Filecoin

United States · filecoin.io · 7 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 7 sub-vendors.

Insights

Last updated 2026-07-07 · revision 1

7 direct vendors, 136 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Filecoin exhibits high migration readiness, scoring 85. Its modern and diverse internal tech stack, including Go, Rust, TypeScript, Python, Solidity, and Docker, is highly conducive to cloud-native adoption and migration. The use of Docker strongly suggests containerization, which simplifies deployment and portability across different environments. The Filecoin Virtual Machine (FVM) with EVM compatibility (FEVM) allows for the migration or development of smart contracts using widely adopted Solidity, reducing friction for dApp migrations. Additionally, the "Fil One" product offers S3-compatible object storage, which is a significant advantage for enterprises looking to migrate large datasets, as S3 compatibility is a de facto standard for cloud storage. The availability of APIs like Filecoin Pin also indicates a modern, programmatic approach to infrastructure interaction, facilitating automated migration processes. The vendor data presents a contradiction: "Total Vendors: 0" is explicitly stated, which, if accurate, implies no vendor lock-in, a major enabler for migration readiness. However, other data points mention "Total Services: 8" and "Vendor HQ Countries: United States", suggesting the presence of unnamed vendors. If vendors do exist and are concentrated in the United States, it could introduce some geographic complexity, but without a clear vendor count, assessing lock-in risk from this perspective is challenging. We prioritize the explicit "Total Vendors: 0" in our assessment, indicating minimal vendor lock-in. Significant gaps in the provided data include the absence of information on the regulatory environment and data residency requirements. These factors are critical for planning and executing a migration, as compliance and data location constraints can introduce substantial complexity and cost. The lack of financial stability data also means we cannot assess the company's capacity to fund a large-scale migration effort. Despite these unknowns, the inherent technological flexibility and modern architecture position Filecoin very well for future migrations.

Compliance

8 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

Filecoin is a decentralized, global storage network that explicitly serves EU/EEA users and storage providers. As a protocol and marketplace for data storage, it processes data on behalf of clients worldwide, including EU/EEA residents. The decentralized nature of the network creates significant GDPR compliance challenges: (1) data stored on the network may include personal data of EU residents; (2) the 'right to erasure' (Article 17) is technically incompatible with immutable, content-addressed storage; (3) identifying a 'data controller' or 'data processor' in a decentralized network is legally ambiguous; (4) data may be replicated across storage providers in multiple jurisdictions without explicit consent mechanisms. Protocol Labs (the primary developer, US-based) and the Filecoin Foundation (US-based) likely process EU employee and partner data. Enforcement risk is elevated given the EU's active GDPR enforcement posture and the novel legal questions posed by decentralized storage. Fines can reach €20M or 4% of global annual turnover.

Evidence: https://filecoin.io/, https://filecoin.io/blog/posts/filecoin-in-2021-looking-back-at-a-year-of-exponential-growth/, https://gdpr-info.eu/art-17-gdpr/

NIS2 (source) — Assessment Required

NIS2 Directive (EU) 2022/2555 includes 'digital infrastructure' and 'digital providers' (including cloud computing services and online marketplaces) as covered entities. Filecoin operates as a decentralized cloud storage marketplace and protocol. If Filecoin Foundation or Protocol Labs entities operate in the EU and meet the size threshold (50+ employees or €10M+ turnover), NIS2 could apply as an 'Important Entity' under the digital providers category. However, the decentralized, open-source, and protocol-layer nature of Filecoin creates ambiguity about whether any single legal entity would be classified as a covered 'digital provider.' The risk is medium because: (1) NIS2 enforcement is still maturing across EU member states; (2) the applicability to decentralized protocols is legally untested; (3) Protocol Labs and Filecoin Foundation are US-headquartered, limiting direct EU NIS2 jurisdiction unless they have EU-established entities.

Evidence: https://filecoin.io/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

CCPA — Assessment Required

Protocol Labs is headquartered in San Francisco, California, making CCPA directly applicable to its operations. CCPA applies to for-profit businesses that: (1) have annual gross revenues over $25M; (2) buy, sell, or share personal information of 100,000+ consumers/households; or (3) derive 50%+ of annual revenues from selling personal information. Protocol Labs likely meets threshold (1) or (2) given the scale of its operations and the Filecoin network's user base. CCPA requires privacy notices, opt-out rights for data sales, and data subject rights. Risk is medium because: (1) Protocol Labs is California-based; (2) the network processes data from California residents; (3) CPRA (California Privacy Rights Act) has strengthened enforcement since 2023.

Evidence: https://filecoin.io/

Financials

Three-year financials

Financial Resilience Score: 5/10

Filecoin/Protocol Labs presents a mixed financial resilience profile that is difficult to assess conventionally due to its decentralized-protocol structure and Protocol Labs' status as a private company with no audited financial disclosures. On the strength side, Protocol Labs raised approximately US$257M in its 2017 ICO/SAFT sale (about $205M public + $52M pre-sale from top-tier investors including Sequoia, a16z, Union Square Ventures, Winklevoss Capital, and DCG), providing significant fiat runway. The combined Protocol Labs and Filecoin Foundation treasuries hold a large multi-year FIL token allocation (part of the ~300M FIL genesis allocation split among Protocol Labs, the Foundation, investors, and mining reserve), worth hundreds of millions of USD even at depressed prices. No debt has been disclosed. However, several factors weigh against resilience: extreme lack of financial transparency (no audited statements or SEC filings), heavy dependency on volatile FIL token prices (which fell ~80%+ from the April 2021 peak of ~US$237), challenging storage-provider unit economics with committed storage capacity falling from ~17 EiB in 2022 to ~4-7 EiB by 2024, and cost pressures evidenced by the February 2023 layoff of ~89 employees (~21% of staff). Regulatory risk is a significant overhang, with the SEC in 2022 indicating FIL may be a security in correspondence related to Grayscale's Filecoin Trust. Competition from Arweave, Storj, Sia, and centralized hyperscalers (AWS S3, Google Cloud) further pressures the business model.

Key strengths: ~US$257M raised in 2017 ICO/SAFT sale providing fiat runway, Large multi-year FIL treasury held by Protocol Labs and Filecoin Foundation, Strong VC backing (Sequoia, a16z, USV, Winklevoss Capital, DCG), No disclosed debt, Live functioning network with real customers (Internet Archive, UC Berkeley, Starling Lab), Ecosystem expansion via FVM launch in March 2023 enabling smart contracts and DeFi

Risk factors: No audited financial statements or public disclosures, Heavy dependency on volatile FIL token price, Storage capacity declined from ~17 EiB peak to ~4-7 EiB, February 2023 layoffs of ~89 employees (~21% of staff), SEC regulatory overhang - FIL may be classified as a security, Competition from Arweave, Storj, Sia, and centralized hyperscalers (AWS, Google Cloud), Challenging storage-provider unit economics

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report