Featurebase

Estonia · www.featurebase.app · 8 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 8 sub-vendors.

Insights

Last updated 2026-07-12 · revision 1

8 direct vendors, 187 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Featurebase demonstrates a high level of migration readiness. Its internal tech stack, featuring Next.js, DigitalOcean, REST API (OpenAPI), Webhooks, and key technologies like AI, NLP, and LLM, indicates a modern, API-driven, and potentially cloud-native architecture that is well-suited for migration. The most significant factor contributing to high readiness is the reported 'Total Vendors: 0'. If this data is accurate, it means Featurebase faces no external vendor lock-in, which drastically simplifies the migration process by eliminating complex vendor relationship management, contract renegotiations, and data transfer challenges associated with third-party services. This interpretation is prioritized for the assessment, despite other data suggesting vendor geographic diversity. While compliance with SOC 2, GDPR, and CCPA adds a layer of complexity to ensure regulatory continuity during migration, it also signifies a structured approach to data governance. The primary unknown is financial stability, as the absence of revenue or growth data makes it difficult to assess the company's capacity to fund a significant migration effort. Overall, the modern technical foundation and the assumed absence of external vendor dependencies are strong indicators of high migration readiness.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

Featurebase has explicitly confirmed SOC 2 Type II certification, which is the highest level of SOC 2 assurance (covering operational effectiveness of controls over a period of time, not just design). This is directly stated in their Security FAQ, on their homepage, in their DPA (Section 4.2), and referenced via their Trust Center (trust.featurebase.app). SOC 2 Type II certification demonstrates that an independent third-party auditor has assessed and validated their security controls across the Trust Service Criteria (Security, and potentially Availability, Confidentiality, Processing Integrity, Privacy). The risk level is Low because the certification is confirmed, the DPA explicitly references it as the primary audit mechanism for customers, and the report is available upon request under NDA.

Evidence: https://help.featurebase.app/articles/8874192-security-faq, https://help.featurebase.app/articles/6556750-data-processing-agreement, https://www.featurebase.app, https://trust.featurebase.app/

ISO 27001 (source) — Assessment Required

No evidence of ISO 27001 certification was found in Featurebase's public documentation. Their security program is aligned to SOC 2 Type II (which covers similar ground to ISO 27001 for information security management), but ISO 27001 is a separate certification requiring accredited third-party audit against the ISO/IEC 27001 standard. The risk level is Low because: (a) Featurebase has SOC 2 Type II which provides comparable assurance for most customers; (b) ISO 27001 is not legally mandated for their industry or jurisdiction; (c) the absence of ISO 27001 does not indicate non-compliance with any legal requirement. Some enterprise customers may require ISO 27001, which could be a commercial risk.

Evidence: https://help.featurebase.app/articles/8874192-security-faq, https://help.featurebase.app/articles/6556750-data-processing-agreement, https://www.featurebase.app

GDPR (source) — Compliant

Featurebase (CORDNET OÜ) is an Estonian company and therefore directly subject to GDPR as an EU-established entity. They have publicly declared full GDPR compliance, maintain a comprehensive and detailed Privacy Policy explicitly referencing GDPR Articles, publish a signed Data Processing Agreement (DPA) incorporating EU Standard Contractual Clauses (SCCs per Commission Implementing Decision 2021/914), maintain records of processing activities per GDPR Article 30, conduct DPIAs, have a 72-hour breach notification procedure aligned to GDPR Article 33, and cooperate with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Data is primarily hosted in the EEA (Germany/Netherlands). The risk level is Low because the company has demonstrably invested in GDPR compliance infrastructure, has a published DPA, and operates in a well-regulated EU jurisdiction with clear supervisory authority oversight. Residual risk exists around ongoing compliance maintenance and sub-processor management, but documented controls are strong.

Evidence: https://help.featurebase.app/articles/4744036-privacy-policy, https://help.featurebase.app/articles/6556750-data-processing-agreement, https://help.featurebase.app/articles/8874192-security-faq, https://help.featurebase.app/articles/2733677-subprocessors, https://www.featurebase.app

Financials

Three-year financials

Financial Resilience Score: 7/10

Featurebase demonstrates strong qualitative financial resilience despite the absence of publicly retrievable financial statements. The company is bootstrapped, profitable, and has taken no outside investment, meaning it carries no debt overhang, no burn-rate risk, and no investor pressure to pursue growth-at-all-costs strategies. With only ~8 employees supporting 1,500+ paying customers across 186+ countries, revenue-per-employee is extremely high—a hallmark of resilient SaaS economics. The customer base is well-diversified geographically and includes reputable logos such as Lovable, Elementor, OpenSea, User.com, Instantly, and Profound. SOC 2, GDPR, and CCPA certifications enable enterprise sales, and the product suite spans multiple pillars (support, feedback, help center, changelog, surveys) providing cross-sell opportunities. However, the score is tempered by significant risks: the very small team creates material key-person risk, competition from well-funded incumbents (Intercom, Zendesk) and AI-native entrants (Chatbase) creates pricing and innovation pressure, and the absence of external capital could constrain strategic flexibility if aggressive investment becomes necessary. Public financial transparency is also limited, requiring reliance on Estonian register filings not retrieved in this session.

Key strengths: Bootstrapped with no external funding, Self-declared profitable, 1,500+ paying customers across 186+ countries, Very high revenue-per-employee with only ~8 staff, Diversified customer base including notable logos, SOC 2, GDPR, CCPA certified enabling enterprise sales, Product suite breadth across 5 pillars, >99.9% uptime and 30M+ conversations handled

Risk factors: Very small team (8 people) creates key-person risk, Highly competitive category with well-funded incumbents (Intercom, Zendesk), AI feature race against hyperscaler-funded competitors, No external capital cushion for major growth investments, Limited public financial transparency, LLM/AI infrastructure cost pressure, Dependence on two engineers who built most of the platform

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report