Front Desk ApS
Denmark · owned by FRONT DESK HOLDING ApS (Denmark) · frontdesksuite.com · 15 vendors
Resilience scores
- Digital Sovereignty: 27
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- CMIT Solutions — United States
- Google LLC — Technology — United States
- Twilio — Telecommunications — United States
- and 12 more
Services catalogue
3 services in catalogue across 1 category; runs on 15 sub-vendors.
- Online Bookings
- Queue Management Systems
- Smart Kiosk
Insights
Last updated 2026-09-13 · revision 1
15 direct vendors, 137 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- Netherlands: 1
- United States: 9
Subvendors by controlling owner country (sample)
- United States: 93
- Bulgaria: 1
- Canada: 2
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Front Desk ApS shows a medium level of migration readiness, primarily driven by its existing reliance on Microsoft Azure, which provides a strong cloud-native foundation for future migrations. The use of modern identity and access management solutions like SAML, Azure AD, and ADFS is a significant advantage for secure and efficient transitions. The availability of 'API Integrations' suggests a modular architecture that can facilitate integration with new systems or microservices during a migration effort. Enterprise-grade security features and GDPR compliance are also positive for meeting regulatory requirements. However, several critical unknowns and potential challenges exist. The application architecture is not explicitly described as containerized or microservices-based; WordPress, a key component, is typically monolithic, which could complicate modernization efforts. 'Data Residency Requirements' are not specified, which is a crucial factor that can heavily influence migration strategy and complexity. Financial stability (ability to fund migration) is also unknown. While 'Total Vendors: 0' is confusing, the reliance on specific platforms like Azure and WordPress implies a degree of vendor lock-in. The 'Vendor Geographic Diversity: 5 unique countries' for vendor HQ/owner countries is positive for reducing geographic concentration risk, but does not negate platform-specific lock-in.
Compliance
9 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
Risk level is MEDIUM because: (1) Front Desk ApS provides digital infrastructure services exclusively to public administration entities (municipalities, job centres, health centres) across Denmark and Germany — public administration is an Essential Entity sector under NIS2 Annex I. As an ICT service provider to public administration, the company may fall under NIS2 as a 'managed service provider' or 'digital provider' category. (2) The NIS2 size threshold (50+ employees OR €10M+ turnover) is uncertain — the company serves 70+ Danish municipalities and 80%+ of the Danish population, suggesting significant scale, but exact employee count and revenue are not publicly disclosed. (3) Denmark transposed NIS2 into national law via the 'Lov om net- og informationssikkerhed' (NIS2-loven), effective October 2024. (4) If the company meets the size threshold, it would likely qualify as an Important Entity (digital provider/ICT service management) or potentially Essential Entity given its critical role in public administration digital infrastructure. (5) Non-compliance risk is moderate as enforcement is still maturing in Denmark, but the company's role in critical public services elevates the risk.
Evidence: https://frontdesksuite.com/produkt/sikkerhed-og-single-sign-on/, https://frontdesksuite.com/, https://www.cfcs.dk/en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.retsinformation.dk/eli/lta/2024/639
GDPR (source) — Partially Compliant
Risk level is HIGH for several compounding reasons: (1) Front Desk ApS is headquartered in Denmark (EU), making GDPR universally applicable with no exceptions. (2) The company processes exceptionally sensitive personal data on behalf of public sector clients — including Danish CPR numbers (national identity numbers), health card data, phone numbers, and birthdates of citizens visiting government offices. CPR numbers are classified as sensitive identifiers under Danish law and GDPR. (3) The company serves 80%+ of the Danish population through municipal Borgerservice offices, meaning a data breach or non-compliance event would have massive societal impact. (4) The company also operates in Norway, Germany, Canada, USA, and Japan, creating cross-border data transfer obligations. (5) The Danish Data Protection Authority (Datatilsynet) is an active enforcement body with a track record of fining public sector data processors. (6) While a GDPR email contact (gdpr@frontdesksuite.com) exists and a privacy policy is published, no formal DPO appointment is publicly disclosed, no GDPR audit reports are available, and the privacy policy references a development server URL (front-desk-dev.de.dedi1336.your-server.de) suggesting it may be outdated. (7) The company acts as a data processor for municipalities (who are data controllers), creating dual obligations under GDPR Articles 28-29 that must be contractually documented.
