Fullstory
United States · owned by Independent (United States) · www.fullstory.com · 29 vendors
Turn your data from a rear-view mirror into a forward-facing guidance system. Fullstory captures complete user behavioral context so your AI stack can see, act, and improve in near real time.
Resilience scores
- Digital Sovereignty: 90
- Digital Resilience: 9
- Financial Resilience: 7
Disruption prediction
Fullstory has a 44% probability of disruption in the next 6 months.
All systems operational (last checked 2026-09-18 15:25 UTC)
20 of Fullstory's 29 vendors monitored for disruptions.
Technology vendors
- Netlify, Inc. — Technology — United States
- Proton AG — Other — Switzerland
- Stripe, Inc. — Financial Services — United States
- and 28 more
Services catalogue
11 services in catalogue across 5 categories; runs on 29 sub-vendors.
- FullStory
- Application Monitoring
- Fullcapture
Insights
Last updated 2026-08-11 · revision 6
29 direct vendors, 328 subvendors
Direct vendors by controlling owner country (sample)
- United States: 26
- Switzerland: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- UK: 2
- Australia: 4
- Italy: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Fullstory exhibits very high migration readiness, largely due to its highly modern and cloud-native technology architecture and the complete absence of vendor lock-in. The internal tech stack, built on Google Cloud Platform (GCP) and Kubernetes, strongly suggests a containerized, microservices-oriented environment, which is inherently flexible and highly conducive to migrations. The use of modern development frameworks like Go, JavaScript, and React further enhances agility. Financially, Fullstory's robust growth and significant funding (Series D, $100M+ ARR) indicate strong capacity to fund any necessary migration initiatives. A key strength for migration readiness is the explicit statement "Total Vendors: 0," which implies no external vendor dependencies or associated lock-in risks, simplifying any potential migration efforts significantly. The primary limitations to a perfect score are the unknown details regarding their specific regulatory environment and data residency requirements. These factors, if complex or stringent, could introduce challenges during a migration, but based on the available data, Fullstory is exceptionally well-positioned for any future migration.
Compliance
12 in-scope frameworks identified; showing 3.
CPRA — Compliant
Fullstory explicitly references CCPA compliance on its privacy resources page. As a US-headquartered technology company with significant California operations and a large US customer base, CCPA/CPRA is directly applicable. The risk is 'Low' because: (1) CCPA compliance is publicly confirmed; (2) Fullstory provides a 'Do Not Sell or Share My Personal Information' link on its website (visible in the footer), demonstrating active CCPA compliance; (3) Fullstory's privacy tools support customer CCPA compliance obligations; (4) the company has invested in privacy infrastructure (ISO 27701, privacy masking tools) that supports CCPA requirements.
Evidence: https://www.fullstory.com/privacy-resources/, https://www.fullstory.com/legal/privacy-policy/, https://www.fullstory.com/, https://help.fullstory.com/hc/en-us/articles/4407610647191-Privacy-Resource-Hub
NIS2 (source) — Assessment Required
NIS2 Directive (EU 2022/2555) applies to Essential and Important Entities operating in the EU. Fullstory has a London office (UK, post-Brexit, so not directly subject to EU NIS2 but subject to UK equivalent) and serves EU customers. As a digital service provider (specifically a 'digital provider' under NIS2 Annex II — online marketplace, online search engine, or cloud computing service), Fullstory could potentially fall under NIS2 as an 'Important Entity' if it qualifies as a managed service provider or cloud computing service with EU operations. However, Fullstory's primary EU presence is through its London office (UK), and its EU operations are primarily commercial/sales rather than infrastructure. The risk is 'Low' because: (1) Fullstory is not in a clearly listed Essential Entity sector; (2) its classification as a 'digital provider' under NIS2 is uncertain without more detail on EU-based infrastructure; (3) NIS2 enforcement is still maturing across EU member states; (4) Fullstory's primary regulatory exposure is GDPR, not NIS2.
