Envoy (Traction Guest)
United States · envoy.com · 34 vendors
Envoy is a San Francisco-based workplace management platform that helps organizations manage visitors, employees, spaces, and onsite communications. It provides a unified platform with solutions for visitor management, desk and room booking, delivery management, and workplace analytics to ensure secure, compliant, and efficient operations.
Resilience scores
- Digital Sovereignty: 85
- Digital Resilience: 8
- Financial Resilience: 6
Disruption prediction
Envoy (Traction Guest) has an estimated 11% probability of disruption in the next 6 months.
20 of Envoy (Traction Guest)'s 34 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- and 31 more
Services catalogue
5 services in catalogue across 3 categories; runs on 34 sub-vendors.
- Traction Guest Visitor Management
- Personal Data Processing
- Workplace Platform
Insights
Last updated 2026-07-30 · revision 2
34 direct vendors, 292 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- Belgium: 1
- United States: 29
Subvendors by controlling owner country (sample)
- Russia: 1
- Canada: 9
- Czech Republic: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Envoy exhibits strong migration readiness, primarily driven by its 'Cloud-Native SaaS Architecture' built on Amazon Web Services (AWS). The active migration from Ember.js to React signifies a commitment to modernizing its frontend, which will improve future migration flexibility. The company's robust 'REST API / Webhook-based Integration Platform' and comprehensive 'Regulatory Compliance Automation' (including ITAR, HIPAA, GDPR, SOC 2, C-TPAT, FSMA, PCI DSS) along with SOC 2 Type II compliance, indicate a structured approach to managing complex requirements, which is crucial for smooth migrations. The geographic diversity of its vendors across three countries (Australia, United States, Denmark) suggests a potentially lower risk of vendor lock-in compared to a highly concentrated vendor base. However, the continued presence of Ember.js, even during migration, could pose challenges for certain legacy components. 'Data Residency Requirements' are 'Not specified,' which could introduce complexities if specific regional data handling becomes necessary. The 'Vendor Lock-in Risk' is 'Unknown,' which is a significant factor as high lock-in can impede migration efforts. Furthermore, the absence of data on financial stability (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund extensive migration projects. While 'Cloud-Native SaaS Architecture' implies modern deployment, explicit mention of containerization or microservices would further solidify its high readiness score.
Compliance
11 in-scope frameworks identified; showing 3.
C-TPAT — Partially Compliant
Envoy explicitly lists C-TPAT as a compliance framework it supports. C-TPAT is a voluntary US CBP program for supply chain security. Envoy's visitor management platform supports C-TPAT minimum security criteria for visitor management at participating organizations. Risk is Low because C-TPAT is voluntary and Envoy's role is limited to supporting customer compliance through platform features.
Evidence: https://envoy.com/legal/compliance
ITAR — Partially Compliant
Envoy explicitly lists ITAR as a compliance framework it supports on its compliance page and markets to the defense and aerospace industry. ITAR is a US State Department regulation controlling the export of defense articles and services. Envoy's visitor management platform can help ITAR-regulated customers verify visitor citizenship and control access — key ITAR requirements. Risk is Medium because: (1) Envoy itself is not an ITAR-regulated manufacturer or exporter, but it serves ITAR-regulated customers; (2) Envoy's platform may process ITAR-controlled technical data if used at defense facilities; (3) the extent to which Envoy's own data handling meets ITAR's strict data residency and access control requirements (e.g., no foreign national access to ITAR data) is not fully documented publicly; (4) Envoy's cloud infrastructure (AWS) and sub-processors may need to meet specific ITAR requirements for data handling.
Evidence: https://envoy.com/legal/compliance, https://envoy.com/industries/defense-aerospace, https://envoy.com/legal/security-and-privacy
GDPR (source) — Compliant
Envoy explicitly confirms GDPR compliance on its official compliance page and has implemented a formal Data Processing Addendum (DPA), Standard Contractual Clauses (SCCs) for EU-to-US data transfers, and a UK International Data Transfer Addendum for UK transfers. The company operates as a data processor for its customers (who are data controllers), which limits direct regulatory exposure but does not eliminate it. Risk remains Medium because: (1) Envoy processes large volumes of personal data (visitor names, photos, health check responses, identity documents) on behalf of thousands of global customers including EU/UK-based organizations; (2) as a data processor, Envoy is still subject to GDPR Articles 28–32 obligations; (3) any breach or sub-processor failure could trigger significant regulatory scrutiny; (4) the EU enforcement environment has become increasingly aggressive with multi-million euro fines. The existence of a formal DPA, SCCs, and documented privacy controls mitigates but does not eliminate this risk.
Evidence: https://envoy.com/legal/compliance, https://envoy.com/legal/gdpr-dpa-addendum, https://envoy.com/legal/security-and-privacy, https://envoy.com/legal/subprocessors, https://envoy.com/legal/privacy-policy
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Envoy is a well-funded, later-stage private US SaaS company with a strong tier-1 investor base including Andreessen Horowitz, Menlo Ventures, and Brookfield Growth. The company raised US$111M in Series C funding in January 2022 at a reported ~US$1.4B valuation, with total disclosed funding of approximately US$170M. Its recurring SaaS revenue model with high gross margins, blue-chip enterprise customer roster (NVIDIA, AWS, Tesla, Databricks, GitHub, Snowflake, Anthropic, Chevron, Roche, Amgen, P&G, PayPal), and diversified sector exposure provide meaningful resilience. However, the company publishes no audited financial statements, making independent verification of runway or profitability impossible. Its core visitor management product depends on physical office attendance, exposing it to structural hybrid work headwinds. The 2022 valuation was set at peak SaaS multiples and faces potential down-round risk given subsequent SaaS re-ratings in 2023-2024. Customer concentration in the US tech sector—which experienced significant 2023-2024 layoffs and real-estate reductions—likely pressured seat counts. The competitive landscape includes well-funded rivals (iLobby, Sine/Honeywell, Proxyclick/Eptura, Robin) and integrated access-control incumbents. Overall resilience is moderate-to-good but opaque.
Key strengths: Tier-1 investor base (a16z, Menlo Ventures, Brookfield Growth) providing capital access and governance discipline, US$111M Series C raised January 2022 at ~US$1.4B valuation; ~US$170M total funding, Blue-chip customer roster across tech, pharma, energy, CPG, and financial services, Recurring SaaS revenue model with high gross margins, Platform expansion from single-product VMS to multi-module workplace suite (mailroom, rooms, desks, signage, notifications), Regulatory tailwinds from ITAR, EAR, OFAC, C-TPAT, and UK Martyn's Law compliance, 16,000+ workplaces served globally
Risk factors: No public disclosure of audited financials — opaque to counterparties, Post-pandemic hybrid work headwinds reducing physical office attendance, Competitive market with well-funded rivals (iLobby, Sine, Proxyclick, Robin, Verkada, HID/Genea), Down-round risk given 2022 peak-valuation and subsequent SaaS multiple compression, M&A integration risk from Traction Guest consolidation, Customer concentration in US tech sector affected by 2023-2024 layoffs and real-estate reductions
Revenue by geography
- North America: 78%
- EMEA: 15%
- APAC: 7%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.