Gloat

United States · www.gloat.com · 39 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 39 sub-vendors.

Insights

Last updated 2026-08-16 · revision 1

39 direct vendors, 350 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Gloat exhibits medium to high migration readiness, primarily driven by its existing adoption of Amazon Web Services (AWS) for its internal tech stack. This indicates a foundational cloud-aware posture and familiarity with cloud operations, which significantly reduces the barrier to further cloud migration or optimization. The company's core technologies, such as Agentic AI, Large Language Models (LLMs), Knowledge Graph, and Graph Databases, are inherently modern and typically deployed in cloud-native architectures, suggesting a compatible environment for migration. A significant advantage is that 'Data Residency Requirements: Not specified,' which provides considerable flexibility in choosing migration targets and strategies without strict geographical constraints. The geographic diversity of implied vendor HQ countries (6 unique countries) also suggests less reliance on a single regional vendor ecosystem, potentially simplifying international migration considerations. However, several factors introduce challenges and unknowns. The reliance on 'Total Services: 26' implies a potentially complex ecosystem with numerous integrations and dependencies, which could complicate migration efforts. 'Vendor Lock-in Risk: Unknown' is a critical missing piece of information; high lock-in could significantly impede migration due to contractual obligations or proprietary technologies. There is no data on financial stability (revenue concentration, growth history) to assess the capacity to fund a large-scale migration. The regulatory environment is also unspecified, meaning potential compliance hurdles during migration are unknown. Lastly, the use of 'WordPress (CMS / website)' might represent a legacy component that would require specific migration strategies if a fully cloud-native or serverless website architecture is desired.

Compliance

6 in-scope frameworks identified; showing 3.

CCPA — Assessment Required

Gloat is headquartered in the United States and serves large US enterprise clients. The CCPA (as amended by CPRA) applies to for-profit businesses that collect personal information of California residents and meet one of the thresholds: (1) annual gross revenues exceeding $25M; (2) annually buy, sell, or share personal information of 100,000+ consumers/households; or (3) derive 50%+ of annual revenues from selling/sharing personal information. Given Gloat's enterprise client base (Fidelity, Mastercard, MetLife, Estée Lauder, etc.) and its processing of employee personal data at scale, it is highly likely Gloat meets at least one threshold. The risk level is Medium because CCPA/CPRA applies to employee data (B2B exemptions were removed in 2023), and non-compliance can result in civil penalties of up to $7,500 per intentional violation.

Evidence: https://gloat.com/security-and-compliance/, https://gloat.com/privacy-policy/

Israeli Privacy Protection Law — Assessment Required

Gloat was founded in Israel and its co-founders (Ben Reuveni, Danny Shteinberg, Amichai Schreiber) have Israeli backgrounds, strongly suggesting R&D and engineering operations in Israel. Israel's Privacy Protection Law (PPL) 5741-1981 and its updated Privacy Protection Regulations apply to companies processing personal data in Israel. Israel's new Privacy Protection Law (PDPL) amendments, which significantly strengthen data protection requirements (closer to GDPR standards), were approved by the Knesset in 2023 and are being phased in. If Gloat maintains R&D or engineering offices in Israel (which is highly likely given founder backgrounds and Israeli tech ecosystem), it must comply with Israeli privacy law for employee data and any data processed in Israel. The risk level is Medium because Israeli privacy law is increasingly stringent, and non-compliance could affect Gloat's ability to transfer data between Israel and the EU (Israel has EU adequacy status under GDPR).

Evidence: https://gloat.com/about-us/, https://gloat.com/security-and-compliance/

SOC 2 (source) — Compliant

Gloat has achieved SOC 2 Type II attestation, which is the most rigorous level of SOC 2 compliance, covering an extended period of operational effectiveness (not just point-in-time design). SOC 2 Type II is independently audited by a licensed CPA firm against AICPA Trust Service Criteria (Security, Availability, Confidentiality). This demonstrates that Gloat's internal controls related to data security, availability, and confidentiality have been independently verified over a sustained period. The risk level is Low because Gloat has achieved the highest standard of SOC 2 compliance, which is the primary framework expected of SaaS cloud service providers by enterprise customers.

Evidence: https://gloat.com/security-and-compliance/, https://compliance.gloat.com/login

Financials

Three-year financials

Financial Resilience Score: 7/10

Gloat is a well-funded, late-stage private enterprise SaaS company in HR-tech with approximately $190M+ in disclosed cumulative funding from top-tier investors including Accel, Generation Investment Management, Intel Capital, and Eight Roads. The company has demonstrated strong commercial traction with a marquee enterprise customer base including Unilever, Mastercard, MetLife, Novartis, Standard Chartered, Spotify, and Fidelity, suggesting substantial multi-year enterprise SaaS revenue contracts. Recognition on Deloitte Technology Fast 500 (2024) implies cumulative multi-year revenue growth exceeding 100%, and the company reported 4x YoY customer growth around its Series C in 2021. However, financial transparency is limited as Gloat is privately held with no SEC filings or published audited financials. This opacity makes precise credit assessment difficult, with no visibility into burn rate, gross margin, ARR, or runway. The company faces category repositioning risk having shifted from 'internal talent marketplace' to 'workforce agility platform' to 'Agentic HR,' and operates in a competitive space with well-resourced competitors including Eightfold AI, Workday Skills Cloud, and native HCM offerings from SAP and Oracle. Reports of layoffs/reorganizations during 2023-2024 add uncertainty, though deep integrations with Microsoft, Workday, SAP, and Oracle provide distribution moats.

Key strengths: Approximately $190M+ in cumulative disclosed funding across multiple rounds, Top-tier investor base (Accel, Generation IM, Intel Capital, Eight Roads), Marquee Fortune 500 enterprise customer base (Unilever, Mastercard, MetLife, Novartis, Spotify), Deloitte Technology Fast 500 recognition in 2024 implying >100% cumulative revenue growth, Deep platform integrations with Microsoft Teams/Copilot, Workday, SAP SuccessFactors, Oracle HCM, Proprietary Loomra Workforce Context Engine and nine years of enterprise AI research, 4x YoY customer growth reported around 2021 Series C

Risk factors: No public financial disclosure - opaque revenue, EBIT, equity and burn rate, Multiple category repositionings may indicate slowing legacy-product growth, Strong competition from Eightfold AI, Fuel50, 365Talents, and native HCM vendors, Likely customer concentration among limited Fortune 500 accounts (high-ACV enterprise model), Geopolitical risk from significant R&D presence in Israel, Variable COGS exposure to LLM/inference infrastructure costs, Reports of layoffs/reorganizations during 2023-2024, Structural risk of hyperscaler HCMs building native equivalents

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report