Evidence: https://www.fullstory.com/privacy-resources/, https://www.fullstory.com/about-us/, https://trust.fullstory.com/
GDPR (source) — Partially Compliant
Fullstory has a London office and explicitly serves EU/EEA customers, processing personal data of EU/EEA residents at scale through its session replay, behavioral analytics, and digital experience platform. GDPR is unambiguously applicable. Fullstory publicly references GDPR compliance, maintains a Data Processing Agreement (DPA), and has implemented privacy-by-design features (Private by Default). However, as a data processor for thousands of clients, the risk remains medium because: (1) Fullstory's customers (controllers) bear primary GDPR obligations, but Fullstory as processor must maintain its own compliance; (2) session replay and behavioral tracking tools have historically attracted regulatory scrutiny in the EU (e.g., CNIL guidance on analytics tools); (3) cross-border data transfers from EU to US require valid transfer mechanisms (SCCs/adequacy decisions); (4) full compliance status cannot be independently verified without access to internal audit reports. The risk is not 'High' because Fullstory has publicly demonstrated significant compliance investment (ISO 27701, DPA availability, privacy controls).
Evidence: https://www.fullstory.com/privacy-resources/, https://trust.fullstory.com/, https://www.fullstory.com/legal/privacy-policy/, https://help.fullstory.com/hc/en-us/articles/4407610647191-Privacy-Resource-Hub, https://www.fullstory.com/legal/
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 7/10
Fullstory demonstrates strong qualitative financial resilience despite the absence of publicly disclosed financial statements. The company is backed by a high-quality investor syndicate including Kleiner Perkins, GV, Stripes, Dell Technologies Capital, Salesforce Ventures, and Permira, providing access to follow-on capital. Its enterprise customer base features blue-chip logos across diversified verticals (Pizza Hut, Chipotle, JetBlue, Adobe, KeyBank, Mastercard, BNY, Shopify, PepsiCo), which typically supports higher net revenue retention and lower churn than SMB-focused SaaS. The company has been named to the Inc. 5000 for five consecutive years, implying sustained double-digit revenue growth. Fullstory reports 2H FY2025 as its fastest overall growth in three years, with StoryAI expanding ~8x over three quarters and adopted by over 50% of new Q4 accounts. The November 2025 Usetiful acquisition indicates balance-sheet capacity for inorganic growth. However, resilience is capped by zero public financial transparency, a 2021 peak-cycle ~$1.8B valuation that may face reset pressure, and intense competitive dynamics against well-funded peers including Amplitude, Contentsquare, Adobe, and free tools like Microsoft Clarity.
Key strengths: Strong investor backing from Kleiner Perkins, GV, Stripes, Dell Technologies Capital, Salesforce Ventures, and Permira, Enterprise segment with sustained double-digit growth for three consecutive years, Diversified enterprise customer base including Pizza Hut, Chipotle, JetBlue, Adobe, Mastercard, BNY, Shopify, PepsiCo, Named to Inc. 5000 for five consecutive years indicating continuous revenue growth, Multi-product expansion motion (Analytics, StoryAI, Anywhere, Workforce, Guides & Surveys), StoryAI grew ~8x over three quarters, adopted by >50% of new Q4 FY25 accounts, M&A capacity demonstrated via Usetiful acquisition (Nov 2025), New CFO Chad Gold appointed April 2025, signaling potential financing/IPO track, Recurring SaaS subscription revenue model
Risk factors: Zero public financial transparency (no revenue, EBIT, equity, or ARR disclosure), Intense competition from Amplitude, Mixpanel, Contentsquare, Adobe, Pendo, and free Microsoft Clarity, 2021 ~$1.8B valuation struck at peak SaaS cycle; potential down-round risk, Reliance on discretionary enterprise marketing/analytics budgets vulnerable to macro downturns, Privacy/regulatory exposure from session replay under GDPR, CPRA, and US wiretapping class actions, AI competitive risk from platform vendors (Adobe, Salesforce, Microsoft) bundling similar features, StoryAI growth narrative concentration risk
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.