Mandrill (an Intuit company) — United States
- Meta Platforms, Inc. — Technology — United States
- and 11 more
Services catalogue
1 service in catalogue across 1 category; runs on 13 sub-vendors.
- Workforce Planning
Insights
Last updated 2026-08-16 · revision 1
13 direct vendors, 207 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
- Denmark: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Canada: 5
- China: 2
- Unknown: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Crunchr shows strong migration readiness, primarily because its core infrastructure is already cloud-hosted (IaaS) and utilizes modern development practices like automated continuous delivery and deployment (CI/CD). The company's existing robust compliance framework, including GDPR, CCPA, and CSRD capabilities, is a significant advantage, as it indicates a mature approach to data governance and regulatory adherence, which is critical for data migration. The provision of an "Analytics API" also suggests an architecture designed for integration and flexibility, potentially easing transitions to new platforms or services. Operating data centers in both the EU and US provides flexibility for potential data residency requirements, even though specific requirements are not stated. The assessment of financial capacity to fund a migration is limited due to missing data on revenue concentration and growth history. While vendor geographic diversity is good, the specific "Vendor Lock-in Risk" is unknown, which could pose challenges if key services are deeply integrated with current providers. Data residency requirements are also "Not specified," which could introduce complexities depending on future target environments. The use of "Single-tenant isolated virtual private servers (VPS)" might indicate a less containerized or microservices-oriented architecture compared to fully cloud-native, which could require additional refactoring during a migration, though it's still within an IaaS context.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 certification has not been explicitly claimed or evidenced on Crunchr's website. Crunchr's security page describes extensive information security controls consistent with ISO 27001 requirements (defense-in-depth architecture, risk management, three-lines-of-defense model, access controls, encryption, incident management, penetration testing, organizational security measures). However, the absence of an explicit ISO 27001 certification claim is notable for a SaaS company of Crunchr's profile serving regulated industries (banking, insurance). The risk is Medium because: (1) Crunchr relies on SOC2 as its primary assurance framework rather than ISO 27001; (2) Many enterprise customers in regulated industries (particularly European banks and insurers) require ISO 27001 certification from their SaaS vendors; (3) Without ISO 27001 certification, Crunchr may face procurement barriers with certain regulated-industry customers; (4) The gap between Crunchr's described security practices and ISO 27001 certification may be small, but formal certification has not been confirmed.
Evidence: https://www.crunchr.com/why-crunchr/security-privacy/
CSRD (source) — Assessment Required
CSRD (EU Directive 2022/2464) applies directly to large EU companies and listed SMEs meeting size thresholds (500+ employees for FY2024 reporting; 250+ employees or €40M+ turnover or €20M+ balance sheet for FY2025 reporting). Crunchr itself, as a growing SaaS company, may or may not meet these thresholds — its exact employee count and revenue are not publicly disclosed. However, Crunchr has built a dedicated CSRD Workforce Reporting solution, indicating deep awareness of the regulation. The risk is Medium because: (1) If Crunchr meets the size thresholds, it must report on ESRS S1 (Own Workforce) metrics including headcount, gender pay gap, working conditions, and social dialogue; (2) Crunchr's own platform could be used to generate its own CSRD workforce disclosures; (3) Non-compliance with CSRD carries reputational and legal risks in the EU. MISSING INFORMATION: Crunchr's exact employee count and annual revenue to determine CSRD applicability.
Evidence: https://www.crunchr.com/solutions/csrd-workforce-reporting/, https://www.crunchr.com/company/about-us/
SOC 2 (source) — Compliant
Crunchr explicitly states on its official security & privacy page that it is audited annually to the SOC2 standard by audit firm 2-Control. SOC2 is a voluntary framework for service organizations (particularly SaaS/cloud providers) covering the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Crunchr's annual SOC2 audit directly addresses its role as a cloud-based SaaS data processor. The risk is Low because: (1) Crunchr has an established annual SOC2 audit cycle; (2) The audit is performed by a named third-party firm (2-Control); (3) The SOC2 report is available on request to prospects and customers; (4) The company's technical controls (encryption, RBAC, MFA, single-tenant architecture, penetration testing) are consistent with SOC2 requirements. Residual risk is minimal but exists because the specific SOC2 type (Type I vs. Type II) and the exact Trust Services Criteria covered are not publicly disclosed.
Evidence: https://www.crunchr.com/why-crunchr/security-privacy/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Crunchr is a privately held Dutch people-analytics SaaS scale-up founded in 2014, and specific financial disclosures such as revenue, EBIT, equity, and headcount are not publicly available. As a small Dutch B.V., it is only required to file abbreviated balance-sheet accounts with the KVK, limiting external visibility into its financial health. Despite this opacity, qualitative indicators suggest a moderately resilient profile: a blue-chip enterprise customer base (Booking.com, AkzoNobel, Randstad, Rabobank, JDE), a sticky SaaS subscription model with high switching costs, and a two-continent commercial presence across EMEA and North America. The company's product expansion into workforce planning, generative AI, skills insights, and CSRD workforce reporting positions it well to capture demand from EU sustainability-reporting regulation, providing a structural tailwind. Founder-led continuity under Dirk Jonker since inception adds strategic stability. However, resilience is constrained by capital dependence typical of growth-stage SaaS companies, competition from much larger and better-funded players (Visier, Workday, SAP SuccessFactors, Microsoft Viva), likely customer concentration risk from an enterprise-logo strategy, and ongoing R&D investment demands in the AI cycle. Overall a mid-range resilience score is warranted given strong customer quality but unverified financial fundamentals.
Key strengths: Enterprise, blue-chip customer base with high switching costs, Recurring SaaS subscription revenue model providing visibility, Product breadth expansion including generative AI and CSRD reporting, Founder-led continuity since 2014, Two-continent presence (Amsterdam and Boston) diversifying geography, Structural tailwind from EU CSRD sustainability-reporting mandate
Risk factors: Small private scale-up competing against much better-capitalized players (Visier, Workday, SAP, Microsoft), Capital dependence with no public information on funding, burn, or profitability, Likely customer concentration risk from enterprise-logo strategy, GDPR, data-residency, and security obligations across 60+ countries, Ongoing R&D investment required to compete in AI-driven HR analytics, Lack of financial transparency limits external assessment
Revenue by geography
- EMEA: 0%
- North America: 0%
Revenue by product/service
- HR Dashboards: 0%
- Data Integrations: 0%
- Workforce Planning: 0%
- Generative AI Assistant: 0%
- People Analytics (core platform): 0%
- Skills Insights / HR Goals / CSRD Workforce Reporting: 0%
Workforce by country
- Netherlands: 0
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.