Fillout
United States · www.fillout.com · 7 vendors
Resilience scores
- Digital Sovereignty: 100
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Demandware — Technology — United States
- HubSpot, Inc. — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- and 4 more
Services catalogue
1 service in catalogue across 1 category; runs on 7 sub-vendors.
- Fillout
Insights
Last updated 2026-08-02 · revision 2
7 direct vendors, 161 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
Subvendors by controlling owner country (sample)
- France: 6
- Australia: 3
- Unknown: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Fillout exhibits good migration readiness due to its cloud-native internal tech stack, leveraging Amazon Web Services (AWS) and Render.com. The use of Next.js and the presence of Webhook / REST API, 50+ Native App Integrations, and Zapier & Make (Integromat) Compatibility suggest a modular and API-driven architecture, which simplifies the process of migrating components or integrating with new platforms. The existing Multi-Region Deployment (US and EU AWS regions) also indicates experience with distributed systems, which is beneficial for complex migrations. Key challenges for migration readiness include the potential for vendor lock-in. If AWS and Render.com are considered the primary infrastructure vendors, this represents a small number of vendors (2), both concentrated in the United States. This aligns with the guidance that 'Few vendors (1-3) indicates high lock-in risk,' which could make migrating away from these platforms complex and costly. Crucially, 'Data Residency Requirements' are 'Not specified,' and the 'Regulatory Environment' is also not detailed, which are vital considerations for any migration strategy. The lack of financial data (Revenue Concentration by Product, Revenue Concentration by Geography, Growth History) also makes it difficult to assess the company's capacity to fund a significant migration effort.
Compliance
6 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
No ISO 27001 certification was found or claimed on Fillout's public website, security page, or terms of service. ISO 27001 is an internationally recognized information security management system (ISMS) standard. While Fillout has achieved SOC 2 Type 2 (which has significant overlap with ISO 27001 controls), these are distinct certifications. The risk is Low because: (1) SOC 2 Type 2 already demonstrates a mature security posture; (2) ISO 27001 is not legally mandated for Fillout's industry or jurisdiction; (3) many US-based SaaS companies of similar size prioritize SOC 2 over ISO 27001. The absence of ISO 27001 is not a compliance gap per se, but may be relevant for enterprise customers in regulated industries or EU markets that prefer ISO 27001.
Evidence: https://www.fillout.com/help/security
GDPR (source) — Partially Compliant
Fillout (operated by Restly, Inc.) is a US-based SaaS form builder that explicitly offers EU server hosting on request, confirming it processes personal data of EU/EEA residents. As a data processor for its customers and a data controller for its own user accounts, GDPR applies. The security page confirms EU server availability via AWS/Render in the EU, and the privacy policy is referenced but not fully detailed publicly. The risk is Medium rather than High because Fillout has demonstrated awareness of data residency (EU servers available), uses encryption in transit and at rest, and is SOC 2 Type 2 certified — all of which are positive compliance signals. However, no explicit GDPR compliance statement, DPA (Data Processing Agreement) template, or DPO appointment was found publicly, which introduces residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://www.fillout.com/help/security, https://www.fillout.com/privacy, https://www.fillout.com/terms
HIPAA (source) — Assessment Required
Fillout is a general-purpose form builder used by 100,000+ organizations across diverse industries. Its integrations and use cases explicitly include healthcare-adjacent workflows (e.g., patient intake forms, medical surveys). If any of Fillout's customers use it to collect Protected Health Information (PHI) on behalf of covered entities, Fillout would qualify as a Business Associate under HIPAA and would need to execute Business Associate Agreements (BAAs). The risk is Medium because: (1) the platform is widely used and healthcare use cases are plausible and common for form builders; (2) no public BAA template or HIPAA compliance statement was found on the website; (3) failure to execute BAAs when required constitutes a HIPAA violation with penalties up to $1.9M per violation category per year. The absence of a publicly advertised HIPAA compliance program is a notable gap for a platform of this scale.
Evidence: https://www.fillout.com/help/security, https://www.fillout.com/enterprise
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 6/10
Fillout (Restly, Inc., rebranding parent to Zite in March 2026) is a private, venture/angel-backed US SaaS company with no public financial disclosures. Revenue, EBIT, equity, burn, and runway are all opaque, which prevents a definitive financial assessment. However, qualitative operational signals are strong: 100,000+ organizations use the platform, millions of forms are served monthly, thousands of paying customers span SMB to Fortune 500, and marquee references include Fairfax County, Domino's, and Bombas. The company markets itself as a lean team with SOC 2 Type 2 compliance and an expanding enterprise motion, indicating disciplined cost management and upmarket potential. The product-led growth model with a broad free/self-serve funnel, expanding product surface (forms, scheduling, PDFs, payments, e-signatures, workflows, AI agent), and 4,000+ integrations suggests durable customer acquisition economics and rising ACV potential. Founder pedigree (Microsoft, Retool, Jet.com) and 20+ angel investors provide credibility but not the growth capital of institutionally funded competitors like Typeform or Jotform. Competitive intensity is high, platform dependency on Airtable/Notion is meaningful, and the March 2026 rebrand to Zite introduces execution risk around SEO and brand equity migration. On balance, resilience appears moderate-to-good but unverifiable from primary sources.
Key strengths: 100,000+ organizations using the platform, Millions of forms served per month, Thousands of paying customers including Fortune 500 (Domino's, Bombas) and government (Fairfax County), SOC 2 Type 2 compliance and enterprise-grade posture, Broad product suite expanding ACV (forms, scheduling, PDFs, payments, e-signatures, workflows, AI), 4,000+ partner integrations, Lean team and remote-first cost structure, Strong customer satisfaction (G2 5/5, Product Hunt 4.7/5), Backed by 20+ top angel investors, Founder/team pedigree from Microsoft, Retool, Jet.com
Risk factors: No public financial disclosures (revenue, EBIT, equity, burn all unknown), Highly competitive market (Typeform, Jotform, Google Forms, SurveyMonkey, Tally, etc.), Platform dependency on Airtable and Notion APIs and ecosystems, AI form generation commoditizing rapidly, March 2026 rebrand to Zite creates SEO/brand transition risk, Concentration on angel funding vs. institutionally funded competitors, Profitability and runway not disclosed, Limited pricing power at SMB tier
Revenue by geography
- EMEA: 0%
- North America: 0%
- Rest of World: 0%
Revenue by product/service
- AI Agent: 0%
- Payments: 0%
- Workflows: 0%
- Scheduling: 0%
- E-Signatures: 0%
- Forms (core): 0%
- PDF Generation: 0%
Workforce by country
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.