Dataddo
Czech Republic · www.dataddo.com · 18 vendors
Resilience scores
- Digital Sovereignty: 11
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- HubSpot, Inc. — Technology — United States
- Looker — Technology — United States
- SMTP2GO — Technology — New Zealand
- and 15 more
Services catalogue
1 service in catalogue across 1 category; runs on 18 sub-vendors.
- Data Connectors
Insights
Last updated 2026-08-16 · revision 2
18 direct vendors, 231 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- New Zealand: 1
- Israel: 1
Subvendors by controlling owner country (sample)
- Luxembourg: 1
- China: 8
- Poland: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Dataddo exhibits a very high level of migration readiness, largely driven by its exceptionally modern, cloud-native, and containerized internal tech stack. The extensive use of major cloud providers (AWS, Azure, GCP) alongside container orchestration platforms (Kubernetes, OpenShift, VMware Tanzu) and event streaming technologies (Apache Kafka) signifies a highly agile and portable infrastructure. The company's product offerings, which include multi-cloud deployment and on-premises data plane options, further indicate deep internal expertise in managing flexible and portable infrastructure, directly translating to high migration capabilities. Dataddo's strong compliance framework (SOC 2, ISO 27001, GDPR, HIPAA) suggests that they have the necessary processes and controls in place to manage regulatory requirements effectively during any migration effort. While the total number of vendors is ambiguously stated as '0', the presence of 39 services from vendors across 5 unique countries, combined with their use of open-source technologies, suggests a diverse vendor ecosystem and lower infrastructure-level vendor lock-in. The primary unknown that prevents a perfect score is the lack of data regarding financial stability (revenue concentration, growth history), which could impact the funding and resources available for large-scale migration initiatives. Data residency requirements are also not specified, though their existing use of EU sovereign clouds suggests preparedness for such considerations.
Compliance
7 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used for non-financial assurance engagements, often applied in the context of sustainability reporting, ESG assurance, or as the international equivalent framework for SOC-type reports outside the US. Dataddo's SOC 2 Type II report is conducted by BDO Czech Republic — BDO is a global audit firm that may apply ISAE 3000 as the underlying standard for assurance engagements in the EU context. However, no explicit ISAE 3000 report or assurance engagement is publicly disclosed by Dataddo. Risk is Low because ISAE 3000 is not a mandatory regulatory requirement for Dataddo's industry, and the SOC 2 Type II report provides equivalent or greater assurance for its primary markets.
Evidence: https://www.dataddo.com/platform/data-security/soc2
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed into Czech law) applies to entities in specific sectors meeting size thresholds. Dataddo operates as a cloud-based data integration and pipeline platform — a 'digital provider' category under NIS2 Annex II (Important Entities), specifically as a managed service provider / ICT service management provider. The Czech Republic transposed NIS2 via Act No. 181/2014 Coll. (Cyber Security Act), updated to align with NIS2. Dataddo's exact employee count and annual revenue are not publicly disclosed, making it difficult to confirm whether it meets the medium enterprise threshold (50+ employees OR €10M+ annual turnover). However, given its global customer base (Uber Eats, Allianz, Kiwi, 1Password, Ogilvy, Publicis Groupe, Microsoft, AWS), it is plausible the company meets these thresholds. Risk is Medium because: (1) if thresholds are met, non-compliance with NIS2 registration and security obligations carries significant penalties (up to €7M or 1.4% of global turnover for Important Entities); (2) the Czech NÚKIB (National Cyber and Information Security Agency) is an active NIS2 enforcement authority; (3) as a digital infrastructure provider, Dataddo's services are critical to its customers' operations.
Evidence: https://www.dataddo.com/, https://www.dataddo.com/legal, https://www.dataddo.com/platform/data-security/soc2
ISO 27001 (source) — Compliant
Dataddo explicitly advertises ISO 27001 certification on its homepage alongside SOC 2 Type II, indicating active certification. ISO 27001 is an internationally recognized information security management standard requiring a formal ISMS, risk assessment, and third-party certification audit. For a cloud data integration platform handling sensitive customer data pipelines, ISO 27001 is both commercially essential and operationally appropriate. Risk is Low because the certification is publicly claimed and consistent with the company's SOC 2 Type II posture, suggesting a mature information security program.
Evidence: https://www.dataddo.com/, https://www.dataddo.com/platform/data-security/soc2
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 6/10
Dataddo appears to be a credible, mid-stage B2B SaaS company with strong qualitative indicators of financial resilience despite limited public financial disclosure. The company has been operating and scaling globally since 2018 with only a modest registered share capital of CZK 3,022,696 and no publicly announced large VC funding round, which suggests either efficient capital-light growth or significant reliance on internal cash flow generation. It has established a broad customer base of 4,000+ organizations across 100+ countries, including blue-chip references such as Uber Eats, 1Password, Allianz, Microsoft, Publicis, and Epic Games, indicating solid ACVs and sticky enterprise relationships. However, the company faces meaningful financial risks. It operates in a heavily capitalized market against competitors (Fivetran, Airbyte, Hevo, Supermetrics) that have raised hundreds of millions of dollars, creating pricing and R&D pressure. The lack of financial transparency (no IR page, no ARR disclosures, no funding announcements) and the structural split between the US Inc. and Czech a.s. entities makes standalone financial assessment challenging. FX exposure (CZK/BRL cost base vs. USD/EUR revenue) and dependency on third-party APIs for its 400+ connectors add operational risk. Enterprise-grade certifications (SOC 2 Type II, ISO 27001, PCI DSS, GDPR) and EU-sovereign positioning provide competitive resilience in regulated markets.
Key strengths: Product breadth with 400+ managed connectors creating high switching costs, Enterprise-grade certifications (SOC 2 Type II, ISO 27001, PCI DSS, GDPR), Blue-chip customer references (Uber Eats, 1Password, Allianz, Microsoft, Epic Games), Gartner Cool Vendor recognition and 4.4-4.7/5 ratings on G2, Capterra, GetApp, Capital-light operations with only CZK 3M registered share capital, 4,000+ organizations served across 100+ countries, EU data-sovereignty positioning aligned with market tailwinds, Beneficiary of EU/Czech public co-financing schemes
Risk factors: Small private company competing against well-capitalized rivals (Fivetran, Airbyte, Hevo), Limited financial transparency with no IR page or funding disclosures, Structural split between US Inc. and Czech a.s. complicates financial analysis, Permanent engineering-cost exposure to third-party API changes across 400+ connectors, FX exposure with CZK/BRL cost base vs. USD/EUR revenue, Small team (~80-130 employees) relative to global enterprise ambitions, No publicly announced priced VC round raises questions about growth capital, Annual accounts on justice.cz arrive 6-18 months late and are unconsolidated
Revenue by geography
- Latin America: 0%
- North America: 0%
- Western Europe: 0%
Revenue by product/service
- Reverse ETL / Data Activation: 0%
- Database Replication / Real-Time CDC: 0%
- SaaS Data Integration (400+ connectors): 0%
- AI Data Foundation & Agentic Data Streaming: 0%
- Legacy Modernization & SAP Data Replication: 0%
Workforce by country
- Brazil: 0
- United States: 0
- Czech Republic: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.