Escapecloud
Denmark · owned by Independent (Denmark) · escapecloud.net · 12 vendors
Resilience scores
- Digital Sovereignty: 25
- Digital Resilience: 4
- Financial Resilience: 5
Technology vendors
- Alibaba Group Holding Limited — Technology — China
- Netlify, Inc. — Technology — United States
- Rock Lobster, LLC — Technology — Japan
- and 10 more
Services catalogue
1 service in catalogue across 1 category; runs on 12 sub-vendors.
- Email Service
Insights
Last updated 2026-08-13 · revision 1
12 direct vendors, 176 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 3
- Unknown: 1
- United States: 5
Subvendors by controlling owner country (sample)
- Japan: 3
- Belgium: 1
- South Korea: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Escapecloud's migration readiness is assessed as high-medium. A significant strength is its reliance on open-source technologies (Nextcloud, WordPress, PHP), which avoids proprietary platform lock-in and offers considerable flexibility in choosing a new cloud environment. Their current use of self-managed servers means they are not locked into any specific public cloud provider, allowing for a free choice of migration destination. Crucially, the data indicates "Total Vendors: 0," which, if interpreted as a lack of operational vendors, dramatically simplifies the migration process by eliminating the need to manage and migrate complex vendor contracts and relationships, often a major hurdle. However, the current architecture, based on self-managed servers, may not be inherently cloud-native (e.g., lacking containerization or microservices), potentially requiring significant refactoring for optimal cloud performance and scalability beyond a simple "lift and shift." The absence of specified data residency requirements and financial stability data (ability to fund a migration) are critical unknowns that could impact the scope and feasibility of a migration.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 risk is Medium because: (1) EscapeCloud is a cloud service provider hosting customer data, which is precisely the profile for which SOC 2 was designed; (2) enterprise and business customers increasingly require SOC 2 Type II reports from cloud vendors as part of their own vendor due diligence and GDPR Article 28 obligations; (3) absence of a SOC 2 report may limit EscapeCloud's ability to win enterprise contracts and could expose customers to unverified security risks; (4) however, SOC 2 is a voluntary US framework (AICPA) and not legally mandated in Denmark/EU — the risk is primarily commercial and reputational rather than regulatory. The risk is not High because SOC 2 non-compliance carries no direct regulatory penalty in the EU context.
Evidence: https://www.escapecloud.dk/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
GDPR (source) — Partially Compliant
GDPR risk is High for EscapeCloud for several compounding reasons: (1) As a cloud hosting provider, EscapeCloud acts in a dual capacity — as a data controller for its own website visitors and customers, AND as a data processor for the personal data of its customers' end-users stored on hosted Nextcloud/WordPress instances. This dual role significantly expands GDPR obligations. (2) The Danish Datatilsynet (Data Protection Authority) is an active enforcement body with a track record of investigating SMEs. (3) Non-compliance penalties can reach up to €20 million or 4% of global annual turnover. (4) While a privacy policy exists and references GDPR and the Danish Databeskyttelsesloven, it lacks several elements required for full compliance: no explicit Data Processing Agreements (DPA) template is publicly available for customers, no DPO appointment is disclosed, no Article 30 Records of Processing Activities (RoPA) are referenced publicly, and the privacy policy does not specify retention periods with precision. (5) As a processor of customer data, EscapeCloud must have robust DPAs in place with all customers — no evidence of this is publicly available. The combination of dual controller/processor role, small company resource constraints, and active Danish enforcement makes this a High risk area.
Evidence: https://www.escapecloud.dk/privatlivspolitik/, https://www.escapecloud.dk/, https://www.datatilsynet.dk/english, https://gdpr-info.eu/art-28-gdpr/, https://gdpr-info.eu/art-30-gdpr/
NIS2 (source) — Assessment Required
NIS2 risk is assessed as Low-to-Medium pending size threshold verification. EscapeCloud operates in the 'digital providers' and 'ICT service management' space as a cloud hosting provider, which falls under NIS2's scope for 'managed service providers' and 'cloud computing service providers' listed as Important Entities. However, NIS2 applies only to medium or large enterprises (50+ employees OR €10M+ annual turnover). Based on all available evidence, EscapeCloud appears to be a micro or small enterprise (single address, small team, individual support staff mentioned), which would place it below the NIS2 size threshold and exempt it from the directive. The risk is Low because: (1) the company very likely falls below the size threshold; (2) even if it were in scope, Denmark has transposed NIS2 into national law (Lov om sikkerhed i net- og informationssystemer) with enforcement by the Danish Centre for Cyber Security (CFCS); (3) penalties for non-compliance exist but enforcement against micro-enterprises is rare. Risk would escalate to Medium/High if the company exceeds size thresholds.
Evidence: https://www.escapecloud.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/, https://www.ft.dk/samling/20231/lovforslag/l111/index.htm
Financials
Three-year financials
- null:
Financial Resilience Score: 5/10
EscapeCloud appears to be a small Danish micro-enterprise operating in the managed hosting space, primarily offering Nextcloud and WordPress hosting. The business model benefits from recurring subscription revenue, which provides predictable cash flow and high customer retention due to switching costs associated with migrating files, calendars, and users. The company has demonstrated longevity, with approximately 7 years of Nextcloud hosting operations since 2019 and a legal entity that has existed for roughly 20 years based on its CVR number range. However, financial resilience is constrained by significant scale and concentration risks. As a likely 1-5 person operation, the company faces material key-person risk typical of small Danish ApS hosting shops. Margins are pressured by competition with hyperscalers, and infrastructure costs (bandwidth, hardware in USD) may rise faster than a small provider can absorb. Product concentration in two open-source ecosystems (Nextcloud, WordPress) that the company does not control adds strategic vulnerability to licensing or roadmap shifts. The European 'digital sovereignty' and GDPR positioning provides a favorable tailwind, especially given regulatory pressure on US hyperscalers (Schrems II, Data Act). No actual financial figures (revenue, EBIT, equity) were accessible for this assessment, limiting the ability to make a data-driven resilience judgment. A mid-range score reflects the balance between defensible niche positioning and small-scale operational risks.
Key strengths: Recurring subscription revenue model provides predictable cash flow, High customer switching costs once migrated to Nextcloud, EU digital sovereignty and GDPR positioning provides tailwind, Approximately 20-year legal entity longevity suggests sustainability at current scale, DKK pegged to EUR mutes EUR FX exposure
Risk factors: Key-person risk typical of micro-enterprise with 1-5 employees, Thin margins competing against hyperscalers, Product concentration in two open-source stacks (Nextcloud, WordPress) not controlled by company, USD exposure on server hardware and upstream bandwidth costs, Limited public financial disclosure hampers counterparty risk assessment, Small scale limits ability to spread rising infrastructure and compliance costs
Revenue by geography
- Denmark: 0%
Revenue by product/service
- WordPress Hosting: 0%
- PHP Hosting and Support: 0%
- Managed Nextcloud Hosting: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.