DePay
Switzerland · depay.com · 9 vendors
Resilience scores
- Digital Sovereignty: 11
- Digital Resilience: 5
- Financial Resilience: 5
Technology vendors
- Google LLC — Technology — United States
- Shopify Inc. — Other — Canada
- Tools for Humanity — United States
- and 6 more
Services catalogue
1 service in catalogue across 1 category; runs on 9 sub-vendors.
- Payments
Insights
Last updated 2026-08-13 · revision 2
9 direct vendors, 148 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- Switzerland: 1
- Japan: 1
Subvendors by controlling owner country (sample)
- Sweden: 3
- Russia: 1
- Japan: 3
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
DePay demonstrates medium migration readiness. The company's tech stack presents a mixed picture: modern web technologies (JavaScript, React, open-source SDKs, RESTful API) and DevOps practices (GitHub Actions) indicate good readiness for migrating these components. However, a significant challenge lies in its core business logic, which is deeply embedded in specialized blockchain technologies (Solidity, Ethereum, Solana, Web3/DeFi). Migrating smart contracts and blockchain-dependent systems is inherently complex, often requiring redeployment and re-integration rather than traditional lift-and-shift, which can be time-consuming and costly. The stated 'Total Vendors: 0' suggests minimal formal contractual vendor lock-in, which is a positive for migration flexibility. However, the reliance on specific blockchain ecosystems (e.g., Ethereum, Solana) and integrations (WalletConnect, Coinbase SDK) represents a form of technological dependency that would need careful management during any migration. Crucially, the absence of specified data residency requirements, regulatory environment details, and financial stability information to fund a significant migration introduces substantial unknowns and potential hurdles that could impact the scope, cost, and feasibility of a migration effort.
Compliance
8 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
DePay AG is a Swiss company that explicitly processes personal data of EU/EEA residents (confirmed by their own privacy policy citing GDPR Art. 13/14), uses EU-based infrastructure (AWS Frankfurt, Germany), and serves a global customer base including EU residents. The privacy policy references GDPR legal bases and data subject rights, indicating awareness and partial implementation. However, several risk factors elevate this to High: (1) The privacy policy still references the EU-U.S. Privacy Shield framework, which was invalidated by the Schrems II ruling in July 2020 — this is a significant compliance gap as Standard Contractual Clauses (SCCs) or other valid transfer mechanisms should have replaced it; (2) No Data Protection Officer (DPO) appointment is publicly disclosed; (3) No cookie consent management platform (CMP) is evidenced; (4) The policy states 'Do Not Track' requests are not supported; (5) As a crypto/fintech platform processing wallet addresses, transaction data, and IP addresses globally, the risk of regulatory scrutiny is elevated. Swiss companies processing EU data are subject to GDPR enforcement by EU supervisory authorities for EU residents' data.
Evidence: https://depay.com/privacy, https://depay.com/imprint, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
SOC 2 (source) — Assessment Required
DePay provides cloud-based payment APIs, SDKs, and infrastructure services to merchants and developers — a profile that strongly aligns with SOC 2 applicability. Enterprise and institutional customers integrating DePay's payment infrastructure into their own platforms (e.g., Uniswap, Shopify merchants) would typically require SOC 2 Type II reports as part of vendor due diligence. The absence of any publicly disclosed SOC 2 certification or report is a medium risk because: (1) it may limit DePay's ability to win enterprise contracts; (2) it signals potential gaps in formal security controls documentation; (3) as a fintech/crypto platform handling transaction data and wallet information, security assurance is critical. Risk is Medium rather than High because SOC 2 is a voluntary framework and DePay's blockchain-native architecture (non-custodial, direct wallet payments) may reduce some traditional security risks.
Evidence: https://depay.com, https://depay.com/docs
Swiss nFADP — Assessment Required
The revised Swiss Federal Act on Data Protection (nFADP/revDSG) entered into force on September 1, 2023, and directly applies to DePay AG as a Swiss-registered company (Zug, Switzerland). The nFADP closely mirrors GDPR in many respects but has Swiss-specific requirements. Risk is High because: (1) DePay's privacy policy was last updated July 25, 2023 — before the nFADP came into force — and may not reflect all new requirements; (2) the nFADP introduces new obligations including mandatory data protection impact assessments (DPIAs), privacy by design/default, mandatory breach notification to the FDPIC, and enhanced transparency requirements; (3) DePay processes significant volumes of personal data (wallet addresses, transaction data, personal identifiers) that fall squarely within nFADP scope; (4) the Swiss Federal Data Protection and Information Commissioner (FDPIC) has enforcement authority; (5) failure to comply can result in criminal sanctions (fines up to CHF 250,000 for individuals) under the nFADP.
Evidence: https://depay.com/privacy, https://depay.com/imprint, https://www.fedlex.admin.ch/eli/cc/2022/491/en
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 5/10
DePay AG operates an asset-light SaaS/API business model in the Web3 payments space, with a peer-to-peer settlement architecture that eliminates custody, float, and chargeback risk from its corporate balance sheet. This structurally reduces regulatory capital needs relative to licensed payment service providers and lowers operational risk. The company has demonstrated credible commercial traction with flagship Web3 brands including Uniswap, World App (Tools for Humanity), Azuki, dYdX, and LooksRare, showing consistent product expansion across 10+ blockchains and major e-commerce platforms (Shopify, WooCommerce, WordPress) since 2020. However, as a small private Swiss AG below statutory publication thresholds (CHF 20m balance sheet, CHF 40m revenue, 250 FTE), no revenue, EBIT, equity, headcount, or runway figures are publicly disclosed. This complete opacity on financial fundamentals materially limits any quantitative resilience assessment. Revenue is likely highly correlated with crypto market cycles and NFT/merch activity, and probable customer concentration among a handful of flagship Web3 protocols creates single-client dependency risk. Regulatory headwinds from MiCA in the EU, evolving FINMA guidance, and travel-rule/AML obligations could raise compliance costs, while the parallel existence of a DEPAY token adds governance complexity. Competition from BitPay, Coinbase Commerce, MoonPay, Transak, Alchemy Pay, Helio, and Stripe's crypto rails is significant. The mid-range resilience score reflects the balance between a structurally low-risk business model and credible customer wins against the total absence of disclosed financials and high cyclical/regulatory exposure.
Key strengths: Asset-light SaaS/API model with low marginal costs, No custody of merchant funds eliminates float and chargeback risk, Blue-chip Web3 references (Uniswap, World App, Azuki, dYdX, LooksRare), Multi-chain coverage across 10+ blockchains reduces single-chain dependency, Swiss domicile in Zug Crypto Valley with favorable regulatory environment, Steady product expansion and move up-market into flagship brand partnerships in 2024-2025
Risk factors: No disclosed financials - runway, profitability, and burn rate are opaque, Revenue highly exposed to crypto market cycles and NFT/merch activity, Probable customer concentration among a few flagship Web3 clients, Regulatory risk from MiCA, FINMA guidance, and AML/travel-rule obligations, Token/entity separation adds governance and regulatory complexity, Strong competition from BitPay, Coinbase Commerce, MoonPay, Stripe crypto rails, and others
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.