DataDome

France · datadome.co · 33 vendors

DataDome is a global cybersecurity company that provides a bot and online fraud protection platform. It detects and mitigates malicious automated traffic, such as web scraping, ad fraud, and account takeovers, across websites, mobile apps, and APIs in real-time.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 33 sub-vendors.

Insights

Last updated 2026-06-19 · revision 1

33 direct vendors, 330 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DataDome exhibits high migration readiness, primarily driven by its advanced and cloud-native technical stack. The adoption of both AWS and GCP, alongside Kubernetes, strongly indicates a containerized, microservices-oriented architecture that is highly portable and adaptable for migration. Their focus on API Protection and an API-first approach further simplifies integration and re-platforming efforts. The use of edge computing with 35+ global PoPs and Cloudflare Workers, combined with a modern monitoring and logging infrastructure, positions them well for flexible deployment and management in diverse environments. The integration with multiple CDNs also demonstrates architectural flexibility. However, the assessment of migration readiness is constrained by the absence of critical information regarding specific regulatory environments, data residency requirements, and financial stability, which are crucial for planning and funding large-scale migrations. The explicit 'Unknown' vendor lock-in risk is also a significant factor; while there is geographic diversity among vendor countries, the actual number of unique vendors for the 34 services is not clear, which could impact migration complexity. The use of WordPress for their website is a minor legacy component but is likely isolated from their core product infrastructure.

Compliance

10 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

DataDome has achieved SOC 2 Type II certification, the most rigorous level of SOC 2 assurance, audited by Coalfire — a well-recognized independent third-party auditor. Type II certification covers a period of time (not just a point-in-time snapshot), demonstrating sustained operational effectiveness of controls. Risk is Low because: (1) certification is confirmed and publicly disclosed; (2) the audit covers Security, Confidentiality, and Availability trust service principles — the most critical for a cybersecurity SaaS provider; (3) Coalfire is a reputable AICPA-accredited auditor; (4) the report is available to customers via the Trust Center and account managers, indicating active maintenance of the certification.

Evidence: https://datadome.co/compliance-data-privacy/, https://trust.datadome.co, https://datadome.co/company/

NIS2 (source) — Assessment Required

NIS2 (Directive 2022/2555, transposed into French law by end of 2024) applies to entities in listed sectors that meet size thresholds (50+ employees OR €10M+ annual turnover). DataDome is a French-headquartered cybersecurity SaaS provider. The cybersecurity/digital services sector is relevant under NIS2 in two ways: (1) DataDome itself may qualify as a 'Managed Security Service Provider' (MSSP) or 'ICT service management' provider — categories explicitly listed under NIS2 Annex I (Essential Entities) or Annex II (Important Entities); (2) DataDome's enterprise customers in regulated NIS2 sectors (energy, banking, transport, health, digital infrastructure) may impose NIS2 supply-chain security requirements on DataDome as a critical third-party provider. DataDome has 200+ employees (confirmed on company page), clearly exceeding the 50-employee threshold. Annual revenue is not publicly disclosed but Series C funding of $42M and 200+ employees strongly suggest €10M+ turnover. Risk is Medium because: NIS2 applicability to MSSPs/cybersecurity providers is still being clarified in national transpositions; enforcement is ramping up across EU member states; and supply-chain security obligations from NIS2 customers could impose contractual compliance requirements on DataDome regardless of direct applicability.

Evidence: https://datadome.co/compliance-data-privacy/, https://datadome.co/company/, https://www.cisa.gov/securebydesign/pledge/secure-design-pledge-signers, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

PDPA — Compliant

DataDome has a Singapore office (one of its three global headquarters: New York, Paris, Singapore) and explicitly self-declares PDPA compliance. Risk is Low because: (1) compliance is publicly declared; (2) DataDome's data minimization approach limits personal data exposure; (3) Singapore's PDPC (Personal Data Protection Commission) enforcement, while active, focuses primarily on data breaches and unauthorized disclosures — areas where DataDome's security posture (SOC 2 Type II) provides strong mitigation.

Evidence: https://datadome.co/compliance-data-privacy/, https://datadome.co/company/

Financials

Three-year financials

Financial Resilience Score: 7/10

DataDome demonstrates solid financial resilience for a private growth-stage cybersecurity SaaS company, though detailed financials are not publicly disclosed. The company has raised approximately $92M+ in cumulative equity funding, including a $35M Series B in 2021 and a $42M Series C in September 2023 led by InfraVia Growth. This capitalization, combined with recurring SaaS revenue from 300+ enterprise customers including PayPal, Etsy, The New York Times, Tripadvisor, and BlaBlaCar, provides meaningful runway and revenue stability. The company benefits from strong category tailwinds in bot management and agentic AI fraud protection, recognized as a Leader in the Forrester Wave for Bot and Agent Trust Management Software (Q2 2026). High switching costs from deep CDN/edge integrations (80+ tech-stack integrations) and geographic diversification across three continents further support resilience. Appearance on the Inc. 5000 list for three consecutive years through 2024 implies substantial multi-year revenue growth. However, key risks include likely ongoing cash burn given headcount quadrupling from 50 to ~200 between 2021 and 2025, intense competition from larger players like Akamai, Cloudflare, HUMAN Security, and Imperva, and dependence on continued VC support without a clear path to profitability disclosed. Disclosure opacity limits external assessment, and concentration in recession-sensitive verticals like e-commerce and ticketing adds cyclical risk.

Key strengths: Recurring SaaS revenue model with 300+ enterprise customers, Well-capitalized with ~$92M+ raised including $42M Series C in Sept 2023, Category tailwinds in bot management and agentic AI fraud, Leader in Forrester Wave for Bot and Agent Trust Management 2026, High switching costs via 80+ tech-stack integrations, Geographic diversification across Paris, New York, Singapore, Three consecutive years on Inc. 5000 fastest-growing list

Risk factors: Likely operating losses to fund rapid growth (headcount 4x since 2021), Intense competition from larger players (Akamai, Cloudflare, HUMAN, Imperva), Dependence on continued VC funding cycles, Limited public financial disclosure, Concentration in recession-sensitive e-commerce and ticketing verticals

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report