Dixa ApS

Denmark · owned by Independent (Denmark) · www.dixa.com · 17 vendors

Dixa is an agentic AI customer service platform built for e-commerce brands. It unifies customer interactions across multiple channels, combining AI automation with intelligent routing and human agents to streamline support operations and deliver personalized service.

Resilience scores

Disruption prediction

Dixa ApS has an estimated 11% probability of disruption in the next 6 months.

11 of Dixa ApS's 17 vendors monitored for disruptions.

Technology vendors

Services catalogue

5 services in catalogue across 2 categories; runs on 17 sub-vendors.

Insights

Last updated 2026-09-13 · revision 6

17 direct vendors, 289 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Dixa exhibits high migration readiness primarily due to its modern, cloud-native technology stack. The extensive use of Amazon Web Services (AWS) with auto-scaling infrastructure, coupled with advanced AI services from Azure OpenAI and Anthropic Claude, indicates a flexible, scalable, and likely microservices-oriented architecture. This foundation significantly reduces the technical hurdles typically associated with migrating legacy systems. Existing GDPR compliance and established data residency practices, with EU customer data hosted in EU data centers and cross-border transfers handled with safeguards, mean that critical regulatory requirements are already being managed, though they impose specific constraints on any migration strategy. However, several factors introduce complexity and reduce the overall readiness score. The company relies on a large number of third-party services (28 services listed, with many distinct vendors in the 'Internal Tech Stack' such as Twilio, Auth0, Stripe, ElevenLabs, etc.). This extensive integration landscape implies numerous dependencies and potential API complexities that would need careful management during a migration. The 'Vendor Lock-in Risk' is 'Unknown', which is a significant blind spot; if there are substantial lock-ins with any of these numerous vendors, it could severely impede migration flexibility and increase costs. Additionally, the 'Assessment Required' status for SOC2 and ISO 27001 means that achieving these certifications would likely need to be integrated into or follow a migration project, adding scope and effort. Finally, the lack of available data on financial stability makes it difficult to assess the company's capacity to fund a potentially complex migration project.

Compliance

8 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is the international assurance standard used for non-financial assurance engagements, including data protection and privacy audits. In the EU/Nordic context, ISAE 3000 (and its Danish equivalent) is sometimes used as an alternative or complement to SOC 2 for cloud service providers. Given Dixa's Danish incorporation and EU customer base, ISAE 3000 assurance reporting could be relevant, particularly for customers in the Nordic financial services or regulated industries sector. Risk is Low because: (1) ISAE 3000 is not a mandatory regulatory requirement for Dixa's industry; (2) It is more commonly required in financial services and regulated sectors; (3) Dixa's primary customer base is ecommerce, where SOC 2 is more commonly requested than ISAE 3000; (4) No evidence of ISAE 3000 engagement found.

Evidence: https://www.dixa.com/legal, https://www.dixa.com/legal/datasecurity

GDPR (source) — Partially Compliant

Dixa ApS is headquartered in Denmark (EU), making GDPR universally applicable. The company processes substantial volumes of personal data as a customer service SaaS platform — including end-customer data, agent data, and conversation records on behalf of 850+ brands across 42 countries. Dixa publicly maintains a GDPR compliance page, a Privacy Policy, a Data Processing Agreement (DPA), an Applicant Privacy Notice, a 3rd Party Sub-processors list, and a Cookie Policy — all strong indicators of active GDPR compliance efforts. Data is stored on AWS servers in Ireland (EU), which supports lawful transfer and storage requirements. However, the platform serves customers globally (including the US, UK, and beyond), and the depth of their DPA, SCCs for international transfers, and DPO appointment cannot be fully verified from public sources alone. Status is 'Partially Compliant' because while strong structural compliance indicators exist, full audit verification is not publicly available. Risk is Medium because the company is clearly aware of and actively managing GDPR obligations, but as a data processor for hundreds of brands, any gap in sub-processor management or DPA coverage could expose both Dixa and its customers to regulatory risk. Danish DPA (Datatilsynet) enforcement is active.

Evidence: https://www.dixa.com/legal/gdpr-compliance, https://www.dixa.com/legal/data-processing-agreement, https://www.dixa.com/legal/3rd-party-services-used-by-dixa, https://www.dixa.com/legal/privacy, https://www.dixa.com/legal/datasecurity, https://www.dixa.com/legal

SOC 2 (source) — Assessment Required

Dixa is a cloud-based SaaS platform that stores and processes customer data on behalf of 850+ enterprise brands. SOC 2 (Type I or Type II) is the de facto standard for cloud service providers serving enterprise customers, particularly in the US and UK markets. Dixa's customers include global brands (e.g., Charles Tyrwhitt, AllSaints, FabFitFun) who are likely to require SOC 2 attestation as part of their vendor due diligence. The absence of a publicly disclosed SOC 2 report is a notable gap for a company of this scale. Risk is Medium because: (1) Enterprise customers increasingly mandate SOC 2 as a procurement requirement; (2) Dixa processes sensitive customer conversation data, order data, and PII; (3) Lack of SOC 2 could be a competitive disadvantage and a vendor risk flag for enterprise procurement teams. However, Dixa may have a SOC 2 report available under NDA that is not publicly disclosed.

Evidence: https://www.dixa.com/legal/datasecurity, https://www.dixa.com/legal/data-security, https://aws.amazon.com/compliance/

Financials

Three-year financials

Financial Resilience Score: 5/10

Dixa ApS is a venture-funded Danish SaaS scale-up with a historically loss-making profile typical of late-stage growth companies. The company has raised substantial external capital, including a ~USD 105M Series C in early 2021 led by General Atlantic at a reported ~USD 700M valuation, on top of earlier rounds from Notion Capital, Project A, and Seed Capital, bringing total disclosed funding well above USD 150M. This provides meaningful equity cushion, but sustained operating losses driven by heavy R&D and go-to-market spend have historically eroded that base. The company underwent significant restructuring in 2023, including two rounds of layoffs and a strategic refocus on the ecommerce vertical, aimed at narrowing operating losses. Its recurring SaaS/ARR revenue model with 850+ brands across 42 countries reduces single-customer concentration risk. However, resilience remains tied to either reaching break-even before cash runs out or securing further funding rounds in a tougher SaaS capital environment. Goodwill from the 2021 acquisitions of Solvemate, Miuros, and Elevio also represents potential impairment risk. Without access to the CVR årsrapport financials in this session, a precise score is not verifiable, but the qualitative profile suggests moderate resilience supported by strong backers but pressured by ongoing burn and competitive intensity.

Key strengths: Tier-1 investor backing (General Atlantic, Notion Capital, Project A, Seed Capital), Total disclosed external funding above USD 150M including ~USD 105M Series C in 2021, Recurring SaaS/ARR revenue model with predictable subscription economics, Diversified international customer base of 850+ brands across 42 countries, 2023 restructuring and cost discipline refocusing on ecommerce vertical, Product repositioning around agentic AI (Mim AI Agent, Co-Pilot) aligned with buyer demand

Risk factors: Sustained historical operating losses and cash burn, Dependence on future equity funding rounds to sustain operations, Intense competition from Zendesk, Freshworks, Intercom, Gorgias, Kustomer, Sierra, Decagon, Ada, Ecommerce vertical concentration exposes company to consumer discretionary cycles, FX exposure (costs in DKK/EUR, revenue partly in GBP/USD/EUR), Goodwill on balance sheet from 2021 acquisitions poses impairment risk, Potential equity erosion as accumulated losses grow

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report