Evidence: https://frontdesksuite.com/privatlivspolitik/, https://frontdesksuite.com/produkt/sikkerhed-og-single-sign-on/, https://frontdesksuite.com/, https://www.datatilsynet.dk/english, https://gdpr-info.eu/art-28-gdpr/
ISAE 3000 (source) — Assessment Required
Risk level is LOW because: (1) ISAE 3000 is primarily relevant for companies providing assurance services or subject to third-party assurance reporting requirements. Front Desk ApS is a SaaS provider, not an assurance services firm. (2) However, ISAE 3000 (or its related standard ISAE 3402 for service organisations) could be relevant if the company's municipal clients require independent assurance reports on the company's internal controls over data processing. (3) The company mentions biennial external audits, which could potentially be ISAE 3000/3402 engagements. (4) In the Danish public sector context, ISAE 3402 (assurance reports on controls at service organisations) is sometimes required by government clients. (5) The risk is low because ISAE 3000 is not a mandatory regulatory requirement for this type of company.
Evidence: https://frontdesksuite.com/produkt/sikkerhed-og-single-sign-on/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or
Financials
Three-year financials
- 2025: gross profit DKK 15.5M, EBIT DKK 2.72M, equity DKK 8.62M
- 2024: gross profit DKK 13.1M, EBIT DKK 2.68M, equity DKK 6.73M
- 2023: gross profit DKK 9.52M, EBIT DKK 502K, equity DKK 5.03M
Financial Resilience Score: 6/10
Front Desk ApS demonstrates strong qualitative financial resilience despite the absence of publicly retrievable financial statements in this research session. The company holds a dominant position in the Danish municipal queue management software market, serving over 70 of Denmark's 98 municipalities and interacting with approximately 80.6% of Danes visiting Borgerservice. This translates to roughly 70% market share of the municipal customer base, providing a sticky, recurring SaaS revenue stream with high renewal rates typical of public-sector contracts. The pure SaaS/web-based model eliminates hardware dependencies, supporting healthy gross margins, and the company's reference customers include Denmark's largest cities (Copenhagen, Aarhus, Aalborg, Odense). International diversification began in 2019 with expansion into Norway, Germany, Canada, USA, and Japan, reducing long-term dependence on the Danish market. However, risks include heavy customer concentration in the Danish public sector, limited pricing power due to public procurement constraints, small absolute company scale (ApS with likely abbreviated accounts under Regnskabsklasse B), capital-intensive internationalisation relative to a small revenue base, and competition from established global QMS vendors like Qmatic, Wavetec, JRNI, and Qnomy in export markets. FX exposure is growing as international revenue expands across CAD, USD, EUR, JPY, and NOK.
Key strengths: Dominant Danish market share: 70+ of 98 municipalities as customers, 80.6% of Danes interact with FrontDesk at Borgerservice, Sticky public-sector SaaS revenue with long contract durations, Pure SaaS/web-based model with no hardware dependency, Blue-chip Danish municipal references (Copenhagen, Aarhus, Aalborg, Odense), International expansion underway since 2019 across 5+ countries
Risk factors: Heavy customer concentration in Danish public sector, Limited pricing power due to public procurement constraints, Small company scale (ApS, likely Regnskabsklasse B), Capital-intensive internationalisation relative to revenue base, Competition from global QMS vendors (Qmatic, Wavetec, JRNI, Qnomy), FX exposure across CAD, USD, EUR, JPY, NOK, Dependence on Danish municipal IT budgets and fiscal policy
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.