Fortanix
United States · www.fortanix.com · 27 vendors
Resilience scores
- Digital Sovereignty: 81
- Digital Resilience: 9
- Financial Resilience: 7
Technology vendors
- HubSpot, Inc. — Technology — United States
- Looker — Technology — United States
- Prometheus — United States
- and 30 more
Services catalogue
1 service in catalogue across 1 category; runs on 27 sub-vendors.
- Data Security Manager
Insights
Last updated 2026-07-30 · revision 5
27 direct vendors, 331 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Germany: 2
- Canada: 1
Subvendors by controlling owner country (sample)
- United Arab Emirates: 1
- France: 14
- Belgium: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Fortanix exhibits high migration readiness, primarily driven by its advanced and flexible technology stack. The company's internal tech stack is highly modern, featuring cloud-native capabilities with adoption of AWS and Google Cloud Platform, extensive use of containerization (Docker), and modern programming languages (Rust, Python, Go, TypeScript). This architecture is well-suited for hybrid and multi-cloud deployments, minimizing technical barriers to migration. Fortanix's core product offerings, such as Data Security Manager™ (DSM) and Key Management Service (KMS), are designed for multicloud key management and integration with external key stores (AWS KMS XKS, Google EKM), demonstrating an inherent capability to operate and secure data across diverse environments. Financially, the company's strong funding and growth history suggest ample resources to invest in and execute complex migration initiatives. However, the regulatory environment presents significant challenges to migration. Regulations such as GDPR, HIPAA, NIS2, and ISAE 3000, which are listed as 'Assessment Required' or potentially applicable, impose stringent requirements on data processing, security controls, and geographic data residency. While Fortanix's multi-region data center architecture supports various data residency requirements, any migration would necessitate careful planning to ensure continuous compliance with these complex regulations, especially for EU and healthcare data. The vendor relationship data is contradictory, stating 'Total Vendors: 0' while also listing vendor HQ countries and geographic diversity. Assuming the geographic diversity across 5 countries is indicative, it suggests a moderate level of vendor diversification, which generally reduces vendor lock-in. However, the explicit 'Vendor Lock-in Risk: Unknown' means this remains an unquantified factor. Despite the regulatory and data residency complexities, Fortanix's modern, multi-cloud-centric technology and financial stability position it strongly for future migrations.
Compliance
6 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
SOC2 compliance is confirmed through visible certifications on the company website. As a cloud services provider handling sensitive data, SOC2 compliance is critical for customer trust and regulatory requirements. The company displays SOC2 certification badges, indicating active compliance.
Evidence: https://www.fortanix.com/trust-center
NIS2 (source) — Assessment Required
NIS2 applicability is uncertain. While Fortanix operates in the EU (Netherlands) and provides critical cybersecurity services that could qualify as 'digital providers' under NIS2, their exact classification as Essential or Important Entity requires further assessment. The company appears to meet size thresholds, but specific sector classification needs verification.
ISO 27001 (source) — Compliant
ISO 27001 compliance is confirmed through certification badges on the company website. This is appropriate for a data security company and demonstrates commitment to information security management. Compliance reduces operational and reputational risks.
Evidence: https://www.fortanix.com/trust-center
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Fortanix is a well-funded late-stage private cybersecurity company backed by tier-1 investors including Goldman Sachs, Intel Capital, In-Q-Tel, Foundation Capital, Neotribe Ventures, and Giant Leap Capital. Cumulative disclosed equity funding stands at approximately US$121M, anchored by a US$90M Series C round led by Goldman Sachs Asset Management in October 2022. The company benefits from a differentiated technology moat in Confidential Computing and Confidential AI, a marquee enterprise customer base (Goldman Sachs, GE Healthcare, NEC, Equinix, Adobe, ServiceNow), and strong regulatory tailwinds from PCI DSS, GDPR, DORA, HIPAA, and post-quantum cryptography mandates. However, the absence of any publicly disclosed audited financial statements (revenue, EBIT, equity) limits visibility into burn rate, runway, and profitability. The last priced funding round closed roughly three years ago, raising legitimate questions about runway in the current repriced cybersecurity funding climate, though no signs of distress have been reported. Competition from hyperscaler-native KMS/HSM offerings (AWS, Azure, GCP) and established players like Thales, Entrust, and Utimaco, along with historical dependence on Intel SGX, are additional structural risks. Overall the resilience profile is solid but not verifiable through primary financials.
Key strengths: Tier-1 investor base: Goldman Sachs, Intel Capital, In-Q-Tel, Foundation Capital, Neotribe Ventures, ~US$121M cumulative equity funding raised through 2022 Series C, US$90M Series C in October 2022 led by Goldman Sachs Asset Management, Differentiated technology moat in Confidential Computing and Confidential AI, Marquee Fortune 500 customer base (Goldman Sachs, GE Healthcare, NEC, Equinix, Adobe, ServiceNow), Regulatory tailwinds: PCI DSS, GDPR, DORA, HIPAA, post-quantum cryptography, Experienced CFO (ex-VeloCloud, Carlyle, Morgan Stanley), Reported >3x ARR growth in 2020 (per company press releases)
Risk factors: No public financials — burn rate, runway, and profitability not visible, Last priced funding round was ~3 years ago (Oct 2022); runway questions, Intense competition from hyperscaler KMS/HSM (AWS, Azure, Google Cloud), Competition from Thales/CipherTrust, Entrust nShield, Utimaco, Anjuna, Edgeless Systems, Historical concentration on Intel SGX hardware stack, Repriced late-stage cybersecurity valuations could lead to a down round, Armet AI / Confidential AI not yet material revenue contributors
Revenue by geography
- APAC: 0%
- EMEA: 0%
- North America: 0%
Revenue by product/service
- Key Insight: 0%
- Armet AI / Confidential AI: 0%
- Data Security Manager (DSM): 0%
- Confidential Computing Manager: 0%
Workforce by country
- India: 0
- Singapore: 0
- Netherlands: 0
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.