HeyGen (Surreal AI, Inc.)

United States · www.heygen.com · 27 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 27 sub-vendors.

Insights

Last updated 2026-08-03 · revision 2

27 direct vendors, 308 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

HeyGen exhibits a high degree of migration readiness, primarily driven by its modern, cloud-native technology stack. The company's foundational reliance on Amazon Web Services (AWS) indicates a cloud-first approach, which significantly reduces the complexity and effort associated with migrating infrastructure and applications. The use of modern frameworks like Next.js for the frontend, coupled with a robust REST API and webhook infrastructure, suggests a modular and potentially microservices-oriented architecture that is inherently more portable. The adoption of an open-source rendering framework like HyperFrames further enhances flexibility and reduces proprietary lock-in in specific areas. Additionally, the absence of specified data residency requirements provides considerable flexibility in choosing deployment regions during a migration. However, certain factors introduce uncertainty or potential challenges. There is no available data on HeyGen's financial stability (revenue, growth), which is crucial for assessing the capacity to fund a significant migration effort. The "Vendor Lock-in Risk" is unknown; while AWS provides a flexible platform, deep integration with specific AWS services for their advanced AI models (e.g., for "Deep Learning / Large AI Model Training" and "Model Orchestration") could still present re-platforming challenges if migrating to an entirely different cloud provider. The conflicting "Total Vendors: 0" data point makes it difficult to fully assess vendor concentration, though the "Total Services: 33" suggests a non-trivial number of external dependencies. The lack of information on the regulatory environment also means potential compliance hurdles during a migration cannot be fully evaluated.

Compliance

7 in-scope frameworks identified; showing 3.

EU-US Data Privacy Framework — Compliant

HeyGen explicitly states DPF certification across multiple official pages and displays the DPF badge on its homepage. The EU-US Data Privacy Framework (adopted July 2023) provides a legal mechanism for transferring personal data from the EU to certified US organizations. HeyGen's DPF certification, combined with SCCs as a backup mechanism, provides a robust legal basis for EU-US data transfers. Risk is Low given explicit certification claims and the use of SCCs as an additional safeguard. The main residual risk is the political/legal stability of the DPF framework itself (it has faced legal challenges historically), but this is a systemic risk, not specific to HeyGen.

Evidence: https://www.heygen.com/security, https://www.heygen.com/gdpr-compliant, https://www.heygen.com/trust-and-safety

EU AI Act (source) — Partially Compliant

HeyGen explicitly references EU AI Act compliance on its homepage and trust & safety page. However, the EU AI Act (Regulation 2024/1689) entered into force in August 2024 with phased implementation through 2026-2027, and full compliance assessment is complex. Risk is High because: (1) HeyGen's core products — AI-generated deepfake avatars, voice cloning, and synthetic media — are directly implicated by the EU AI Act's provisions on 'deep fakes' and synthetic content, which require mandatory disclosure/labeling (Article 50); (2) biometric categorization systems and emotion recognition systems face strict requirements or prohibitions; (3) HeyGen's avatar technology may qualify as a 'high-risk AI system' under Annex III depending on use cases (e.g., employment, education, law enforcement contexts); (4) the Act's transparency obligations for AI-generated content are directly applicable to HeyGen's output; (5) penalties for non-compliance can reach €35M or 7% of global annual turnover; (6) 'Partially Compliant' reflects that HeyGen acknowledges the Act and has trust/safety measures, but full technical compliance with all phased requirements (especially transparency labeling, conformity assessments) is still evolving.

Evidence: https://www.heygen.com/trust-and-safety, https://www.heygen.com/security, https://www.heygen.com

CCPA — Compliant

HeyGen explicitly lists CCPA compliance on its homepage, security page, and trust & safety page. As a US-based company (incorporated in the US, headquartered in the US) serving California residents at scale, CCPA compliance is mandatory. HeyGen's privacy policy and data rights processes address CCPA requirements. Risk is Low given explicit compliance claims, the company's US base, and the alignment of its existing GDPR compliance program (which is more stringent) with CCPA requirements.

Evidence: https://www.heygen.com/security, https://www.heygen.com/trust-and-safety, https://www.heygen.com/privacy

Financials

Three-year financials

Financial Resilience Score: 7/10

HeyGen demonstrates exceptional growth momentum with ARR doubling from ~$100M to $200M in just eight months (late 2025 to mid-2026), backed by top-tier venture capital investors including Benchmark, Thrive Capital, Conviction, and Bond. The company claims category-leading capital efficiency at approximately $2.70 ARR per $1 of equity raised, comparing favorably to Zoom and Datadog at IPO, suggesting a relatively lean burn profile. Enterprise adoption is strong with 85% of Fortune 100 as customers and blue-chip logos including J.P. Morgan, HP, Autodesk, Intel, and Workday. However, as a private company, HeyGen does not disclose audited financials, EBIT, or shareholders' equity, limiting transparency. The generative AI video space faces intense competition from Synthesia, Runway, Pika, and hyperscalers like Google (Veo), OpenAI (Sora), and Meta. Compute/inference costs pose gross-margin risks, and regulatory exposure around deepfakes and the EU AI Act adds compliance costs. Overall, the growth trajectory and investor quality support a solid resilience score, tempered by lack of profitability disclosure and competitive intensity.

Key strengths: ARR doubled to $200M in 8 months (June 2026), Top-tier VC backing: Benchmark, Thrive Capital, Conviction, Bond, 85% of Fortune 100 as customers, Capital efficiency of ~$2.70 ARR per $1 equity raised, 30M+ registered users across 196 countries, Product-led growth with strong word-of-mouth funnel, Diversified customer mix (solopreneurs to Fortune 100)

Risk factors: No audited financials or EBIT disclosure publicly available, Intense competition from Synthesia, Runway, Pika, and hyperscalers (Google Veo, OpenAI Sora), High compute/inference costs create gross margin pressure, Regulatory risk around deepfakes, likeness rights, and EU AI Act, Consumer/SMB churn risk on monthly subscription plans, Elevated private-market AI valuations create future dilution risk, Historical geopolitical/founder scrutiny around Chinese ties

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report