Hostpoint AG

Switzerland · www.hostpoint.ch · 12 vendors

Resilience scores

Technology vendors

Services catalogue

6 services in catalogue across 4 categories; runs on 12 sub-vendors.

Insights

Last updated 2026-08-06 · revision 2

12 direct vendors, 179 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Hostpoint AG demonstrates a medium-to-high level of migration readiness (Score: 65). The company's technology stack is a strong enabler for future migrations. The extensive adoption of open-source technologies (Linux, FreeBSD, OpenStack, Docker, GitLab, PostgreSQL, MariaDB, Nginx, Apache, PHP, Valkey, Memcached) significantly reduces proprietary vendor lock-in and enhances portability. The use of Docker for containerization and OpenStack for private cloud infrastructure indicates a modern architectural approach that aligns well with cloud-native principles, making it easier to transition workloads to public cloud environments or other private cloud platforms. GitLab for CI/CD also suggests mature development and deployment practices that facilitate agile migration efforts. However, several factors present potential challenges to migration. The explicit commitment to storing "All data stored in Swiss data centers" implies a strong adherence to Swiss data residency, which could become a significant constraint if migrating to global cloud providers that do not have a strong presence or specific offerings within Switzerland, or if strict data sovereignty requirements are in place. While the software stack is largely open-source, the reliance on specific hardware vendors (NetApp for storage, Dell for servers) and a particular data center provider (Digital Realty / Interxion) introduces some infrastructure-level lock-in that could complicate a full-stack migration. The lack of information regarding financial stability (revenue concentration, growth history) also means the company's capacity to fund a potentially large-scale migration project cannot be assessed. Furthermore, the "Vendor Lock-in Risk: Unknown" prevents a definitive evaluation of contractual complexities with existing vendors.

Compliance

8 in-scope frameworks identified; showing 3.

Swiss Telecommunications Act — Assessment Required

The Swiss Telecommunications Act (Fernmeldegesetz, FMG) and regulations from OFCOM (Federal Office of Communications / BAKOM) may apply to Hostpoint AG as a provider of telecommunications-adjacent services including email, cloud office, and internet infrastructure. The revised FMG (in force since 2021) expanded obligations for providers of 'derived communication services' (abgeleitete Kommunikationsdienste). Risk is Medium because: (1) Hostpoint provides email services, cloud office, and file transfer services that may qualify as derived communication services; (2) Obligations may include lawful interception capabilities, data retention requirements, and registration with OFCOM; (3) As Switzerland's largest hosting provider, regulatory scrutiny is plausible; (4) Non-compliance with FMG could result in regulatory sanctions from OFCOM/BAKOM.

Evidence: https://www.hostpoint.ch/email/, https://www.hostpoint.ch/hostpoint/unternehmen.html

ISAE 3000 (source) — Assessment Required

ISAE 3000 is an international assurance standard used for non-financial assurance engagements, including data protection audits, sustainability reporting, and IT controls assessments. It is the international equivalent framework underlying SOC 2 and similar assurance reports. For a Swiss hosting provider like Hostpoint AG, ISAE 3000 could be relevant if customers or regulators require independent assurance over data processing controls, privacy compliance, or security measures. Risk is Low because: (1) ISAE 3000 is not a regulatory requirement for Swiss hosting providers; (2) it is primarily relevant when providing assurance reports to third parties; (3) Hostpoint's ADV already provides contractual assurance mechanisms; (4) the primary assurance demand in Hostpoint's market is more likely to be ISO 27001 or SOC 2 rather than ISAE 3000 specifically. However, as Hostpoint processes data under GDPR as a processor, an ISAE 3000-based assurance report (e.g., on data protection controls) could be valuable for enterprise customers.

Evidence: https://hostpoint-static.ch/legal/de_AGB-Webhosting_ADV+TOMS.pdf

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA for service organizations (particularly cloud and SaaS providers) that store, process, or transmit customer data. Hostpoint AG is clearly a cloud/hosting service provider managing data for over 1.3 million domain customers and providing web hosting, managed servers, email, and cloud office services. As such, SOC 2 is highly relevant to Hostpoint's business model. Risk is Medium because: (1) Hostpoint's enterprise and business customers increasingly require SOC 2 reports as part of vendor due diligence; (2) the absence of a publicly disclosed SOC 2 report may be a competitive disadvantage and a gap in third-party assurance; (3) Hostpoint does have documented TOM (Technical and Organisational Measures) and security controls, but these have not been independently audited under SOC 2 standards. The risk is not High because SOC 2 is voluntary and Hostpoint's primary market (Swiss SMEs) may not yet universally require it.

Evidence: https://hostpoint-static.ch/legal/de_AGB-Webhosting_ADV+TOMS.pdf, https://www.hostpoint.ch/hostpoint/unternehmen.html

Financials

Three-year financials

Financial Resilience Score: 8/10

Hostpoint AG demonstrates strong financial resilience despite being a private company with limited public financial disclosure. The company has achieved uninterrupted revenue growth every year since its founding in 2001, growing from CHF 1.5M in 2003 to CHF 32M in 2023 — a compound annual growth rate of approximately 16%. The subscription-based recurring revenue model from hosting and domain renewals provides high customer retention and low churn, proven resilient through COVID-19 (2020: +~10% growth) and macroeconomic slowdowns. The company is owner-operated, debt-light, and self-financed, with both founders owning 50/50 since 2017. Hostpoint reinvests profits into infrastructure and staff, as evidenced by workforce growth of ~70% between 2020 and 2025. Market leadership in Switzerland as the largest hosting provider and largest .ch registrar (>30% of DNSSEC-signed .ch domains) provides a defensible competitive position, further strengthened by its 'Swissness'/data-sovereignty positioning. Risks include concentration on a single small market (Switzerland), commoditisation pressures from global hyperscalers (Microsoft 365, Google Workspace, AWS), and key-person risk given the two-founder ownership structure. However, product diversification into E-Mail & Cloud Office, file transfer, and managed servers reduces dependency on commoditised shared hosting.

Key strengths: Uninterrupted revenue growth every year since 2001 (~16% CAGR over 20 years), Recurring subscription-based revenue model with high retention, Owner-operated, debt-light, self-financed growth model, Market leadership in Switzerland (largest hosting provider and .ch registrar), Strong 'Swissness'/data-sovereignty positioning, Product diversification across hosting, domains, cloud office, and managed services, Resilient performance through COVID-19 and macro slowdowns, Workforce growth of ~70% over 2020-2025 signals healthy cash generation

Risk factors: Concentration on single small market (Switzerland) with limited international diversification, Commoditisation and price pressure from global hyperscalers (Microsoft, Google, AWS), Consolidation of Swiss hosting market with foreign-acquired competitors, ICT talent scarcity explicitly cited by company, Key-person concentration risk with two founders owning 100%, Limited financial transparency as a private AG, Regulatory/technology risks around DNS/domain policy and cybersecurity, Reliance on single Swiss data centre (Digital Realty/Interxion, Glattbrugg)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report