Danhost ApS

Denmark · owned by Combell N.V. (Belgium) · danhost.dk · 7 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 7 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

7 direct vendors, 109 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Danhost ApS demonstrates high migration readiness. A key strength is the presence of Kubernetes in its internal tech stack, indicating a strong foundation for containerization and a move towards cloud-native architectures, which significantly streamlines migration efforts. The absence of specified data residency requirements also provides considerable flexibility for choosing cloud providers and regions. However, the tech stack is mixed, with traditional technologies such as Windows Server, ASP.NET, and Microsoft SQL Server alongside modern ones. This suggests that some legacy applications may require refactoring or specific lift-and-shift strategies, potentially increasing migration complexity and cost. The 'Vendor Lock-in Risk: Unknown' is a concern, as potential dependencies on existing service providers could complicate the transition. The 'Total Vendors: 0' data point is inconsistent with other vendor information (8 services, vendor countries), making it difficult to accurately assess vendor-related migration challenges. Additionally, the lack of financial data prevents an assessment of the company's capacity to fund a substantial migration initiative.

Compliance

8 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is an assurance standard used by auditors to provide assurance on non-financial information, including IT controls, sustainability reporting, and compliance statements. For a web hosting provider like Danhost, ISAE 3000 (or its IT-specific variant ISAE 3402) could be relevant if Danhost provides assurance reports to customers about its internal controls over hosted services. The risk level is Low because: (1) ISAE 3000/3402 is not legally mandated; (2) it is typically pursued voluntarily or at customer request; (3) ISO 27001 and SOC 2 are more commonly pursued by hosting providers as assurance frameworks; (4) there is no evidence Danhost currently offers or is required to provide ISAE 3000 assurance reports.

Evidence: https://danhost.dk, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or

GDPR (source) — Assessment Required

Danhost ApS is headquartered in Denmark (EU member state) and operates as a web hosting and digital services provider, meaning it processes substantial volumes of personal data as both a Data Controller (customer account data, billing data, contact information) and a Data Processor (hosting customer websites and email, which may contain end-user personal data). The Danish Data Protection Authority (Datatilsynet) is an active enforcement body with a track record of issuing fines and reprimands. The combination of EU domicile, large-scale data processing across multiple service lines, and membership in the pan-European team.blue group (which implies cross-border data flows) elevates the risk level to High. Non-compliance can result in fines up to €20 million or 4% of global annual turnover. No public GDPR audit evidence or DPO appointment was found on the public-facing website during this assessment.

Evidence: https://danhost.dk, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679, https://www.datatilsynet.dk/afgoerelser-domme-og-udtalelser

SOC 2 (source) — Assessment Required

Danhost ApS is a cloud/hosting services provider — the exact type of organization for which SOC 2 was designed. SOC 2 (developed by the AICPA) is not legally mandated but is a widely expected industry standard for hosting providers, particularly when serving business customers who require assurance over security, availability, processing integrity, confidentiality, and privacy of their hosted data. The risk level is Medium because: (1) SOC 2 is not legally required in Denmark/EU, so there is no regulatory penalty for non-compliance; (2) however, absence of SOC 2 or equivalent assurance (e.g., ISO 27001) may represent a competitive and contractual risk, particularly for enterprise customers; (3) as part of team.blue, group-level SOC 2 or ISO 27001 certifications may exist but were not confirmed for Danhost specifically.

Evidence: https://danhost.dk, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

Financials

Three-year financials

Financial Resilience Score: 7/10

Danhost ApS benefits from significant financial resilience primarily through its ownership by team.blue, one of Europe's largest hosting and domain groups with consolidated revenue above €300m and strong private-equity backing from Hg Capital and Cinven. This group-level scale provides infrastructure investment capacity, security capabilities, and cross-selling opportunities that a standalone small Danish hosting company would lack. The company also benefits from a 25+ year operating history since 1997 and a subscription-based recurring revenue model with typically high renewal rates and predictable cash flow. However, verified financial figures (revenue, EBIT, equity) for the last three fiscal years could not be retrieved from CVR/virk.dk or Proff.dk during this research session. As a small Danish ApS filing under Regnskabsklasse B, disclosure is typically abbreviated and revenue is often not disclosed. Additionally, the customer-facing business appears to have been migrated to sister brands ScanNet and DanDomain, suggesting the Danhost legal entity itself may be in wind-down mode with declining stand-alone operating activity. The Danish hosting market is also highly competitive with pressure from One.com, Simply.com, GratisDNS, Curanet, and hyperscalers.

Key strengths: Part of team.blue group (>€300m revenue, Hg Capital and Cinven backed), Long brand history since 1997 (25+ years), Recurring subscription revenue model with high renewal rates, Consolidation onto sister brands ScanNet and DanDomain reduces duplicated costs, Predictable cash flow from hosting/domain/email subscriptions

Risk factors: Brand migration risk - customers being funneled to ScanNet and DanDomain, Danhost brand may be in wind-down, Highly competitive Danish hosting market (One.com, Simply.com, GratisDNS, Curanet, Hostnordic, Wannafind, hyperscalers), Continuous price pressure on entry-level web hotels, Technology/security exposure (DDoS, ransomware, GDPR), Limited financial disclosure as small ApS reduces transparency, Stand-alone entity financials may not reflect underlying customer economics

Revenue by geography

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report