Daily.co
United States · www.daily.co · 22 vendors
Resilience scores
- Digital Sovereignty: 91
- Digital Resilience: 9
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- Clerk, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 21 more
Services catalogue
1 service in catalogue across 1 category; runs on 22 sub-vendors.
- Daily
Insights
Last updated 2026-08-16 · revision 1
22 direct vendors, 293 subvendors
Direct vendors by controlling owner country (sample)
- United States: 20
- Australia: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- Ireland: 2
- Spain: 2
- China: 8
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Daily.co exhibits high migration readiness, primarily driven by its highly modern, cloud-native, and distributed technical architecture. The tech stack, built on Rust, WebAssembly, WebRTC, and leveraging multi-cloud infrastructure and a Global Mesh Network, is inherently flexible and portable. The Pipecat Cloud platform's containerized deployment and automatic scaling capabilities further enhance its readiness for migration to new environments. The use of the open-source Pipecat framework also reduces proprietary lock-in. Existing strong regulatory compliance (ISO 27001, SOC 2, HIPAA, GDPR) means the company has established frameworks for managing data and security requirements, which can simplify compliance aspects during a migration. Vendor relationships show geographic diversity across 3 countries, which can be beneficial for managing external dependencies during a transition. However, key unknowns temper the readiness score: data residency requirements are not specified, which could introduce significant complexity if strict rules apply. Financial stability (revenue concentration, growth history) is also unknown, making it difficult to assess the company's capacity to fund a large migration. Crucially, the specific vendor lock-in risk is unknown, despite the indication of 28 services being used, which could pose a significant challenge if dependencies are tightly coupled.
Compliance
7 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
Daily.co does not explicitly claim ISO 27001 certification for its own organization on its public security pages. However, the underlying AWS infrastructure used by Daily.co is stated to be ISO 27001 certified. ISO 27001 certification of the cloud provider (AWS) does not automatically confer ISO 27001 status on Daily.co itself. For enterprise customers — particularly in regulated industries — the absence of Daily.co's own ISO 27001 certification may be a procurement or vendor risk concern. Risk is Medium because: (1) the gap between AWS ISO 27001 and Daily.co's own certification is a real vendor risk for enterprise buyers; (2) Daily.co's SOC 2 Type 2 certification provides substantial overlapping assurance; (3) the company's security posture (encryption, data minimization, access controls) appears mature. The risk would be Low if Daily.co obtained its own ISO 27001 certification.
Evidence: https://www.daily.co/security/secure-infrastructure, https://www.daily.co/security/
CCPA — Assessment Required
Daily.co is headquartered in the United States and serves US consumers and businesses. The California Consumer Privacy Act (CCPA), as amended by CPRA, applies to for-profit businesses that collect personal information of California residents and meet certain thresholds (annual gross revenue >$25M, or buy/sell/share personal data of 100,000+ consumers/households, or derive 50%+ of revenue from selling personal data). Daily.co's revenue and exact California consumer data volumes are not publicly disclosed, making a definitive threshold determination impossible. However, as a global cloud platform with significant US operations and a developer/enterprise customer base, it is plausible that CCPA thresholds are met. Risk is Medium because: (1) CCPA/CPRA enforcement is active; (2) Daily.co's privacy policy addresses data minimization but does not explicitly reference CCPA rights; (3) the company's stated policy of not selling data is consistent with CCPA compliance.
Evidence: https://www.daily.co/legal/privacy, https://www.daily.co/security/
HIPAA (source) — Compliant
Daily.co explicitly offers HIPAA-compliant video infrastructure as a paid add-on ('Healthcare Add-on') and publicly states it will sign a Business Associate Agreement (BAA). This is a strong indicator of active HIPAA compliance for customers in the healthcare sector. The risk is Low because Daily.co has built HIPAA compliance into its product offering, has a documented BAA process, and has published detailed HIPAA compliance documentation. The residual risk relates to the fact that HIPAA compliance is conditional on customers enabling the Healthcare Add-on and executing a BAA — customers who use Daily.co for healthcare use cases without the add-on may not be covered.
Evidence: https://www.daily.co/security/, https://www.daily.co/blog/announcing-hipaa-compliance-for-the-daily-co-video-chat-api, https://www.daily.co/blog/hipaa-compliance-details-for-the-daily-co-video-call-api, https://www.daily.co/security/data-protection
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Daily.co is a privately held, venture-backed company that does not disclose audited financial statements, revenue, EBIT, or equity. As a result, direct visibility into burn rate, runway, gross margins, and ARR growth is limited. However, the company has raised approximately $60M across three rounds in 18 months, culminating in a $40M Series B in November 2021 led by Renegade Partners, with a strong investor syndicate including Tiger Global, Freestyle, Y Combinator, Salesforce Ventures, Root Ventures, and notable angels. This capitalization provides meaningful cushion, though the most recent disclosed round dates to a very different valuation environment. Strategically, Daily is well positioned in the fast-growing voice/video AI infrastructure space via its open-source Pipecat framework and Pipecat Cloud offering, with enterprise-grade certifications (SOC-2, HIPAA, GDPR, EU-US DPF) and a 99.99% uptime SLA. Customers span regulated verticals (Epic Systems in healthcare) as well as AI-native companies (NVIDIA, Cresta, Tavus, HeyGen), and technical leadership includes WebRTC IETF/W3C contributors. Risks include intense competition (LiveKit, Agora, 100ms, Amazon Chime SDK, cloud-provider WebRTC stacks), infrastructure-heavy COGS from a 75+ PoP global mesh network, dependence on the continued momentum of the voice-agent AI market, and no publicly announced funding round since 2021 in a tougher fundraising environment.
Key strengths: ~$60M total funding raised through Series B (Nov 2021), Top-tier investor syndicate: Tiger Global, Renegade Partners, Freestyle, Y Combinator, Salesforce Ventures, Enterprise-grade compliance: SOC-2, HIPAA, GDPR, EU-US Data Privacy Framework, 99.99% uptime SLA and 75+ global points of presence, Strategic positioning in voice/video AI via open-source Pipecat framework, Diversified customer base across telehealth, education, AI agents, and events, Technical moat via WebRTC IETF/W3C standards contributions, Notable enterprise customers: NVIDIA, Epic Systems, Cresta, Mercor, Tavus, HeyGen, Cal.com, Scale
Risk factors: No public financial disclosure — opaque revenue, EBIT, margins, and runway, Most recent disclosed funding round dates to November 2021 (different capital environment), Intense competition from LiveKit, Agora, 100ms, Amazon Chime SDK, and hyperscalers, Heavy strategic pivot to voice-AI agents ties growth to a nascent market, Infrastructure-heavy cost base with meaningful bandwidth/compute commitments, No confirmed post-2021 fundraising in tougher market conditions
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.