deSEC e.V.
Germany · desec.io · 3 vendors
Resilience scores
- Digital Sovereignty: 67
- Digital Resilience: 7
- Financial Resilience: 4
Technology vendors
- a4a GmbH — Germany
- PostgreSQL Project — Technology — United States
- Prometheus — United States
- and 8 more
Services catalogue
1 service in catalogue across 1 category; runs on 3 sub-vendors.
- deSEC DNS
Insights
Last updated 2026-06-13 · revision 2
3 direct vendors, 57 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 2
- United States: 1
Subvendors by controlling owner country (sample)
- Australia: 1
- South Korea: 1
- Canada: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
deSEC e.V. exhibits high migration readiness primarily due to its highly modern and cloud-native friendly technology stack. The extensive use of Docker for containerization ensures excellent application portability, a key enabler for cloud migration. The entire internal tech stack is open-source (Python/Django, PostgreSQL, PowerDNS, Linux), which inherently minimizes proprietary vendor lock-in and simplifies licensing considerations during a transition. The presence of a fully documented REST API further facilitates integration and automation in new cloud environments. However, several critical data gaps impact a complete assessment. Information regarding the regulatory environment and specific data residency requirements is not available, which could introduce significant compliance challenges and constraints during a migration. Similarly, financial stability data (revenue, growth) is missing, making it difficult to assess the company's capacity to fund a substantial migration effort. The vendor relationship data is contradictory, stating "Total Vendors: 0" but then detailing "Total Services: 10" and vendor geographic information. Assuming vendors exist, the "Vendor Lock-in Risk" for these 10 services is unknown, which could pose unforeseen challenges depending on their nature and contractual terms, despite the open-source nature of deSEC's core infrastructure.
Compliance
4 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for deSEC as they provide security-focused DNS services and handle sensitive infrastructure. While not legally mandated, ISO 27001 certification demonstrates systematic information security management and is increasingly expected for infrastructure service providers. Risk is medium as lack of certification could impact customer confidence and competitive positioning, particularly for security-focused services.
Evidence: https://desec.io, https://github.com/desec-io/desec-stack
SOC 2 (source) — Assessment Required
SOC2 is relevant for deSEC as they provide cloud-based DNS hosting services to customers, making them a service organization that should demonstrate controls over security, availability, and confidentiality. While not legally mandated, SOC2 compliance is increasingly expected by enterprise customers for cloud service providers. Risk is medium as lack of SOC2 certification could limit business opportunities and customer trust, though it's not a legal requirement.
Evidence: https://desec.io, https://desec.readthedocs.io/
GDPR (source) — Assessment Required
GDPR applies with HIGH certainty as deSEC e.V. is headquartered in Germany (EU member state) and processes personal data through user registrations, API access, and DNS management services. Non-compliance risks include fines up to 4% of annual turnover or €20M, regulatory investigations, and reputational damage. As a DNS service provider handling user accounts and potentially logging DNS queries, they process significant amounts of personal data requiring comprehensive GDPR compliance including data protection policies, user consent mechanisms, data subject rights implementation, and potential DPO appointment.
Evidence: https://desec.io, https://github.com/desec-io/desec-stack
Financials
Financial Resilience Score: 4/10
deSEC e.V. is a German non-profit association (eingetragener Verein) providing free secure DNS hosting services. As an e.V., it is not subject to commercial publication requirements under the HGB, and it does not voluntarily publish annual accounts. Consequently, no revenue, EBIT, equity, headcount, or segment data is publicly available, making quantitative financial resilience assessment impossible. Qualitatively, the organization benefits from a mission-driven, low-cost operational model based on open-source software, and has industrial backing from Secure Systems Engineering GmbH (SSE), which provides operational and likely financial support. deSEC has a strong niche reputation in the European technical community for DNSSEC-by-default and privacy-respecting free DNS services. However, significant risks weigh on resilience: the service is provided free of charge with no diversified revenue streams, creating heavy dependence on donations and a single corporate sponsor (SSE). This single-supporter concentration risk means any change in SSE's strategy or financial position would materially affect deSEC. Additionally, free DNS services attract abuse (spam, phishing domains) that can drive up operational costs without offsetting revenue. The lack of financial transparency makes external risk assessment impossible for counterparties or partners, which is a structural weakness even if the underlying operation is sustainable.
Key strengths: Mission-driven, low-cost operational model based on open-source software, Industrial backing from Secure Systems Engineering GmbH (SSE), Strong niche reputation in European technical community for DNSSEC and privacy, Non-profit legal form (e.V.) reduces commercial pressure
Risk factors: No diversified revenue - service is free, dependent on donations and sponsor, Single-supporter concentration risk via SSE GmbH, No published financial accounts - lack of transparency, Operational scale risk from abuse (spam, phishing) driving costs, Not registered with Initiative Transparente Zivilgesellschaft (ITZ)
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.