Efty

Netherlands · www.efty.com · 5 vendors

Efty is a domain name marketplace and platform that enables investors to manage, market, and monetize their domain name portfolios. It facilitates the buying and selling of domain names through its platform, offering tools like Efty Investor and Efty Pay for secure transactions and portfolio management.

Resilience scores

Technology vendors

Insights

Last updated 2026-07-30 · revision 4

5 direct vendors, 84 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Efty demonstrates high migration readiness, primarily driven by its modern and cloud-native technical architecture. The extensive use of Google Cloud Run, coupled with languages like Go and Node.js, strongly indicates a containerized and microservices-oriented environment. This architecture is inherently portable and significantly simplifies migration to alternative cloud providers or on-premises solutions. The presence of REST APIs further supports a modular and migratable system. Additionally, the absence of specified data residency requirements provides flexibility and reduces complexity for potential migration efforts. Despite these strengths, certain factors could pose challenges. The complete lack of financial data makes it impossible to assess Efty's capacity to fund a significant migration project, which can be a substantial undertaking. While the tech stack is largely modern, the inclusion of PHP could suggest some legacy components that might require additional modernization or refactoring during a migration. The "Vendor Lock-in Risk" is unknown, and although Efty uses 6 services from vendors in three countries, the specific nature of these services and their contractual terms are not detailed, meaning potential vendor dependencies could introduce unforeseen complexities or costs during a migration.

Compliance

8 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). As a cloud-based SaaS and marketplace platform processing personal data, financial transaction data, and domain portfolio data, Efty would benefit from ISO 27001 certification. Risk is Medium because: (1) Efty Pay processes financial transactions (domain sales), making information security a critical concern; (2) a breach of customer financial or personal data would trigger GDPR notification obligations and potential fines; (3) no evidence of ISO 27001 certification or equivalent ISMS has been found; (4) however, the company's small size means the risk of a sophisticated breach may be lower than for larger enterprises, and the absence of certification is common among SMEs in this sector.

Evidence: https://efty.com/privacy/, https://efty.com/legal/

GDPR (source) — Partially Compliant

Efty B.V. is headquartered in Groningen, Netherlands (EU), and explicitly processes personal data of EU/EEA residents and global users. The privacy policy demonstrates awareness of GDPR obligations — it identifies lawful bases for processing, enumerates data subject rights (access, rectification, erasure, portability, restriction, objection, withdrawal of consent), and references the right to lodge complaints with a Data Protection Authority. However, several gaps elevate risk: (1) No Data Protection Officer (DPO) is publicly identified, which may be required if large-scale processing of personal data occurs; (2) No cookie consent management platform or explicit consent banner is evidenced on the website; (3) The privacy policy does not specify a Data Processing Agreement (DPA) framework for sub-processors beyond Stripe and PayPal/Braintree; (4) No record of processing activities (ROPA) is publicly disclosed; (5) The policy states data 'may be transferred' outside the Netherlands without specifying Standard Contractual Clauses (SCCs) or other transfer mechanisms for non-EEA transfers. The risk is Medium rather than High because the company has a published privacy policy with GDPR-aligned language, and the domain marketplace sector is not among the highest-risk categories for enforcement. Dutch DPA (Autoriteit Persoonsgegevens) is an active enforcer.

Evidence: https://efty.com/privacy/, https://efty.com/legal/, https://efty.com/legal/general-terms-and-privacy-policy/

SOC 2 (source) — Assessment Required

SOC 2 (System and Organization Controls 2) is a voluntary framework developed by the AICPA, relevant to cloud service providers and SaaS companies that store, process, or transmit customer data. Efty operates Efty Investor (a subscription SaaS platform), Efty Pay (a payment/transaction processing platform), and Efty Market (an online marketplace) — all of which are cloud-based services processing customer personal and financial data. Enterprise or institutional domain investors using Efty's platform may require SOC 2 reports as part of their vendor due diligence. Risk is Medium because: (1) Efty processes financial transaction data through Efty Pay, which heightens the sensitivity of data handled; (2) absence of SOC 2 certification could be a barrier to enterprise customer acquisition; (3) however, Efty appears to be a small company primarily serving individual domain investors rather than large enterprises, reducing the immediate commercial pressure for SOC 2 certification.

Evidence: https://efty.com/products/efty_pay/, https://efty.com/products/efty_investor/, https://efty.com/privacy/

Financials

Three-year financials

Financial Resilience Score: 6/10

Efty B.V. is a small, privately held Dutch technology company operating in the niche domain-name aftermarket. As a small Dutch BV, it is not required to publicly disclose profit-and-loss figures, so revenue, EBIT, and equity are not verifiable from primary sources. Qualitatively, the business appears resilient due to a diversified revenue model combining recurring SaaS subscriptions (Efty Investor), transaction-based commissions (Efty Pay, Efty Market), and brokerage fees. The asset-light software/marketplace model implies modest capital requirements and structurally high SaaS gross margins. The company has been operating continuously since 2013, indicating durability, and expanded into payments/escrow with the July 2024 launch of Efty Pay, opening a new monetization stream. However, the company faces meaningful risks including concentration in a single cyclical niche, competition from much larger players (GoDaddy/Afternic, Sedo, Dan.com, Squadhelp, Atom.com), regulatory/compliance exposure from operating a payments product in the EU, FX exposure (USD-denominated transactions vs EUR reporting), and key-person risk from a small executive team. Without visibility into profitability or runway, a moderate resilience score is appropriate.

Key strengths: Diversified revenue model combining recurring SaaS subscriptions, transaction commissions, and marketplace fees, Established niche leadership since 2013 with ~6 million monthly visitors, Asset-light software/marketplace business model with structurally high SaaS gross margins, New Efty Pay product (launched July 2024) expands revenue take-rate opportunity, Lease-to-own offering creates recurring cash flow streams from larger deals

Risk factors: Limited public disclosure — no published income statement means profitability and runway cannot be verified, Concentration in a single cyclical niche (domain-name aftermarket), Competition from much larger, better-funded players (GoDaddy/Afternic, Sedo, Dan.com, Squadhelp, Atom.com), Regulatory/compliance risk from operating Efty Pay (money transmission, KYC/AML, PSD2 in the EU), FX exposure — transactions predominantly USD while reporting likely in EUR, Key-person risk from small executive team

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report