Gather

United States · www.gather.town · 35 vendors

Gather is a virtual collaboration platform that provides customizable 2D virtual spaces where users can interact through spatial video chat. It aims to bring the best aspects of in-person interaction to distributed teams, fostering spontaneous collaboration and communication. Users can move around, chat, and interact with objects in these virtual environments, mimicking a physical office or event space.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 35 sub-vendors.

Insights

Last updated 2026-03-12 · revision 3

35 direct vendors, 316 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Gather's migration readiness is assessed at 48, indicating medium readiness with notable challenges. The modern features of Gather 2.0, such as its use of WebRTC and integrations via APIs (Google Calendar, GitHub, Spotify), suggest a potentially flexible architecture. Furthermore, SOC 2 Type II compliance indicates a structured security and operational environment that can facilitate a controlled migration. However, significant weaknesses and unknowns hinder readiness. The continued existence of 'Gather Events (Gather 1.0 – Legacy)' suggests a mixed technology environment that could complicate a unified migration effort. Crucially, 'Data Residency Requirements' are 'Not specified', which is a major unknown that could introduce substantial complexity and cost if strict requirements exist. Financial stability data (revenue concentration, growth history) is also missing, making it impossible to assess the company's capacity to fund a significant migration. The 'Vendor Lock-in Risk' is explicitly 'Unknown', and while 'Vendor Geographic Diversity' is present across 6 countries, the contradictory 'Total Vendors: 0' data point makes it difficult to accurately assess vendor concentration and potential lock-in. These significant unknowns and the presence of a legacy platform reduce Gather's overall migration readiness.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Gather is a US company that processes personal data of EU/EEA residents through their virtual workspace platform. While they state most processing doesn't fall directly within GDPR territorial scope, they acknowledge GDPR applies when acting as data processor for EU customers and have implemented compliance measures including Data Processing Agreements and Standard Contractual Clauses. Medium risk due to cross-border data transfers and complexity of determining territorial scope.

Evidence: https://www.gather.town/security

ISO 27001 (source) — Assessment Required

ISO 27001 certification is important for information security management, especially for SaaS providers handling corporate data. While Gather has SOC 2 certification and implements security measures (encryption, access controls), no specific ISO 27001 certification was found. Medium risk as this is a common expectation for enterprise software providers, though SOC 2 provides similar assurance.

Evidence: https://www.gather.town/security

SOC 2 (source) — Compliant

Gather is SOC 2 Type II certified, which is appropriate for their SaaS business model. SOC 2 compliance is critical for cloud service providers and Gather has achieved this certification, indicating proper security controls are in place. Low risk due to active certification status.

Evidence: https://www.gather.town/security, https://trust.gather.town/

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report