GoPublic A/S
Denmark · owned by Independent (Denmark) · www.gopublic.dk · 28 vendors
GoPublic A/S provides a Content Management System (CMS) tailored for municipalities, state authorities, and member organizations. Their platform offers features such as web accessibility tools, AI-driven functionalities, custom module development, and robust IT security and GDPR compliance. The company aims to provide an all-in-one solution for digital presence and content management for public sector entities.
Resilience scores
- Digital Sovereignty: 21
- Digital Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Box, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 26 more
Services catalogue
4 services in catalogue across 1 category; runs on 28 sub-vendors.
- GoBasic
- GoPublic Platform
- Web Platform / CMS
Insights
Last updated 2026-09-13 · revision 9
28 direct vendors, 402 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 3
- Canada: 1
- Norway: 1
Subvendors by controlling owner country (sample)
- Luxembourg: 1
- Denmark: 20
- Latvia: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
GoPublic A/S exhibits high migration readiness, primarily driven by its modern and flexible architectural principles. The adoption of a Headless CMS, Composable Architecture, and RESTful APIs (GoPublic API) indicates a modular and API-driven system, which is highly conducive to migration to modern cloud-native environments. The company's strong GDPR compliance and explicit commitment to EU data residency requirements simplify the regulatory aspects of any migration within the EU/EEA. However, certain factors present challenges. The current reliance on dedicated physical server hosting (Hetzner, Germany) suggests a traditional infrastructure setup, which may necessitate significant re-platforming efforts if migrating to a fully cloud-native or serverless architecture. The 'Vendor Lock-in Risk: Unknown' is a significant data gap; while the identified number of core vendors (Hetzner, Akamai, Arbor, Juniper, Let's Encrypt, Zendesk, Vimeo) is not excessively high, the deep integration of infrastructure-level vendors could complicate a move. The absence of financial stability data prevents an assessment of the company's capacity to fund a major migration. Furthermore, pending regulatory assessments for NIS2, SOC2, and ISO 27001 could introduce additional compliance requirements or complexities that need to be addressed during a migration project. While 'Composable Architecture' implies modularity, explicit mention of containerization or microservices is not provided, which could impact the ease of refactoring for optimal cloud deployment.
Compliance
5 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
Company handles sensitive data for public sector clients and emphasizes security. While their hosting partner Hetzner has ISO 27001 certification, GoPublic itself shows no evidence of ISO 27001 certification. Given their client base and security focus, this represents a medium risk for competitive positioning and client requirements.
Evidence: https://www.gopublic.dk/platformen/it-sikkerhed-og-gdpr
GDPR (source) — Compliant
Company is headquartered in Denmark (EU) and processes personal data of customers, employees, and website visitors. They have implemented comprehensive GDPR compliance measures including data processing agreements based on Danish Data Protection Authority templates, privacy policy, and annual ISAE 3000 audits specifically for GDPR compliance. Risk is low due to proactive compliance approach and regular auditing.
Evidence: https://www.gopublic.dk/platformen/it-sikkerhed-og-gdpr, https://www.gopublic.dk/privatlivspolitik, https://www.gopublic.dk/isae-3000-erklaering
SOC 2 (source) — Assessment Required
As a cloud-based CMS provider serving public sector organizations with sensitive data, SOC2 compliance would be valuable for demonstrating security controls. While they have ISAE 3000 audits, SOC2 is increasingly expected by enterprise clients. Risk is medium as lack of SOC2 could impact competitive positioning and client trust.
Evidence: https://www.gopublic.dk/isae-3000-erklaering
Financials
Three-year financials
- 2025: revenue DKK 28.8M, EBIT DKK 5.98M, equity DKK 5.98M
- 2024: revenue DKK 25.2M, EBIT DKK 3.36M, equity DKK 3.92M
- 2023: revenue DKK 24.0M, EBIT DKK 8.84M, equity DKK 8.17M
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.