HappyCo
United States · www.happyco.com · 18 vendors
Resilience scores
- Digital Sovereignty: 89
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Interplay Learning — United States
- MRI Software — Technology — United States
- and 15 more
Services catalogue
1 service in catalogue across 1 category; runs on 18 sub-vendors.
- Happy Inspector
Insights
Last updated 2026-08-13 · revision 2
18 direct vendors, 231 subvendors
Direct vendors by controlling owner country (sample)
- United States: 16
- Denmark: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Canada: 6
- Belgium: 2
- Switzerland: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
HappyCo exhibits strong migration readiness due to its modern and cloud-centric tech stack, including "Cloud-based SaaS" and "Cloud SaaS" as key technologies. The use of "REST API" suggests good interoperability and ease of integration during migration. "SOC 2 Type II" compliance indicates established security and operational controls that can facilitate a smoother transition to new cloud environments. The primary challenge for migration readiness is the lack of financial data ("Revenue Concentration by Product", "Revenue Concentration by Geography", "Growth History"), which prevents an assessment of the company's ability to fund a significant migration effort. "Data Residency Requirements" are not specified, which could introduce complexities if strict requirements exist. The vendor relationship data is confusing; while "Total Services: 21" implies a potentially complex ecosystem, "Total Vendors: 0" is contradictory, and "Vendor Lock-in Risk: Unknown" means the impact of vendor relationships on migration flexibility cannot be fully assessed. The "Regulatory Environment" is also not specified, which could present unknown compliance hurdles during migration.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
HappyCo is a US-headquartered company but explicitly acknowledges EEA and UK individuals in its Privacy Policy (sections 9 and 10), providing legal bases for processing and enumerating data subject rights. This confirms they process personal data of EEA/UK residents (e.g., website visitors, potential EU-based customers, employees). As a SaaS platform that could be used by property managers in the EU, and given the company's international footprint (Australia, Canada, and 'elsewhere'), GDPR exposure is real. The risk is Medium rather than High because: (1) HappyCo's primary market is North America (US multifamily), limiting the volume of EU data subjects; (2) they have demonstrated GDPR awareness in their privacy policy; (3) no evidence of EU regulatory enforcement action. However, the risk is not Low because: the privacy policy does not mention a Data Protection Officer (DPO), no EU Standard Contractual Clauses (SCCs) or adequacy decisions are explicitly referenced for international transfers, and the policy states data 'may be accessed, shared or processed by our offices, located in the United States' without specifying the transfer mechanism used.
Evidence: https://happy.co/privacy-policy, https://www.happyco.com
SOC 2 (source) — Compliant
HappyCo has publicly disclosed and prominently displays its SOC 2 Type II certification on its website footer and company timeline. SOC 2 Type II is the most rigorous level of SOC 2 certification, requiring an independent auditor to assess the design and operating effectiveness of security controls over a defined period (typically 6–12 months). This certification was first obtained in December 2022 and is referenced as current on the website (as of 2026). Risk is Low because: (1) the certification is publicly confirmed; (2) SOC 2 Type II demonstrates sustained operational security controls, not just point-in-time design; (3) as a cloud SaaS provider handling sensitive tenant and property data, this certification is directly relevant and appropriate. The main residual risk is that the current audit period and scope are not publicly disclosed, so it is unknown whether the certification remains current or has lapsed.
Evidence: https://www.happyco.com, https://happy.co/company, https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services
Australian Privacy Act 1988 — Assessment Required
HappyCo was founded in Adelaide, Australia and maintains an active engineering and design office there (expanded in December 2022). The company explicitly lists Australia as a location where team members work. The Australian Privacy Act 1988 applies to organizations with annual turnover exceeding AUD $3 million (a threshold HappyCo almost certainly exceeds given its Series B funding, 200+ employees, and profitable status). The Privacy Act is currently undergoing significant reform (Privacy and Other Legislation Amendment Act 2024, with further reforms pending), introducing a statutory tort for serious invasions of privacy and enhanced enforcement powers. Risk is Medium because: (1) Australian operations are confirmed and substantial (engineering/design hub); (2) HappyCo processes personal data of Australian employees; (3) the original platform was built in Australia and may still process Australian property/tenant data; (4) however, the primary customer base is North American, limiting the volume of Australian consumer data.
Evidence: https://happy.co/company, https://happy.co/privacy-policy
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
HappyCo is a mature, venture-backed private SaaS company operating in the multifamily PropTech space with a recurring subscription revenue model that provides sticky, predictable cash flows. The company self-reports being profitable, has raised through Series B (Camber Creek, 2022) plus strategic real-estate LP capital totaling an estimated US$70-80M cumulative, and has scaled its platform from ~10K units in 2013 to reportedly 6M+ units by 2026. Its blue-chip customer base including Cushman & Wakefield, CBRE, JLL, Berkadia, Greystone, Walker & Dunlop, and Freddie Mac Multifamily reduces customer concentration risk and provides institutional embeddedness. However, resilience assessment is significantly constrained by disclosure opacity — no audited financials, no SEC filings, and no verified revenue, EBIT, or equity figures are publicly available. The company faces sector cyclicality tied to multifamily real estate transaction volumes and interest-rate cycles (due-diligence revenue was pressured during 2022-2024 rate hikes), intense competition from larger PropTech incumbents (AppFolio, RealPage, Yardi, Entrata, MRI), and heavy R&D investment in unproven AI products (JoyAI, Voice-Assist). Geographic concentration in North American multifamily and a tightened late-stage SaaS funding environment add further risk. The score reflects strong qualitative business fundamentals offset by verification limitations and market cyclicality.
Key strengths: Recurring B2B SaaS subscription revenue model, Blue-chip diversified customer base (Cushman & Wakefield, CBRE, JLL, Berkadia, Freddie Mac), Strategic Freddie Mac partnership (Optigo Happy℠ platform), Platform scale of 5.5-6M+ multifamily units under management, Diversified product suite across Maintenance, Asset Management, Due Diligence, and AI, Company self-reports profitability, Series B funded (Camber Creek lead, Jan 2022), SOC 2 Type II certified since Dec 2022, Successful M&A track record (Call Complete 2021, Yuhu 2022)
Risk factors: No audited public financials — full disclosure opacity, Multifamily real estate sector cyclicality and interest-rate sensitivity, Intense competition from larger incumbents (AppFolio, RealPage, Yardi, Entrata, MRI), Geographic concentration in North American multifamily, Heavy R&D burden on unproven AI products (JoyAI, Voice-Assist), Tightened late-stage SaaS private funding environment since 2022, Transaction-linked due-diligence revenue exposed to M&A slowdowns, Limited vertical diversification outside multifamily
Revenue by geography
- Australia / New Zealand: 0%
- North America (US + Canada): 0%
Revenue by product/service
- JoyAI: 0%
- Asset Management: 0%
- Maintenance Operations: 0%
- Asset Evaluation / Due Diligence: 0%
- Maintenance Services (Call Complete): 0%
Workforce by country
- Canada: 0
- Australia: 0
- New Zealand: 0
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.