FileCloud

United States · www.getfilecloud.com · 14 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 14 sub-vendors.

Insights

Last updated 2026-08-17 · revision 2

14 direct vendors, 227 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

FileCloud demonstrates a medium-to-high level of migration readiness, primarily driven by its strong cloud-native foundation. The extensive use of major cloud providers (AWS, Azure, Oracle Cloud Infrastructure) indicates a modern infrastructure and existing expertise in cloud operations, which is highly conducive to migration efforts. The tech stack includes modern components like S3-compatible object storage and REST APIs, facilitating data and application portability. Furthermore, the existing multi-cloud environment suggests a strategic approach to avoid single-cloud vendor lock-in at the infrastructure level, which can ease future re-platforming or migration between cloud providers. While the 'Total Vendors: 0' is a contradictory data point, the diverse set of technologies listed in the internal tech stack implies a varied vendor landscape, potentially reducing overall vendor lock-in at the application level. However, significant challenges exist. FileCloud operates in a highly regulated environment, evidenced by its 'FileCloud FedRAMP High' offering, use of 'AWS GovCloud,' and FIPS 140-2/140-3 compliance. Migrations in such environments are inherently more complex, costly, and time-consuming due to stringent security, compliance, and auditing requirements. The absence of specified 'Data Residency Requirements' is a critical unknown; given global operations and high compliance, it's highly probable that specific data residency rules exist, which could significantly complicate and constrain migration strategies. Lastly, the lack of data on financial stability (revenue concentration, growth history) makes it impossible to assess FileCloud's capacity to fund a substantial migration effort. The 'Vendor Lock-in Risk' for specific services also remains unknown.

Compliance

12 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

FileCloud Technologies Limited is registered in Ireland (an EU member state) and operates as a digital infrastructure/ICT service provider — a category explicitly listed under NIS2 as either an Essential Entity (digital infrastructure) or Important Entity (digital providers/managed service providers). FileCloud provides cloud-based enterprise file sharing and sync services to organizations across critical sectors including healthcare, banking/finance, government, and defense. NIS2 Directive (EU 2022/2555) came into force in October 2024 and Ireland's transposing legislation (NIS2 Regulations 2024, S.I. No. 322 of 2024) is in effect. The risk is Medium rather than High because: (1) FileCloud's exact classification (Essential vs. Important Entity) under NIS2 depends on a formal self-assessment of employee count and turnover thresholds for the EU entity specifically; (2) as a software/SaaS provider rather than a direct operator of critical infrastructure, the applicability tier requires regulatory confirmation; (3) no public NIS2 compliance assessment or registration with Ireland's NCSC has been found. Risk is not Low because the EU entity clearly operates in the digital services sector covered by NIS2 and serves regulated industries.

Evidence: https://www.filecloud.com/about-filecloud-team/, https://trust.filecloud.com/, https://www.filecloud.com/security/, https://www.filecloud.com/

FINRA — Assessment Required

FileCloud explicitly references FINRA compliance support documentation on its website and serves banking, finance, and insurance customers. FINRA (Financial Industry Regulatory Authority) rules require broker-dealers to maintain books and records, including electronic communications, in a compliant manner (FINRA Rules 4370, 4511, 4512). FileCloud's audit logging, data retention, and immutable record-keeping features support FINRA compliance for financial services customers. Risk is rated Low because FINRA compliance is primarily the responsibility of the financial services firm using FileCloud, not FileCloud itself as a technology provider.

Evidence: https://www.filecloud.com/filecloud-compliance-standards-finra-hipaa/, https://www.filecloud.com/private-secure-file-sharing-sync-banking-finance-insurance-companies/

ISAE 3000 (source) — Assessment Required

ISAE 3000 (Revised) is the international standard for assurance engagements other than audits or reviews of historical financial information, issued by the IAASB. It is commonly used as the basis for SOC 2-equivalent assurance reports in non-US jurisdictions (e.g., ISAE 3402 for service organizations, or ISAE 3000 for privacy/sustainability assurance). FileCloud has achieved SOC 2 Type 2 (the US AICPA equivalent), which covers substantially similar ground to an ISAE 3000-based assurance report. Risk is rated Low because: (1) FileCloud's SOC 2 Type 2 provides equivalent assurance to an ISAE 3000 report for most practical purposes; (2) the company's EU entity in Ireland may be subject to requests for ISAE 3000-based assurance from European customers or auditors; (3) no specific ISAE 3000 engagement was found in public materials. The risk is not higher because SOC 2 Type 2 is widely accepted as equivalent and FileCloud's existing certifications (ISO 27001, SOC 2) provide robust assurance coverage.

Evidence: https://trust.filecloud.com/, https://www.filecloud.com/filecloud-compliance-standards-finra-hipaa/

Financials

Three-year financials

Financial Resilience Score: 6/10

FileCloud (CodeLathe Technologies Inc.) is a privately held US company with no publicly disclosed financial statements, making a precise resilience assessment impossible from outside. However, qualitative indicators point to a moderately resilient mid-market SaaS business. The company is backed by three growth-equity investors (Savant Growth, Kennet Partners, Level Equity) and announced a strategic growth funding round in January 2025, suggesting fresh capital runway. Its recurring subscription revenue model, 3,000+ enterprise customers across 90+ countries, and strong compliance moat (FedRAMP High, ISO 27001, SOC 2 Type 2, HIPAA, ITAR, GDPR, Saudi PDPL) create sticky, defensible revenue in regulated verticals. Leadership quality is a positive signal: CEO Ray Downes and CFO George Lo previously scaled Kemp Technologies from ~$10M to $70M+ revenue and sold it to Progress Software for $258M in 2021, indicating a credible growth-and-exit playbook. Recent moves — Signority acquisition (May 2024), Riyadh regional HQ (Feb 2025), AWS ISV Accelerate (Apr 2025), and FedRAMP High authorization (Mar 2026) — show disciplined investment in expansion and compliance. On the risk side, FileCloud competes in a crowded EFSS market against Microsoft, Google, Box, Dropbox, and Egnyte, with limited pricing power against hyperscaler bundling. Zero public financial disclosure means outside parties cannot verify profitability, cash burn, or leverage. Multi-entity structure (US, Ireland, Saudi Arabia, Canada) adds FX and integration complexity. Overall, the company appears operationally sound and well-funded, but the absence of hard numbers caps the confidence level of any resilience score.

Key strengths: PE-backed with fresh strategic growth funding announced January 2025, Recurring SaaS/subscription revenue model with high retention in regulated verticals, Diversified base of 3,000+ enterprise customers across 90+ countries, Strong compliance moat: FedRAMP High, ISO 27001, SOC 2 Type 2, HIPAA, ITAR, GDPR, Saudi PDPL, Experienced leadership team with prior Kemp Technologies exit ($10M to $70M revenue, $258M sale), Product expansion via Signority (e-signature) acquisition in May 2024, Geographic expansion with Riyadh regional HQ (Feb 2025) and multi-region cloud footprint

Risk factors: Zero public financial disclosure prevents external verification of profitability or cash position, Highly competitive EFSS market with hyperscaler competitors (Microsoft, Google) and bundling pressure, Small scale relative to hyperscalers limits pricing power, Concentration in regulated/on-prem workloads dependent on continued self-hosted content demand, Multi-entity structure across US, Ireland, Saudi Arabia, Canada creates FX and integration complexity, Undisclosed size of 2025 funding round and Signority acquisition price

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report